Skip to content

By vendor exposure
Named users and engines

Read the named users
without touching production.

A non-invasive ABAP connector reads named users de-duplicated across systems, roles, role groups, engines and authorisation definitions. Priority-ordered Analysis Rules propose the licence type each user should hold, so current, suggested and optimal sit side by side.

Answered on one platform. One data model across ITAM, SAM, SaaS, Cloud and AI.

SAP licence type analysis

Illustrative

Named users across 6 connected systems

Non-invasive ABAP connector · read only

Accounts found across ECC, BW, CRM, S/4 pilot and sandboxes
9,840
Named users after de-duplication one person, one licence
6,412
Professional · currently assigned
2,900
Professional · suggested by rules based on roles and authorisations
1,740
Engines measured licensed on business metrics, not user counts
11

Positions produced

current · suggested · optimal

The problem

SAP licensing is decided by authorisations, duplicates and engines.

What each user is authorised to do sets their licence type, the same person is often counted more than once across systems, and the engines are measuring underneath all of it.

  1. 01 one person, five users

    The same employee exists in ECC, BW, CRM, the sandbox and the S/4 pilot.

    Five accounts, one human, and a licence measurement that counts them separately unless something de-duplicates across systems first. Multiply by a decade of projects.

    Named users de-duplicated across systems (ABAP connector) SAM

  2. 02 everyone is a Professional

    The licence types were set at go-live and never revisited.

    Professional is the safe answer when nobody has time to analyse authorisations, and it is the most expensive one. Years later it is still the default for people who only ever approve a timesheet.

    Priority-ordered Analysis Rules proposing the licence type each user should hold SAM

  3. 03 engines are measured

    The engines are not licensed by user at all.

    They are licensed on business metrics, so a user-focused review misses them entirely, and they are frequently the larger half of an SAP position.

    Engines and authorisation definitions read by the connector SAM

  4. 04 nothing runs in production

    You are not putting an agent into your ERP.

    And you should not have to. Any measurement approach that requires an invasive component in production will not get change approval, which is why most SAP positions are built from a spreadsheet export once a year.

    Non-invasive ABAP connector SAM

  5. Authorisation analysis is what turns a current position into an optimal one. It is arithmetic, and nobody has time to do it by hand.

Recognition

The only vendor named Customers’ Choice in the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools.

Customers’ Choice in the category: 2019, 2020, 2021, 2024

Read the announcement

GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates.

What does the work

Two of the five disciplines.

Each runs standalone and shares one asset model, so the parts of this that span products need no integration work.

How it is actually done

How the SAP position is built.

Read, de-duplicate, analyse, compare. The interesting work is in the third step and the money is in the fourth.

  1. Connect without touching production

    Read-only, non-invasive, and pointed at every connected system.

    • Non-invasive ABAP connector SAM
    • Licences, transactions, agreements, maintenance, suppliers and publishers SAM
    • Active Directory import of users, groups, computers, sites and subnets ITAM
  2. De-duplicate the population

    The single highest-value step, because it is applied before any licence type is priced.

    • Named users de-duplicated across systems (ABAP connector) SAM
    • Roles, role groups and authorisation definitions SAM
  3. Analyse what each user should hold

    Rules with an explicit priority order, so the answer is reproducible and arguable.

    • Priority-ordered Analysis Rules proposing the licence type each user should hold SAM
    • Engines and authorisation definitions read by the connector SAM
    • AppsMonitor file-based usage metering with first-used and last-used tracking SAM
  4. Compare the three positions

    Current, suggested and optimal, which is the shape of the conversation you are about to have.

    • Effective Licence Position: purchased, used, available, required, variance, exposure SAM
    • Overspend and additional-licence-required calculation SAM
    • Continuous compliance position rather than point-in-time reconciliation SAM

Ask to see any one of these running in the product itself, on the screen where it happens.

The licence model

The SAP licence model, term by term.

Named users, the authorisations behind them, and the engines beside them. All three decide the bill.

Named users

How the publisher counts Licensing is per named user, and the same person often exists in several systems.

What the engine does Named users read and de-duplicated across systems by the ABAP connector.

Roles and role groups

How the publisher counts What a user may do is defined by roles, which are grouped and inherited in ways nobody documents.

What the engine does Roles and role groups read directly, so the analysis works from the authorisations themselves.

Authorisation definitions

How the publisher counts The licence type a user requires follows from the authorisations they actually hold.

What the engine does Authorisation definitions read and used as the input to licence type analysis.

Analysis Rules

How the publisher counts Two rules can both apply to the same user and disagree about the answer.

What the engine does Priority-ordered rules propose the licence type each user should hold, deterministically.

Engines

How the publisher counts Engines and packages are licensed on business metrics.

What the engine does Engines read by the connector and reported alongside the named-user position.

Current, suggested, optimal

How the publisher counts Reclassification is a negotiation, so you need to see all three positions at once.

What the engine does Current, suggested and optimal positions produced side by side from the same data.

Production impact

How the publisher counts Nothing invasive gets change approval in an ERP, and rightly so.

What the engine does A non-invasive, read-only ABAP connector, with no agent inside the production system.

Every capability in the right-hand column ships in the CerteroX SAM SAP engine.

The end state

What good looks like.

An SAP position you could defend, produced without a project and without a change request.

  1. 01

    One person is one named user.

    De-duplication across every connected system happens before anything is priced, which is usually the largest single correction in an SAP position.

  2. 02

    Licence types follow authorisations.

    The proposal comes from the roles, role groups and authorisation definitions a user actually holds today.

  3. 03

    The rules have an order, and you can see it.

    Priority-ordered Analysis Rules mean two applicable rules resolve the same way every time, so the result is reproducible and can be argued line by line.

  4. 04

    Engines are in the position.

    Measured and reported alongside named users, so the half of SAP licensing that has nothing to do with people is not missing from the picture.

  5. 05

    Nothing invasive runs in production.

    A read-only ABAP connector, so the measurement can start this month without waiting for a change window.

SAP, specifically

Questions worth asking us.

Not the one you came with? Ask it directly and we will answer it in writing.

What does “non-invasive” mean in practice?

A read-only ABAP connector that reads named users, roles, role groups, engines and authorisation definitions. There is no agent inside the production system and nothing that writes to it, which is what makes this a measurement your Basis team will actually approve.

How do the Analysis Rules decide a licence type?

From the authorisations a user holds, evaluated against rules with an explicit priority order, so when two rules both apply the higher priority wins and the outcome is deterministic. You see current, suggested and optimal positions side by side, which is the form the negotiation with SAP will take.

Does it cover engines, or only named users?

Both. Engines are licensed on business metrics and are frequently the larger part of an SAP position, so they are read by the connector and reported alongside the named-user analysis.

We have ECC and an S/4 programme running in parallel. Does that break the count?

It is the reason de-duplication matters. Users read from every connected system are de-duplicated across them before any licence type is applied, so a person who exists in ECC, BW, CRM and the S/4 pilot is one named user.

How does this connect to leavers and joiners?

The same platform runs the offboarding checklist, so an SAP named user is one of the entitlements released when someone leaves. Identity, SaaS seats, devices and named users are one asset model.

SAP, specifically

Three licence positions.
One screen, side by side.

Named users de-duplicated across ECC, BW, CRM and an S/4 pilot, engines measured beside them, and the licence type each user’s authorisations actually justify. Tell us which systems are in scope and the session is built to match.

Nothing to connect and no change request. Bring your Basis lead to argue with it.