SAP Runtime Authority

A valid SAP role does not authorize every business transaction.

IntentGate extends SAP governance beyond roles and authorization objects into the live execution of business actions, evaluating transaction context and parameters against approved authority before execution.

Traditional governance

Does this identity have access?

SAP roles, profiles and authorization objects determine whether the identity can reach the application capability.

ACCESS IS PROVISIONED
Runtime authority

Is this specific action authorized?

IntentGate evaluates the live transaction against approved purpose, business scope, contextual rules and parameter boundaries.

ACTION IS EVALUATED

From SAP role to business authority.

IntentGate governs the approved Business Authority. SAP exposes what is provisioned. IntentGate evaluates what is actually attempted.

01
Tier 1 · Governed Authority

Business Authority

Business purpose, permitted transaction scope, contextual constraints, SoD policy, limits and certification state.

Runtime activation: approved Business Authority can be expressed as a bounded, time-limited IntentGrant for runtime authorization.

AuthorityApproved business actionDefined before execution
02
Tier 2 · Provisioned Authority

SAP Authorization Model

PFCG roles, authorization objects, Fiori catalogs, OData services and RFC/BAPI execution rights.

Provisioned stateRole / profile / endpointWhat SAP technically permits
03
Tier 3 · Actual Execution

Runtime Authorization

IntentGate evaluates the live action, business object, target, organizational context and transaction parameters at runtime.

Runtime decisionAllow · Hold · Restrict · BlockWhat is actually authorized now

Business rules become runtime controls.

A broad SAP role no longer has to mean broad business authority. IntentGate can enforce the business boundary when the transaction is attempted.

Role membership answers whether the identity can reach the transaction. Runtime authority answers whether this exact execution should proceed.
Illustrative runtime evaluation

Transaction request

SAP roleVALID
Business AuthorityMATCHED
IntentGrantACTIVE
Transaction scopeAUTHORIZED
Parameter boundaryOUTSIDE AUTHORITY
BLOCKED, business authority exceeded

The SAP role is valid, but the attempted transaction falls outside the approved runtime authority.

Reconcile what was approved, provisioned and executed.

The same SAP control becomes part of the Continuous Authority reconciliation loop.

Governed

Business Authority

What the business has approved the identity to do.

Governed Authority
Provisioned

SAP

What roles and authorization objects technically permit.

Provisioned Access
Executed

Runtime Evidence

What was actually attempted, authorized, enforced and executed.

Execution Evidence

IntentGate performs the reconciliation end to end — Business Authority → IntentGrant → Runtime Authorization → Enforcement → Continuous Proof.

Access says the identity can use SAP. Runtime authority decides whether this specific business action is allowed.

SAP is one example of the broader IntentGate runtime authority model.