Skip to main content
SAP integration

Operations and evidence

SAP monitoring alerts as incidents, HANA and EarlyWatch Alert evidence, SAP authorisations and SoD, licence measurement and the read-only Cloud ALM bridge.

Beyond transports, the SAP integration brings day-to-day SAP operations into TENSOR: monitoring alerts become incidents, HANA and EarlyWatch Alert data become evidence on the CI, SAP role assignments are checked against a risk catalog, and user-master data feeds licence measurement. For cloud transitions, Cloud ALM records are mirrored read-only.

Monitoring alerts to incidents

  • CCMS and Solution Manager alerts create real incidents with SAP as reporting source and the alarm ID as reference.
  • When the alert's SID matches an SAP system CI, the incident is linked to that CI as the affected CI.
  • A repeated alert on an open incident increases its occurrence count instead of creating a duplicate. After the incident is resolved, a new alert opens a new incident.
  • Severity follows a per-connection map. By default level 1 maps to SEV1, 2 to SEV2, 3 and 4 to SEV3, and 5 to SEV4. The agent maps CCMS colours red, yellow and green to levels 1, 3 and 5. The per-connection override has no screen yet.

Alerts arrive through the agent's monitoring collector or through a signed webhook. Incidents created this way follow your tenant's incident SLAs and notifications — see Incidents.

Alert acknowledgement write-back to SAP — Planned, not yet available. Acknowledging the incident in TENSOR does not clear the alarm in SAP today.

HANA status

Each HANA snapshot shows:

  • replication role (Primary, Secondary, No replication) and replication lag;
  • full and log backup age;
  • tablespace usage;
  • capture time;
  • BackInt tool (Veeam, Commvault, Dell PPDM).

Risk badges make the thresholds visible:

MeasureBadge
Full backup older than 24 hoursAt risk
Log backup older than 1 hourAt risk
Tablespace at 85 percentWarning
Tablespace at 95 percentCritical

The HANA database CI is updated with replication role, last full backup and last restore test through normal CMDB versioning, so the CI history shows how backup and replication state changed over time.

BackInt job cross-reference (for example Veeam) — Planned, not yet available. The HANA snapshot shows which BackInt tool is in use; the cross-reference to that tool's jobs is not built yet.

EarlyWatch Alert evidence

EarlyWatch Alert (EWA) reports are uploaded as PDF per SAP system, with their period. Each file is virus-scanned and kept as evidence, and appears both in the list under EarlyWatch Alert evidence and on the SAP system CI under EWA reports.

  • The newest report marks the evidence Evidence current. If the newest report is older than 100 days, the badge changes to Evidence stale.
  • Removing a report only hides it; the file and the audit trail stay.

EWA evidence is partially available: manual upload works; upload by the agent is planned.

SAP authorisations and SoD

The authorisations collector reads SAP role assignments, and TENSOR checks them for risky combinations:

  • Role assignments per SAP connection, with composite and single roles distinguished from the role hierarchy.
  • User mappings of SAP users to TENSOR users per connection.
  • A curated catalog of 53 risky role pairs across procure-to-pay, finance, order-to-cash, user administration, Basis and development, and HR, each with its regulatory reference. Wildcards such as Z_FI_AP_PAYMENT_* cover customer Z-role families.
  • SoD violations per connection, listing users who hold a risky combination, with the rule and its regulatory reference.
  • The catalog is included in the Berechtigungskonzept export (needs the flag bait_berechtigungskonzept_export).

This area is partially available: assignments and findings are visible, but SAP-to-TENSOR user mappings cannot yet be created in the UI.

You load the catalog with Seed SoD risk catalog in the initial setup. You read the results on the Authorizations page of the SAP settings (/settings/sap/authorizations), which is not yet linked in navigation and is English only. When you find a violation, remove the risky combination in SAP or document an exception in your authorisation process; the next sync shows the new state.

SAP usernames and role assignments are classified as identifying personal data.

Licence measurement (USMM and SLAW)

TENSOR schedules USMM measurement runs per system. For each due run, the agent collects the user-master facts — user, user type, name — and TENSOR records the measurement. SLAW aggregation across systems counts a named user once, at their highest licence type. A failed run is recorded as failed, never silently skipped. The USMM scheduler runs daily at 03:00 UTC, and the licence true-up offers an SAP USMM vendor format.

The agent does not execute SAP's USMM transaction. A formal licence audit still runs USMM in SAP, so results can differ from SAP's own USMM.

Licence measurement is partially available: collection and recording exist, but scheduling runs and viewing SLAW results have no screen yet.

Cloud ALM bridge

For tenants moving through Cloud ALM, TENSOR reads Cloud ALM tasks and Business Service Management events read-only and shows them under Cloud ALM records, with Kind and Status filters.

  • The poll ticks every 15 minutes and, by default, fetches each connection every 30 minutes, with backoff.
  • Requirements have no public read API; they can be delivered by push only.
  • When both a Cloud ALM record and its linked TENSOR record changed since the last sync, the record shows Drift. Resolve the difference in the leading system.
  • TENSOR never writes back to Cloud ALM.

Cloud ALM drift, like transport drift and degraded agents, raises an integration health event on the connection.

Step-by-step instructions for these areas are split by audience: HANA and EWA in Guides for setup and Basis administrators, SAP-raised incidents in Guides for change managers and the CAB, and authorisations, the Berechtigungskonzept and Cloud ALM in Guides for auditors and migration.