{"id":11488,"date":"2024-05-21T09:50:55","date_gmt":"2024-05-21T07:50:55","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=11488"},"modified":"2025-07-04T11:22:25","modified_gmt":"2025-07-04T09:22:25","slug":"success-case-hcm-role-redesign-at-emt","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/","title":{"rendered":"Success Story: SAP\u00ae HCM Role Redesign at EMT"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">One of our company&#8217;s biggest success stories in the SAP\u00ae Security Area was the execution of a Role Redesign project in an HCM (Human Capital Management) system. This project focused on redesigning the role model and structural profiles to minimize access to modify and view sensitive information in EMT&#8217;s Human Resources system.<\/span><\/p>\n\n<p><span style=\"font-weight: 400;\">The Empresa Municipal de Transportes de Madrid (<\/span><b>EMT<\/b><span style=\"font-weight: 400;\">) is a public limited company owned by the Madrid City Council. EMT is the global manager of surface mobility in the city of Madrid and is responsible for the management and operation of urban bus services; public bicycles (BiciMAD); municipal crane, public and resident parking, and the Cable Car. EMT is integrated into the Madrid Regional Transport Consortium, the authority responsible for public transport planning in Madrid.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11472\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-1.png\" alt=\"\" width=\"702\" height=\"441\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-1.png 1300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-1-300x188.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-1-1024x643.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-1-600x377.png 600w\" sizes=\"(max-width: 702px) 100vw, 702px\" \/><\/p>\n<h2><b>The Challenge<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The project&#8217;s difficulty was, on the one hand, defining a risk matrix specific to the critical accesses of the Human Resources organization and the definition and implementation of a new role model adapted to their needs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The key to the project was to define roles by position (composite roles) that would improve day-to-day user management without losing focus on access restrictions at the infotype and structural profile level, as well as reducing critical and segregation of duty risks in the system.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is worth mentioning that this project was very comprehensive, as it also involved the implementation of SSO (a single sign-on authentication procedure that enables the user to access multiple systems with a single instance of identification) and the implementation of SAP\u00ae GRC Access Control (EAM, ARA, ARM, BRM, and PSS).<\/span><\/p>\n<h2><b>Inprosec Solution<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The project was divided into 4 Blocks, where the first 2 specifically related to the HR part, which we will detail below (risk matrix design and role reengineering), another block related to SSO, and another with the configuration of SAP\u00ae GRC AC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Each of the blocks was divided into 3 phases:<\/span><\/p>\n<ul>\n<li aria-level=\"1\"><b>Risk Matrix Definition HCM (Block I)<\/b><\/li>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Initial Analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Business Responsible Interviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Matrix Publication<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>Role Model Implementation HCM (Block II)<\/b><\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Definition of the New Role Model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Deployment of the New Role Model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Information Transfer<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3><b>Risk Matrix Definition HCM (Block I)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The project began with the definition of the risk matrix, as it is the fundamental pillar for designing and implementing the new role model based on best practices, and using it to perform the risk analysis in SAP\u00ae GRC Access Control (Access Risk Analysis). This way, we can measure the initial risks that users have and the reduction achieved once the remediation project is completed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">HR systems are usually very customized, meaning there are a large number of custom transactions (Z transactions) in use. Therefore, the biggest challenge was to perform a detailed analysis of each custom transaction to identify its functionality and confirm whether it should be added to the risk matrix.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11474\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-2.png\" alt=\"\" width=\"700\" height=\"305\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-2.png 744w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-2-300x131.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-2-600x261.png 600w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Once the Z transactions were analyzed, and based on the standard SAP\u00ae HR risk matrix included in SAP\u00ae GRC, a first draft of the risk matrix was created to conduct functional interviews with the responsible parties for human resources business processes and the internal audit team. The risk matrix was defined at the level of segregation of duties (SoD) risks and critical actions.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11476\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-3.png\" alt=\"\" width=\"699\" height=\"380\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-3.png 1073w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-3-300x163.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-3-1024x556.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-3-600x326.png 600w\" sizes=\"(max-width: 699px) 100vw, 699px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Once the first draft of the risk matrix was available, work meetings with human resources business representatives began to achieve the following objectives:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm risks and functions of the standard risk matrix.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify risks and functions specific to EMT.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm custom transactions to add to the risk matrix.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify risks between SAP\u00ae systems.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define compensatory controls associated with the risks identified in the risk matrix.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">To maintain the risk and control matrices&#8217; lifecycle over time, the associated procedures were defined to achieve this goal. Specifically, the periodic update procedure of the risk matrix and the secure code development procedure were established.