AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

SAP HANA Cloud Agent Memory Service — persistent, governed memory for business agents

SAP HANA Cloud Agent Memory Service — persistent, governed memory for business agents — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-04

What is SAP HANA Cloud Agent Memory Service?

SAP HANA Cloud Agent Memory Service, introduced in the September 2026 HANA Cloud release, gives business agents persistent memory backed by the Vector Engine. SAP's reference demo scopes records by agent and invoker, enforces end-user access in CAP, shares a record between agents only on explicit user confirmation and supports revocation; GDPR retention, erasure and poisoning controls remain the application's job.

What the service is

SAP HANA Cloud Agent Memory Service arrived with the September 2026 SAP HANA Cloud release (the release notes call it "SAP Agent Memory Service"). SAP describes it as persistence and retrieval for agent memory, backed by the HANA Cloud Vector Engine: a managed API that stores memories and conversation messages and retrieves them semantically, so an agent can carry a relevant preference or decision into a later session without replaying its whole history. The motivating problem is practical. A business agent that forgets everything between conversations makes users repeat themselves; one that remembers everything indiscriminately becomes a privacy and security liability. The service is SAP's attempt to give memory a governed home beside the data it relates to. The sources reviewed do not state a general-availability status or a date for the service beyond its appearance in the September 2026 release highlights, so verify the status for your HANA Cloud edition.

SAP first signalled "agentic memory" for HANA Cloud at TechEd in November 2025, describing agents that persist context across long-running sessions and memorise past inputs and decisions. The September 2026 service is the productised form of that direction, and SAP Community material shows it working with Joule agents.

How the reference demo is built

The SAP Community post that introduces the service uses a two-agent procurement scenario. A planner-side agent learns a user preference and remembers it; a fulfillment agent later uses that preference to propose a delivery plan. Four design choices in the demo are the real content for architects.

Why it matters

  • Agents that forget are annoying and agents that remember everything are a liability: the design question is who may write, read, share and delete memory, and SAP's demo answers it with scoping, explicit sharing and revocation outside the agents.
  • Memory is personal data in GDPR terms and a persistent input channel in security terms, so retention, erasure, correction and poisoning defences must be designed before the first record is written.
  • It sits next to, not instead of, grounding and the knowledge graph: grounding for shared company knowledge, graph for relationships, memory for what one user told one agent.

Key points

  • Introduced in the September 2026 SAP HANA Cloud release as persistent agent memory and semantic retrieval, backed by the HANA Cloud Vector Engine; release notes call it 'SAP Agent Memory Service'.
  • Managed API for memories and conversation messages; GA status or date not stated in the sources reviewed (4 October 2026).
  • Records are organised by agentID and invokerID; CAP derives the scope from the authenticated user and enforces end-user access.
  • Selective sharing: a second agent gets read-only access to one explicitly shared record for the same user.
  • Sharing and revocation run through a separate Joule skill with user confirmation; neither agent has a tool to grant itself access.
  • Retrieval is vector-based (REAL_VECTOR, cosine similarity, L2 distance); the application still decides what to remember, correct and forget.
  • GDPR: purpose limitation, minimisation, storage limitation, accuracy, erasure and privacy by default apply to memory (our reading, not SAP's or legal advice).
  • Security: persistent memory is a poisoning target (OWASP agentic risk class); validate writes, keep provenance, make shared records read-only.

Terms used on this page

Agent memory
Persistent store of facts, preferences and decisions an agent can recall across sessions.
invokerID
Identifier of the user on whose behalf an agent runs; with agentID it scopes a memory record.
Selective sharing
Granting a second agent read-only access to one chosen memory record, after user confirmation.
Revocation
Removing a previously granted share without deleting the original record.
Vector Engine
HANA Cloud capability storing embeddings in REAL_VECTOR columns and comparing them by similarity.
Knowledge Graph Engine
HANA Cloud engine for RDF graphs queried with SPARQL, used for relationships rather than personal memory.
Memory poisoning
Writing adversarial content into persistent memory so it steers later sessions (OWASP agentic risk).

Sources

  1. SAP Community — Give Business Agents Memory with SAP HANA Cloud Agent Memory Service
  2. SAP Community — What's New in SAP HANA Cloud, September 2026
  3. SAP Community — What's new in SAP Cloud Application Programming Model, September 2026 (search listing only)
  4. SAP News — New agentic capabilities in SAP BTP (TechEd, Nov 2025): agentic memory, HANA Cloud MCP
  5. SAP Community — SAP HANA Cloud Becomes Agentic: Discovery Agent & Data Agent
  6. SAP Learning — SAP HANA Cloud Vector Engine (REAL_VECTOR, similarity functions)
  7. SAP Learning — SAP HANA Cloud Knowledge Graph Engine
  8. MIT AI Agent Index — Joule Agents (state retention, guardrails, documentation gaps)
  9. SAPinsider — SAP Business AI Platform: BTP foundation (Sapphire 2026; Build, Contextualize & Reason, Govern)
  10. SAPinsider — SAP Sapphire 2026: knowledge graph and Business Data Cloud as data foundation
  11. SAP Help Portal — Joule Integration Guide (2026-09-28): conversation-log opt-in/out, unsubscribing erases tenant data
  12. SAP Community — SAP Joule Work mobile app version 3.2
  13. GDPR Article 5 — principles relating to processing of personal data
  14. GDPR Article 17 — right to erasure
  15. GDPR Article 25 — data protection by design and by default
  16. OWASP Agent Memory Guard (incubator project; memory poisoning defence)
  17. Vectorize — OWASP ASI06: Memory and Context Poisoning explained

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →