> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/hris-and-erp/erp.md).

# ERP Integration (SAP)

## Overview

The **ERP Entitlements Integration** gives Herd a read-only, daily view of **who in your organization can move money**: employees who can wire funds, approve purchase orders, modify vendor records, or release payments. Those people are flagged as **high-value BEC targets**, so simulations and reporting can focus on the employees real attackers would go after. Nothing is ever written back to the ERP.

It also syncs your **vendor list**, powering a classic vendor-fraud simulation: lures that impersonate a real (but dormant) vendor of yours.

{% hint style="warning" %}
The ERP integration is enabled **per organization after a security review** — contact your Herd representative to turn it on for your plan. Until then the tile shows a locked state.
{% endhint %}

***

## Connecting SAP

Under **Settings → Integrations**, open the **SAP** card (in the **HRIS & ERP** section) and expand **ERP Connection Settings**:

* **ERP Provider** — **SAP** is supported today (Oracle and Microsoft Dynamics 365 are coming later).
* **ERP Base URL** — your S/4HANA gateway host (HTTPS only), for example `https://s4.acme.com`.
* **Service Path** — the entitlement OData service or report path relative to the base URL, exposing who can wire money, approve POs, modify vendors, or release payments (read-only).
* **Service Account Username** / **Service Account Password** — a dedicated service account with read-only access. The password is stored encrypted and never displayed again.

Click **Save ERP Configuration**. Once connected, Herd syncs daily; **Sync now** pulls immediately, and the tile shows outcome counts: **Matched**, **Updated**, **Flagged (high-value)**, **Cleared**, and **Unmatched**. If the ERP starts rejecting Herd's permissions, the tile shows an **Auto-sync paused** warning — fix the permissions and click **Sync now** to resume.

***

## Dormant-vendor phishing simulations

Once vendor data has synced, the tile shows a **Dormant vendors** panel — vendors you haven't paid in roughly 18 months. These make ideal lures: an "updated bank details" or "overdue invoice" email from a vendor your finance team vaguely remembers is exactly how real vendor fraud arrives.

Each row shows the vendor, its domain, and when it was last paid. Click **Launch simulation** to have Herd generate a vendor-fraud phishing template impersonating that vendor. Generated templates land **unapproved** on the [auto-generated simulations](/herd-security-docs/simulations/phishing-simulations/auto-generated-simulations.md) review surface — use the **Review simulation** link to inspect and approve before anything is sent, and the lure sends from the vendor-styled domain, not your own.

***

## Disabling

Click **Disable** on the tile to stop the sync. Entitlement data already synced is kept, but high-value-target flags stop updating until you reconnect.
