SAP licensing is widely accepted to be one of the most complex models any major
publisher operates. The reason is structural rather than accidental. Unlike most
vendors, SAP licenses on usage — and then does not always define usage
explicitly or unambiguously. The gap between those two facts is where SAP
customers lose money, in both directions.
The named user
The primary metric for SAP applications is the Named User. It is assigned to a
person, not to a device or a session, and it is not shared. There are three
principal types:
- Professional user. Able to perform operational tasks such as system
administration or system management roles that fall within the agreed licence
metrics. This user also holds the rights specified for the SAP Application
Limited Professional User.
- Limited professional user. Performs limited operational roles as defined
by the software licence.
- Employee user. Performs tasks purely for their own use, not on behalf of
anyone else, as set out by the software licence.
Two things follow from this that catch people out.
The first is that the type is determined by what a user is entitled to do, not
what they actually did. A user with wide authorisations who logs in twice a year
is still classified on their authorisations. This is why over-classification is
so common: roles get granted generously during an implementation and are never
narrowed afterwards.
The second is that a person with accounts on several SAP systems is one named
user, not several — but only if the accounts are recognised as belonging to the
same person. Where they are not de-duplicated, the same human being is counted
and licensed repeatedly.
Packages
Beyond named users, SAP sells packages: additional software components bought
separately, such as the SAP Payroll Package.
Packages use different metrics from the Named User, and those metrics are based
on data created in the SAP system rather than on people. Many different types of
measurement exist, developed by SAP in collaboration with customers so that the
metric reflects a real business quantity: the number of orders processed, the
number of contracts tracked, gross written premiums, and so on.
The licensed level of such a metric reflects the required capacity of the
package. That is designed to be flexible — as the business grows and
requirements change, licences can be adjusted. Be aware, though, that
reductions are usually difficult to secure unless the right to reduce was
negotiated into the agreement in the first place. Growth is easy to buy.
Shrinkage is a contract clause you either have or do not.
Because package consumption is driven by business volume rather than by IT
activity, it moves without anybody in IT touching anything. A good quarter in
sales can push you past a licensed capacity level. Nobody involved will have
done anything wrong, and nobody will necessarily notice.
What has changed since this was written
Two developments since 2016 have altered the shape of the problem enough that
any current reading of SAP licensing has to account for them.
Digital Access. For years, indirect use of SAP — third-party systems
reaching SAP through a service account — could only be licensed by counting the
people behind the connection as named users. That made indirect access one of
the most contested areas in enterprise licensing. In 2018 SAP introduced Digital
Access, which licenses indirect use by the documents that indirect use creates
in the system rather than by user. This changes the shape of the exposure; it
does not remove it. You still have to know which integrations generate
documents, of which types, at what volume, before you can tell whether the
document-based model or named users is the better position for you. Both answers
depend on measurement you have to produce yourself.
S/4HANA and the conversion question. Movement from ECC to S/4HANA, and to
the bundled commercial models built around it, means many organisations are not
simply renewing a licence position but converting one — with entitlement
restated in Full Use Equivalent terms rather than in the named user categories
they have tracked for a decade. A conversion is negotiated against your measured
position. If the measured position is over-classified, you carry the
over-classification into the new agreement and pay for it for years.
That is the practical reason to get user classification right before a
conversion conversation, not during one.
Measurement is the whole game
SAP provides its own measurement — system measurement runs and the License
Administration Workbench consolidating them — and you should run it. But it
answers SAP’s question, which is what you appear to be consuming under the
classifications you have already assigned. It does not answer yours, which is
what you should have assigned.
The original version of this post advised setting up alerts against package
metrics so that an organisation can see when it is approaching full consumption,
because without them you can become non-compliant without ever knowing. That
advice was right, and it is worth restating that consumption drift is silent by
default. What has changed is that it no longer has to be a manual discipline
somebody remembers to build.
What CerteroX SAM does with SAP
SAP is one of six publishers with a dedicated licence engine in CerteroX SAM,
alongside Microsoft, Oracle, IBM, Adobe and Salesforce. The SAP-specific
mechanics are these:
A non-invasive ABAP connector. It reads named users de-duplicated across
systems, together with roles, role groups, engines and authorisation
definitions. Nothing is installed into production to make that happen, which
matters because the most common reason SAP measurement does not get done
properly is that nobody will approve a change to the production system.
Priority-ordered Analysis Rules. Rather than reporting what each user is
currently classified as, the rules propose the licence type each user should
hold, based on their authorisations and behaviour. You get the current position,
a suggested position and an optimal position side by side. That comparison is
the deliverable: it is what turns “we hold 4,000 professional licences” into “we
need this many, and here is the evidence for each reclassification.”
A continuously computed effective licence position. Purchased, used,
available, required, variance and exposure, calculated continuously rather than
reconciled the week a measurement is due. Overspend and additional-licence
requirements are both surfaced, because the point is to find the over-licensed
categories as well as the under-licensed ones.
Threshold alerts and trend charts over that position, so package consumption
approaching a licensed capacity level raises a flag on the way up rather than in
an annual declaration.
Entitlement held with the contract. Licences, transactions, agreements,
maintenance, suppliers and publishers in one record, with subscription flags and
expiry tracking. When a conversion negotiation starts, the entitlement history
is already assembled.
The point
SAP licensing is complex, but the complexity is not evenly distributed. Almost
all of it concentrates in two questions: which type each named user genuinely
needs, and what business volume your packages are actually consuming. Answer
those two continuously and most of the rest is administration.
Answer them once a year, under time pressure, from a system measurement run that
reflects classifications nobody has reviewed since go-live, and you are
negotiating against a number that was never yours.
Book a demo, or read more about CerteroX SAM.