XYZ Admin Portal

Platform administration only • Financial data access is not inherited
Role: Platform AdministratorEnvironment: Admin
Tenants
12
11 healthy
Connectors
37
35 healthy
AI Agents
9
8 active
Critical Alerts
2
Admin/platform scope

Platform Health

ServiceStatus
API GatewayHealthy
AuthorizationHealthy
Agent OrchestratorHealthy
Knowledge ServiceAttention

Security Principle

Platform administration does not automatically grant access to customer financial reports.

Admin access should be separated from business-data permissions and audited independently.

Tenant & Environment Management

TenantDEVQAPRDIdentityStatus
Customer AConfiguredConfiguredConfiguredOIDCHealthy
Customer BConfiguredPendingNot enabledSAMLSetup

Users, Roles & Access Governance

User / GroupRoleTenantEnvironmentBusiness DataStatus
Finance ControllersGroup ControllerCustomer APRDGroup scopedActive
XYZ Platform OpsPlatform AdminCustomer AAdminNone by defaultActive
Audit TeamAuditorCustomer APRDRead-only assignedActive

Authorization Dimensions

User → Tenant → Environment → Role → Group/Entity Scope → Classification → Permission → Approval Policy

Integration Connectors

ConnectorTargetModeSecret RefHealthAction
SAP Group ReportingS/4HANA PRDRead/Simulatekv/sap/prdHealthy
HANA MonitoringHANA PRDRead-onlykv/hana/prdHealthy
ITSMServiceNowCreate/Updatekv/itsmHealthy
Email / TeamsM365Notifykv/m365Attention

Raw credentials must never be displayed. The UI shows secret references only.

Crawler Sources
4
SAP, ITSM, Documents, Web
Enabled
3
Scheduled collection
Knowledge Store
Live
Normalized + deduplicated
Failed Jobs
0
Review queue

SPIDER Crawling & Intelligence Service

Approved sources only: discover → collect → validate → normalize → classify → deduplicate → chunk/index → agent consumption → refresh/expire → audit.

SourceTypeScheduleClassificationState
SAP Group Reporting DeltaSAP15 minConfidential FinanceReady
ITSM ResolutionsITSM30 minInternalReady
Approved RunbooksDocuments60 minInternalReady
SAP Public DocumentationAllowlisted WebDailyInternalDisabled

Operational Areas

SourcesSchedulesJobsWorker QueueDocumentsDeduplicationKnowledge IndexFailed JobsACL / ClassificationAudit

AI Agent Configuration

AgentDomainToolsAutonomyStatus
GR ExpertGroup ReportingSAP read, Knowledge, ReportsAdvisoryActive
IC AgentIntercompanySAP read, RulesAdvisoryActive
Journal CopilotAdjustmentsRules, Simulation, ApprovalHuman approvedActive
Incident AgentOperationsMonitoring, ITSM, EmailControlledActive
Learning AgentKnowledgeEvidence, Review, RegressionHuman governedActive

Business Catalog Configuration

Configure customer-specific metadata that drives the Business Portal without hard-coding SAP structures in the UI.

CatalogExamplesSourceStatus
Consolidation Units & GroupsUS23, DE11, GLOBALSAP / Tenant ConfigPublished
FS ItemsRevenue, EBITDA, CashSAPPublished
Close ProcessesCollection, Validation, IC, FXTenant ConfigPublished
Report CatalogExecutive, Variance, ICTenant ConfigPublished
Materiality / ThresholdsIC threshold, alert severityFinance-approved Rule SetApproved

Policies, Guardrails & Approvals

ActionDefault PolicyApprovalProduction Auto-Execute
View ReportRole + scopeNoN/A
Export Finance ReportClassification + permissionOptionalN/A
Journal SimulationPrivileged finance roleOptionalNo posting
Journal PostingSeparate permission + SoDRequiredNo by default
SAP Config ChangeChange workflowRequiredNo
Restart HANA/SAPTechnical privileged workflowRequiredNo by default

Self-Learning Governance

CandidateSourceRiskRegressionDecision
US23 validation resolution patternResolved Close IncidentMediumPassed
IC mismatch routing improvementUser FeedbackLowPassed

Observe → Candidate → Evidence → SME Review → Regression → Publish → Measure → Rollback if needed

Security & Secrets

Identity

OIDC / SAML • MFA • Group mapping • Session policy

Secrets

External secrets manager • Rotation • No secrets in prompts/browser/logs

Data Controls

Tenant isolation • Encryption • Classification • Retention

AI Controls

Tool allowlists • Prompt-injection defenses • Output filtering • Evaluation

Audit & Observability

TimeActorEventTenantResult
10:02platform-adminConnector TestCustomer ASuccess
10:05security-adminRole AssignmentCustomer AApproved
10:07agent-servicePolicy Deny: journal.postCustomer ADenied

Centralize application, connector, policy, security and AI evaluation telemetry.

Deployment & Environment Management

EnvironmentVersionAI ConfigCatalog VersionStatus
DEV1.4.0-devai-22cat-17Healthy
QA1.3.2ai-20cat-16Healthy
PRD1.3.1ai-19cat-16Healthy