SAP License Audits Contact Us
Home/Journal/Named User Licensing/Article
Named User Licensing

License keys, SLAW, and the administrative trail an auditor follows first.

The license key is not a billing artifact. It is the contract's enforcement instrument inside the system — and the first document an auditor matches against the latest USMM extract.

May 2026 8 min read Editorial Desk · SAPLicenseAudits
A basis administrator reviewing SLAW key allocation against contract entitlements on a workstation
— A basis administrator reviewing SLAW key allocation against contract entitlements on a workstation

An SAP named user license key is the cryptographic instrument that ties a system installation, an installation number, and a hardware key to the entitlements documented in the underlying contract. Most procurement teams treat the key as a basis-team housekeeping concern. SAP's audit team treats it as the primary evidence of installed entitlement, and the file that gets requested first when an audit notice lands. Where the key, the USMM extract, and the contract schedule disagree, the audit team uses the most expensive of the three as the negotiation baseline.

This piece sets out how license keys are issued, where they are applied, what SLAW does with them, and the four administrative steps procurement teams should close out before the next measurement window opens.

How the license key actually works

An SAP license key is issued from the SAP Support Portal against a specific installation number and the hardware key of the host system. The key encodes the customer's permitted product set, the licensed user count per type, the engine entitlements, and the temporary or permanent status of each entitlement. The key is loaded into the system using transaction SLICENSE, where it is then enforced by the kernel at logon and at the use of any entitlement-bound transaction.

Temporary versus permanent

Every new installation, every system copy, and every hardware migration starts with a temporary key with a four-week validity. The basis team then requests a permanent key against the same installation number once the contract entitlements have been confirmed. The transition from temporary to permanent is the moment when the contract numbers crystallise inside the system, and any mismatch between the requested key and the contract schedule travels into the audit baseline until it is corrected.

The licence audit flag inside the key

Recent license keys include flags that determine which extract transactions are permitted to run. A key issued under a contract that has reverted to in-scope measurement carries a different flag set than one issued under a deferred or capped measurement clause. Customers who do not read the key as part of the renewal process are unaware that the audit perimeter has been changed inside the key itself, ahead of any communication from the SAP account team.

SLAW: the consolidation layer

The SAP License Administration Workbench (SLAW), now bundled into the broader License Auditing infrastructure inside Solution Manager, is the tool that consolidates USMM measurement outputs across an entire system landscape. SLAW receives the per-system measurement files, applies the global user identification rules, and produces a single consolidated measurement document that the customer submits to SAP for billing reconciliation.

Why the consolidation matters

The contractual entitlement is held at the global level for named user types. A user who appears in three systems is one user under the contract — not three. SLAW resolves the same human across systems by matching on user identifier, email address, employee number, or any of several configurable fields. The matching rule used inside SLAW is the single biggest determinant of the consolidated user count, and getting the rule wrong can inflate the apparent population by twenty to forty per cent.

Field note — the matching rule audit A defensible measurement requires a documented matching rule, validated against a sample of known users who exist in multiple systems. We have seen audit positions inflated by 28 per cent because the matching rule excluded the employee-number field on a single technical system where IDs were generated locally rather than from the central HR feed.

The four administrative steps procurement teams miss

Most basis teams perform the technical license-key lifecycle competently. The administrative steps that wrap the lifecycle — the steps that connect the technical key to the procurement contract — are the ones that get dropped. Four matter most for the audit position.

1. Reconcile the installed key against the most recent order form

When a renewal or true-up order is signed, the entitlement numbers change. The new key is usually issued and installed within two weeks, but the procurement team rarely confirms that the installed key matches the signed paperwork. We routinely find installed keys that reflect a different user-tier mix than the contract — usually the basis team applied a key from a prior order form because the new key had not arrived yet. The auditor uses the installed key as evidence of entitlement, and the order form difference becomes a finding.

