SAP S/4HANA Fiori UX · Security Redesign
Healthcare and Life Sciences SAP Fiori SAP Fiori Launchpad SAP GRC
Moving off SAPGUI and rebuilding security roles: a healthcare diagnostics company’s S/4HANA UX transformation
Molecular diagnostics company Delivered 2022
Mindset delivered a standard Fiori launchpad and a portfolio of standard Fiori apps across all process areas, then added a full SAP security role redesign, giving a fast-growing diagnostics company a modern user experience and a clean security foundation built for how the business actually operates.
By the numbers
-
12 weeks
Fiori app build phase, all process areas
-
2 workstreams
UX and security delivered in parallel
-
1
Unified test track across the multi-vendor program
Before
SAPGUI and an aging security model
- Business users navigating SAPGUI on S/4HANA, with a mix of transitional and custom app approaches under consideration.
- A security role landscape and GRC setup that had not been redesigned for the new S/4HANA environment.
- UX and security being planned separately, creating risk of misalignment mid-program.
After
Fiori launchpad, standard apps, rebuilt roles
- Fiori Launchpad live as the S/4HANA preferred logon, with standard Fiori apps across all process areas.
- A redesigned SAP security role model built in lockstep with the UX, using the traceability matrix as the connective thread.
- A single user testing track coordinated across the multi-vendor program.
Why this matters
UX and security as one integrated program rather than two workstreams that could collide. The traceability matrix connecting personas, roles, and apps was the artifact that made that possible.
The challenge
A fast-growing healthcare diagnostics company wanted to complete a UX transformation on SAP S/4HANA, moving its users off SAPGUI and onto modern Fiori applications. The core question was how far standard SAP Fiori could take them before custom development became necessary.
At the same time, the company's SAP Center of Excellence wanted to modernize its security posture. The existing role landscape, including its an identity-governance vendor GRC tooling, needed a thorough assessment, and the security role structure needed to be redesigned in step with the new Fiori UX so both programs moved forward together rather than creating conflicts.
What we did
Mindset ran two coordinated workstreams through the year.
The first was a Fiori Assessment followed by a build phase. The four-week assessment focused on fit-to-standard feasibility for Fiori Lighthouse apps, reviewed SAPGUI usage across all process areas, and produced a Persona-to-Security-Role-to-Fiori-App traceability matrix, a Fiori Launchpad architecture and implementation plan, a mobility use-case register with identified gaps, and an implementation project plan.
The 12-week Fiori build phase implemented the Fiori Launchpad as the S/4HANA preferred logon and designed, delivered, and scaled standard Fiori apps across all process areas using two-week Agile sprints. FLP theming and branding were included, and security role recommendations from the traceability matrix drove the design. Mid-engagement, the company moved from an interim set of transitional apps to a full standard-app approach, which a change order captured. User testing was coordinated with the broader multi-vendor S/4HANA program in a single collaborative testing track so all business-user tests ran through Fiori.
The second workstream was a dedicated security engagement: a two-to-four-week SAP S/4HANA Security Assessment covering the existing role landscape, SSO, and GRC strategy, followed by an eight-to-ten-week Security Redesign that rebuilt the role model in alignment with the new Fiori UX. A dedicated SAP Security Engineer joined the team for this phase.
The outcomes
The company finished the year with a live Fiori Launchpad as its S/4HANA preferred logon, standard Fiori apps deployed across every process area, and a redesigned SAP security role model that reflected how the business actually works.
The engagement expanded twice during delivery, first to move from transitional apps to full standard-app coverage, and then to add the full security assessment and redesign, both of which indicated the work was landing well. Business users who had been navigating SAPGUI moved to a modern, consistent Fiori experience without disrupting the broader S/4HANA program delivery happening in parallel.
If we built this today
Concept · not delivered scopeStandard Fiori, the agentic way.
This is a forward-looking concept, not the scope we delivered on this engagement. It is the build we would reach for now, grounded in SAP that ships today.
This healthcare diagnostics company asked how far standard SAP Fiori could carry its move off SAPGUI, and how to redesign security roles in step, exactly the work a Joule-led fit-to-standard assistant would own today.
The data product
Cloud ERP Intelligence
Grounds the agent in governed S/4HANA semantics, real transaction and app-usage patterns plus the authorization model, so the fit-to-standard and role-redesign proposals are based on how the system is actually used, not a guess. It keeps the persona-role-app picture honest as adoption grows.
Intelligent Application on SAP Business Data Cloud
The Joule agent
Knowledge Graph Navigator
Reads the live S/4HANA persona, role, and transaction-usage picture against the SAP Fiori apps reference library and the SAP Knowledge Graph, then proposes a fit-to-standard mapping of which SAPGUI transactions a standard Fiori app already covers and which personas need which authorization role. It drafts the persona-to-role-to-app traceability and flags the few real custom-development gaps.
SAP S/4HANA, SAP Fiori, SAP Fiori Launchpad, SAP GRC · PROPOSE · Share of SAPGUI transactions met by standard Fiori (fit-to-standard coverage)
The Fiori app
SAP Fiori launchpad with embedded Joule
The launchpad itself becomes the workspace, with Joule sitting in it to find the right app, explain a role, and walk a user off a SAPGUI habit toward its standard Fiori equivalent. Joule Work gives each persona a curated set of apps instead of a transaction code to memorize.
Embedded in the SAP Fiori launchpad
In practice we would mine the real transaction usage in SAP Signavio first, map the role and app estate in SAP LeanIX, and let MIND accelerators carry the old SAPGUI patterns over to the new Fiori and security model.
What we built
-
Full fit-to-standard analysis and implementation plan delivered
Fiori fit-to-standard assessment
A four-week assessment reviewing SAPGUI usage across all process areas and producing a Persona-to-Security-Role-to-Fiori-App traceability matrix, launchpad architecture plan, and implementation project plan.
-
Fiori Launchpad as the primary S/4HANA entry point
Fiori Launchpad implementation
The Fiori Launchpad deployed as the S/4HANA preferred logon, with FLP theming and branding for the company.
-
12-week build, all process areas covered
Standard Fiori apps across all process areas
Standard SAP Fiori applications designed, delivered, and scaled across all process areas in 12 weeks of Agile two-week sprint delivery, moving from a transitional approach to full standard-app coverage.
-
UX and security aligned through a single artifact
Persona-to-role-to-app traceability matrix
A detailed mapping of personas to security roles to Fiori apps that connected the UX design to the underlying security model from the start.
-
Single test track across all vendors
Unified user testing track
Coordinated with the multi-vendor S/4HANA program so all business-user testing ran through Fiori, eliminating duplicate test cycles across the program.
-
Full security landscape reviewed
SAP security landscape assessment
A two-to-four-week assessment of the existing security role landscape, SSO configuration, and GRC strategy including the existing an identity-governance vendor tooling.
-
Full role model rebuilt in step with Fiori UX
SAP security role redesign
An eight-to-ten-week redesign of the SAP S/4HANA security role model, aligned to the new Fiori UX and redesigned to reflect actual business operations.