Skip to main content
SAP integration

SAP integration

Bring SAP transports, systems, monitoring alerts and authorisation data into the same change, incident, CMDB and audit processes as the rest of your IT.

Preview — not yet field-tested

The SAP integration is built, but it has not yet been validated against real customer SAP environments. The connector agent and every collector have been tested in fixture mode with SAP-shaped sample data only; no live SAP system, HANA database or Cloud ALM tenant has been connected yet. Run a pilot in a test tenant against a non-productive SAP landscape before you use it for production transports or audit evidence.

The TENSOR SAP integration brings your SAP landscapes into the same change, incident, CMDB and audit processes as the rest of your IT:

  • SAP transport requests become Changes, with approvals and separation of duties.
  • SAP systems become configuration items in the CMDB.
  • SAP monitoring alerts become incidents, linked to the system they concern.
  • SAP authorisation data becomes evidence for your authorisation concept (Berechtigungskonzept).

The module is designed as a successor path for SAP Solution Manager ChaRM and ITSM, whose mainstream maintenance ends in 2027. It supports on-premises SAP (ECC, S/4HANA on-premises, Solution Manager) and cloud SAP (S/4HANA Cloud, SAP BTP, SAP Cloud ALM), and it lets you run TENSOR in parallel with Solution Manager until a measurable cutover checklist is complete.

Ingest, don't fetch

TENSOR never opens an RFC connection into your network. A small connector agent that you run on your own premises reads SAP and pushes signed data to TENSOR. Your RFC and HANA credentials stay on that machine. Only cloud systems (Cloud ALM) are called directly from TENSOR, read-only and through OAuth.

Who uses the SAP integration

PersonaWhat they do
Tenant administratorSwitches the integration on, registers SAP systems, creates connector agents, defines landscapes, runs the initial setup, imports SolMan history and controls the migration mode.
SAP Basis administratorInstalls and runs the connector agent, confirms that scheduled transport imports were executed in SAP STMS, watches HANA and agent health.
Change managerWorks the Changes created from transport requests, schedules imports into maintenance windows, handles collisions and drift.
CAB member / change approverApproves transport Changes through the normal TENSOR approval flow.
Service desk and incident managerHandle incidents raised from SAP monitoring alerts.
Auditor, compliance officerRead SAP settings, authorisation findings and the SolMan archive; export archive evidence.

Problems the SAP integration solves

  • Solution Manager end of maintenance. Transport-based change control, SAP-specific separation of duties and collision checks continue in TENSOR.
  • Stranded history. SAP's own migration path does not carry ChaRM change documents and ITSM tickets. TENSOR imports them into a sealed, read-only archive.
  • Unapproved transports. Every transport created in development becomes a Change, and TENSOR records when SAP moved a transport further than its Change allowed.
  • Object conflicts. Two transports that touch the same SAP object are flagged before import.
  • Authorisation evidence. SAP role assignments are checked against a catalog of 53 risky role combinations and feed the Berechtigungskonzept.
  • Scattered monitoring. CCMS alerts, HANA backup status and EarlyWatch Alert reports land next to the CIs they concern.

Key concepts

TermMeaning
SAP connectionOne SAP system registered in TENSOR, either RFC (on-premises) or OAuth 2.0 (cloud). Stored as an integration of kind SAP.
LandscapeA named transport path that maps a DEV, a QA and a PROD connection, for example the ERP landscape.
Connector agentA command-line program you run on your network. It reads SAP via RFC (and HANA via SQL), and pushes signed envelopes to TENSOR.
CollectorOne reading task of the agent: transports, system inventory, authorisations, licence measurement, monitoring alerts or HANA status.
EnvelopeOne signed, idempotent data package from the agent. A replayed envelope is recognised and not processed twice.
Transport request (TR)An SAP transport, for example DEVK900123. In TENSOR it is linked to exactly one Change.
Landscape positionWhere a transport currently is: DEV, QA or PROD, with the import timestamps.
Transport driftA recorded moment where SAP moved a transport further than its Change allowed. Recorded, not blocked.
CollisionTwo in-flight transports that change the same SAP object.
SolMan archiveImported Solution Manager ChaRM changes and ITSM tickets, sealed into the audit chain and read-only.
Migration modeOff, parallel run or cut over: how far the tenant has moved from Solution Manager to TENSOR.

Where to find it

Everything is behind the capability flag sap_integration (default off). With the flag off, the SAP settings pages show SAP integration is off for this tenant instead of their content.

WhatWhere
Switch the integration onSettings → Regulatory features, flag sap_integration
Connections, initial setup, landscapes, HANA status, EarlyWatch Alert evidence, Cloud ALM records, SolMan migrationSettings → SAP integrations
Connector agents and their collectorsSettings → SAP connector agents
Transport auto-sync, drift and linked transportsThe Transports page of the SAP settings, at /settings/sap/transports
SAP role assignments and SoD violationsThe Authorizations page of the SAP settings, at /settings/sap/authorizations
SolMan history imports and evidence exportSettings → SolMan archive imports
Browsing the SolMan archiveChanges → SolMan archive
SAP collisions across all in-flight transportsChanges → Calendar, SAP collisions view
Transport drift, collisions and the import schedule for one transportCards and the SAP import schedule panel on the Change page
Berechtigungskonzept with SAP risksReports → Berechtigungskonzept

The Transports and Authorizations pages are not yet linked in navigation — open them by their address. They, and the import schedule panel on the Change page, are English only for now.

A typical sequence per persona

PersonaTypical sequence
Tenant administratorEnable sap_integration → run initial setup → add SAP systems → define landscapes → create a connector agent → set collectors → switch migration mode to parallel run → import SolMan history.
SAP Basis administratorInstall and enrol the agent → run one pass → start the scheduler → watch heartbeats and HANA status → confirm executed imports.
Change managerReview auto-created transport Changes → check collisions → schedule imports into maintenance windows → watch drift.
CAB memberApprove transport Changes; the system refuses approval by the Change creator.
AuditorCheck SoD violations and the Berechtigungskonzept → browse the SolMan archive → export batch evidence.

In this section

For the reasoning behind recording drift instead of blocking SAP, see SAP transport auto-sync — and why drift is recorded, not blocked.