Method
Rules first, AI second.
The engine calculates effective permissions, tests documented conflict pairs, evaluates privileged and stale access, and scores each result. The AI layer receives only the selected finding and its evidence.
AccessGraph AI
An explainable IAM and segregation-of-duties lab that maps identities to roles and systems, detects risky access combinations, and lets reviewers test remediation safely.
Findings come from testable permission and account-lifecycle checks.
The lab contains no customer, employee, or production information.
AI translates evidence into plain language but cannot create findings.
Identities
7
Role catalog
12
Privileged users
4
Critical risks
4
High risks
4
Import up to 100 identities using the documented role IDs. Validation and analysis run locally in your browser; the CSV is not uploaded.
Enterprise access map
Select a cyan identity node to inspect its effective access.
Rules produce the findings; AI only explains the selected evidence.
Session audit trail
Baseline scenario loaded. Findings recalculate automatically.
Method
The engine calculates effective permissions, tests documented conflict pairs, evaluates privileged and stale access, and scores each result. The AI layer receives only the selected finding and its evidence.
About this lab
This lab uses fictional names and simplified checks based on IAM, least-privilege, and SAP Access Control concepts. It is not an SAP-certified product or a substitute for a formal access review.