SAP License Audits Contact Us
Home · Journal · Indirect Access · Indirect Access

Customer portals as indirect-access exposure

When the customer-facing portal posts to SAP behind the scenes, SAP’s audit team reads every authenticated user as a licensable event. The buyer-side response.

Published Customer PortalsBy The SAPLicenseAudits Editorial Desk12 min readIndirect Access
Indirect Access editorial photograph

An indirect-access exposure does not always live inside an integration platform or a custom-built RFC. In a growing share of estates it lives inside a customer portal — a web front-end, hosted on the buyer’s own infrastructure or a third-party CRM, that lets customers, dealers, or partners read or write to the SAP back-end. SAP’s reading of these portals, when the audit lands, is that every human who logs in is a user of SAP. The buyer’s reading is rarely the same. This article walks through the structural exposure, the contractual basis on which it can be narrowed, and the measurement work that turns a notional portal population into a defensible licensed count.

The structural exposure

A customer portal exposes SAP in two ways. The first is read traffic — a logged-in customer queries an order status, a delivery date, a service ticket, or an invoice. The query flows through middleware into ECC or S/4 and reads from a transactional table. The second is write traffic — the same customer creates a new order, updates an address, opens a support case, or initiates a return. The write posts a document in SAP.

Under the legacy indirect-use clause, both flows can be read by SAP’s audit team as constituting use of the SAP software by the human at the portal session. Under the Digital Access model the read traffic is generally not chargeable, but the write traffic creates documents that are. Either way the portal is the asset that turns a non-SAP user into an SAP licensing event.

What SAP looks for in an audit

SAP’s audit team asks three questions about a customer portal. How many distinct humans authenticated to the portal in the measurement window. What proportion of their sessions touched SAP, read or write. And what licensing posture is in place to cover them. The opening claim, when the answers are missing, treats the entire authenticated population as named users of SAP at the price of the closest professional category. For a portal with twenty thousand authenticated customers, the arithmetic is a multi-million-dollar opening number.

The buyer-side response is to convert each of those three questions into a measured answer with documentary basis. The audit defence pillar covers the broader process; the work specific to portals is described below.

The authentication-population question

The portal owner has the data: each authenticated session is logged, with the user identifier and timestamp. The first measurement is the count of distinct identifiers active in the window. The second is the active-versus-dormant split — in most estates, a sizeable fraction of the authenticated population is inactive in any given month. SAP’s opening count is rarely sensitive to that split. The buyer’s response should be.

The SAP-touch question

Not every portal action touches SAP. A customer who logs in to view marketing content, complete a profile, or browse a knowledge base does not touch the ERP. The session logs at the middleware layer separate the SAP-touching transactions from the rest. The proportion varies widely by portal design; we have measured estates where as little as fifteen per cent of sessions touched SAP, and others where the figure was over ninety. The number matters because it bounds the population that is contractually relevant.

The contractual footing

The contractual basis for narrowing portal exposure sits in three places. The named-user definition, which in older agreements often reads broadly enough to cover any human who accesses SAP — but in negotiated agreements is usually restricted to employees, contractors, or named third parties on a specified list. The indirect-use clause, which in older agreements applies broadly and in newer agreements has been replaced by the Digital Access model. And the Use Definition, which in some master agreements carves out customer-facing self-service from the scope of paid licensing.

The reading of these clauses against the portal topology is the analytical step that turns the structural exposure into a contractually bounded number. The work is best done before an audit lands. The SAP ECC topic page and the SAP Note 868191 explainer describe the underlying mechanics.

The conversion option

For estates where the portal volume is high and the contractual narrowing is weak, the Digital Access conversion is often the favourable path. The conversion exchanges the open-ended portal exposure for a measured document-count entitlement at the tier price negotiated in the order form. The economics turn on the proportion of portal sessions that result in document-creating writes — the read traffic is generally out of scope under Digital Access, and the document count is bounded by the actual portal activity. The conversion economics, including the tier negotiation, are detailed in the Digital Access Pricing Decoded white paper.

A conversion is not automatic. It is negotiated in, with a baseline that reflects the buyer-side measurement and an exemption schedule that excludes the document types the portal does not generate. The Digital Access negotiation service describes how we structure that conversation.

What a portal audit response looks like

The response, when the count and the contract have been worked, follows a defined sequence. The portal authentication log is extracted for the measurement window and de-duplicated to a distinct-user count. The middleware log is joined to identify the proportion of sessions that touched SAP. The session count is mapped against the named-user definition and the indirect-use clause in the master agreement. The position paper sets out the contractually licensed posture, the documentary basis, and the offered remediation — usually a Digital Access conversion or a defined named-user expansion for the population that meets the named-user definition.

SAP’s response to a position paper of this calibre is rarely an immediate acceptance. The negotiation proceeds, usually over six to twelve weeks, with the buyer holding the documentary high ground throughout. The retailer-defeats-indirect-access case file documents one such engagement in full.

Where the risk sits going forward

The portal-as-indirect-access pattern is not going away. As more SAP-backed transactions move to customer self-service, the surface area grows. The buyer-side discipline that holds the exposure inside acceptable limits is fourfold. Document the portal-to-SAP integration topology in writing. Measure the authentication population and the SAP-touch proportion quarterly. Read the named-user definition and indirect-use clause in the master agreement against the topology and write down the licensed posture. And include the portal exposure in the standing renewal-cycle data room, so that the conversion to Digital Access — if it becomes the right structure — can be negotiated on the buyer’s timetable, not under audit duress.

Most portal-driven indirect-access claims, when defended on documentary measurement, settle for between fifteen and thirty-five per cent of SAP’s opening number. The settlement gap is the measurement gap.

The five-point portal review

For an SAM team that wants to scope its portal exposure inside a week, the five-point review is the most useful starting structure. Identify every customer-facing portal that integrates to SAP, listing the integration path and the originating system. Extract the authentication log for the trailing twelve months and de-duplicate to distinct humans. Pull the middleware session log and compute the SAP-touch proportion. Read the named-user definition and the indirect-use clause in the active master agreement. Write the resulting licensed-posture statement against the topology and circulate it to the legal, procurement, and SAP basis teams. The work, end to end, is six to ten analyst-days. The output is a defensive document of indefinite shelf-life.

The quarterly review cadence

Customer-portal exposure is a moving number. Each new portal feature, each new integration flow, and each change to the named-user definition in the master agreement can shift the licensed posture. The discipline that keeps the exposure inside acceptable bounds is a quarterly review run by the SAM function, the product-owner of the portal, and the procurement counterpart. The review covers the authentication population, the SAP-touch proportion, the document attribution where Digital Access applies, and the contractual reading against the current master agreement. The deliverable is a one-page summary that goes to the procurement steering committee. The cumulative effect, over a three-year horizon, is that the next portal-driven audit finds an exposure measured in months rather than years and a settlement negotiation that closes on documentary ground rather than under audit duress.

The review is not optional in any estate where the portal is materially integrated to SAP. The cost of running it is single-digit analyst-days per quarter. The cost of skipping it is the open-ended exposure that comes due at the next audit cycle. The audit-readiness checklist describes how the review fits into the broader compliance programme.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Speak with a specialist before responding.

The first conversation is at no cost and under privilege. We will tell you whether you need us.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.