|GUMAHUB PRODUCT
GumaHub Govern — Access & Governance for Modern ERPs
See exactly who has access to what — across roles, permission sets, and effective grants. Detect Segregation of Duties violations before auditors do. Read-only by design, deployable in days.
ERP access is complex. Governance shouldn't be.
Large ERPs ship with hundreds of permission sets and thousands of role-projection combinations. Nobody can answer 'who can post a journal entry?' from the standard UI — and yet auditors will ask. GumaHub Govern turns the access model of your ERP into a clear, navigable graph, with continuous SoD analysis layered on top.
FEATURES
Everything you need to govern ERP access
All standard authentication, authorization, and governance capabilities — in one product.
Permission Set Browser
Search, filter and inspect every permission set in your ERP — functional roles, end-user roles, projection grants, child roles, and assigned users.
User & Access Lifecycle
View every user, their directly granted roles, and their resolved effective grants across the full role hierarchy. Joiner-mover-leaver visibility at a glance.
Role Comparison
Side-by-side diff between any two roles: projections only in A, only in B, common, and access level differences. Refactor roles with confidence.
User Comparison
Compare effective permissions between any two users across all their granted roles — perfect for 'use my colleague as a template' onboarding.
Role Hierarchy Graph
Interactive visual graph of role trees with auto-layout. Click any node to drill into projections, child roles, or assigned users.
Segregation of Duties
Built-in SoD rule library plus your own custom rules. Continuous scanning flags violations and shows the exact role combinations that cause them.
Role Template Library
200+ pre-built department role templates (Finance, Procurement, HR, Manufacturing, Sales, IT…) — SoD-aware compositions ready to deploy.
Audit & Compliance Reports
One-click reports for SOX, GDPR, ISO 27001 and internal audit reviews. Export to Excel, PDF, or push to your GRC platform.
Access Certifications
Periodic manager attestation campaigns — reviewers confirm or revoke access in-app, with full audit trail of every decision.
Read-only, Zero Impact
Connects via standard REST / OData APIs — never writes to your ERP. Safe to run in production from day one.
Modern Authentication
OAuth 2.0 / OIDC single sign-on, MFA-friendly, and respects your existing identity provider. No new password store.
Caching & Performance
Smart caching layer means even large tenants load in seconds, with configurable TTLs per data type.
How it works
Connect
Point the product at your ERP's API endpoint with a read-only service account. Connection in minutes.
Discover
Initial scan inventories every role, permission set, user and grant — building the access graph.
Govern
Run SoD analysis, browse and compare roles, generate audit reports, launch attestation campaigns.
Continuous
Scheduled re-scans keep the picture live. Webhook alerts on critical violations.
Works with your ERP
ERP-agnostic by design — connects to any modern enterprise platform that exposes a REST or OData API, cloud or on-premise. Custom connectors available for proprietary stacks.
Who it's for
Internal Audit & Compliance
Replace weeks of access analysis with one dashboard. Walk into your audit with the data already exported.
ERP Application Owners
Refactor the role model with confidence — see exactly what changes before you ship them.
Security & GRC Teams
Continuous SoD monitoring across the ERP, with violation alerts and a clean evidence trail.
Implementation Projects
Stand up a defensible role model on day one with the template library — and prove it during UAT.
Ready to see your ERP access clearly?
30 minutes is enough. We'll connect to a sandbox of your choice and show you your real access graph live.
Book a 30-min demo