Platform
The transactions GRC can't see.
Tcodex classifies every transaction by its SE93 type, resolves what each one really runs, and surfaces custom 'wrapper' transactions — like ZME23 quietly calling ME23N — that bypass GRC's transaction-level SOD checks entirely. Each finding carries its role-reach blast radius.
Exposetcodex
The transactions GRC can't see
0GRC reported
vs7wrappers Tcodex exposed
ZME23→ME23Ncustom T-code silently bypasses the SOD check- Classify every transaction. Resolve each T-code by its SE93 type — Dialog, Report, Parameter, Variant, OO-Method, Area-Menu — and what it actually runs.
- Expose wrapper transactions. Custom T-codes like ZME23 that quietly call ME23N bypass GRC's transaction-level checks entirely. Tcodex resolves the chain and flags them.
- Role-reach blast radius. Every wrapper finding carries the number of production roles that grant it — so you triage by real exposure.
Tcodex · Wrapper FindingsSearch… ⌘KAC
Wrapper Findings
142 T-codes classified7 wrappers3 MM3 FI1 HR
| Custom T-code | Type | Wraps | Reach | Domain | |
|---|---|---|---|---|---|
| ZME23 | PARAMETER | ME23N | 3 | MM | WRAPPER |
| ZFB03_CUST | PARAMETER | FB03 | 2 | FI | WRAPPER |
| ZZ_CHAIN1 | PARAMETER | ME23N | 1 | MM | WRAPPER |
ZME23Display Purchase Order — custom default screenrole reach 3
ZME23→ME23NWRAPPER → ME23N
GRC AC treats every T-code as an opaque string. ZME23 wraps ME23N, so 3 production roles silently grantaccess that GRC's transaction-level SOD checks report as zero.
Interactive replica · illustrative data — no real client systems or content.
Try Tcodex in the live app ↗