Our production support teams wants access to the production systems

Our production support teams wants access to the production systems

Our SAP production support teams would like full transactional access (display/change/create) into production systems. This conflicts with some of our strategies and policies. Do you have any guidelines for best practices in this area - what is generally the norm for internal support roles for other companies? Any help will be appreciated.

    Requires Free Membership to View

    When you register, you will start receiving targeted emails from my award-winning team of editorial writers. Our goal is to keep you informed on the hottest topics and biggest challenges faced by SAP professionals today.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSAP.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSAP.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Very simple question. No. There are a number of rules, best practices, and common sense that would argue in your favor. The norm is for support people to have display access for most transactional functions, where problems are noted so they should be replicable in your testing environment (assuming you have a good QA process). The support personnel should then find the solution for the problem, move it to test and then promote to production. If you give support people production functional access, they will start processing transactions and have both the knowledge and access to violate most internal controls.

Alternatively, I have seen some process teams identify specific transactions they need in production due to specific business rules (Tax rate updates, Monthly close support) and receive business sign-off. This is acceptable and warranted. There are always exceptions.

Furthermore, you should work with your audit community to understand your obligations under Sarbanes-Oxley Section 404 on internal and system controls. Your external auditor may not be willing to attest to the soundness of your control environment if multiple segregation of duty issues exists.

This was first published in June 2003