Filip Nowak
Founder & CEO, GRC Advisory
15+ years in SAP Security, GRC Access Control, and S/4HANA authorization design. Led GRC Access Control deployments for 30+ enterprises across DACH, Nordics, and CEE. CISA, CISM, ISO 27001 Lead Auditor.
Built by GRC Advisory — SAP Security & GRC consultancy with 20+ years of authorization, audit, and license-optimization experience.
GRC Advisory has delivered SAP GRC, Access Control, and compliance projects to more than 100 organizations across Poland and Europe, including the largest SAP GRC Access Control deployment in Poland. We know where license math breaks down because we have been cleaning up after it for years.
Aura is what we wished we had on every one of those rollouts: not another Excel export, but a live view of which assigned access is actually used — and which PUPM license tiers that usage actually justifies.
In 2024, while running an SAP S/4HANA Cloud Public Edition migration for a 1,500-user manufacturer, we hit a recurring problem: their SAP licensing bill grew 40% post-migration, even though the actual user behavior had not changed. The reason: under PUPM, every user assigned to an Advanced Business Catalog gets billed at the highest tier — even if 90% of them only use Core-level functionality.
We tried to solve it with Excel, SAP STAR reports, and ABAP queries. None gave a clear, actionable picture. So we built one. GRC Aura is the tool we wished existed — connecting directly to SAP Cloud ERP and showing actual usage per user, per Business Catalog, per FUE persona — so every PUPM tier you pay for is backed by real activity.
In 12 weeks of pilot deployments, our customers identified 25–35% reduction potential in annual SAP licensing spend. That is GRC Aura's promise: not another dashboard, but the difference between paying for assigned access and paying for actual access.
Founder & CEO, GRC Advisory
15+ years in SAP Security, GRC Access Control, and S/4HANA authorization design. Led GRC Access Control deployments for 30+ enterprises across DACH, Nordics, and CEE. CISA, CISM, ISO 27001 Lead Auditor.
SAP Security & License Engineers
Senior SAP consultants with combined 80+ years of experience in authorization design, role refactoring, segregation of duties, and FUE/PUPM analysis. Active in SAP Community and SAP Partner Network.
Product Development
Engineers and SAP architects building GRC Aura on SAP BTP. Continuous research into SAP Cloud ERP licensing rules, Business Catalog evolution, and authorization analytics — feeding the rule engine that powers Aura.
Information Security Management certified
Listed in SAP Partner Finder
EU-based data processing & storage
Built natively on SAP Business Technology Platform
Whether you need GRC Aura for your own SAP tenant or want to explore a partnership, we're happy to talk.