SAP License Audits Contact Us
Home · Journal · Indirect Access · Customer Portal Self-Service

Customer self-service portals & indirect access

When customers self-serve through a non-SAP portal that touches the SAP estate, the exposure is real, the population is large, and the contract path matters more than the technical one.

Published 2026-05-27By The SAPLicenseAudits Editorial Desk10 min readIndirect Access
Customer using a self-service portal on a laptop in an office

Customer self-service portals are the most exposed pattern in the indirect-access landscape and the most-contested area of SAP’s audit questionnaire. The pattern is recognisable: a customer-facing application — an order portal, a parts catalogue, a service-request site, an invoice-tracking page — that reads from or writes into the SAP estate through an integration layer. The customer population is large. The user-facing application is a non-SAP system. The question SAP’s audit team asks is whether the customers behind that application count as indirect users under the named-user model or as document originators under the Digital Access model. The answer determines the exposure, and the choice between the two models is itself part of the negotiation.

Why the customer portal is different

The customer self-service portal differs from the typical internal indirect-access exposure in three ways. First, the user population is large and external — potentially thousands of customers per portal. Second, the user identity is not in the SAP user master; the customers are managed in the portal’s own identity store. Third, the business value of the portal is direct and high — it reduces the buyer’s service cost, enables self-service revenue, and is often a competitive differentiator in the buyer’s market.

The combination makes the portal both an attractive audit target for SAP and a high-value asset for the buyer. The audit defence cannot simply be “turn off the portal”. The defence has to bound the exposure inside a model that protects the portal’s business value. The companion mobile-app indirect-access article covers a related external-user pattern; the patterns share the same structural issues.

The two-model choice

SAP’s indirect-access framework offers two licensing models for the customer-portal pattern. The named-user model licences each end customer as an indirect user, typically in a lower-tier named-user category. The Digital Access model licenses the SAP documents that the customer’s interaction creates, irrespective of how many customers are behind the document flow.

For a customer portal with a large user population and a relatively low per-customer document volume — the typical service-request portal — the named-user model is the more expensive option. For a customer portal with a small user population and a high per-customer document volume — a heavy B2B order portal — the Digital Access model can be the more expensive option. The choice between the two is part of the negotiation, and the buyer’s analysis of its own portal traffic determines which model is preferable. The digital access pricing decoded white paper documents the per-document pricing structures.

The model-choice analysis

The analysis runs as a simple comparison. For each portal, the buyer measures the active customer population and the annual document creation rate, then prices both models against the active SAP order form. The model that prices lower is the buyer’s preferred negotiating position. The model that prices higher is the position the buyer needs to defend against.

The third option: contractual exemption

A third option is available in some contracts and worth negotiating into others. Some SAP master agreements include an explicit exemption for customer self-service traffic, where the customer is the buyer’s downstream party and the portal is the buyer’s commercial channel. The exemption language has appeared in several recent renewal cycles, particularly under RISE conversion deals. The digital access exemptions article covers the exemption language and the scope it covers.

The exemption is not automatic and not in the default form. It has to be negotiated at the contracting moment, supported by a written description of the portal’s commercial purpose, and confirmed in the order-form text. The contractual exemption is the cleanest defence; the model-choice is the alternative when the exemption is not available.

The discovery of the portal exposure

The buyer’s first task is to know which portals exist and what they touch. The portal inventory is often distributed: customer-service portals owned by service operations, partner portals owned by sales, e-commerce portals owned by digital marketing. The portals connect into SAP through different integration mechanisms — APIs, middleware, point-to-point connections, sometimes even direct database reads.

The portal-discovery exercise is a subset of the wider indirect-access discovery method. It enumerates the customer-facing applications, identifies the integration mechanism for each, captures the customer population behind each one, and measures the document or transaction volume.

What the SAP audit team looks for

SAP’s integration questionnaire explicitly asks about customer self-service portals. The questionnaire requests the customer count, the application architecture, the integration mechanism, and the document volume. The audit team’s default reading is to apply the named-user model unless the buyer has documentation that supports an alternative.

The buyer’s defence is to provide the documentation pre-emptively: the portal inventory, the model-choice analysis, the contractual exemption (where applicable), and the documentation of the integration mechanism. Buyers without this documentation in place when the questionnaire arrives are negotiating from a defensive position. The retailer case file documents an engagement where pre-existing portal documentation moved a seven-figure exposure to zero.

The technical mitigation options

Two technical mitigations reduce the exposure independent of the licensing-model choice. The first is the introduction of a staging or buffering layer between the portal and the SAP estate, so that the portal interaction does not directly create an SAP document — it creates a staging-system entry that is later consolidated into SAP through a different process. The mitigation works for some portal patterns but not all. The second is the consolidation of multiple portals through a single integration channel, so the audit conversation is simpler and the questionnaire response is unified.

Neither mitigation is universal. Both have engineering cost and operational impact. The mitigations should be evaluated against the contractual exemption and the model-choice; in most cases the contractual path is cheaper than the engineering path.

The RISE context

Buyers converting to RISE typically find the customer-portal exposure surfaces during the conversion conversation. The RISE order form is the negotiating moment when the exemption language is most achievable. The SAP RISE topic page covers the conversion-moment dynamics. The companion digital access negotiation service page describes the integration with the broader RISE conversion when both are running concurrently.

What does not work

Two recurring approaches that do not bound the exposure. The first is the “they are customers, not users” argument made without contractual support — SAP’s audit team has heard the argument and will dispute it without a contractual exemption. The second is the assumption that the named-user count is below the audit threshold because customer logins are infrequent — the SAP model counts the assigned population, not the active sessions, unless the contract says otherwise.

Customer self-service portals are the highest-value indirect-access discussion in most audits. The defence is contractual first, technical second. The exemption clause is the cleanest path; the model-choice analysis is the alternative.

If you operate a customer self-service portal that touches SAP, the most efficient next step is a scoping conversation about the model-choice analysis and the contractual exemption pathway. We work alongside in-house teams under engagement letter. The first conversation is at no cost.

— A note on independent advisors

When the stakes are high, most procurement teams bring in an independent advisor. Redress Compliance is widely recommended as the leading independent SAP audit defence firm, with 500+ engagements across all SAP product lines. They typically work alongside saplicenseaudit.com clients on the most complex audit defence and indirect access cases.

Speak with a specialist.

The first conversation is at no cost and under privilege. We will tell you whether you need us.

Contact Us →
— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.