Analytics Legends The knowledge platform for SAP Analytics
Academy module

GSTACK 101 — Operating Governance Discipline on SAP Analytics Engagements

GSTACK 101 governance workshop flow: Frame, Threat tree, Ownership map, Override audit, Risk register — architecture diagram for GSTACK 101 — Operating Governance Discipline on SAP Analytics Engagements, Analytics Legends Academy module M303

As of 2026-08-16

GSTACK is the three-discipline governance shorthand (threat-first × ownership × secure-by-default) every SAP analytics consultant carries across every engagement. This module is the 60-minute workshop that lets a Y3-Y8 consultant operate it on day 1 of a new mission. By the end the consultant has drafted (a) a threat-tree per critical data flow, (b) an ownership map for every identified control, (c) the override-vs-default ledger for the engagement, and (d) the GSTACK-tagged risk register the client's auditor will read in week 12.

What you will learn

  • Operate GSTACK on day 1 of a new SAP analytics engagement.
  • Produce a 4-step threat tree per critical data flow.
  • Convert threat-tree findings into an ownership map with bus-factor flags.
  • Walk the secure-by-default pattern library and produce the override ledger.
  • Consolidate into a GSTACK-tagged risk register for the client's auditor.

60-minute workshop structure

0-10 min · Frame Why GSTACK exists, what the three disciplines mean, how the [GSTACK · canonical-skill · severity] tag works. See concept card C304 for the framework overview.

10-25 min · Threat-tree practice Pick one real data flow from the engagement (ECC → Datasphere → SAC story is the default exercise). Walk the 4 steps: asset inventory · trust boundaries · STRIDE-light per boundary · blast-radius scoring. Produce the 1-page output. See concept card C305 for the framework.

25-40 min · Ownership map For each control identified in the threat tree, name: owner (human, not alias) · runbook link · bus factor · RTO. Convert the threat tree into an ownership document. Bus-factor 1 entries get a 'fix before go-live' flag.

40-55 min · Secure-by-default override audit Walk the pattern library (concept card C306). For each pattern, decide: keep default, or document override + owner + reason. Produce the override ledger. Any override without owner = blocker.

Prerequisites

  • Y3+ SAP analytics consulting experience
  • Read the platform charter + a written playbook

Outcomes

  • By end of workshop: 1 threat tree · 1 ownership map · 1 override ledger · 1 risk register
  • Concrete artefacts the auditor reads, not theatre

Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.

Open in the app →