Platform Health
| Service | Status |
|---|---|
| API Gateway | Healthy |
| Authorization | Healthy |
| Agent Orchestrator | Healthy |
| Knowledge Service | Attention |
Security Principle
Platform administration does not automatically grant access to customer financial reports.
Admin access should be separated from business-data permissions and audited independently.
Tenant & Environment Management
| Tenant | DEV | QA | PRD | Identity | Status |
|---|---|---|---|---|---|
| Customer A | Configured | Configured | Configured | OIDC | Healthy |
| Customer B | Configured | Pending | Not enabled | SAML | Setup |
Users, Roles & Access Governance
| User / Group | Role | Tenant | Environment | Business Data | Status |
|---|---|---|---|---|---|
| Finance Controllers | Group Controller | Customer A | PRD | Group scoped | Active |
| XYZ Platform Ops | Platform Admin | Customer A | Admin | None by default | Active |
| Audit Team | Auditor | Customer A | PRD | Read-only assigned | Active |
Authorization Dimensions
User → Tenant → Environment → Role → Group/Entity Scope → Classification → Permission → Approval Policy
Integration Connectors
| Connector | Target | Mode | Secret Ref | Health | Action |
|---|---|---|---|---|---|
| SAP Group Reporting | S/4HANA PRD | Read/Simulate | kv/sap/prd | Healthy | |
| HANA Monitoring | HANA PRD | Read-only | kv/hana/prd | Healthy | |
| ITSM | ServiceNow | Create/Update | kv/itsm | Healthy | |
| Email / Teams | M365 | Notify | kv/m365 | Attention |
Raw credentials must never be displayed. The UI shows secret references only.
SPIDER Crawling & Intelligence Service
Approved sources only: discover → collect → validate → normalize → classify → deduplicate → chunk/index → agent consumption → refresh/expire → audit.
| Source | Type | Schedule | Classification | State |
|---|---|---|---|---|
| SAP Group Reporting Delta | SAP | 15 min | Confidential Finance | Ready |
| ITSM Resolutions | ITSM | 30 min | Internal | Ready |
| Approved Runbooks | Documents | 60 min | Internal | Ready |
| SAP Public Documentation | Allowlisted Web | Daily | Internal | Disabled |
Operational Areas
SourcesSchedulesJobsWorker QueueDocumentsDeduplicationKnowledge IndexFailed JobsACL / ClassificationAudit
AI Agent Configuration
| Agent | Domain | Tools | Autonomy | Status |
|---|---|---|---|---|
| GR Expert | Group Reporting | SAP read, Knowledge, Reports | Advisory | Active |
| IC Agent | Intercompany | SAP read, Rules | Advisory | Active |
| Journal Copilot | Adjustments | Rules, Simulation, Approval | Human approved | Active |
| Incident Agent | Operations | Monitoring, ITSM, Email | Controlled | Active |
| Learning Agent | Knowledge | Evidence, Review, Regression | Human governed | Active |
Business Catalog Configuration
Configure customer-specific metadata that drives the Business Portal without hard-coding SAP structures in the UI.
| Catalog | Examples | Source | Status |
|---|---|---|---|
| Consolidation Units & Groups | US23, DE11, GLOBAL | SAP / Tenant Config | Published |
| FS Items | Revenue, EBITDA, Cash | SAP | Published |
| Close Processes | Collection, Validation, IC, FX | Tenant Config | Published |
| Report Catalog | Executive, Variance, IC | Tenant Config | Published |
| Materiality / Thresholds | IC threshold, alert severity | Finance-approved Rule Set | Approved |
Policies, Guardrails & Approvals
| Action | Default Policy | Approval | Production Auto-Execute |
|---|---|---|---|
| View Report | Role + scope | No | N/A |
| Export Finance Report | Classification + permission | Optional | N/A |
| Journal Simulation | Privileged finance role | Optional | No posting |
| Journal Posting | Separate permission + SoD | Required | No by default |
| SAP Config Change | Change workflow | Required | No |
| Restart HANA/SAP | Technical privileged workflow | Required | No by default |
Self-Learning Governance
| Candidate | Source | Risk | Regression | Decision |
|---|---|---|---|---|
| US23 validation resolution pattern | Resolved Close Incident | Medium | Passed | |
| IC mismatch routing improvement | User Feedback | Low | Passed |
Observe → Candidate → Evidence → SME Review → Regression → Publish → Measure → Rollback if needed
Security & Secrets
Identity
OIDC / SAML • MFA • Group mapping • Session policy
Secrets
External secrets manager • Rotation • No secrets in prompts/browser/logs
Data Controls
Tenant isolation • Encryption • Classification • Retention
AI Controls
Tool allowlists • Prompt-injection defenses • Output filtering • Evaluation
Audit & Observability
| Time | Actor | Event | Tenant | Result |
|---|---|---|---|---|
| 10:02 | platform-admin | Connector Test | Customer A | Success |
| 10:05 | security-admin | Role Assignment | Customer A | Approved |
| 10:07 | agent-service | Policy Deny: journal.post | Customer A | Denied |
Centralize application, connector, policy, security and AI evaluation telemetry.
Deployment & Environment Management
| Environment | Version | AI Config | Catalog Version | Status |
|---|---|---|---|---|
| DEV | 1.4.0-dev | ai-22 | cat-17 | Healthy |
| QA | 1.3.2 | ai-20 | cat-16 | Healthy |
| PRD | 1.3.1 | ai-19 | cat-16 | Healthy |