Users with unused roles
Exactly who carries role assignments that never appear in the Security Audit Log. Revoke with evidence, not guesswork.
SAP Cloud ERP (formerly SAP S/4HANA Cloud Public Edition) licenses are billed by PUPM – per user, per month, based on assigned Business Catalogs. GRC Aura shows what is actually used so every license tier you pay for is backed by real activity.
SAP Cloud ERP tells you what you assigned. GRC Aura tells you what is actually used: per user, per role, per Business Catalog.
Exactly who carries role assignments that never appear in the Security Audit Log. Revoke with evidence, not guesswork.
Advanced-licensed users whose real activity fits Core or Self-Service. Every downgrade is a recoverable FUE.
Quantified recoverable FUE per user and per role, refreshed for the period you care about: 1 month to 2 years.
Catalog-level usage: which Business Catalogs are actually opened, which push users into higher tiers, and which are assigned but never touched.
GRC Aura correlates three standard SAP Cloud ERP data sources into a single, clear picture of real license usage.
Captures real user actions: which Fiori apps are actually opened.
User → Role → Catalog → App mapping.
App metadata and pricing categories per release.
Users · Roles · Applications · Actionable insights.
Typically 3 to 4 days to configure in SAP Cloud ERP.
OAuth 2.0 (preferred) or Basic Auth depending on the API endpoint.
Aura tracks Fiori app versions for your SAP release automatically.
Analyze 1 month, 6 months, 1 year, or selected calendar years.
SAP's official tool for determining user license types in SAP Cloud ERP is a manual Excel worksheet - roles, task mappings, workshops, and guesswork. GRC Aura replaces the guesswork with actual usage data.
SAP's official approach: a multi-tab Excel file with 29+ predefined roles, hundreds of task-to-license mappings, and a summary tab that estimates user counts by type. You fill it in manually - role by role, person by person.
GRC Aura reads your SAP Cloud ERP Security Audit Log and Business Roles API. Instead of estimating what each person might need, it shows what they actually used - in the last 30 days, 6 months, or 2 years.
GRC Aura connects via standard SAP Cloud ERP APIs. No agents. No middleware. Nothing to install on your system.
Open Maintain Communication User in SAP Cloud ERP. Create a dedicated communication user for Aura API access and record the credentials securely.
Create a Communication System (inbound, no host required). Configure Communication Arrangements: OAuth 2.0 for most APIs, Basic Auth for others.
Test each endpoint using the Service URL from Communication Arrangements. Once validated, Aura begins pulling data immediately.
In-depth articles from the GRC Advisory team - the mechanics of FUE and PUPM, real project cases, and how to embed license intelligence into your access process.
Every engagement starts with a structured 30-day pilot. We connect to your SAP Cloud ERP tenant, you validate the results. Subscription starts only after you've seen the data.
We start with a short call to confirm your environment and scope. Before any data is shared, we sign a mutual NDA - standard practice when working with SAP Security Audit Log data. This typically takes 2–3 business days to complete.
Your SAP admin creates a dedicated read-only Communication User. We configure GRC Aura against your tenant - no changes to your SAP Cloud ERP system, no agents installed, no write access. Typically completed within 3–4 business days of credentials being provided.
GRC Aura begins processing your Security Audit Log and role assignments. A first dashboard with license usage per user and role becomes available - on your actual data. We walk you through the findings in a short call.
You have 30 days to review the data, discuss findings with your license manager or SAP team, and assess the savings potential against your specific contract situation. At the end of the pilot, you decide whether to subscribe. If not - we disconnect, no invoice.
Enter your total SAP user count, the share of Advanced licenses, and your average FUE cost. The calculator runs locally. Aggregated inputs are sent anonymously to Google Analytics. No personal data collected.
One price per SAP Cloud ERP tenant, scaled by user count. No per-seat fees, no setup costs. Billed annually. Every engagement starts with a 30-day pilot - subscription begins only after you've validated the results.
All plans include read-only API access, zero changes to your SAP Cloud ERP system, and setup support.
Need a quote for a specific user count? Write to us →
Tell us about your tenant and we will send a sample analysis showing where your FUE budget is stuck. No obligation, no sales call unless you want one.
Standard SAP APIs only.
Savings visible on first login.
Read-only. No changes to SAP.
Prefer a live walkthrough? Book a call →
Advisory firms and system integrators can extend their offering with GRC Aura - Reseller and VAR models, transparent margins, 24-month pipeline protection.