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Both the risk and control matrices and the associated procedures were presented to EMT&#8217;s internal team through training sessions.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11478\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-4.png\" alt=\"\" width=\"700\" height=\"297\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-4.png 1129w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-4-300x127.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-4-1024x434.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-4-600x255.png 600w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The deliverables associated with this block were as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Matrix update procedure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure code development procedure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk and control matrices.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analysis report of Z transactions, including actions and recommendations.<\/span><\/li>\n<\/ul>\n<h3><b>Role Model Implementation HCM (Block II)<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The role model was designed for all over 300 users of EMT&#8217;s SAP\u00ae HCM system. A sustainable and scalable role model was implemented over time, with a single, easy-to-understand nomenclature aligned with the HR risk matrix defined in Block 1 of the project.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Initially, a transactional use analysis of EMT&#8217;s SAP\u00ae HCM system users was conducted to identify which transactions would be included in the new roles. Before designing and building the new roles, a role nomenclature was defined and agreed upon with EMT, allowing for efficient identification and maintenance of the new model.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The classification of transactions into roles was based on functions respecting the defined risk matrix. Enabler Roles were created to grant access to authorization objects that require specific restrictions, such as those containing the infotype field and personnel area. Accesses were also defined based on the organizational structure, using structural profiles.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Roles and structural profiles were created in the development environment and transported to the quality environment for functional testing and User Acceptance Testing (UAT). It was agreed with EMT&#8217;s responsible parties that users would perform acceptance tests of the new model, aiming to have at least one reference user for each defined job position, confirming the operability of all composite roles.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11480\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-5.png\" alt=\"\" width=\"699\" height=\"433\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-5.png 725w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-5-300x186.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-5-600x372.png 600w\" sizes=\"(max-width: 699px) 100vw, 699px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The start of this second phase coincided with the deployment of the SAP\u00ae GRC Access Control&#8217;s Access Risk Analysis tool, which was used to perform the initial risk analysis and compare it with the analysis conducted at the project&#8217;s end.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The deployment phases of the new role model for different user groups were agreed upon with EMT. This way, EMT could determine the order in which users were migrated, minimizing operational impact without affecting business processes. Additionally, new roles would not be simultaneously assigned to all users of the same user group to reduce the potential impact of the new solution&#8217;s deployment.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11482\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-6.png\" alt=\"\" width=\"697\" height=\"392\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-6.png 724w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-6-300x169.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-6-600x337.png 600w\" sizes=\"(max-width: 697px) 100vw, 697px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Parallel to the model&#8217;s deployment, information was transferred to EMT&#8217;s role management team to properly manage and maintain the new role model implemented once the support period for each deployed user group was completed. Specific training sessions were conducted to detail each of the procedures defined in the previous phases.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-11484\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-7.png\" alt=\"\" width=\"699\" height=\"235\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-7.png 720w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-7-300x101.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/Rediseno-de-Roles-HCM-7-600x202.png 600w\" sizes=\"(max-width: 699px) 100vw, 699px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The deliverables associated with this block were as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Initial risk report and risk reduction simulation. This will help define one of the project&#8217;s baselines.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Functional and technical design of the new role model to be implemented in EMT&#8217;s SAP\u00ae HCM system.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Report on the actions taken: roles created\/transactions assigned.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Final report on residual SoD risks of the project.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Training and maintenance manuals for the new role model.<\/span><\/li>\n<\/ul>\n<h2><b>Results<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The implementation of a Human Resources-specific risk matrix allowed EMT not only to identify and monitor its most critical standard accesses but also its custom accesses (Z Transactions).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Regarding the implementation of a new Role Model, the main benefits were:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Definition of a new role nomenclature adapted to their needs, facilitating daily identification.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Functionality-based roles, avoiding assigning a role that includes transactions with functionalities the user does not need.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduction in the number of risks and accesses available with the previous role model.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Definition of composite roles by job position, facilitating the management of &#8220;Onboarding&#8221; and &#8220;Movers&#8221;.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification of the infotypes accessible to the different positions in EMT&#8217;s organization. Additionally, each was limited to the allowed permissions: View and\/or Modify.