HomeTraining AcademySAP Licensing MasterySession 33
SAP Licensing Mastery · Module 7 – Audits and compliance defence · Session 33 of 40 · 19:51

Defending a digital access finding

The document metric, the evidence that reduces it, and where the conversation actually lands. Three knowledge checks along the way, and 4 clips from a senior licensing analyst.

What you will be able to do after this session

  • 1Explain the metric precisely. Which document types count, what triggers a count, and why the scope is wider than people expect.
  • 2Map your own sources. Every integration that creates documents, and whether a licensed human sits behind it.
  • 3Challenge attribution. Documents created by licensed people through an interface are not digital access, and that distinction is large.
  • 4Interrogate the method. Duplicates, cascades and reprocessing inflate counts. Ask what was counted and how.
  • 5Aim at the real destination. These settle as a forward licensing model, not as a cheque for the opening number.

How the session works

This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. 4 times in the session the frame splits and a senior licensing analyst gives the view from inside real SAP negotiations, and the instructor picks the clip apart when the slides return.

Homework before session 34, about one hour

  • 1Count your documents. Sales orders, purchase orders, invoices and material documents created last year, by source. Most teams have never done this.
  • 2Split by attribution. For each source, is there an authenticated licensed human behind it, or is it genuinely unattended?
  • 3Find the cascades. Pick your highest volume flow and count how many documents one business event creates.
  • 4Check the reprocessing rate. How many postings are retries, reversals or corrections? The integration logs will tell you.
  • 5Read your own definition. The digital access clause in your agreement, including which types carry reduced weighting.

Session transcript

The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.

Welcome and objectives 0:02

Welcome back. Session thirty three, and today is the one people are most anxious about, which is digital access. This is where the largest findings in the market come from, and I want to be useful rather than dramatic about it. A digital access finding is a number produced by a counting method, and counting methods can be examined. So today: what actually gets counted, where your documents really come from, the attribution question that moves the number more than anything else, how to interrogate the method, and where these conversations genuinely land. Three knowledge checks. Let's begin.

Five objectives. First, explain the metric precisely, meaning which document types count, what triggers a count, and why the scope is wider than people expect. Second, map your own sources, so every integration that creates documents and whether a licensed human sits behind it. Third, challenge attribution, because documents created by licensed people through an interface are not digital access and that distinction is large. Fourth, interrogate the method, since duplicates, cascades and reprocessing inflate counts, so ask what was counted and how. And fifth, aim at the real destination, because these settle as a forward licensing model rather than as a cheque for the opening number.

Why the first number is enormous 1:33

Four things to frame it. Unbounded, because there is no headcount ceiling and document volume follows business activity and integration design. Invisible, since most organisations cannot state their own document count, so the vendor's figure arrives unopposed. Usually wrong, as opening counts routinely include licensed humans, duplicates and reprocessed documents. And it settles forward, because the realistic outcome is a licensing model change priced on a volume you verified. Let me explain what the metric actually is, because the fear here comes from a misunderstanding of what changed.

Guest analyst clip.

Usually enormous, and usually wrong. Both halves of that matter. It is genuinely a large number, because a modern estate really does create documents constantly through things nobody thinks of as users. And it is genuinely wrong, because the opening count includes things that should not be in it. Your job is not to be outraged. It is to find which parts.

How documents are counted 3:34

So the metric itself, four things, and the precise terms are in your own agreement which is worth reading closely. Document types: sales, purchase, invoice, material and similar core types, with several counted at a reduced weighting. Creation rather than reading, so the count is triggered by creating a document, and reading data is treated differently, which matters to your architecture. Initial creation only, meaning a document is counted when it is first created, so understand how updates and reversals are treated in your contract. And priced in tiers, because it is volume bands rather than a flat rate, which makes the tier boundary matter as much as the count itself. Read your own definition before accepting any count, because agreements differ and the definition is the whole argument.

