Skip to content
Platform

Govern the rulebook your analysis runs against.

Import a GRC Access Control ruleset, convert it into one clean model, and author your own rules on top of a shared base library — then approve and activate it. Nothing gets analysed against an unapproved rulebook, which is exactly what makes the conflicts downstream defensible when an auditor asks where a rule came from.

Authorruleset-check

Govern the rulebook every SOD check runs against

  1. 01Import
  2. 02Author
  3. 03Approve
  4. 04Activate
GRC AC exportbase v4approved and activated before anything is analysed
Risks 214Functions 118T-codes 512Auth objects 361
  • Import and convert. Bring in a GRC Access Control or Pathlock ruleset export and convert it into one clean model — with a dry-run preview of what will change before anything is committed.
  • Author on a shared base. Build and version client-specific rules on top of a shared base library, so every engagement starts from the same known-good policy instead of a fresh spreadsheet.
  • Approve, then activate. Analysis only runs against an approved, activated base ruleset. That gate is what makes every downstream conflict defensible when an auditor asks where the rule came from.
Ruleset Check · Base RulesSearch… ⌘KAC

Active base ruleset

active
v4 version214 risks118 functions512 T-codes361 auth objects

Converted from a GRC AC export · approved by D. Okafor on 6/14/2026. Analysis will not run against an unapproved ruleset.

Risk IDRisk nameRatingAreaFunctions
FI-001Post and Approve AP InvoicesCRITICALFI2
FI-002Vendor Master and Payment ProcessingHIGHFI2
MM-001Create PO and Post Goods ReceiptHIGHMM2
BASIS-001Create Users and Assign RolesCRITICALBASIS2
SD-001Sales Order and Credit ReleaseMEDIUMSD2
Pending import · dry-run preview
18 added7 changed189 unchanged4 awaiting approval

Nothing is committed until an org admin approves the version and sets it as base.

Interactive replica · illustrative data — no real client systems or content.

Try Ruleset Check in the live app ↗