Four names, three tools, and one two-character field that writes the bill
USMM, LAW, SLAW and STAR are four names for three tools, and the one most buyers get wrong is the one that decides their S/4HANA bill. USMM measures a single system; LAW consolidates the landscape and SLAW is just a transaction code into it, not a bigger tool; STAR is a service SAP delivers that classifies users from what their roles permit, not from what they did. None of the three measures digital access. All of it narrows to field LIC_TYPE in table USR06, and almost nobody on the business side has heard of it.
Prepared by Redress Compliance · August 9, 2026 · SAP advisory. Based on 25 to 35 SAP measurement reviews run 2024 to 2025.
Executive summary
The measurement discovers nothing; it publishes what you already decided. USMM measures one system and produces two lists, chargeable users by license type and licensed engines, and LAW only adds arithmetic on top.
LAW, SLAW, SLAW2 and LICENSE_ADMIN are one tool with several entry points, not a family of products, and the one commercially decisive step in its consolidation is deduplication: the same person holding accounts in ECC, BW and a sandbox counts three times unless the matching rule collapses them.
And duplicate identities inflated the LAW total in one in two of the landscapes we reviewed.
Pick the matching rule deliberately, reconcile the user master and the e-mail field before a single file is loaded, and record why.
User classification is the biggest lever because the spread across the bands is a factor of 25. A Professional user lists around 4,500 to 6,500 dollars against an Employee Self Service user at 180 to 300, and classification is not an administrative attribute, it is the multiplicand.
USMM decides nothing about it: it reads field LIC_TYPE in table USR06 for every user, totals the codes and prints the result, and in most estates that field was set once by whoever built the user creation template, on a Professional profile because it was the safe choice at go live.
Correcting classification to the lowest type each person's actual work requires took 20 to 40 percent off the named user line before anyone opened a discount conversation.
The engine list is the half nobody reads, and it carries the larger single line items.
USMM ships a measurement program for some engines and counts for itself; for the self declaration products there is no program at all, so USMM prints whatever number is sitting in the field, unvalidated, and SAP reads it as a statement your company made under its own hand.
In our reviews those figures were routinely inherited, typed at go live and owned by nobody currently employed, so every self declaration number needs a named owner and a source document, and an unsourced number rounded up is a priced admission at list.
The engine list is also the cheapest place to find shelfware: an engine measuring zero against a paid line is the strongest termination evidence you will ever hold, generated by SAP's own program.
Under RISE and S/4HANA Cloud the named user chain stops setting the price; Full Use Equivalents do.
The ABAP stack still runs USMM and SLAW2, but the commercial metric is FUE at ratios written into the Service Use Descriptions: 1 FUE for 1 advanced user, 5 core, 30 self service, and 0.5 developer, and an FUE cannot be divided between package types.
So a population that looks tidy rounds upward on each line separately.
STAR sets those classifications on the way in, mapping from what a role permits rather than what the person did, so a wide legacy role and three transactions a month still maps to advanced use.
It is a rule set, and a rule set is arguable: role remediation ahead of STAR is the cheapest FUE reduction available, and it is the one nobody schedules because it belongs to security and the money belongs to procurement.
What each name actually is, and what it decides
| Name | What it is | What it decides |
|---|---|---|
| USMM | Measurement program, current version USMM2, transaction USMM | Chargeable users and engine counts on one system |
| LAW | License Administration Workbench, one tool, package SLIM2 | Which duplicate identities collapse into one licensed person |
| SLAW / SLAW2 / LICENSE_ADMIN | Three transaction codes for LAW, not separate products | Nothing LAW does not already decide |
| STAR | S/4HANA Trusted Authorization Review, an SAP service | Your S/4HANA user types and FUE mapping on migration |
| Digital access estimate | A report you install, SAP Note 2644139 on ECC or 2644172 on S/4HANA | The document count SAP opens the indirect access conversation with |
STAR is not a digital access tool, and it is the only one you can negotiate with a human being.
It is a service delivered by SAP's Global License Auditing organization, running the Authorization Object Analyzer from SAP Note 3113382 against your existing roles and returning a proposed mapping from legacy ECC licenses to S/4HANA user types and FUE.
Two consequences follow, both commercial: it classifies on what a role permits rather than what the person did, so a wide legacy role maps upward.
