An initiative by Solutive AG
solutive.ag
Change & Release

Cross-cutting audit trails: How SAP customers can cover the EU AI Act, SOX, NIS2, and DORA in a single architecture

Four regulations, four retention periods, four reporting logics: How to design an audit logging architecture that satisfies all of them simultaneously without storing logs four times.
May 4, 2026
min Lesezeit
42
Change & Release

SAP DevOps and CI/CD for ABAP: A 2026 Reality Check on gCTS and Project Piper

A technical assessment of the landscape between standard solutions, community tools, and an impending toolchain gap
May 4, 2026
min Lesezeit
40
SAP ALM

SAP Cloud ALM and the gaps in change management: Status as of 2026

What Cloud ALM can do today, what is still missing, and which migration strategies are truly sustainable
May 4, 2026
min Lesezeit
38
AI Governance

MCP server governance for SAP: Whitelist, sandbox, and tool-call audit

An assessment framework for CISOs, SAP Basis teams, and architects in the era of 40+ community servers and the OWASP MCP Top 10.
May 4, 2026
min Lesezeit
38
SAP ALM

SAP-Hinweis 11599: Warum Transport-Imports irreversibel sind und welche Recovery-Patterns trotzdem funktionieren

Ein operatives Framework für CAB, SAP-Basis und Change Manager
March 18, 2025
min Lesezeit
38
AI Governance

Agentic AI in SAP Change Management: From Concept to Pipeline and the Governance Gap

Agentic AI refers to AI systems that autonomously execute multi-step tasks. This creates new governance requirements in SAP change management.
April 29, 2026
min Lesezeit
25
Change & Release

Audit trail in the SAP change process: Requirements from the EU AI Act, SOX, NIS2, and DORA and their operational implementation

An audit trail in the SAP change process is the end-to-end, audit-proof recording of all activities related to a change.
April 29, 2026
min Lesezeit
25
Change & Release

SOX and the four-eyes principle in the SAP change process: What must be technically enforceable and what is only documented

SOX Section 404 requires a verifiable internal control system for changes to financial SAP systems.
April 27, 2026
min Lesezeit
21
Change & Release

Test automation and impact analysis in the SAP environment: From isolated tools to pipeline integration

Test automation and impact analysis in SAP environments must be considered together to reach their full potential.
April 27, 2026
min Lesezeit
20
SAP ALM

Hybrid SAP ALM Architecture: Strategy for the 78 percent majority not running a pure cloud environment

A hybrid SAP ALM architecture manages SAP cloud and on-premise components within a consistent change process.
April 29, 2026
min Lesezeit
20
Change & Release

Triple Compliance 2026: NIS2, DORA, and the EU AI Act as an integrated change architecture challenge

Triple compliance in May 2026 refers to the simultaneous applicability of NIS2, DORA, and the EU AI Act. The three regulatory frameworks consume the same operational evidence: audit trail, incident reporting, supply chain inventory, human oversight, and training. An integrated architecture reduces effort and closes gaps.
May 11, 2026
min Lesezeit
20
AI Governance

The NIST AI Risk Management Framework in the SAP context: Govern, Map, Measure, Manage

The NIST AI RMF is the most widely used voluntary risk framework for AI. This article explains its four functions, the Generative AI profile, the 2026 critical infrastructure profile, and the distinction from ISO 42001 and the EU AI Act, translated into SAP governance.
June 8, 2026
min Lesezeit
18
SAP ALM

The 2027 operational SolMan gap: what will replace monitoring, Focused Run, and LaMa after maintenance ends

It is not just ChaRM that will disappear in 2027. Monitoring, landscape automation, and landscape data also require a successor, and not every solution is SAP-native.
min Lesezeit
17
AI Governance

ISO/IEC 42001 in the SAP world: Provider-deployer separation according to Klein's Sapphire 2026 statement

SAP achieved ISO 42001 certification for SAP Business AI in Q1 2026 and is positioning itself as a provider. Klein's Sapphire statement on May 11, 2026, reinforces the provider role with a governance commitment for SAP-native agents. Operator obligations under Article 26 remain with the SAP customer and are non-transferable.
May 11, 2026
min Lesezeit
17
Change & Release

The five-layer architecture for SAP Change Governance: who decides at which level

An analytical lens for SAP Change Governance: five layers with distinct tasks and decision-making rights, and why ALM is not the same as governance.
min Lesezeit
16
AI Governance

SAP Business AI Q1 2026: Joule Studio in general availability and what the Q1 wave means for SAP customers in concrete terms

SAP Business AI is the collective term for the AI functions that SAP embeds in its products or provides as a standalone service on the SAP BTP.
April 27, 2026
min Lesezeit
16
AI Governance

Open vs. closed agent architecture: SAP A2A, Salesforce Headless 360, and ServiceNow Action Fabric

Three platforms, two opposing answers to the same question: Who controls the agent that touches SAP production?
min Lesezeit
15
AI Governance

The Frankenstein architecture: Cross-vendor agents and the gap Klein didn't close in Orlando

Frankenstein architecture: Saueressig's term from November 2025, extended to cross-vendor agents from SAP, Microsoft, Salesforce, Workday, and Community-MCP. What Klein's Sapphire statement from May 11, 2026, solves and what it leaves open. Tool comparison and five operational consequences for operators.
May 11, 2026
min Lesezeit
15
AI Governance

AI toolchains in the enterprise: architecture, operations, and governance

AI toolchains, MLOps, and LLMOps structure the operation of AI systems. Governance requirements must be integrated into the architecture from the very beginning.
April 28, 2026
min Lesezeit
15
SAP ALM

The new ABAP developer toolchain 2026: ABAP MCP server, VS Code, and the custom code agent in the lifecycle

