ERP Integration (SAP)
Connect your ERP (SAP) to Herd read-only to flag high-value BEC targets and launch dormant-vendor phishing simulations.
Overview
The ERP Entitlements Integration gives Herd a read-only, daily view of who in your organization can move money: employees who can wire funds, approve purchase orders, modify vendor records, or release payments. Those people are flagged as high-value BEC targets, so simulations and reporting can focus on the employees real attackers would go after. Nothing is ever written back to the ERP.
It also syncs your vendor list, powering a classic vendor-fraud simulation: lures that impersonate a real (but dormant) vendor of yours.
The ERP integration is enabled per organization after a security review — contact your Herd representative to turn it on for your plan. Until then the tile shows a locked state.
Connecting SAP
Under Settings → Integrations, open the SAP card (in the HRIS & ERP section) and expand ERP Connection Settings:
ERP Provider — SAP is supported today (Oracle and Microsoft Dynamics 365 are coming later).
ERP Base URL — your S/4HANA gateway host (HTTPS only), for example
https://s4.acme.com.Service Path — the entitlement OData service or report path relative to the base URL, exposing who can wire money, approve POs, modify vendors, or release payments (read-only).
Service Account Username / Service Account Password — a dedicated service account with read-only access. The password is stored encrypted and never displayed again.
Click Save ERP Configuration. Once connected, Herd syncs daily; Sync now pulls immediately, and the tile shows outcome counts: Matched, Updated, Flagged (high-value), Cleared, and Unmatched. If the ERP starts rejecting Herd's permissions, the tile shows an Auto-sync paused warning — fix the permissions and click Sync now to resume.
Dormant-vendor phishing simulations
Once vendor data has synced, the tile shows a Dormant vendors panel — vendors you haven't paid in roughly 18 months. These make ideal lures: an "updated bank details" or "overdue invoice" email from a vendor your finance team vaguely remembers is exactly how real vendor fraud arrives.
Each row shows the vendor, its domain, and when it was last paid. Click Launch simulation to have Herd generate a vendor-fraud phishing template impersonating that vendor. Generated templates land unapproved on the auto-generated simulations review surface — use the Review simulation link to inspect and approve before anything is sent, and the lure sends from the vendor-styled domain, not your own.
Disabling
Click Disable on the tile to stop the sync. Entitlement data already synced is kept, but high-value-target flags stop updating until you reconnect.
Last updated