SAP Note 868191 was published in 2006 in the SAP Service Marketplace knowledge base as a note titled “Use of SAP products by external users.” It is fewer than 1,500 words long, contains no contractual amendment language, and was issued not as a contract change but as guidance on how SAP’s licence model applies to integrated systems. Two decades later, it remains the most-cited document in every indirect-access dispute we see, and SAP’s audit team reaches for it on the opening slide of nearly every indirect-access finding. Understanding what the note actually says, what it leaves open, and how buyer-side advisors have learned to interpret the gaps is foundational to indirect-access defence. The cases that settle at five to fifteen per cent of the opening claim are the cases where the buyer’s position paper engages with the note line by line. The cases that settle at sixty to eighty per cent are the cases where the buyer treats the note as settled doctrine.
What Note 868191 actually says
The note has three substantive elements. The first is a definition: any access to the licensed SAP system by a person, regardless of the means of access, requires a corresponding SAP named-user licence. The second is an illustration: it provides examples of integration patterns — portals, intermediary systems, batch interfaces — and asserts that the human users behind those interfaces require licences. The third is a caveat: machine-to-machine integrations that do not involve human users on the “far side” do not, under the note, require named-user licences for the absent humans.
What the note does not contain is any defined measurement methodology, any pricing mechanism for indirect users, any list of specific licence classes that apply to indirect users, or any contractual amendment to existing master agreements. Those silences are the interpretation surface. SAP’s audit team treats the silences as opportunities to apply the most expansive reading; the buyer’s position paper engages with the silences directly.
The four interpretation gaps
Four interpretation gaps in the note matter for audit defence. They are the gaps that account for most of the variance between SAP’s opening claim and a defensible buyer position. They appear, in some combination, in nearly every indirect-access matter.
Gap one: what counts as “access”
The note says “access” without defining whether read-only data retrieval, write-back to SAP, or schema-level integration patterns count differently. SAP’s audit team typically treats all three patterns as equivalent. The buyer-side position is that the patterns are technically and commercially distinct: a read-only data retrieval into a downstream warehouse is materially different from a write-back transaction that originates business documents in SAP. The position paper categorises every integration pattern in the estate and treats each category separately. The RFC connections article describes the categorisation methodology.
Gap two: who is the “person”
The note says the person behind the access requires a licence, but does not define what counts as a person for the purposes of measurement. SAP’s reading is that any individual whose action eventually produces a transaction in SAP, however distantly, is a measured person. The buyer-side position is that only individuals whose access is purposeful, direct, and traceable to a discrete SAP transaction are measurable. Customers placing orders on a public e-commerce front-end that batches into SAP overnight, employees of a service partner with no direct SAP credentials, public-facing portals with anonymous browsing — all of these have well-developed counter-readings in the buyer-side literature.
Gap three: what licence class applies
The note does not specify which licence class — Professional, Limited Professional, Employee, ESS, or any of the engine-based classes — applies to indirect users. SAP’s audit team typically applies the most expensive applicable class, often defaulting to Professional. The buyer-side position is that the licence class for an indirect user should reflect the actual functional scope of the indirect access, not the maximum capability of the SAP system. An indirect user who only triggers a sales order line item is not a Professional user; that user is, at most, an ESS-class indirect.
Gap four: the relationship to Digital Access
The note predates the 2018 introduction of Digital Access by twelve years. SAP’s commercial team has, at times, taken the position that Note 868191 and Digital Access are alternative routes to the same liability and that the buyer must license under one or the other. The buyer-side reading is that Digital Access is an alternative outcome model that — in many integration patterns — is dramatically cheaper than indirect-user licensing under the note. The SAP S/4HANA topic page describes the Digital Access mechanic; the relationship is covered in detail in our indirect-to-digital access migration article.
What the note does not say
Equally important is what the note does not say. It does not say that historic integration patterns are retroactively liable. It does not say that the price-list rate at the time of audit applies to indirect users discovered in audit. It does not say that the indirect-user count is measured at audit-time rather than at integration-establishment time. It does not say that contract amendments are required to use the note’s definitions, which means the note’s applicability to any specific master agreement is itself disputable.
Each of those silences is a defensible position. We have closed indirect-access matters where the principal lever was a written argument that the master agreement, predating the note, did not incorporate its definitions and therefore could not be enforced under its reading. The argument does not always win — SAP’s counter is that the note represents industry practice — but it changes the negotiation. The retailer defeats indirect access claim case file describes a matter that turned on this point.
How SAP’s audit team uses the note
SAP’s audit team uses Note 868191 in a predictable sequence. The opening slide cites the note as the authority for indirect access exposure. The integration topology questionnaire enumerates every system that integrates with SAP. Each integrated system is assumed, under the note, to involve indirect users. The headcount of the integrated system is treated as the indirect-user count. The Professional licence class is applied to the headcount. The price-list rate at the time of audit is applied. The result is the opening claim. The opening claim is almost always large because each assumption in the sequence is the maximum reading.
The buyer’s task is to break the sequence at each step. Not every integration pattern produces indirect access under the note. Not every user of an integrated system is an indirect user. Not every indirect user is a Professional. Not every measurement applies the audit-time list. Working through the sequence breaks the opening claim at every step. The SAP Indirect Access Survival Guide white paper sets out the full breakdown.
Drafting the counter-position
The counter-position is drafted into the indirect-access section of the audit position paper. It begins by acknowledging the note’s existence and the buyer’s engagement with its principles, in the spirit of co-operation. It then sets out the buyer’s categorisation of integration patterns, the buyer’s reading of which patterns produce indirect access under the note, the buyer’s view of the appropriate licence class for each pattern, and the buyer’s alternative position if Digital Access is the more appropriate model. The section is footnoted to the evidence pack of the integration topology and to the contractual analysis of the applicable master agreement.
The counter-position works because it is structured. It does not deny the existence of indirect access. It engages with the principle and disputes the application. SAP’s commercial leadership can settle a structured counter-position because the position gives them somewhere to land internally.
Note 868191 in 2026: what has changed
The introduction of Digital Access in 2018 changed the practical implementation of Note 868191 but did not retire it. The note still applies to indirect users that fall outside the Digital Access scope — principally, integrations that do not produce countable documents. The introduction of RISE in 2022 changed the commercial structure of indirect access, with RISE contracts including a defined Digital Access component but typically retaining the note’s framework for non-document integrations. The introduction of GROW in 2023 followed the RISE pattern.
The 2024-2026 audit cycle has seen SAP’s audit team apply Note 868191 increasingly in the context of AI integrations, low-code platforms, and customer-facing portals that combine document and non-document integration. The interpretation gaps are widening, and the buyer-side opportunity to negotiate is correspondingly larger.
Note 868191 is short, ambiguous, and old. The gaps it leaves open are the negotiation surface. Buyers that engage with the gaps settle at five to fifteen per cent of the opening claim; buyers that do not, settle at sixty per cent plus.
If you have an active indirect-access exposure or are sizing one in advance of an audit, the position paper’s indirect section is the highest-leverage artefact. Our SAP indirect access advisory describes how we structure the work. The first conversation is at no cost.
— A note on independent advisors
When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.