Skip to main content
SAP integration

Guides for auditors and migration

Step-by-step guides to review SAP authorisations, generate the Berechtigungskonzept, read Cloud ALM records, import and supersede SolMan history, export archive evidence and cut over from Solution Manager.

These guides are for auditors and compliance officers reviewing SAP evidence, and for tenant administrators moving from Solution Manager. For background, see Operations and evidence and SolMan migration.

Review SAP authorisations and SoD violations

Find SAP users with risky role combinations. Prerequisite: integration.config.read; the authorisations collector is active.

  1. Open the Authorizations page of the SAP settings (address /settings/sap/authorizations).
  2. Select an SAP connection.
  3. Read SoD Risk Violations: users holding a risky role pair, with the rule and its regulatory reference.
  4. Check User Mappings (SAP user to TENSOR user) and Role Assignments.

Then remove the risky combination in SAP, or document an exception in your authorisation process. The next sync shows the new state.

The Authorizations page is not yet linked in navigation and is English only. User mappings can be read here but cannot yet be created in the UI.

Generate the Berechtigungskonzept with SAP risks

Produce the authorisation concept document including the SAP SoD catalog. Prerequisite: reporting.berechtigungskonzept.export; flag bait_berechtigungskonzept_export.

  1. Open Reports → Berechtigungskonzept.
  2. Select Generate Berechtigungskonzept.
  3. Download the result from Generation history.

Review Cloud ALM records

See Cloud ALM tasks and events next to TENSOR during a transition. Prerequisite: integration.config.read; a Cloud ALM connection.

  1. Open Settings → SAP integrations and go to Cloud ALM records.
  2. Filter by Kind (Incident, Task, Requirement) and Status.
  3. Look for the Drift marker: both the Cloud ALM record and its linked TENSOR record changed since the last sync. Resolve the difference in the leading system.

TENSOR reads Cloud ALM only; it never writes back. Requirements arrive by push only, because Cloud ALM has no public read API for them.

Import SolMan history

Preserve ChaRM change documents and ITSM tickets in a sealed archive. Prerequisite: integration.config.manage; a CSV export from Solution Manager.

  1. Open Settings → SolMan archive imports.
  2. Paste the file into CSV content and enter CSV filename and Batch label.
  3. Select Dry-run import.
  4. Review the report: row counts, rejected rows with reasons and the Overlap warning for records already imported.
  5. Fix rejected rows in the export if needed and repeat the dry run.
  6. Select Confirm import.

The batch is imported and sealed with its content hash in the audit chain. Its records appear in the SolMan archive.

XLSX files are not read directly. Export Solution Manager data to CSV; every SolMan export tool can do this.

Supersede an import batch

Correct an earlier import without changing sealed data. Prerequisite: integration.config.manage.

  1. Open Settings → SolMan archive imports.
  2. Select Supersede prior batch below any batch in the list.
  3. Choose the batch to be replaced from the list.
  4. Paste the corrected CSV and enter a Batch label.
  5. Select Confirm import. Select Cancel to leave without changes.

The corrected data is imported and sealed as a new batch, and the old batch is marked as superseded. Both remain on record.

Browse the SolMan archive and export evidence

Answer audit questions about historic changes and tickets. Prerequisite: sap.archive.read; export needs sap.archive.export.

  1. Open Changes → SolMan archive.
  2. Search, and filter by Kind (ChaRM change, ITSM ticket), Status, Batch or Year.
  3. Open a record to see its Provenance: Import batch, Imported at, Content hash and Sealing audit.
  4. To hand evidence to an auditor, open Settings → SolMan archive imports and select Export evidence on the batch.

The export is a CSV with a signed manifest. Requesters and assignees are masked for roles without de-masking rights.

Run the SolMan parallel run and cut over

Move from Solution Manager to TENSOR in a controlled way. Prerequisite: integration.config.manage.

  1. Open Settings → SAP integrations and go to SolMan migration.
  2. Under Migration mode, choose Parallel run.
  3. Select Open migration dashboard (page SolMan migration).
  4. Review Agent health, Inventory coverage, Transport-sync freshness, Drift and Archive import.
  5. Work through the Cutover checklist; select Fix next to an item to open the page that resolves it.
  6. When every item is green, choose Cut over and confirm Record the cutover?

The cutover date is recorded in the audit trail and the dashboard widget shows Migrated from Solution Manager.

The checklist item Production CAB configured for every landscape checks the CAB role per landscape stage, which has no screen to set it yet.