Skip to content

Creating a SAP Effective Licence Position (ELP)

SAP's own LAW and USMM reports were built to help SAP settle a true-up, not to help you optimise. What an Effective Licence Position actually requires, and the four things LAW will never tell you.

Many organisations believe the tools SAP supplies — LAW and USMM — will give them what they need to optimise their SAP licensing. That is a common and expensive mistake.

Those tools exist to aggregate audit data for contract compliance. They were built for SAP’s benefit, not yours, and they carry no usage data for named users at all. They will not produce an Effective Licence Position.

What an ELP actually is

An Effective Licence Position compares your entitlements against what is actually deployed in the business.

Getting to one requires a full inventory of software assets, reconciled against your licence documentation and against the installations themselves. The output tells you where you are over-deployed and where you are under-licensed — and, crucially, what to do about each.

That last part is what separates an ELP from a compliance report. A compliance report tells you the gap. An ELP tells you the gap and the options.

Why the LAW output is a worst case, not a position

The LAW report is taken as-is by SAP and used for true-ups. SAP has no interest in whether the position it describes is optimised, because optimisation reduces what you owe them.

So what LAW shows you is the licences that have been allocated, not how they are being used, and not whether each user holds the licence type that matches what they actually do. It does not show whether a user is using SAP at all, or at what level of functionality.

There is a specific trap inside this. Where no licence type has been assigned to a user in SAP, that user defaults to Professional — the most expensive type. Your LAW-derived position is therefore your worst-case scenario almost by construction. Basic housekeeping alone will improve it: expiring dormant users, assigning licence types deliberately rather than by default, and reviewing role allocation.

The four things LAW will not tell you

LAW omits exactly the information you need to move from a compliance number to an optimised one:

  • Unused licences — entitlements you hold and nobody is consuming.
  • Inactive users — accounts that have not touched the system for months, or ever, and are still consuming a licence.
  • Role analysis — what each user’s assigned roles actually permit, which is what determines the licence type they need.
  • User usage — whether the person behind the account uses SAP, and how.

Every one of those is a cost lever. None of them appear in the report SAP asks you to send back.

Indirect access

Indirect access is where organisations increasingly find themselves non-compliant. It occurs where a non-SAP application reaches SAP data, typically through a single service account. Under a named user metric, the people behind that account may each need a valid named user licence for you to remain compliant.

The definition of indirect access in the SAP licence agreement has historically been vague, which means you need to be able to identify and manage it yourself rather than wait for someone else to interpret it at a true-up.

LAW can help you identify indirect access after it has occurred. By that point you are already non-compliant and already liable. There is no early warning in it.

Editor’s note, July 2026. This post was written in 2016. SAP introduced its document-based Digital Access model in 2018, which licences indirect use by counting the documents that indirect use creates rather than the people behind it. That changes the shape of the exposure without removing it — you still have to know which integrations are generating documents, and at what volume, to tell which model leaves you better off. The point below about needing your own measurement stands; the assumption that named user is the only route does not.

Producing the position

Your SAP Effective Licence Position is produced by comparing discovered installations of named users and packages against your entitlements. It is what you will be presented with at the time of an audit — so it is worth being the one who produced it first.

This is where doing the work by hand stops being viable. Most SAP landscapes run to many thousands of users across multiple systems and multiple packages, often across several countries. A manual reconciliation is out of date before it is finished.

What the SAP engine in CerteroX SAM does

CerteroX SAM carries a dedicated SAP licence engine, one of six publisher engines in the product alongside Microsoft, Oracle, IBM, Adobe and Salesforce. It addresses the LAW gaps directly.

It reads SAP without touching production. A non-invasive ABAP connector pulls named users de-duplicated across systems, together with roles, role groups, engines and authorisation definitions. The de-duplication matters more than it sounds: SAP licences per named person, so the same individual holding accounts on four systems must resolve to one licence, not four.

It proposes the right licence type per user. Priority-ordered Analysis Rules encode your agreement’s licence definitions and apply them to what each user’s roles and authorisations actually permit. You get your current position, a suggested position and an optimal position side by side — which is the comparison the LAW output structurally cannot give you.

It measures usage, not just allocation. AppsMonitor records first-used and last-used dates per application and reports a utilisation figure over a rolling 90-day window. That is how dormant and inactive users surface as a list you can act on rather than a suspicion.

It computes the position continuously. The Effective Licence Position is expressed as purchased, used, available, required, variance and exposure, with overspend and additional-licence-required calculated alongside it. It is a continuous compliance position rather than a point-in-time reconciliation you run when a letter arrives.

The point

Creating an ELP is the first step, not the destination. The position LAW produces is your worst case; the position you produce yourself, with role analysis and real usage behind it, is the one worth negotiating from.

Do the housekeeping — expire the dormant accounts, assign licence types deliberately, review the roles. Then optimise. The gap between those two numbers is usually the whole business case.

Book a demo, or read more about CerteroX SAM.

Related reading

Other posts covering the same ground.

  • Oracle ULA – What are the dangers and how do you avoid them?

    An Oracle Unlimited Licence Agreement is only unlimited within its clauses. What certification actually asks of you, where toxic consumption creeps in, and why the measurement work has to start at the beginning of the term rather than the last six months.

    • SAM
    • Governance
    6 min
  • Microsoft Licensing Update – August 2025

    Microsoft's August 2025 Product Terms changes: Extended Term standardised across programmes, Exchange and Skype for Business Server Subscription Editions, the Exchange and Windows 10 ESU programmes, and the Dynamics 365 F&O enforcement dates.

    • SAM
    • Governance
    4 min
  • Oracle ULA: know your options. Exit with confidence.

    Renew, rescope or exit — an Oracle ULA gives you three routes and a narrow window to choose between them. The questions to settle first, and a six-point health check to see how ready you actually are.

    • SAM
    • Governance
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.