And because it is a service and not a program there is a named SAP employee on the other side of the output and a rule set that can be requested and contested.
Ask for the rules in writing before you accept any output, then test them against RSUSR200 and the actual transaction profile, and narrow a role that is wider than the work before the mapping runs rather than disputing it afterward.
Digital access is measured by none of USMM, LAW or STAR; it runs off the estimation report, and the model is set out in the digital access measurement tools guide.
The five named user types, and what each one costs
| User type | What it covers | List band per user | What wrongly triggers it |
|---|---|---|---|
| Professional | Full functional and configuration access across modules | $4,500 to $6,500 | Template defaults and Active Directory auto provisioning |
| Limited Professional | Operational transactions in defined modules, little config | $1,900 to $2,400 | Left at Professional after a role change nobody reflected |
| Employee | Self service plus limited operational display and approval | $350 to $550 | Approvers licensed as Limited Professional out of habit |
| Employee Self Service | Own record only: time, travel, personal data | $180 to $300 | Shop floor and field staff carried as Employee |
| Developer | ABAP development and system configuration | $8,000 to $12,000 | Developer keys left open after a project closed |
Those bands are pre-discount list figures from enterprise schedules and quotes seen 2023 to 2025, not a published rate card, because SAP withdrew its public price list years ago. Use them as the anchor you test a quote against; do not quote them back to SAP as published prices.
Work one reclassification on a population: USMM returns 1,200 Professional at 4,500 dollars, a 5,400,000 line, and RSUSR200 over the last twelve months, the cheapest evidence in the exercise, shows 300 of them only display and approve documents, which Limited Professional covers.
Reclassify those 300 through SU10 and the line falls to 4,620,000, a 780,000 or 14.4 percent cut, and because Enterprise Support is 22 percent of the license fee, 171,600 dollars a year rides on that same misclassification for every year the contract runs.
Reclassifying does not terminate a license and 780,000 is list value not a refund, but it removes 300 Professional units from the shortfall SAP is about to price and lowers the baseline for the next purchase. The bands match the SAP licensing guide.
Controlling the result, and the RISE conversion underneath it
You control the result by controlling the inputs, because the tools report what you give them, including your mistakes.
Run USMM on each system and review the classification, reclassify users to the lowest type their actual work requires, and configure LAW to deduplicate identities across systems.
Choosing the matching rule at the combine users step before anything else runs: identical user name is reliable if provisioning is consistent, identical e-mail is the fallback where IDs differ by system.
And last name plus first name is a last resort that both misses duplicates and merges two different people.
Under RISE the arithmetic changes shape.
The same 5,040 people classified on evidence land as 900 advanced, 3,500 core, 600 self service and 40 developer, which converts to 900 plus 700 plus 20 plus 80, a total of 1,700 FUE; carry the same 300 misclassified users across as advanced rather than core and the total rises to 1,940 FUE.
Three hundred people cost 240 FUE, 14.1 percent of the contract, and unlike a perpetual overbuy it recurs in every year of the subscription.
Digital access does not disappear under RISE either: it arrives as a document block priced off the same estimation report.
And filtering matters, because on one landscape the raw 2,400,000 chargeable documents fell to 1,680,000 once documents created by a licensed SAP user and internal document to document jobs were removed, a 30 percent cut at the 0.40 dollar per document list anchor.
The indirect access model sits in the digital access licensing guide and the indirect access pillar.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across SAP measurement reviews, 2024 to 2025
Across 25 to 35 SAP measurement reviews in 2024 and 2025, the fight was almost never about arithmetic. It was about who was allowed to decide the contents of one two character field, and the common handling of the measurement is what loses it.
Most estates hand USMM to a Basis administrator with a recurring ticket, someone careful and competent who holds none of the three things that decide the outcome, the contract, the price list, and the authority to reclassify anybody:
How much the named user line fell once users classified above their actual transaction profile were corrected, before any discount conversation opened.
Landscapes where one person holding several user IDs, with no consolidation rule chosen, inflated the LAW total through duplicate identities.
So the administrator does the responsible thing, runs it as delivered, changes nothing they cannot justify, and submits on time, and every unexamined code in USR06 is thereby certified as correct by an organization that never looked at it.
The measurement is not a reading taken off an instrument; it is a document your company authors and signs, and SAP's licensing auditors read it as your own statement of position, so after it is sent every conversation is you arguing against yourself in writing on SAP's letterhead.