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Activation of organizational restriction by establishing structural profiles in the new role model implemented. This meant that positions with access to infotypes had limited information to the personnel division they belonged to.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Activation of a restriction that limited access to certain infotypes through a structural profile. There are authorization objects, such as P_ORGINCON, that allow expanding access to infotype information by using a less restricted structural profile, or vice versa.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of our company&#8217;s biggest success stories in the SAP\u00ae Security Area was the execution of a Role Redesign project in an HCM (Human Capital Management) system. This project focused on redesigning the role model and structural profiles to minimize access to modify and view sensitive information in EMT&#8217;s Human Resources system. The Empresa Municipal&#8230;<\/p>\n","protected":false},"author":6,"featured_media":13278,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[61,53],"tags":[170,167],"class_list":["post-11488","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-security-en-2","category-success-stories","tag-diseno-de-roles-en","tag-role-model-design"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Success Story: SAP\u00ae HCM Role Redesign at EMT - Inprosec<\/title>\n<meta name=\"description\" content=\"We redesigned the role system in the SAP HCM of the Empresa Municipal de Transportes de Madrid (EMT), optimizing security and access management. The project included the definition of a risk matrix and the implementation of SSO and SAP GRC Access Control, reducing risks and improving operational efficiency.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Success Story: SAP\u00ae HCM Role Redesign at EMT\" \/>\n<meta property=\"og:description\" content=\"We redesigned the role system in the SAP HCM of the Empresa Municipal de Transportes de Madrid (EMT), optimizing security and access management. The project included the definition of a risk matrix and the implementation of SSO and SAP GRC Access Control, reducing risks and improving operational efficiency.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-21T07:50:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-04T09:22:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/SAP-HCM-EMT-EN.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"Success Story: SAP\u00ae HCM Role Redesign at EMT\",\"datePublished\":\"2024-05-21T07:50:55+00:00\",\"dateModified\":\"2025-07-04T09:22:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/\"},\"wordCount\":1309,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/SAP-HCM-EMT-EN.jpg\",\"keywords\":[\"Dise\u00f1o de Roles\",\"Role Model Design\"],\"articleSection\":[\"SAP Security\",\"Success stories\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/\",\"name\":\"Success Story: SAP\u00ae HCM Role Redesign at EMT - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/SAP-HCM-EMT-EN.jpg\",\"datePublished\":\"2024-05-21T07:50:55+00:00\",\"dateModified\":\"2025-07-04T09:22:25+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"We redesigned the role system in the SAP HCM of the Empresa Municipal de Transportes de Madrid (EMT), optimizing security and access management. The project included the definition of a risk matrix and the implementation of SSO and SAP GRC Access Control, reducing risks and improving operational efficiency.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/SAP-HCM-EMT-EN.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/SAP-HCM-EMT-EN.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/success-case-hcm-role-redesign-at-emt\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Success Story: SAP\u00ae HCM Role Redesign at EMT\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Success Story: SAP\u00ae HCM Role Redesign at EMT - Inprosec","description":"We redesigned the role system in the SAP HCM of the Empresa Municipal de Transportes de Madrid (EMT), optimizing security and access management. The project included the definition of a risk matrix and the implementation of SSO and SAP GRC Access Control, reducing risks and improving operational efficiency.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/","og_locale":"en_US","og_type":"article","og_title":"Success Story: SAP\u00ae HCM Role Redesign at EMT","og_description":"We redesigned the role system in the SAP HCM of the Empresa Municipal de Transportes de Madrid (EMT), optimizing security and access management. The project included the definition of a risk matrix and the implementation of SSO and SAP GRC Access Control, reducing risks and improving operational efficiency.","og_url":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/","og_site_name":"Inprosec","article_published_time":"2024-05-21T07:50:55+00:00","article_modified_time":"2025-07-04T09:22:25+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/SAP-HCM-EMT-EN.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"Success Story: SAP\u00ae HCM Role Redesign at EMT","datePublished":"2024-05-21T07:50:55+00:00","dateModified":"2025-07-04T09:22:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/"},"wordCount":1309,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/SAP-HCM-EMT-EN.jpg","keywords":["Dise\u00f1o de Roles","Role Model Design"],"articleSection":["SAP Security","Success stories"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/","url":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/","name":"Success Story: SAP\u00ae HCM Role Redesign at EMT - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/SAP-HCM-EMT-EN.jpg","datePublished":"2024-05-21T07:50:55+00:00","dateModified":"2025-07-04T09:22:25+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"We redesigned the role system in the SAP HCM of the Empresa Municipal de Transportes de Madrid (EMT), optimizing security and access management. The project included the definition of a risk matrix and the implementation of SSO and SAP GRC Access Control, reducing risks and improving operational efficiency.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/SAP-HCM-EMT-EN.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2024\/05\/SAP-HCM-EMT-EN.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/success-case-hcm-role-redesign-at-emt\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"Success Story: SAP\u00ae HCM Role Redesign at EMT"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/11488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=11488"}],"version-history":[{"count":4,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/11488\/revisions"}],"predecessor-version":[{"id":13283,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/11488\/revisions\/13283"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/13278"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=11488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=11488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=11488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}