AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

Joule Guardrails — SAP's Trust Layers for Joule and the Orchestration Service

Joule Guardrails — SAP's Trust Layers for Joule and the Orchestration Service — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-06

What is Joule Guardrails?

‘Joule Guardrails’ is not a product but a stack of controls: identity and principal propagation, agents limited to approved tools with human confirmation for high-stakes actions, content filtering and data masking in the orchestration service, contractual no-retention by LLM providers, and SAP's AI ethics review, red-teaming and ISO/IEC 42001 certification. Knowing which layer SAP runs and which one you configure is the whole job.

What the term covers

There is no SAP SKU called Joule Guardrails. The phrase is shorthand for the controls SAP builds around Joule and, for your own AI applications, into the orchestration service of the generative AI hub. Earlier versions of this card described a three-layer framework with a tamper-resistant "Audit Journal" logging every prompt; SAP documents no such component. What SAP does document can be read as six layers, some operated by SAP, some configured by you.

Layer 1 — identity and authorization

Joule authenticates users through SAP Cloud Identity Services (Identity Authentication and Identity Provisioning) with single sign-on, and "doesn't have its own permission system": it acts on behalf of the user through principal propagation, so it can only read or change what that user may already read or change in the connected SAP application (SAP Community, SAP security advisory post). Business actions go through the applications' official APIs, which apply their own validations and segregation-of-duties rules and leave their usual application logs. This is the most important guardrail and the least visible one: a badly designed role concept in S/4HANA or SuccessFactors is inherited by Joule unchanged.

Why it matters

  • Joule inherits the user's authorizations through principal propagation — a weak role concept in the backend becomes a weak Joule, whatever the content filters do.
  • Since 13 August 2026 Prompt Shield ignores system and developer messages: untrusted text injected there is no longer screened for prompt attacks.
  • SAP's certifications and red-teaming cover SAP as provider; the deployer's EU AI Act obligations and your own agent design remain yours.

Key points

  • ‘Joule Guardrails’ is a label for layered controls, not an SAP product; no ‘Audit Journal’ logging every prompt is documented.
  • Identity: SAP Cloud Identity Services, SSO, principal propagation — Joule has no permission system of its own.
  • Agents: restricted to approved tools and actions; high-stakes operations need explicit user authorization; your Joule Studio design defines this for custom agents.
  • Orchestration content filtering: Azure Content Safety (Hate/Violence/Sexual/SelfHarm, severity 0-2-4-6, Prompt Shield, protected code) and Llama Guard 3 (14 categories), input and output.
  • Data masking via SAP Data Privacy Integration: anonymization (MASKED_ENTITY) or pseudonymization (MASKED_ENTITY_ID, reversible); entity coverage varies by language and country.
  • LLM providers: no storage, retention or training on customer data (contractual); Joule is not designed for personal or sensitive data; outputs must be reviewed.
  • SAP governance: ethics classification (minimal / high risk / red line), internal and external red-teaming, ISO/IEC 42001 covering Joule, AI Core, AI Launchpad.
  • 2026 changes: Prompt Shield skips system/developer messages (13 Aug); Azure OpenAI global filter blocks medium/high severity (7 Sep).

Terms used on this page

Principal propagation
Passing the end user's identity to the backend so that Joule acts only with that user's authorizations.
Content filtering module
Optional orchestration module that screens input and output with Azure Content Safety and/or Llama Guard 3.
Prompt Shield
Azure Content Safety feature detecting prompt attacks on input; since August 2026 it no longer scans system and developer messages.
Severity level
Azure Content Safety rating 0, 2, 4 or 6 per harm category; the filter threshold is configured per category.
Llama Guard 3
Meta safety classifier used by orchestration, returning Boolean flags for 14 hazard categories.
Anonymization
Masking that replaces personal data with MASKED_ENTITY; the original cannot be restored.
Pseudonymization
Masking that replaces personal data with MASKED_ENTITY_ID placeholders that are restored in the response.
Red line use case
Category in SAP's AI ethics classification for prohibited AI uses, which are stopped.

Sources

  1. SAP AI Core — Content Filtering (SAP-docs)
  2. SAP AI Core — Data Masking (SAP-docs)
  3. SAP AI Core service guide incl. What's New (PDF, 4 Sep 2026)
  4. Integrating Joule with SAP Solutions (PDF, 14 Sep 2026)
  5. SAP Community (SAP) — Principles to Practice: Securing SAP Business AI
  6. SAP Community — Trust by Design: Security, Guardrails & Governance in Joule (Aug 2026)
  7. SAP Community (SAP) — SAP Business AI earns ISO/IEC 42001 certification
  8. SAP Cloud SDK for AI — filtering and masking builders (JS)
  9. SAP News Center — Secure AI agents: how SAP and NVIDIA co-define enterprise-grade agent execution (NVIDIA OpenShell, 2026-05-12)
  10. SAP Help — Orchestration service (generative AI hub) overview
  11. SAP Help — Integrating Joule with SAP: prerequisites
  12. SAP News Center — Autonomous enterprise, business transformation management and SAP AI agents at scale: AI Governance Assistant (2026-09-22)
  13. SAP News — SAP and NVIDIA OpenShell: security for auditable AI agents (Joule Studio runtime, free through October 2026, FedRAMP/FIPS roadmap)
  14. Forrester — Oktane 2026 recap: unified IAM control plane, agent governance and identity details unclear
  15. Computerworld — US FTC will investigate Anthropic and OpenAI (consumer-protection information demands, agent security incidents)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →