Direct answer

During SAP cutover, system access is controlled using an approved user-and-role inventory, a defined access freeze, named and time-bound exceptions for migration tasks, tested authorizations, proof of approvals and privileged activity, and a business release gate. Security, Basis, functional and business owners coordinate the sequence; temporary elevated rights are removed or reviewed after go-live.

Why cutover access needs its own plan

Uncontrolled production edits can change the frozen data baseline, interfere with loads or compromise reconciliation. Yet locking every account indiscriminately may stop essential jobs and integrations. Access must follow the cutover sequence: protect the baseline, execute controlled tasks, test results, authorize normal operations and remove exceptions.

Separate people and technical identities

Business users need their operational access after release. Named cutover operators need only the permitted tasks in their assigned windows. Background jobs and interfaces may use technical identities that must keep working under controlled conditions. Emergency support users require explicit approval and review. Where the landscape uses ABAP role administration, SAP PFCG roles and authorization objects translate business responsibilities into enforceable permissions.

Freeze access without assuming every lock ends activity

The cutover lead and security owner specify which user groups are restricted, which technical identities remain operational and who may approve exceptions. SAP documentation for ABAP user administration explains that a manual user lock takes effect at the next logon and does not automatically end a session already running. Account locks alone therefore cannot replace checks on active sessions, job schedules, integrations and other change channels.

Security and business colleagues reviewing cutover user role approvals and an access sign-off
Role approvals and access windows are business decisions coordinated with the technical cutover team.

Approve time-bound privileges by named task

A migration operator may need a specific permission to run a load, restart an interface or investigate a failed job. Document the requester, approver, system, intended task, actual role or permission, start and end times and evidence reviewer. Where SAP Access Control Emergency Access Management is installed, its firefighter arrangements can govern elevated activity, but they are not present in every SAP landscape. Avoid uncontrolled shared administrator credentials.

Rehearse permissions before the cutover weekend

A mock cutover should confirm both sides of access control: that each approved operator can execute an assigned step and that routine users cannot perform restricted changes during the protected window. Include job ownership, interface credentials, fallback escalation and sign-off. An account shown as active is not proof that its owner can run the necessary business task.

Four-stage timeline for cutover role design, access freeze, go-live validation and removal of temporary access
Each stage needs a named owner and evidence, from role design through access closure.

Release normal users at the readiness gate

After final loads, reconciliations, interface checks and smoke tests meet approved criteria, the go/no-go decision permits a staged return to normal access. Process owners then confirm that critical business activities work with intended roles. The method varies across SAP products and customer identity designs; a single blanket unlock is not a universal answer.

Remove temporary permissions after stabilization

Close emergency sessions, expire short-term assignments, review logs and compare the remaining access list with the approved baseline. Any ongoing elevated support permission needs fresh approval and an expiry, not silent permanence.

Example: an AP migration exception

When a supplier open-item load fails, a named migration operator receives narrow authorization to rerun the affected step. The AP business owner validates balances without administrator rights. Security retains the approval, the operator retains job logs, Finance signs off and the temporary permission expires. Unlocking all AP users during reconciliation could change the population under review.

Warning signs to escalate

An access list without owners, indiscriminate technical-user locks, privileged rights without expiry, absent activity evidence or critical permissions first requested on go-live night all threaten cutover sequence and accountability.

Read next

See How a Cutover Plan Is Built, How Cutover Dependencies Are Managed, What a Mock Cutover Is and How Final Balance Migration Is Validated. Return to the Consulting & ERP Projects hub.

Official SAP References