ROK
ROK is an organization-centric hyperautomation platform that unites a living org chart, no-code and generative-AI application building, and native identity governance in a single cloud hub. Built by a French vendor for complex, multi-entity, regulated organizations.
What is ROK?
ROK describes itself as an organization-centric hyperautomation platform. Instead of starting from an application and bolting governance on afterwards, it starts from the real organizational chart and derives processes, access rights and compliance from it. The vendor frames the contrast bluntly: the market builds the application first, giving it roles and then assigning users and security, whereas ROK builds the organization first, so every person exists with a role, tasks flow to people, and security follows. It references the Gartner BOAT category, Business Orchestration and Automation Technologies, while claiming to stand apart from it.
Three pillars structure the product. Orchestrate is the living org chart: multi-axis, covering hierarchical, matrix, functional and geographic views, and synchronised with the HRIS and corporate directories in either direction, the HRIS feeding ROK or ROK driving the HRIS. Create is the hyperautomation layer: no-code BPM, workflow and RPA building, an advanced rules engine, and a generative AI that turns a plain-language request into a complete application with flows, screens, forms, business rules and documentation. That AI is presented as external and working without direct access to internal data. Secure is native identity governance and administration: rights derive from the org chart rather than from a separate IAM project, an approach the vendor calls architectural security and compliance by design, aimed at DORA, ISO 27001, GDPR, SOX and NIS2.
Around that core sit Team Management with Kanban, Gantt, PERT and lean boards, AI-assisted connectors, a browser-based user portal, and a product range: ROK Lifecycle for arrivals and departures, ROK Index for document governance, ROK Risk for internal audit, ROK Access for ERP and SAP entitlements. The platform is cloud, multi-entity and extensible, connecting to HRIS, ERP, SAP, CRM, document management, ITSM and directories such as Active Directory, LDAP and Azure AD. The portal requires no installation and runs on desktop, tablet or mobile, while a modelling studio is installed separately.
The home page advertises deployment in under a month, 75% lower operating costs, 28 countries served and twelve years of R&D, with customer references including HSBC, Elis, Novares and Transdev. The publisher is SAS OP.Serv, in Paris, trading as ROK Solution.
What it does
- Model the real organization in a multi-axis org chart, hierarchical, matrix, functional and geographic, synchronised with the HRIS and corporate directories
- Build business applications and workflows in no-code, or generate them from a plain-language description with generative AI
- Grant, review and revoke access rights automatically as people join, move or leave
- Enforce segregation of duties in real time and run periodic access review campaigns with manager sign-off
- Govern SAP roles, profiles and licences from the org chart, without going through SAP GUI
- Centralise documents, procedures and audit evidence with versioning and OCR
- Generate compliance reports on demand for SOX, GDPR, ISO 27001 and NIS2
When to use ROK / When not to
A quick filter to help you decide if ROK is the right fit.
When to use ROK
- Multi-entity, multi-site groups whose matrix or hybrid structure no single HRIS, ERP or directory manages end to end
- CIOs, CISOs and IAM teams that want access rights to follow HR movements automatically, from joiner to mover to leaver
- Regulated organizations in banking, insurance and supervised professions working towards DORA, SOX, ISO 27001, NIS2 or GDPR evidence
- Enterprises running SAP at scale that need to govern profiles, segregation-of-duties matrices and licence consumption from outside SAP GUI
- Business teams that want to build their own applications and workflows without developers, but inside a framework their IT department still governs
When not to use ROK
- Buyers looking for a tool they can price and subscribe to online: there is no public pricing and no self-service sign-up, every route goes through a meeting or the contact form
- Projects that need customer identity management: the vendor explicitly states that ROK is not positioned as a CIAM
- Small structures with no HRIS or corporate directory to synchronise and no formal organizational model to describe
- Developers who expect a documented public API: none is published, only no-code building of connectors towards third-party APIs and web services
- Teams that just want to sketch a quick prototype, which the vendor rules out itself, or to open a portal to the general public rather than to internal users
How to use ROK
A typical end-to-end flow, from setup to results.