Move the signature: Basis keeps the run, but the classification decision moves to whoever owns the SAP contract, with the price list open beside the user list, and nothing leaves the network until that person has seen the delta priced.
On the estates where we moved that decision, the argument with SAP stopped being about whether our number was wrong and started being about whether our evidence was good enough, which is a far better argument to be having.
Run USMM and LAW yourself first, fix the data, reconcile to entitlement, and the formal audit loses most of its surprises. The audit response framework sits in the SAP audit defense framework, and RISE conversion tactics in the RISE negotiation tactics.
Your first five moves
- Run USMM on every productive client and check whether your SAP_BASIS level puts you on the USMM2 program or the legacy one behind USMM_OLD, because two systems on different support packages propose different types for the same user.
- Export USR06 LIC_TYPE for every user and put the list price band next to it: the spreadsheet is the argument, and RSUSR200 over twelve months is the cheapest evidence for reclassifying to actual profile.
- Choose the LAW matching rule deliberately and reconcile the user master and e-mail field before a single file is loaded, so duplicates collapse upstream rather than inflating the consolidated total.
- Give every self declaration engine number a named owner and a source document, and read the engine list for zero-usage paid lines, the strongest termination evidence SAP's own program will hand you.
- Move the classification signature from Basis to whoever owns the contract, with the price list open, and remediate wide roles before STAR runs. The SAP practice runs the position with you.
Frequently asked questions
What is the difference between USMM, LAW, SLAW and STAR?
They are four names for three tools. USMM measures one system, producing chargeable users by license type and licensed engines, with USMM2 the current program.
LAW, the License Administration Workbench, consolidates the landscape, and SLAW, SLAW2 and LICENSE_ADMIN are three transaction codes into that same tool, not separate products. STAR, the S/4HANA Trusted Authorization Review, is a service SAP delivers that maps your roles to S/4HANA user types.
None of the three measures digital access, which runs off a separate estimation report.
Why is SAP user classification the biggest cost lever?
Because the spread across the bands is a factor of 25: a Professional user lists around 4,500 to 6,500 dollars against an Employee Self Service user at 180 to 300, and classification is the multiplicand, not an administrative attribute.
USMM decides nothing about it, it just reads field LIC_TYPE in table USR06 and prints the totals. In our reviews, correcting users to the lowest type their actual work required took 20 to 40 percent off the named user line before any discount conversation.
Is the SAP annual measurement an audit?
No, and treating it as one is what costs money.
The measurement is a document your company authors and signs, not a reading taken off an instrument, and SAP's licensing auditors read it as your own statement of position, so after it is sent every conversation is you arguing against yourself in writing.
Run USMM and LAW yourself first, fix the classification and duplicate data, reconcile to entitlement, and move the classification signature from a Basis administrator to whoever owns the contract.
How does RISE change the way SAP measures you?
The ABAP stack still runs USMM and SLAW2, but the named user count no longer prices the contract. Full Use Equivalents do, at ratios in the Service Use Descriptions: 1 FUE for 1 advanced user, 5 core, 30 self service, and 0.5 developer.
An FUE cannot be divided between package types, so each line rounds upward on its own, and STAR sets the classifications on the way in from what your roles permit. Role remediation before STAR runs is the cheapest FUE reduction available.
How is SAP digital access measured?
By none of USMM, LAW or STAR. It runs off an estimation report you install yourself, SAP Note 2644139 on ECC or 2644172 on S/4HANA, which returns raw document counts by type.
Raw is not what you owe: filtering out documents whose initial creation came from a licensed SAP user, and internal jobs creating documents from documents already counted, cut one landscape's 2,400,000 chargeable documents to 1,680,000.
A 30 percent reduction at the 0.40 dollar per document list anchor, before any negotiation.
What are self declaration engines in a SAP measurement?
Engines for which SAP ships no measurement program, so USMM prints whatever number sits in the field, unvalidated, and SAP reads it as a statement your company made under its own hand.
In our reviews these figures were routinely inherited, typed at go live and owned by nobody currently employed, so every self declaration number needs a named owner and a source document.
An unsourced number rounded up to be safe is a priced admission at list, and the engine list is also where zero-usage paid shelfware surfaces.