GSTACK — Governance Discipline for SAP Analytics Consultants
As of 2026-09-27
What is GSTACK?
GSTACK names three governance disciplines a consultant carries every engagement — threat-first architecture, a control ownership map with a named human and bus-factor flag, and secure-by-default patterns per SAP layer.
The three disciplines
GSTACK is not a product, not a tool, not a certification. It is a methodology shorthand that names three governance disciplines an SAP analytics consultant carries across every engagement:
1. Threat-first architecture (T)
Before writing a line of model-building code, the consultant maps:
- What can go wrong — the attack tree on the data flow (Datasphere replication → SAC story → embedded export). What does an attacker control? Where do trust boundaries sit?
- What already does — the incident history on this client. Past data leaks, regulator findings, internal audit reports.
- Blast radius — worst-case if the BW/4HANA extractor is compromised, if SAC sharing is mis-scoped, if the Datasphere intelligent lookup view leaks PII via row-level security gaps.
The canonical Analytics Legends skill is security-threat-model.
2. Control ownership map (O)
For every control identified (RLS policy, encryption at rest, log retention, who can publish a story, who can re-grant access to a model), the consultant writes down:
- Owner — name + role + email (NOT a team alias; one human who picks up the phone)
- Runbook — confluence/notion/wiki link with the operational steps
- Bus factor — flag if owner is N=1
- Recovery time objective (RTO) — how long until restoration if the owner is offline
The canonical Analytics Legends skill is security-ownership-map.
Why it matters
- Every control (RLS policy, encryption, log retention, publish rights) needs a named owner — not a team alias — plus a runbook, a bus-factor flag, and a recovery-time objective.
- Threat-first architecture maps what can go wrong, what already has (incident history, regulator findings), and the worst-case blast radius before any model-building code is written.
- Secure-by-default patterns replace first-principles reasoning each time with concrete defaults per platform — Datasphere, BDC, SAC, BW/4HANA.
Key points
- GSTACK = threat-first architecture × control ownership × secure-by-default — three disciplines applied as one lens.
- Maps to three canonical skills: security-threat-model, security-ownership-map, security-best-practices.
- Every finding ships with [domain · <skill> · <severity>] attribution — the audit-trail contract.
- Always-on: pre-deploy + post-deploy + threat conversations + ownership questions + compliance reviews + governance commits.
- Operator standing order is the platform's governance charter — read on every session start.
- Extending GSTACK to Joule agents adds new threat-tree leaves (prompt injection, tool-scope creep, service-account inheritance) that a pre-agentic threat model misses by default.
- Register each agent's ownership-map entry against its SAP AI Agent Hub record rather than a separate spreadsheet — duplicating the registry lets the two drift apart within a quarter.
- Any capability extension to an existing agent (e.g. adding a write path) is a new GSTACK cycle in miniature — re-score blast radius, re-test adversarially, update the Hub classification before flipping the flag, not after.
Terms used on this page
- Threat tree
- Hierarchical decomposition of attacker goals against an SAP analytics surface (e.g. Datasphere → SAC → embed).
- Bus factor
- Number of people who must vanish before a control becomes unmaintained. Bus factor 1 = single point of failure.
- Blast radius
- Set of users/data/services affected if a given trust boundary is breached. Smaller = better.
- RTO
- Recovery Time Objective — maximum acceptable downtime if a control owner is unavailable.
- Secure-by-default
- Implementation patterns where the safe choice is the path of least resistance (e.g. RLS ON by default, public sharing off by default).
Sources
- Microsoft STRIDE threat model framework
- EU AI Act Art. 9 risk management requirements
- NIST — SP 800-218 Secure Software Development Framework (SSDF) v1.1
- OWASP — Threat Modeling Cheat Sheet
- NIST — AI Risk Management Framework
- SAP News Center — Autonomous Enterprise: SAP AI Agents Work at Scale (AI Governance Assistant, 2026-09-22)
- LeanIX — SAP LeanIX Announces Launch of AI Agent Hub and Key Industry Partnerships (2025-11-04)
- SAP Help Portal — SAP Datasphere row-level security (Data Access Controls)
- SAP Help Portal — SAP Analytics Cloud sharing and story workspace settings
- EUR-Lex — Regulation (EU) 2022/2554 (DORA)
- SAP Help Portal — SAP BW/4HANA documentation
- NIST — AI 600-1 Generative AI Profile of the AI Risk Management Framework (risk-control catalogue for GenAI governance)
- SAP Architecture Center — SAP AI Agent Hub reference architecture (agent/LLM/MCP inventory and governance)
- SAP News — AI Agent Sprawl: Why AI Governance Is Now a Board-Level Issue (August 2026, SAP viewpoint, partly vendor positioning)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.