With Sapphire 2026, ABAP development is becoming agentic: ADT for VS Code and ABAP MCP servers are available, with a custom code migration agent to follow. An analysis of the new toolchain and its implications for the SAP change lifecycle.
June 8, 2026
min Lesezeit
14
AI Governance

Digital Omnibus trilogue April 2026: Status before April 28 and the watermarking deadline of November 2, 2026

The Digital Omnibus trilogue aims for a political agreement during the second trilogue on April 28.
April 27, 2026
min Lesezeit
14
AI Governance

CVE-2026-27681 and the ABAP security blind spot: What the April Patch Day means for AI-assisted code generation in SAP

CVE-2026-27681 is a critical SQL injection vulnerability in SAP BPC and BW with a CVSS score of 9.9.
April 27, 2026
min Lesezeit
14
AI Governance

The EU AI Act: Requirements, roles, and action items for businesses

The EU AI Act is the world's first comprehensive AI regulatory framework. It applies extraterritorially and designates SAP customers as deployers.
April 28, 2026
min Lesezeit
14
Change & Release

The SAP CAP supply chain attack: what the April 2026 npm incident reveals about change governance

In late April 2026, official SAP CAP npm packages were compromised. The attack targets the development toolchain before the first transport. Analysis of the incident, the control points, and the consequences for change governance.
June 8, 2026
min Lesezeit
13
SAP ALM

SAP Cloud ALM Q1 2026: Retrofit App, ATC integration, and the remaining functional gaps

SAP Cloud ALM Q1 2026 brings the Retrofit app and ATC integration. The functional gap compared to ChaRM remains.
April 27, 2026
min Lesezeit
13
SAP ALM

DSAG Investment Report 2026: Three percent SAP AI versus 43 percent total AI—what this gap means strategically

The DSAG Investment Report 2026 documents a strategic gap: 43 percent total AI investment, but only 3 percent in SAP AI.
April 27, 2026
min Lesezeit
13
AI Governance

AI Governance: Fundamentals, Requirements, and Operational Implementation

AI governance manages the use of AI in companies. It is not a sub-area of IT governance, but a distinct framework.
April 28, 2026
min Lesezeit
13
SAP ALM

The Extended Maintenance trap: what SAP Note 3255311 really covers for Solution Manager after 2027

Many read 2030 as a breather. In reality, Extended Maintenance is reduced, tied to Business Suite 7, and sees some components phased out as early as 2027.
min Lesezeit
12
Change & Release

Release Governance: Planning, managing, and controlling SAP releases

Release governance manages the transition from individual changes to coordinated, controlled production cycles.
April 25, 2025
min Lesezeit
12
Change & Release

Transport management in SAP: From request to production deployment

Transport management controls the path of changes from the development system to production. Three classes of errors dominate daily operations.
May 6, 2025
min Lesezeit
11
Change & Release

Change management in the SAP world: fundamentals and principles

Change management in SAP encompasses all changes to code, customizing, and configuration. It does not end with the transport.
May 21, 2025
min Lesezeit
11
SAP ALM

SolMan Migration: The path from SAP Solution Manager to its successors

SolMan maintenance ends on December 31, 2027. Those who have not yet migrated must begin their functional inventory now.
April 28, 2026
min Lesezeit
11
SAP ALM

What is SAP ALM? Application Lifecycle Management in the SAP world

SAP ALM is the discipline of end-to-end management of SAP systems, from the initial requirement to decommissioning.
February 27, 2025
min Lesezeit
11
SAP ALM

The SAP ALM Tool Landscape: Market Overview and Structural Gaps

The SAP ALM tool landscape is divided into four categories. None of them covers the entire lifecycle.
January 13, 2025
min Lesezeit
10
SAP ALM

SAP Sapphire 2026: Autonomous Enterprise, AI Agent Hub, and the Unresolved Questions of the Governance Layer

At SAP Sapphire 2026 in Orlando, SAP announced the Autonomous Enterprise architecture on May 12, 2026: Business AI Platform, AI Agent Hub on LeanIX, and Joule Studio 2.0.
May 18, 2026
min Lesezeit
8
Change & Release

NIS2 in Germany: BSI enforcement phase May 2026 and its consequences for SAP Change Management

NIS2 is the EU directive on cybersecurity. Transposed into German law via the BSIG. BSI audit phase active since May 2026; personal liability for management effective since December 2025.
May 18, 2026
min Lesezeit
6
AI Governance

Digital Omnibus on AI: What the provisional agreement of May 7, 2026, means for companies

The Digital Omnibus on AI is an EU Commission package designed to simplify and partially postpone obligations under Regulation (EU) 2024/1689 (EU AI Act). On May 7, 2026, the Council and Parliament reached a provisional agreement during the third trilogue.
May 18, 2026
min Lesezeit
6
AI Governance

Digital Omnibus on AI: What the delay really means for SAP customers

The Digital Omnibus on AI aims to postpone the high-risk obligations of the EU AI Act. For SAP customers, this changes less than hoped.
April 28, 2026
min Lesezeit
6
AI Governance

EU AI Act Article 26 for SAP users: Deployer obligations effective August 2, 2026, not postponed

Article 26 of Regulation (EU) 2024/1689 defines the operational obligations for deployers of high-risk AI systems. For SAP users, these obligations remain unchanged as of August 2, 2026.
May 18, 2026
min Lesezeit
6
SAP ALM

Cloud ALM vs. ChaRM: The CSOL gap in single-landscape scenarios

Cloud ALM can replace ChaRM for many scenarios. However, for single-landscape customers with parallel tracks, critical CSOL protection is missing.
November 24, 2025
min Lesezeit
5