Appendix H · Plate H.1 — The Autonomous Enterprise
interactive walkthrough · running example: SAP MDG cost centre → SAP SuccessFactors position
Appendix H: Reference Integration Diagrams
End-to-end reference integration architecture — data flow across SAP Signavio, SAP LeanIX, WalkMe, SAP BTP, SAP AI, SAP Build Process Automation and SAP Build Work Zone, including execution, adoption and AI-consumption paths. Companion to "Integrating Architecture, Processes, and AI on SAP BTP" (SAP PRESS).
Our View of the Autonomous Enterprise
Appendix H · Reference Integration Diagrams — process · architecture · adoption · execution · AI-consumption paths
FP&A-controllable
Hybrid-aware · Policy-aligned
SAP API Policy v.4.2026a §2.2.2 compliant
The Governed
Grounding Chain
LLM → AI Hub, never LLM → spine
1
Agent / prompt intent
raised in the AI consumption
tier
2
AI Grounding Endpoint
the only door — policy gate
§2.2.2
3
GROUNDING_BUNDLE
validated, versioned,
role-scoped — from the spine
4
Model invoked
SAP-RPT-1 / LLM via AI Core
+ AI Hub
5
Inference
detect · score · explain ·
draft
6
INFERENCE_EVENT
model_version + content_hash
recorded
7
Hash-chained AUDIT_EVENT
joined to the immutable
chain
8
Validation funnel
SUGGESTION → human verdict →
spine effect
THE AI BOUNDARY
Experience & Interaction Surfaces
How people, partners and non-SAP systems meet the enterprise
SAP Applications
S/4HANA
CX
Concur
SuccessFactors
Joule Work
Hyper-Personalize
Multimodal / Live
Central Entry
Web & Mobile
Consumption Surfaces — each governed, role-scoped, audit-producing
SAP Build Work Zone
navigation
Joule
inquiry
SAP Build Process
Automation
workflow
AI Agents
autonomous
Customer & Partner Apps
extend the surface — same governance
Non-SAP Estate
A2A platforms · external services · zero-copy data
governed
AI Consumption Tier
Agents and models that consume the spine — only through grounding bundles
Agents
App-specific Agents
(S/4 · CX · Concur)
Custom Agents
Partner Agents
Gateway Agents & MCP
SAP AI Agent Hub
registers & governs non-SAP agents under
one contract · A2A: Vertex · Watson · Glean
3rd-party LLM agents
Enterprise iPaaS / RPA
In-house custom
AI Hub & Models
Generative AI Hub
SAP Domain Models
SAP-RPT-1
tabular FM
SAP-ABAP-1
3rd-Party LLMs
Runtime & Authoring
SAP AI Core
(inference)
Joule Studio (agent
authoring)
AI Launchpad
Data Products Studio
Reuse & Data Foundation
Doc AI
Predictive AI
Tabular AI
HANA Cloud — Knowledge
Graph · Vector Engine
Business Data Cloud —
Datasphere · SAC ·
Zero-Copy
governed
The Cross-Vendor Validation Funnel
Every suggestion — whatever its origin — enters one governed surface
Joule on S/4HANA
Joule reaching ECC
3rd-party LLM agent (via
AI Agent Hub)
In-house custom agent
SUGGESTION — single surface, risk_class routing
VALIDATION_VERDICT
ACCEPT
REJECT
MODIFY
High-risk classes require dual sign-off · “the controllability of a multi-vendor estate rests on the funnel, not on vendor goodwill”
governed
Governed API Surfaces
The only doors to the spine — no direct table access, ever
Ingestion API
Access API
Governance API
AI Grounding
Endpoints
AI
Event Mesh
SAP API Policy v.4.2026a §2.2.2 — no AI-orchestrated API call sequences. Agents receive validated bundles; they never assemble context from the spine’s APIs.
governed
The Canonical Data Spine — on SAP BTP
One writer per entity · explicit version · immutable, hash-chained lineage
Process & execution objects
PROCESS
PROCESS_VERSION
ACTIVITY
APPLICATION
INTERFACE
EXECUTION_CONTEXT
Master data & lifecycle state
MASTER_DATA_REFERENCE
ACTIVITY_MASTERDATA_REF
PUBLISH_STATE
VALIDATION_RESULT
INGESTION_LOG
Audit & AI-side join entities
AUDIT_EVENT
hash-chained
INFERENCE_EVENT
GROUNDING_BUNDLE
AI_MODEL
MODEL_VERSION
content_hash
DEPLOYMENT
AI consumes the spine ONLY as a validated, versioned, role-scoped GROUNDING_BUNDLE.
AI never publishes, never approves, never mutates canonical state.
Every inference advances the hash-chained AUDIT_EVENT — lineage is reconstructable from a single row.
governed
Governed Ingestion & Validation
Event-driven, idempotent, one entity per event — nothing reaches the spine unvalidated
Idempotent event
ingestion
VALIDATION_LOG (PASS /
quarantine)
Promotion →
PUBLISH_STATE
Reconciliation &
lineage
Validation is a precondition for consumption — no payload reaches an execution service or grounding bundle until a definitive verdict exists.
governed
Sources of Record
Each source owns its data — single writer; the spine is downstream
SAP Signavio
SAP LeanIX
WalkMe
SAP Cloud ALM
S/4HANA (Cloud)
ECC / on-prem
S/4HANA
hybrid bridge
SuccessFactors
Concur
The ECC bridge is a transition device, not a target architecture — the spine is the destination.
Identity &
Audit Spine
one identity · one audit chain
Corporate IdP
workforce + machine
identities
SAP IAS
identity federation hub
SAP IPS
principal & role sync
SAP BTP XSUAA + ATM
scopes · role collections
· trust
Token types
user · client-credentials
· AI-agent
Hash-chained
AUDIT_EVENT
Every ingestion,
consumption, inference
and verdict writes one
immutable, hash-linked
row.
Controller’s defence
a row plus its join graph
INFERENCE_EVENT
→ GROUNDING_BUNDLE
→ VALIDATION_VERDICT
→ AUDIT_EVENT
AI is a pattern detector, an anomaly scorer, an explainer and a draft-author. It is never the decider.
Authority is held by human roles and the service accounts explicitly delegated to act for them.
AI augments governance; it does not replace authority.
Our View of the Autonomous Enterprise — extended from the SAP Business AI Platform reference architecture (C. Knabel) into our governed-spine view.
Appendix H lead plate · “Integrating Architecture, Processes, and AI on SAP BTP” (SAP PRESS) · animated walkthrough in online supplements.
v1.0
grounding chain
audit / hash-chain
canonical spine
governed flow
principle / boundary
← Back
Next →
Use ← / → keys, or click a layer on the plate