Identity shouldn't stop at the edge of SAP.
A user crosses into SAP, Oracle, or Salesforce and — for most identity products — the audit trail goes dark. Axowl's Deep Connector carries sealed identity, grants, and audit continuity into the systems your business actually runs on. It runs as an Edge Box inside your own VPC: it reads the ERP's event stream locally and forwards only sealed, hashed events, so no cloud vendor ever reaches into your core.
Where ERP Integration breaks today
The audit trail goes dark at the ERP edge
Your identity platform knows who signed in and stops there. What that person then did inside SAP or Oracle lives in the ERP's own log, on a system the same administrators control — so "who changed this posting" is answered by the very stack under review.
SOX §404 — requires verifiable internal controls over financial reporting systems
SCIM stops at "who exists"
SCIM is the right tool for modern SaaS: it creates, updates, and deprovisions accounts on a directory event. But SAP and Oracle barely speak it — they carry their own authorization models, and a directory copy tells you nothing about the permission a user actually holds inside the ERP.
SCIM 2.0 — syncs identities, not what happened inside the ERP
Nobody approves a cloud reaching into the core
The usual integration asks you to open an inbound path from a vendor's cloud into the system that holds your ledger and your master data. Security teams at banks and manufacturers reject that shape on sight — which is why so many ERP audit gaps are simply left open.
0 bytes — of raw ERP data leaves your VPC — the Edge Box forwards sealed events only
Three patents, deployed against this industry's threat model
Each of Axowl's three filed patents maps to a specific structural failure mode in ERP Integration. Together they form a single, end-to-end defense.
Hierarchical Distributed Trust Fabric — Workstation (L1) · Edge Box beside the ERP (L2) · Sealed archive (L3)
The user's workstation carries a hardware-bound identity at L1. The Edge Box — the axowl-enterprise-sdk running as a small VM next to SAP, Oracle, or Salesforce — is L2: it authenticates outbound with a Plugin Token issued at Organization Settings → Keys, and never accepts an inbound connection. The sealed archive in a separate region is L3, out of reach of the administrators who run the ERP.
Transition-Sealed Integrity System — The ERP's own events, sealed at the edge
Each ERP audit event — a posting, an approval, a master-data change, a permission grant — is bound to its actor's identity and hashed inside your network before anything is sent. What leaves is a sealed event, not your data. The chain that receives it is the same tamper-evident core that seals the rest of the platform, so "who did what in SAP" stays provable after the fact and cannot be rewritten by the team that runs the system.
Pre-grant LLM Conflict Verification — ERP authorizations mapped, conflicts refused before the grant
The Deep Connector maps the ERP's permission model into Axowl's scope grammar instead of copying a directory. That makes cross-system combinations visible to the pre-grant gate: a request that pairs vendor-master maintenance in the ERP with payment release in the finance app is a separation-of-duties conflict, and it is refused at the moment someone tries to grant it — not found in next quarter's access review.
Deployment that fits the threat model
Most ERP deployments start at the Standard tier, where SCIM 2.0 is already included on the Business plan and covers the modern SaaS around the core. The Defense tier is what the core itself needs: the Edge Box in your VPC, sealed event forwarding, and audit continuity that a bank's security review will accept.
Recommended tier: T1 · Standard → T2 · Defense
Deployment path: SCIM 2.0 for the SaaS tier · Edge Box (axowl-enterprise-sdk) beside the ERP
Operational detail: 1 · SaaS tier — nothing to deploy. SCIM 2.0 is included on the Business plan. Connect your IdP (Okta, Entra ID, Google) and create / update / deprovision follow the directory event. If every system you care about speaks SCIM, you are done here.
2 · Issue a Plugin Token. Organization Settings → Keys. This is the credential the Edge Box authenticates with; nothing else is needed to pair it.
3 · Stand up the Edge Box. The axowl-enterprise-sdk runs as a small VM inside your own VPC, next to SAP / Oracle / Salesforce. It is outbound-only — you open no inbound path, and Axowl never reaches into your core.
4 · Point it at the ERP's event stream. Each audit event is bound to its actor's identity and hashed locally, then forwarded over Bearer Plugin Token auth. Raw ERP data stays in your network; only sealed events leave.
5 · Map the permission model. The connector translates the ERP's own authorizations into Axowl's scope grammar, so a separation-of-duties conflict that spans the ERP and a SaaS app reaches the pre-grant gate instead of next quarter's review.
6 · Add connectors as needed. Priced as a per-connector add-on, each system separately. The same Edge Box appliance also seals your database rows at rest — one box, both jobs.
Three concrete deployments
Financial close with SOX evidence
Postings, approvals, and journal adjustments inside the ERP arrive in the sealed chain with the actor's identity attached. The evidence an auditor asks for at close is a query against a tamper-evident record, not a manual export from the system being audited.
Separation of duties across ERP and SaaS
Because ERP authorizations are mapped into the same scope grammar as the rest of the stack, a conflict that spans two systems is visible to one gate. The combination is refused when someone requests it, and the refusal itself is a sealed event the compliance team can point at.
A security review that actually passes
The connector is outbound-only and lives inside your perimeter, so there is no inbound path from a vendor's cloud into the ledger. Raw ERP data never leaves the VPC — only sealed, hashed events do. That is the shape a bank's or a manufacturer's security team will sign off on.
Versus what's deployed today
Today — SCIM-only sync + the ERP's own log
Directory sync tells you who exists, and the ERP's internal log tells you the rest — but that log sits on a system its own administrators control, and it stops at the system boundary. Cross-system conflicts are invisible until someone assembles a spreadsheet from two exports.
With DPSM — Axowl DPSM
The audit chain does not break at the perimeter. ERP events are sealed inside your own network and mirrored to an archive the ERP's administrators cannot reach, permissions from both worlds share one scope grammar, and the pre-grant gate sees the combination before it is ever issued.
Standards & regulatory frameworks aligned
- SOX §404
- SOC 2 Type II
- ISO 27001 / 27002
- NIST 800-53 AU family
- GDPR Article 32
- K-SOX operating report (2026 effective)