A valid SAP role does not authorize every business transaction.
IntentGate extends SAP governance beyond roles and authorization objects into the live execution of business actions, evaluating transaction context and parameters against approved authority before execution.
Does this identity have access?
SAP roles, profiles and authorization objects determine whether the identity can reach the application capability.
Is this specific action authorized?
IntentGate evaluates the live transaction against approved purpose, business scope, contextual rules and parameter boundaries.
From SAP role to business authority.
IntentGate governs the approved Business Authority. SAP exposes what is provisioned. IntentGate evaluates what is actually attempted.
Business Authority
Business purpose, permitted transaction scope, contextual constraints, SoD policy, limits and certification state.
Runtime activation: approved Business Authority can be expressed as a bounded, time-limited IntentGrant for runtime authorization.
SAP Authorization Model
PFCG roles, authorization objects, Fiori catalogs, OData services and RFC/BAPI execution rights.
Runtime Authorization
IntentGate evaluates the live action, business object, target, organizational context and transaction parameters at runtime.
Business rules become runtime controls.
A broad SAP role no longer has to mean broad business authority. IntentGate can enforce the business boundary when the transaction is attempted.
Transaction request
The SAP role is valid, but the attempted transaction falls outside the approved runtime authority.
Reconcile what was approved, provisioned and executed.
The same SAP control becomes part of the Continuous Authority reconciliation loop.
Business Authority
What the business has approved the identity to do.
SAP
What roles and authorization objects technically permit.
Runtime Evidence
What was actually attempted, authorized, enforced and executed.
IntentGate performs the reconciliation end to end — Business Authority → IntentGrant → Runtime Authorization → Enforcement → Continuous Proof.
Access says the identity can use SAP. Runtime authority decides whether this specific business action is allowed.
SAP is one example of the broader IntentGate runtime authority model.