- Request a meeting through the Book a meeting page or send the contact form; the vendor promises a reply within 24 hours
- Ask for a trial: an acknowledgement email arrives first, then a second email with your credentials and access links
- Sign in to your ROK workspace with those credentials and open the web user portal
- Install the modelling studio from the link provided and follow the getting-started guide
- Model your organization: synchronise the org chart with your HRIS and directories, choosing whether the HRIS feeds ROK or ROK drives the HRIS
- Design an application in four steps: draw the flow by drag and drop, assign the roles, design the interfaces, then set the rules and connect existing tools such as ERP, CRM or HRIS
- Or describe the need in plain language and let the generative AI produce the flow, interfaces, rules and documentation, then edit what it returns
- Build the connectors you need in no-code towards any third-party API or web service, with the AI design assistant
- Switch on identity governance: derive access rights from the org chart, set segregation-of-duties rules and launch access review campaigns
- Roll out progressively, one site, one user group, one sensitive application, an SAP perimeter or a single access review, and let end users work from the seven-tab portal on desktop, tablet or mobile
Pros & Cons
Pros
- One platform for three things usually bought separately: an organizational repository, no-code automation and access governance
- Access rights derive from the org chart, which structurally reduces orphan accounts, accumulated entitlements and forgotten revocations when someone leaves
- No-code that business teams can actually use, but inside a framework the IT department governs, which is a credible answer to shadow IT
- Generative AI that produces a complete application, flows, interfaces, rules and documentation included, rather than suggestions to assemble by hand
- Unusually deep SAP expertise for a no-code platform: profiles, SoD matrices and licence optimisation with a cost dashboard
- Substantial customer references in demanding sectors, including HSBC in banking, Elis in services, Novares in industry and Transdev in transport
- French publisher, website hosted by OVH in France and French law applicable, with twelve years of R&D and a patented innovation claimed
Cons
- No public pricing anywhere on the site: no price page, no rate card and no order of magnitude across the 86 published URLs
- No terms and conditions published; the only legal pages are the legal notice, the privacy policy and the cookie policy
- No public API documentation, only the ability to build connectors in no-code
- No data processing agreement, no sub-processor list and no trust or security page
- The site never states where the platform's customer data is hosted; the only host named is the website's, and nothing is said about model training or a customer-data opt-out
- No certification is claimed by the publisher: ISO 27001, SOX and NIS2 appear as frameworks the platform helps cover, not as credentials ROK holds; product interface languages are not announced either
- Self-service trial sign-up has disappeared, the Get started for free link now redirecting to the contact form, and several headline figures, 75% lower operating costs, deployment in under a month, tenfold and hundredfold gains, come without any published methodology
Pricing & Plans
No pricing is published. A review of the 86 URLs listed in the site's sitemap found no price page, no rate card, and no amount, currency or billing unit anywhere. The commercial model observed is contact-sales: every entry point, whether the Book a meeting page or the contact form, leads to a conversation with the vendor. No permanent free plan is documented. A trial exists but must be requested, the former self-service sign-up page now redirecting to the contact form. The only economic argument published is indirect and concerns SAP perimeters, where the vendor claims that reducing unused SAP licences by 20% often generates savings that fully finance the entire ROK project. Prospective buyers should therefore expect a quotation-based engagement with no public entry price.
Data, GDPR & hosting
A consolidated view of how ROK handles your data.
GDPR overview
GDPR compliance is claimed explicitly: the privacy policy states that the publisher complies with the General Data Protection Regulation and refers to French and European law, notably Regulation 2016/679 of 27 April 2016. Rights of access, rectification, objection and withdrawal or deletion are offered and can be exercised by post at 3 Rue du Faubourg Saint-Honore, 75008 Paris, by email at contact@rok-solution.com, by phone on +33 1 42 81 51 98 or through the contact form. A data protection officer is designated: OP.Serv, at the same email address. The publisher being established in France, no Article 27 EU representative is required. Two gaps remain: no data processing agreement and no sub-processor list are published, and the policy covers only the website contact form, not the personal data handled inside the platform.
Who owns the data?
The published privacy policy covers only the data collected through the website contact form: first name, last name, email, phone, job title, company and message. OP.Serv acts as controller and also names itself as data protection officer, reachable at contact@rok-solution.com. It states that this data serves one purpose only, replying to the enquiry, that it is never used for commercial or advertising purposes, and that it is never transmitted or resold to third parties. No terms and conditions are published, so nothing on the site addresses who owns the org-chart records, documents, workflows and audit evidence processed inside the ROK platform itself. That point has to be settled contractually.
Reuse rights
One purpose only is declared for the data collected on the website: answering the message sent through the contact form. Statistical cookies are set through Google Analytics behind a consent banner that can be refused, and cookies are kept for thirteen months at most. The privacy policy acknowledges that some technical services, namely hosting, security and audience measurement, may sit outside the European Union, and states that those established in the United States adhere to the Data Privacy Framework validated by the European Commission. On the product side the vendor says its generative AI builds applications from the organizational chart without direct access to your internal data, but nothing is published about model training, about any reuse of customer data or about an opt-out, and neither a data processing agreement nor a sub-processor list is available. Whether a customer may freely reuse the data it extracts from the platform, and under which conditions, is therefore not documented anywhere on the site and must be clarified before signing.
Data retention & training
Hosting summary
A distinction has to be made between the website and the platform. For the website, the legal notice names the host: OVH SAS, 2 rue Kellermann, BP 80157, 59053 Roubaix Cedex 1, France. DNS resolution matches that picture, the domain pointing to 213.186.33.16, an address geolocated in France (Dunkirk, AS16276 OVH SAS). The publisher is established in Paris and declares French law applicable, so the website falls under French and European jurisdiction. For the ROK platform itself, nothing is published: no page states in which country or region customer data is stored, no data residency option is described, and there is no trust or security page. The privacy policy adds one caveat that concerns the website, namely that some technical services covering hosting, security and audience measurement, Google Analytics included, may be located outside the European Union, and that those established in the United States adhere to the Data Privacy Framework validated by the European Commission. Buyers with data residency requirements should obtain a written hosting commitment from the vendor, since the website cannot answer that question.
Things to keep in mind
Risks and trade-offs to weigh before adopting ROK.
- No public pricing: the budget cannot be estimated before a commercial conversation, and no order of magnitude exists anywhere on the site
- No terms and conditions published, so contractual conditions, liability and the ownership of data processed inside the platform cannot be reviewed before contact
- No data processing agreement and no sub-processor list: both must be requested explicitly during procurement, especially where personal data will flow through the platform
- The site does not say where the platform's customer data is hosted, and says nothing about model training or an opt-out covering customer data
- ISO 27001, SOX and NIS2 are frameworks the platform helps cover, not certifications the publisher holds; the two should not be confused in an audit file
- Self-service trial sign-up no longer exists, the Get started for free link redirecting to the contact form, so plan for a sales cycle rather than an evening of hands-on testing
- Because access rights are derived automatically from the org chart while generative AI writes whole applications, an inaccurate organizational model or an unreviewed generated workflow propagates silently; performance claims are published without methodology, so human review of the model, of what the AI produces and of the vendor's figures remains essential
Setup & Integrations
Technical difficulty
Moderate, and lighter than a classic integration project. Applications are built without code through four visual steps, flow, roles, interfaces, then rules and connections, and the vendor claims an application in thirty minutes with generative AI and a deployment in under a month, with progressive rollout on one site, group or SAP perimeter. It remains an information-system project: it presumes a modellable organization and an HRIS or directory to synchronise, connector building requires reading the target software's documentation, and the vendor concedes that effort depends on existing data quality and scope.
Deployment
Integrations
Behind ROK
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement ROK.
Frequently asked questions
What makes ROK different from other automation platforms?
Does ROK replace our existing applications?
What happens when someone is onboarded, changes role or leaves?
Does ROK integrate with Active Directory, LDAP or an IAM we already run?
Is there a public API?
How much does ROK cost?
Can I try ROK before buying?
Do we have to install anything?
Which compliance frameworks does ROK cover, and is it ISO 27001 certified?
Where is customer data hosted?
Should you pick ROK?
ROK makes a genuinely unusual bet. Where most platforms build an application first and add governance later, it turns the organizational chart into the origin of both processes and access rights, so an onboarding, a transfer or a departure moves entitlements without a separate identity project. That single idea is what sets it apart from BPM suites, RPA vendors and IAM tools alike, and it runs consistently through the product, from the no-code builder to the segregation-of-duties engine.
The depth on SAP is the second surprise: profiles and roles managed outside SAP GUI, SoD matrices, automatic licence reclamation with a real-time cost dashboard. That level of specialisation is rare for a no-code platform and, combined with access review campaigns and on-demand SOX, GDPR, ISO 27001 and NIS2 reporting, it explains references such as HSBC, Elis, Novares and Transdev, serious names in demanding sectors.
The counterpart is commercial and documentary opacity. Across 86 published pages there is no pricing, no terms and conditions, no API documentation, no security or trust page, no data processing agreement and no sub-processor list. The site never states where platform data is hosted, says nothing about model training, and the self-service trial has been replaced by a contact form. Several headline claims, 75% lower operating costs, deployment in under a month, tenfold and hundredfold gains, arrive without methodology, and ISO 27001, SOX and NIS2 are frameworks the platform helps cover rather than certifications the publisher holds.
The result is a differentiated and credible product from a modest French vendor whose visibility remains largely domestic. If the organization-first premise fits your context, ROK deserves the meeting, but expect pricing, contractual terms and hosting commitments to come out of that conversation rather than from the website.
- Choosing a selection results in a full page refresh.
- Opens in a new window.