Five categories of SAP user account exist to support the system rather than to use it: test users, training users, emergency access accounts, technical service users, and reference users. Each of these has a defensible classification that is not Professional, and in some cases not a chargeable user at all. The misclassification of these accounts is one of the most common drivers of inflated Professional user counts in the USMM extract, and the correction is one of the cheapest pre-measurement cleanup activities available.
This article explains how each of the five account categories should be classified, the four misclassification patterns we routinely encounter, and the cleanup steps that materialise before the next measurement.
Test users
Test users are accounts created in productive systems to support testing of new functionality, regression testing of patches, or user-acceptance testing of project deliverables. They are typically created during a project, used for a defined testing window, and then either repurposed for the next testing cycle or left dormant.
The defensible classification depends on what testing the account actually performs. An account used by a project team for functional testing during a project is doing real SAP work, even if temporarily, and the appropriate classification is whatever the underlying activity would be classified as if performed by a productive user. An account used for automated regression testing — a test harness account that executes scripted transactions — is a technical account and should be classified as such, not as a named user at all in most contract vintages.
The misclassification we see most often is dormant test users from prior projects, left in the system with Professional-equivalent roles assigned, counting against the productive user baseline. The cleanup is to identify accounts that have not logged on for an extended period and either delete or lock them ahead of the next measurement. See our dormant user cleanup analysis for the specific cadence.
Training users
Training users are accounts created to support training delivery — either accounts used by trainees during instructor-led sessions or accounts used by trainers to demonstrate functionality. They typically exist in dedicated training clients within productive systems, or in separate training systems that share a user master with the productive landscape.
The defensible classification depends on the training system's licensing position. If the training system is a separately licensed non-productive system — many ECC and S/4HANA contracts include a non-productive system allowance — the training users do not count against the productive user baseline. If the training system is a client within a productive system, the classification follows the activity rule above: trainees performing real SAP work during a training session are doing productive work, and the appropriate classification reflects that.
The common misclassification is treating all training accounts as Professional users by default, regardless of whether they sit in a productive or non-productive system. The cleanup is to verify the system's licensing position and either reclassify or remove the accounts as appropriate.
Emergency access accounts
Emergency access accounts are the named "firefighter" accounts used by support staff to access production systems during incidents. They are typically tightly controlled, with elevated privileges that are only activated for the duration of a specific incident, and with comprehensive audit logging.
The defensible classification is the activity-based view: a firefighter account that is used twice a year to resolve specific production incidents is not a named productive user, and most contract vintages support a technical-account classification for these. The argument requires evidence: a clean audit log showing the activation pattern, a documented governance process around activation, and a clear separation between the firefighter account and the support user's regular productive account.
The misclassification is treating each firefighter account as a full Professional user regardless of actual use. The cleanup is to document the firefighter governance process, attach the audit log to the USMM submission, and argue the technical-account classification on the supporting evidence.
Technical service users
Technical service users are the accounts used by interfaces, batch jobs, and automated processes. They are not associated with a human user and they exist to support system-to-system communication. Examples include RFC users, IDoc processing users, web service users, and middleware connection users.
The defensible classification is "communication user" or equivalent technical type, which in most contract vintages is not a chargeable named user. The argument is that the account does not represent a human user accessing SAP functionality — it represents a system process that the customer has already licensed through other means (the interface licence, the engine metric, the digital access framework).
The misclassification is treating technical service users as named users where the user ID happens to have a person's name attached for governance purposes. The cleanup is to identify all communication-type users, ensure they are flagged as such in the user master, and exclude them from the named user classification in the USMM submission. See our named user audit risk analysis for the surrounding patterns.
Reference users
Reference users are the template accounts used by SAP basis teams to define standard role profiles that other accounts then reference. The reference user does not log on, does not perform productive work, and exists solely as a configuration construct.
The defensible classification is non-chargeable. The reference user is not a user in any meaningful sense. The misclassification we see is treating reference users as Professional users because the user master record exists and has roles assigned. The cleanup is to flag reference users explicitly in the user master, document the configuration purpose, and exclude them from the user classification submission.
The cleanup workflow
The cleanup is a defined six-step workflow that needs to complete at least sixty days before the next USMM submission. The steps are: pull the full user master extract from the productive system; segment users by the five categories above using last-logon, user type, and role-assignment signals; verify each segment against the underlying activity using the audit log; reclassify or remove users as appropriate; document the cleanup decisions in a written log that supports the eventual USMM submission; and rerun the USMM to confirm the reduced baseline.
The cleanup is most effective when run quarterly rather than as a one-off pre-measurement exercise. Quarterly cleanup keeps the baseline clean continuously and removes the scramble at submission time. See our licence optimisation service for the framework we use to maintain the cadence.
The defensive documentation
The cleanup decisions need to be documented in a form that survives audit challenge. SAP audit teams routinely ask why certain accounts are classified as technical rather than named, and the customer needs to be able to point to a documented governance position rather than a verbal argument. The documentation includes a written classification policy for each of the five account categories, an inventory of accounts mapped against the policy, and an audit log demonstrating that the classification matches the actual activity.
For the broader context on user classification, see our Professional vs Functional vs Limited Professional analysis. For the white paper treatment of the underlying measurement framework, see our USMM defence white paper. The audit-defence framework that ties this work back to a live audit is described in our audit defence service.