SAP Concur exposes no admin/privileged-role or audit/activity API, so this integration is an access-inventory source (users and Spend Role Extension role assignments) rather than a posture or detection source.
Prerequisites
- Administrator permission on the Oleria workspace
- Access to your SAP Concur company’s Authentication Admin settings
Create an OAuth 2.0 application in SAP Concur
1
Open OAuth 2.0 Application Management
Sign in to SAP Concur and go to Administration → Company → Authentication Admin → OAuth 2.0 Application Management.
2
Create a new application
Create a new OAuth 2.0 application. After it’s created, note the Client ID and Client Secret shown - you’ll need both to connect Oleria.
3
Note your Company UUID
On the same page, note your company’s Company UUID. It’s shown alongside the Company Request Token described in the next step.
4
Generate a Company Request Token
From the same OAuth 2.0 Application Management page, generate a Company Request Token.
The Company Request Token is valid for 24 hours and is only needed for the very first connection. Oleria exchanges it for a refresh token during setup and doesn’t need it again on later syncs.
Connect SAP Concur to Oleria
1
Open the integration
Log in to your Oleria workspace, navigate to Integrations, and select SAP Concur.
2
Complete the connection form
A side panel opens. Enter the following details:
- Company UUID - your SAP Concur company’s UUID, from Authentication Admin → OAuth 2.0 Application Management
- Client ID - the Client ID of the OAuth 2.0 application you created
- Client Secret - the Client Secret issued when the OAuth 2.0 application was created
- Company Request Token - the 24-hour token you generated in the previous section
- Starting Region (optional) - leave as United States unless your SAP Concur contact told you otherwise, or you’re connecting to a Test/Implementation environment
Oleria automatically discovers and stores your company’s actual API host from the first token exchange, so an incorrect Starting Region selection never misroutes later syncs.
3
Authenticate
Select Authenticate to complete the connection.
4
Verify the connection
Verify the SAP Concur integration status from the connected integrations page.
What Oleria discovers
Remediation actions
Beyond discovery, Oleria can act on SAP Concur user accounts to remediate risk. The following actions are supported:Known limitations
- SAP Concur has no admin/privileged-role signal, so Oleria can’t distinguish admin accounts for this integration.
- SAP Concur has no audit or activity log API for identity/access actions, so activity data isn’t available for this integration.
- Role assignment and removal aren’t supported as governance actions. Concur’s Spend Role Extension roles are a business-process concept managed in Concur’s own admin console.
- If the refresh token issued during setup expires or is revoked (SAP Concur’s typical refresh token lifetime is about 6 months), sync starts failing. Recovering requires generating a new Company Request Token and reconnecting the integration from scratch.

