Pathlock
by Pathlock · SOX & Internal Controls
Identity governance and access-risk automation for SOX controls across SAP, Oracle, Workday.
Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.
- Works with
SAP
SAP S/4HANA
Oracle
Workday
Microsoft Dynamics 365
PeopleSoft- Deployment
- Cloud
- Company size
- Mid-market, Enterprise
- Pricing
- Quote-based
- Headquarters
- 1675 Larimer St, Suite 700, Denver, CO 80202, United States
Overview
Pathlock is a compliance-centric identity governance and application-GRC platform that secures and governs human and non-human identities across ERP systems and other business-critical applications. The platform brings together identity and access governance, application-level GRC (segregation of duties, emergency access, dynamic data access control), continuous controls monitoring, and ERP cybersecurity in a single suite, aimed primarily at automating SOX 302/404 compliance, SoD analysis, and IT general controls for mid-market and large enterprises.
Core modules include Application Access Governance (fine-grained SoD and sensitive-access risk analysis across SAP, Oracle, Workday, PeopleSoft and other applications), Compliant Provisioning (automated joiner/mover/leaver workflows), Access Certifications (automated user access reviews), Elevated Access Management (time-bound privileged/firefighter access with full audit trails), Role Management, Dynamic Access Control (real-time data masking and transaction blocking), Continuous Controls Monitoring (automated control testing and financial-impact analysis of 100% of transactions), and Cybersecurity Application Controls (vulnerability management, threat detection, transport/code-change control for SAP).
Pathlock reports over 1,300 customers, including Aramco, P&G, Jabil, Chevron, Toyota, Siemens, Microsoft, Electrolux and the University of California, and is delivered as a cloud SaaS platform ("Pathlock Cloud") with pre-built connectors for 150+ applications plus no-code tools for custom integrations.
Screenshots & demo
Demo video from the vendor's YouTube channel. Screenshots sourced from Pathlock.
Features & capabilities
Identity & Access Governance
Automates core identity lifecycle and access-request processes across ERP and business applications.
- Compliant provisioning (automated joiner/mover/leaver onboarding and offboarding)
- Self-service access request portal
- Automated manager access certifications and user access reviews
- Role management with automatic entitlement grouping by job title
- Non-human identity governance for service accounts and bots
- AI-powered role suggestions to resolve conflicts without disrupting access
Application GRC / Access Risk Analysis
Detects and remediates segregation-of-duties and sensitive-access risk across the application landscape.
- Fine-grained Segregation of Duties (SoD) conflict detection across SAP, Oracle, Workday and PeopleSoft
- Cross-application SoD analysis rather than single-system checks
- Emergency / firefighter access with full workflow tracking
- Dynamic Access Control: real-time data masking and sensitive-transaction blocking
- Entitlement design and testing for compliant ERP roles
- Out-of-the-box risk rulesets, customizable to organizational risk appetite
- Peer benchmarking and risk-impact simulation before access changes
Continuous Controls Monitoring & Audit
Automates control testing, transaction analysis, and audit evidence collection.
- Continuous Controls Monitoring (CCM) with real-time compliance-rule alerts
- Enriched transaction monitoring to analyze 100% of transactions for financial impact
- Centralized Controls Management mapping controls to regulations, risks and policies
- Risk Quantification of financial exposure to prioritize remediation
- Change Monitoring for critical configuration and master-data changes
- Tamper-proof audit trails of who changed what data and when
- Out-of-the-box audit reporting for external auditors
ERP Cybersecurity
Secures the underlying ERP application layer against vulnerabilities and unauthorized changes.
- Vulnerability management to find and patch security gaps in core business systems
- Real-time threat detection for active attacks on financial systems
- Transport/code-change control to prevent malicious or flawed updates reaching production
- Cybersecurity Application Controls delivered without touching the SAP core
Common use cases
- Automating SOX 302/404 IT general controls (access reviews, provisioning, change tracking) for a public company's annual audit
- Continuously identifying and remediating SoD conflicts across SAP and Oracle instead of relying on periodic manual reviews
- Streamlining user access certifications so managers can complete SOX-required reviews on time with full audit evidence
- Granting and logging privileged/firefighter access in SAP with automated revocation to control elevated-access SOX risk
- Preparing for UK-SOX by automating internal controls and IT access security ahead of upcoming reporting deadlines
- Masking or blocking sensitive SAP transactions in real time via Dynamic Access Control to reduce role explosion
- Consolidating access-risk and controls-monitoring evidence across SAP, Oracle and Workday into a single audit-ready reporting layer
Strengths & considerations
Strengths
- Cross-application SoD and access-risk analysis spanning SAP, Oracle, Workday, PeopleSoft and other systems from one platform, versus single-system tools like native SAP GRC
- Fine-grained, permission-level risk analysis of actual user activity (not just theoretical access) to reduce false positives
- Continuous Controls Monitoring analyzes 100% of transactions for financial impact rather than sampling
- Cybersecurity Application Controls layer (vulnerability management, threat detection, transport control) bundled alongside identity governance and GRC
- Pre-built connectors for 150+ applications plus a no-code Connector Studio for custom integrations
ERP integrations
PeopleSoftIncluding PeopleSoft Campus Solutions
Pricing
Pathlock does not publish pricing on its website; the /pricing/ URL returns no content and every CTA routes to "Schedule Demo" / "Book One-to-One Demo". Quotes are provided after a sales consultation. Get an independent shortlist with pricing guidance below.
Technical & security
- Hosting
- SaaS (Pathlock Cloud)
- Compliance
- ISO 27001, SOC 1 Type II, SOC 2 Type II
About the vendor
- Headquarters
- 1675 Larimer St, Suite 700, Denver, CO 80202, United States
Alternatives to Pathlock in SOX & Internal Controls
Pathlock — frequently asked questions
Does Pathlock automate SOX 302 and 404 compliance?
Yes. Pathlock's SOX use case page states it automates SOX 302 and 404 compliance through continuous SoD analysis, compliant provisioning, periodic access certifications, and elevated-access management, producing audit-ready evidence for external auditors.
What ERP systems does Pathlock integrate with?
Pathlock provides pre-built connectors for 150+ applications, including SAP ERP, SAP S/4HANA, SAP Ariba, Oracle E-Business Suite, Oracle ERP Cloud, Workday, Microsoft Dynamics 365 and PeopleSoft, plus no-code tools in its Connector Studio for custom integrations.
What security certifications does Pathlock hold?
According to Pathlock's privacy policy, the company maintains and undergoes regular audits for ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 certifications.
Can Pathlock analyze segregation-of-duties risk across more than one application at once?
Yes. Pathlock's Access Risk Analysis product analyzes SoD and sensitive-access risk across SAP, Oracle, Workday, PeopleSoft and other applications from a single platform, rather than one system at a time as with native SAP GRC.
Does Pathlock publish its pricing?
No. Pathlock does not publish pricing on its site; prospects schedule a demo or request a quote, and pricing is provided through a sales consultation.
Evaluating SOX & Internal Controls?
Tell us your ERP and requirements and we'll send an independent shortlist — including Pathlock and the best-fit alternatives — with honest pros and cons.