Where the documents come from 4:29

Now where the documents actually come from. Five sources. Customer facing channels, so web shops and portals creating sales orders, which is usually the largest single source and the easiest to forget. Supplier and logistics integration, meaning EDI, carrier systems, warehouse and scanning devices creating deliveries and material documents. Third party applications, so CRM, planning, e commerce and finance tools posting into SAP through an interface. Automation and bots, meaning RPA and scheduled jobs creating documents on behalf of a process rather than a person. And internal systems you inherited, because acquired estates arrive with their own interfaces, frequently undocumented, and they get discovered during the audit rather than before it.

Knowledge check 1 5:24

First knowledge check. Your web shop creates two million sales orders a year in SAP. What is that under digital access? A, nothing, since the shoppers are not SAP users. B, two million countable documents, unless a licensed human is properly attributed to them. C, covered by the licence for the web shop platform. D, only countable if the orders are viewed in SAP by staff. Pause here and pick an answer before you continue.

B. The document exists in SAP and something other than a licensed named user created it, which is precisely the situation the metric was written for. A is the most common and most expensive misconception in this whole subject, because the shoppers being unlicensed is the reason those documents count rather than a reason they do not. C confuses two separate agreements, since a platform licence covers the platform. And D imports a reading test that simply is not in the metric. Now, note the qualifier in that answer, because attribution is where the number moves.

The attribution question 6:42

Five points on attribution. A person behind the interface: a named user creating an order through a portal is a licensed human rather than digital access, because the interface is a window onto the same person. Technical accounts hide people, since if the interface posts under one service account then every document looks like system access until you show otherwise. Prove it with the interface design, meaning documentation showing the authenticated user is carried through, plus a sample trace, which is the evidence that actually works. Separate the genuinely unattended, because batch jobs and machine to machine flows have no human and they are the part you will actually license. And do the split before pricing, since every document you move out of scope here is one you never negotiate a price for. This is worth dwelling on.

Guest analyst clip.

A factual correction to an attribution. That is the right framing, and notice that it needs a document you either have or do not: the interface design. If you have it, this is a short conversation with evidence. If you do not, you are asserting something you cannot show, and assertions do not reduce findings.

Knowledge check 2 8:50

Second knowledge check. A finding counts one business order as four documents: order, delivery, material document and invoice. What do you do? A, accept it, since four documents were created. B, ask for the counting method and how related documents were treated. C, refuse to discuss the finding until it is withdrawn. D, divide the total by four and propose that. Pause here before you continue.

B. Contracts treat cascading documents in specific ways, several types carry reduced weighting, and reprocessing can duplicate entries, so the only way to know whether this count is right is to see how it was produced. A accepts a method you have not seen. C is a posture that delays a conversation you have to have anyway, and it costs you credibility in that conversation. And D produces a number exactly as arbitrary as the one you are objecting to, which is a weak place to stand. Let me expand on the cascade problem, because it is where a plausible number becomes an implausible one.

Interrogating the method 10:05

So, the questions that move the number. What period was counted, because a peak quarter annualised overstates a normal year, and you need twelve months of your own volume data. How were related documents treated, since one event creating four records can quadruple a count, and you need process documentation for the main flows. Was reprocessing excluded, because retries and reposts inflate counts silently, and the integration error logs answer it. Who was attributed, since licensed humans behind interfaces are not digital access, and interface design documents plus a sample trace prove it. And which types were weighted, because several document types count at a reduced rate, and your contract's own definition is the authority. Not one of those is an argument about principle.

Guest analyst clip.

A number nobody can explain is not a number you should be paying. I would put that on the wall. And notice how unaggressive the request is: you are asking how a figure was derived, which is what any organisation does before accepting an invoice for anything.

Arguments that reduce the number 12:14

Right, what actually reduces a finding. Five arguments. Correct attribution, meaning documents created by licensed people through an interface, which is usually the largest single reduction available. Remove duplicates and reprocessing, because retries, reversals and batch reruns are not additional business events and should not be counted as documents. Use a representative period, so a normal twelve months rather than an annualised peak, evidenced with your own volume history. Apply the contract's weighting, since reduced weight types counted at full rate is a straightforward arithmetic correction. And re architect where it is cheap to do so, because some flows can read rather than create, or batch rather than post individually, and that is a change often worth making for its own reasons.

