SAP integration
Bring SAP transports, systems, monitoring alerts and authorisation data into the same change, incident, CMDB and audit processes as the rest of your IT.
Preview — not yet field-tested
The SAP integration is built, but it has not yet been validated against real customer SAP environments. The connector agent and every collector have been tested in fixture mode with SAP-shaped sample data only; no live SAP system, HANA database or Cloud ALM tenant has been connected yet. Run a pilot in a test tenant against a non-productive SAP landscape before you use it for production transports or audit evidence.
The TENSOR SAP integration brings your SAP landscapes into the same change, incident, CMDB and audit processes as the rest of your IT:
- SAP transport requests become Changes, with approvals and separation of duties.
- SAP systems become configuration items in the CMDB.
- SAP monitoring alerts become incidents, linked to the system they concern.
- SAP authorisation data becomes evidence for your authorisation concept (Berechtigungskonzept).
The module is designed as a successor path for SAP Solution Manager ChaRM and ITSM, whose mainstream maintenance ends in 2027. It supports on-premises SAP (ECC, S/4HANA on-premises, Solution Manager) and cloud SAP (S/4HANA Cloud, SAP BTP, SAP Cloud ALM), and it lets you run TENSOR in parallel with Solution Manager until a measurable cutover checklist is complete.
Ingest, don't fetch
TENSOR never opens an RFC connection into your network. A small connector agent that you run on your own premises reads SAP and pushes signed data to TENSOR. Your RFC and HANA credentials stay on that machine. Only cloud systems (Cloud ALM) are called directly from TENSOR, read-only and through OAuth.
Who uses the SAP integration
| Persona | What they do |
|---|---|
| Tenant administrator | Switches the integration on, registers SAP systems, creates connector agents, defines landscapes, runs the initial setup, imports SolMan history and controls the migration mode. |
| SAP Basis administrator | Installs and runs the connector agent, confirms that scheduled transport imports were executed in SAP STMS, watches HANA and agent health. |
| Change manager | Works the Changes created from transport requests, schedules imports into maintenance windows, handles collisions and drift. |
| CAB member / change approver | Approves transport Changes through the normal TENSOR approval flow. |
| Service desk and incident manager | Handle incidents raised from SAP monitoring alerts. |
| Auditor, compliance officer | Read SAP settings, authorisation findings and the SolMan archive; export archive evidence. |
Problems the SAP integration solves
- Solution Manager end of maintenance. Transport-based change control, SAP-specific separation of duties and collision checks continue in TENSOR.
- Stranded history. SAP's own migration path does not carry ChaRM change documents and ITSM tickets. TENSOR imports them into a sealed, read-only archive.
- Unapproved transports. Every transport created in development becomes a Change, and TENSOR records when SAP moved a transport further than its Change allowed.
- Object conflicts. Two transports that touch the same SAP object are flagged before import.
- Authorisation evidence. SAP role assignments are checked against a catalog of 53 risky role combinations and feed the Berechtigungskonzept.
- Scattered monitoring. CCMS alerts, HANA backup status and EarlyWatch Alert reports land next to the CIs they concern.
Key concepts
| Term | Meaning |
|---|---|
| SAP connection | One SAP system registered in TENSOR, either RFC (on-premises) or OAuth 2.0 (cloud). Stored as an integration of kind SAP. |
| Landscape | A named transport path that maps a DEV, a QA and a PROD connection, for example the ERP landscape. |
| Connector agent | A command-line program you run on your network. It reads SAP via RFC (and HANA via SQL), and pushes signed envelopes to TENSOR. |
| Collector | One reading task of the agent: transports, system inventory, authorisations, licence measurement, monitoring alerts or HANA status. |
| Envelope | One signed, idempotent data package from the agent. A replayed envelope is recognised and not processed twice. |
| Transport request (TR) | An SAP transport, for example DEVK900123. In TENSOR it is linked to exactly one Change. |
| Landscape position | Where a transport currently is: DEV, QA or PROD, with the import timestamps. |
| Transport drift | A recorded moment where SAP moved a transport further than its Change allowed. Recorded, not blocked. |
| Collision | Two in-flight transports that change the same SAP object. |
| SolMan archive | Imported Solution Manager ChaRM changes and ITSM tickets, sealed into the audit chain and read-only. |
| Migration mode | Off, parallel run or cut over: how far the tenant has moved from Solution Manager to TENSOR. |
Where to find it
Everything is behind the capability flag sap_integration (default off). With the flag off, the SAP settings pages show SAP integration is off for this tenant instead of their content.
| What | Where |
|---|---|
| Switch the integration on | Settings → Regulatory features, flag sap_integration |
| Connections, initial setup, landscapes, HANA status, EarlyWatch Alert evidence, Cloud ALM records, SolMan migration | Settings → SAP integrations |
| Connector agents and their collectors | Settings → SAP connector agents |
| Transport auto-sync, drift and linked transports | The Transports page of the SAP settings, at /settings/sap/transports |
| SAP role assignments and SoD violations | The Authorizations page of the SAP settings, at /settings/sap/authorizations |
| SolMan history imports and evidence export | Settings → SolMan archive imports |
| Browsing the SolMan archive | Changes → SolMan archive |
| SAP collisions across all in-flight transports | Changes → Calendar, SAP collisions view |
| Transport drift, collisions and the import schedule for one transport | Cards and the SAP import schedule panel on the Change page |
| Berechtigungskonzept with SAP risks | Reports → Berechtigungskonzept |
The Transports and Authorizations pages are not yet linked in navigation — open them by their address. They, and the import schedule panel on the Change page, are English only for now.
A typical sequence per persona
| Persona | Typical sequence |
|---|---|
| Tenant administrator | Enable sap_integration → run initial setup → add SAP systems → define landscapes → create a connector agent → set collectors → switch migration mode to parallel run → import SolMan history. |
| SAP Basis administrator | Install and enrol the agent → run one pass → start the scheduler → watch heartbeats and HANA status → confirm executed imports. |
| Change manager | Review auto-created transport Changes → check collisions → schedule imports into maintenance windows → watch drift. |
| CAB member | Approve transport Changes; the system refuses approval by the Change creator. |
| Auditor | Check SoD violations and the Berechtigungskonzept → browse the SolMan archive → export batch evidence. |
In this section
- How it works — the ingest model, what data lands where, tenant isolation, background jobs, data protection, the audit trail and the technical detail for IT administrators.
- Roles and permissions — who can configure, schedule, confirm and force imports, and the separation-of-duties rules enforced in code.
- Connections and the connector agent — supported systems, landscapes, the agent, its states and its collectors.
- Transports and imports — transports as Changes, drift, object-level collisions and import scheduling.
- Operations and evidence — alerts to incidents, HANA status, EarlyWatch Alert reports, authorisations and SoD, licence measurement and the Cloud ALM bridge.
- SolMan migration — the sealed archive, migration mode, the parallel run and cutover.
- Compliance — the regulatory requirements the module produces evidence for, and the flags you need.
- Guides for setup and Basis administrators — switching on, connecting systems, landscapes, the agent, EWA and HANA.
- Guides for change managers and the CAB — auto-sync, reviewing, scheduling, confirming and forcing imports, and SAP-raised incidents.
- Guides for auditors and migration — authorisations, the Berechtigungskonzept, Cloud ALM, the SolMan archive and cutover.
- Troubleshooting and FAQ — symptoms, causes and what to do.
- Availability — the implementation status of every capability.
For the reasoning behind recording drift instead of blocking SAP, see SAP transport auto-sync — and why drift is recorded, not blocked.
Availability
What Vulnerability Management offers on the current release as of 24 September 2026, and the specified target behaviour of capabilities that are still planned.
How the SAP integration works
The ingest model, where each kind of SAP data lands in TENSOR, and the isolation, protection, audit and runtime details behind it.