2. Document the hardware-key changes

Every hardware migration changes the hardware key, which means a new license key is required. The migration triggers a temporary key, then a permanent key, and the audit trail of why the temporary key was used and for how long needs to exist in writing. Migrations that overlap with a measurement period without documented hardware-key transition leave room for the auditor to question whether the measurement is representative.

3. Confirm SLAW consolidation rule consistency

The matching rule used by SLAW should be the same across all measurement cycles. A rule that changes between years produces a discontinuity in the user count that the auditor interprets as either suppressed users in the lower year or over-counted users in the higher year. The defence is a written rule and a one-page change-control log. For deeper context on the measurement process, see our piece on the engine-metric self-declaration process.

4. Pre-validate SLAW output against the contract schedule

The consolidated SLAW output should be compared against the contract entitlement schedule before it is submitted to SAP. Variances above five per cent on any single user type are findings in waiting and need to be explained, corrected, or accompanied by a contemporaneous narrative. Submitting a SLAW output that exceeds the entitlement in any line is an invitation to a true-up order from the account team. See our overview of USMM and LAW measurement for the procedural background.

The audit trail SAP looks at first

When an audit notice arrives, the SAP audit team's standard opening request is a copy of the most recent license key, a copy of the most recent SLAW consolidation, and the corresponding per-system USMM extracts. The three documents together establish the audit baseline. Any inconsistency among them is a finding to be reconciled, and the reconciliation almost always tilts toward the most expensive interpretation unless the customer can produce supporting evidence on the spot.

$180M+
Client savings to date
500+
Audits closed
20+ yrs
Combined experience

A defensible audit response, therefore, requires the customer to have those three documents in agreement, with a written explanation for any deliberate variance, before the audit notice arrives. Customers who run a quarterly internal reconciliation are materially better placed than those who only reconcile during the annual measurement cycle.

The renewal-window key conversation

License keys are reissued at every renewal, and the conversation that produces the new key is one of the most under-attended touch points in the SAP commercial relationship. The customer's basis lead receives the key through the support portal with limited visibility into the commercial terms that drove the entitlement set. The procurement lead approves the renewal paperwork without seeing the technical key implications.

The simplest fix is a single conversation, scheduled fifteen days before renewal signature, that puts the procurement, basis, and licence management leads in the same room with the draft key in front of them. The conversation surfaces unanticipated entitlement changes, identifies temporary-to-permanent transitions that should be triggered, and produces a one-page handover that both teams sign. We have seen this single meeting eliminate audit findings in the year following renewal that historically averaged in the high six figures per cycle for mid-market estates.

What an auditor reads in the key

The basis team can produce a human-readable extract of the installed key using a vendor-supplied script or the support-portal license overview. The extract contains, at minimum: the installation number, the system ID, the hardware key, the validity dates, the licensed product set, the licensed engine list, and the user-tier counts. An auditor reads the extract front-to-back and matches each line against the contract schedule.

A clean extract is one in which every line matches, the validity dates are current, and no temporary entitlements have outlived their declared term. A noisy extract — one with expired temporary entitlements that have not been cleared, or with engine lines that reference deprecated product codes — is read by the auditor as evidence of weak controls, which in turn lowers the threshold for further investigation. Strong controls do not eliminate audit findings, but they meaningfully change the auditor's posture.

What to do this quarter

Three actions are worth taking inside the next thirty days for any customer with an annual measurement cycle. The first is a documented extract of the currently installed key against the most recent contract order form, with reconciliation notes attached. The second is a written matching-rule document for SLAW consolidation, attached to the change-control system. The third is a calendar entry to repeat the reconciliation forty-five days before the next USMM run, with the basis team, procurement, and licence management lead invited. For the broader practical view of how these artifacts are used in defence, our SAP Audit Defence Playbook sets out the full procedural map, and the European bank named-user reduction case file shows the dollar impact across a recent matter. See also our service overview on USMM and LAW measurement advisory for engagement details.

— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.