Skip to content
Platform

The transactions GRC can't see.

Tcodex classifies every transaction by its SE93 type, resolves what each one really runs, and surfaces custom 'wrapper' transactions — like ZME23 quietly calling ME23N — that bypass GRC's transaction-level SOD checks entirely. Each finding carries its role-reach blast radius.

Exposetcodex

The transactions GRC can't see

0GRC reported
vs
7wrappers Tcodex exposed
ZME23ME23Ncustom T-code silently bypasses the SOD check
  • Classify every transaction. Resolve each T-code by its SE93 type — Dialog, Report, Parameter, Variant, OO-Method, Area-Menu — and what it actually runs.
  • Expose wrapper transactions. Custom T-codes like ZME23 that quietly call ME23N bypass GRC's transaction-level checks entirely. Tcodex resolves the chain and flags them.
  • Role-reach blast radius. Every wrapper finding carries the number of production roles that grant it — so you triage by real exposure.
Tcodex · Wrapper FindingsSearch… ⌘KAC

Wrapper Findings

142 T-codes classified
7 wrappers3 MM3 FI1 HR
Custom T-codeTypeWrapsReachDomain
ZME23PARAMETERME23N3MMWRAPPER
ZFB03_CUSTPARAMETERFB032FIWRAPPER
ZZ_CHAIN1PARAMETERME23N1MMWRAPPER
ZME23Display Purchase Order — custom default screenrole reach 3
ZME23ME23NWRAPPER → ME23N

GRC AC treats every T-code as an opaque string. ZME23 wraps ME23N, so 3 production roles silently grantaccess that GRC's transaction-level SOD checks report as zero.

Interactive replica · illustrative data — no real client systems or content.

Try Tcodex in the live app ↗