AI & Analytics Legends The knowledge platform for SAP Analytics
Academy module

Agent Memory and Runtime Safety for Joule Agents — HANA Cloud Agent Memory Service and NVIDIA OpenShell

Agent Memory and Runtime Safety for Joule Agents — HANA Cloud Agent Memory Service and NVIDIA OpenShell — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-04

A security-design module for Joule agents that keep state. It explains what the SAP HANA Cloud Agent Memory Service pattern does (scope derived from the authenticated user through CAP, agentID and invokerID, sharing and revocation through a separate user-confirmed skill), states its status as demonstrated in a 30 September 2026 post and not announced as GA, and teaches how to design what an agent remembers, isolate and revoke it, and defend against memory poisoning (OWASP ASI06, MINJA). It then covers NVIDIA OpenShell, embedded by SAP in the Joule Studio runtime: four policy layers, YAML policy, credential injection, and the open item that links to SAP authorization, IAM and audit are under development. A ten-case red-team checklist and a hands-on lab close the module.

What you will learn

  • Explain what the SAP HANA Cloud Agent Memory Service does according to SAP's 30 September 2026 post, and state its status without overclaiming
  • Write a memory charter for a business agent: what is stored, why, who reads it, how long it lives, how it is removed
  • Design identity-derived memory scope, a separate user-confirmed sharing grant and a revocation path that also purges derived data
  • Name the memory attacks and map them to OWASP ASI06, ASI03, ASI07 and LLM06, with the conditions behind published attack-success figures
  • Describe NVIDIA OpenShell's four policy layers, which are static and which hot-reloadable, and how SAP positions it next to business authorization in Joule Studio
  • Run a ten-case red-team checklist for memory and runtime, and report pass, fail and not-testable results

Module overview

Who this is for. You can build and test a Joule agent (M326, M374) and you know the basic security model for SAP AI (M368: prompt injection, exfiltration, authorisations). This module covers the two design problems that appear the moment an agent stops being stateless: what it is allowed to remember, and what it is allowed to do at runtime whatever it has remembered. The first is addressed by the SAP HANA Cloud Agent Memory Service, the second by the NVIDIA OpenShell runtime that SAP is embedding in Joule Studio. Both are recent: read the status lines before you quote anything to a client. The platform vocabulary is SAP Business AI Platform (formerly SAP BTP); SAP HANA Cloud keeps its name.

Prerequisites

  • Completion of M374 (Joule Agents in Production) and M368 (Security for SAP AI) or equivalent hands-on experience with agent testing and prompt-injection defences
  • Working knowledge of SAP CAP authorization annotations (@requires, @restrict) and of SAP HANA Cloud
  • Optional: access to the SAP Community posts of 28 to 30 September 2026 and to NVIDIA's OpenShell documentation to reproduce the lab

Outcomes

  • Describe the Agent Memory Service pattern and its status accurately to a client, without presenting a demonstration as a product commitment.
  • Produce a memory charter and an isolation design in which scope comes from identity and sharing is a separate user-confirmed grant.
  • Write a revocation test that checks recipient answers, caches and derived stores.
  • Draft a least-reach sandbox policy and explain which layers are static and which can be reloaded.
  • Run the ten-case memory and runtime red-team checklist and report not-testable cases as findings.

Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.

Open in the app →