Where defences fail 13:10

Five traps. Arguing the principle, so debating whether indirect use should be chargeable at all, which you will not win and which makes the room worse. No interface inventory, because without your own list the vendor's list becomes the accepted one, including the parts of it that are wrong. Letting engineers answer freely, where a helpful architect describing a flow in a workshop writes the other side's evidence for them. Negotiating price before scope, since a discount on an inflated count is still an inflated count and it locks the volume in. And ignoring the forward model, because settling history without agreeing how documents are licensed from now on simply leaves the same conversation waiting for you.

Knowledge check 3 13:57

Last knowledge check. You receive a large digital access finding. What is the first thing you do? A, request the counting method and the underlying data. B, ask for a discount on the stated number. C, escalate to legal and dispute the principle. D, start re architecting your integrations. Pause here, and think about what every later step depends on.

A. You cannot verify, correct or price a number until you know how it was produced, and every other action on that list assumes a count you have not yet checked. B negotiates a percentage of a figure that is probably wrong, which is the single most common mistake in this whole area. C spends credibility on an argument that has not gone well for customers, and it delays the work that does reduce the number. And D is often worth doing while taking quarters rather than weeks, so it belongs in the forward plan rather than in the response. Let me tell you where these conversations usually land, because knowing the destination changes how you travel.

Guest analyst clip.

Running document exposure 16:03

Negotiating a purchase rather than settling an accusation. So, five things for running document exposure deliberately. Measure your own document volume by type, by source, monthly, because if you know the number then nobody else's number can surprise you. Keep the interface inventory current, so what connects, what it creates, and whether an authenticated human sits behind it. Review new integrations for the metric, because a design question at build time is free while the same question after go live is a licence purchase. Watch the tier boundaries, since document licensing is banded and you want to know how close you are to the next band before growth takes you through it. And own it jointly with architecture, because licensing cannot see the flows and architecture cannot see the price list, and neither of them works alone.

Recap 16:58

Three sentences. The metric counts specific document types created by anything that is not a licensed human, which makes it unbounded and makes web shops, EDI, automation and inherited interfaces the sources that matter. Opening findings are routinely inflated by attribution errors, cascading documents, reprocessing and unweighted types, and every one of those is a factual question about method rather than an argument about principle. And these conversations settle as a forward licensing model priced on a verified volume, so arrive with your own document count, a clean split between licensed humans and genuine system access, and a view on the volume you actually need. Next session takes the finding into the negotiation and turns it into a forward deal on your terms.

Homework 17:52

Homework before session thirty four, about two hours, and this one produces the artefact the next session assumes. One, count your documents, so sales orders, purchase orders, invoices and material documents created last year, by source, and most teams have never done this. Two, split by attribution, asking for each source whether there is an authenticated licensed human behind it or whether it is genuinely unattended. Three, find the cascades, so pick your highest volume flow and count how many documents one business event creates. Four, check the reprocessing rate, meaning how many postings are retries, reversals or corrections, and the integration logs will tell you. And five, read your own definition, which is the digital access clause in your agreement including which types carry reduced weighting.

Further reading 18:51

Five guides, all on redresscompliance dot com. SAP digital access explained covers the document types, the weightings and the tiers in detail, which is the reference version of today. Indirect use and interface design covers where documents come from and the design choices that change the count. Defending an audit finding goes into the method questions and the evidence that answers them. The SAP audit process explained is session thirty one's reference and shows how the finding reached you in the first place. And audit settlements and forward deals is where session thirty four picks up, so turning a finding into a purchase.

That is session thirty three. The thing to take away is that a finding is a number produced by a method, so get the method, correct the attribution, and settle it forward. Next time, negotiating the audit settlement. See you then.

Learning the playbook and want it applied to your numbers? We work on contingency: 25% of what we save you. Nothing saved, nothing paid.
Review my deal