Concept card
Secure-by-Default for SAP Analytics Delivery (the S in GSTACK)
As of 2026-10-06
What is Secure-by-Default for SAP Analytics Delivery (the S in GSTACK)?
Secure-by-default is a pattern library, not a principle — every default (RLS on, public sharing off, watermarked exports, TLS on every RFC) pairs with a named override path and a gate that catches deviations at write time.
The pattern library
Each pattern is a one-liner default that a consultant applies on every Datasphere / BDC / SAC / BW/4HANA engagement, plus the gate that catches the override.
Datasphere
| Pattern | Default | Override requires |
|---|---|---|
| Row-level security | ON for every fact view | sign-off + reason in model.security filter off reason |
| Consumption role | consume-only (no edit on production view) | architect explicit grant |
| Public sharing | OFF | data-classification re-review |
| Federated source PII | data-mask layer required | InfoSec review |
| Audit-log on view read | ON | none — never off |
Business Data Cloud (BDC)
| Pattern | Default | Override requires |
|---|---|---|
| Iceberg writes | staged with provenance metadata (table + commit) | architect sign-off + post-write audit-log entry |
| Joule enterprise agent | guard-rails: data-scope = caller's session role | InfoSec review for elevated scope |
| Cross-tenant join | DENY | per-tenant explicit grant + data-classification re-review |
| Lakehouse object-store ACL | least-privilege, principal-aware | platform-team approval |
SAP Analytics Cloud (SAC)
| Pattern | Default | Override requires |
|---|---|---|
| Story workspace | private until reviewed | story-publish approval |
| Embedded export | watermarked | export-policy sign-off |
| Public link | OFF | data-owner approval + expiry stamp |
| Live connection roles | least-privilege, scoped to dataset | architect grant |
| Drill-through to federated source | RLS verified at every hop | re-test on every model edit |
Why it matters
- Row-level security defaults ON for every Datasphere fact view; turning it off requires sign-off and a reason logged in the model's security-filter field — not a silent choice.
- SAC story workspaces default private until reviewed and embedded exports default watermarked — publication and export both require explicit sign-off to override.
- The gate contract catches overrides at write time via pre-commit hooks for code-defined controls and postbuild audits — not at audit time, months later.
Key points
- Default = safe path. Override = explicit cost + sign-off.
- Pattern library covers Datasphere · BDC · SAC · BW/4HANA — four products, ~20 default patterns.
- Every pattern carries a gate: pre-commit / postbuild / live-origin probe.
- Audit ledger captures overrides, not heroics. Trail of consent ≠ trail of guesses.
- Maps to canonical skill `security-best-practices`. Refresh quarterly.
- Two new agentic defaults belong in the library: narrowest tool grant by default (not broadest available), and a human checkpoint default for any write-capable agent until an adversarial test on that specific capability has passed.
- A capability extension that reuses an existing gated pattern's shape (e.g. another 'gated write scope') still needs its own adversarial test if its blast radius differs — reusing the pattern's form without its test coverage is scope creep in disguise.
- Record override history and adversarial-test cadence in SAP AI Agent Hub's AI Governance Assistant rather than a parallel spreadsheet only the consulting team can read.
Terms used on this page
- Choice architecture
- The structure of options presented to the user, designed so the safe path is the default. Coined by Thaler/Sunstein.
- Pre-commit hook
- Audit gate that runs locally before a commit lands — catches overrides at write time, not audit time.
- Postbuild audit
- Audit gate that runs after the build produces an artefact — catches content-level overrides like SAC story public links.
- RLS
- Row-level security — restricts which rows a user can see in a query, typically based on attributes of the user (country, role, employer).
- Narrowest tool grant
- The secure-by-default pattern for agentic AI: an agent's default tool/scope grant is the minimum its stated task requires, with any broader grant treated as an explicit, sign-off-gated override.
- Adversarial-test-passed flag
- A recorded, dated result confirming a specific agent capability was tested for manipulation (prompt injection, out-of-policy action) before being enabled — the artefact a pre-commit hook can check for before allowing a tool-grant expansion.
- Scope creep (agentic)
- Extending an agent's capability by reusing an existing gated pattern's shape without re-running the adversarial test for the new capability's actual blast radius — looks like reuse, functions like an ungated expansion.
Sources
- NIST Secure Software Development Framework (SSDF)
- SAP Datasphere Authorization Concept
- SAP Analytics Cloud Security Configuration
- SAP Datasphere — official product page
- SAP BW/4HANA — Help Portal
- The Challenges You Face and How SAP Business Data Cloud Helps — SAP Community (Data Professionals Blog posts)
- Key figure / column based security in Datasphere — SAP Community (Technology Blog Posts by Members)
- SAP Analytics Cloud in Business Data Cloud Achieves IBCS Re-Certification until February 2028! — SAP Community (Technology Blog Posts by SAP)
- CDS View Linkage between Outbound Delivery, ODO, Warehouse Order & Warehouse Task — SAP Community (Enterprise Resource Planning Blog Posts by SAP)
- SAP Business Data Cloud - Consolidated Error Messages in SAC Story Designer — SAP Community (Technology Blog Posts by SAP)
- Planning & Analytics (P&A) is an essential part of SAP Business Data Cloud (SAP BDC) — SAP Community (Technology Blog Posts by SAP)
- Session 1 Recap & Highlight - SAP BDC The Future of Intelligent Data Architectures 🚀 — SAP Community (Enterprise Architecture Blog Posts)
- [Portuguese] SAP Business Data Cloud: Sessões de Expert-Guided Implementation — SAP Community (Technology Blog Posts by SAP)
- UPDATE: SAP Datasphere and SAP Analytics Cloud Availability via SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
- Accelerate Business Value with SAP Business Data Cloud — SAP Community (Max Success Plan Blog Posts)
- Easily Find the Link between Deliveries ↔ Freight Orders – Thanks to a CDS View — SAP Community (Supply Chain Management Blog Posts by Members)
- SAP Business Data Cloud : Cybersecurity, Compliance and Data Protection — SAP Community (Technology Blog Posts by SAP)
- This Is the Way: Rethinking Analytics Orchestration with REST in SAP Datasphere — SAP Community (Technology Blog Posts by Members)
- SAP Business Data Cloud : SAP Analytics Cloud のプロビジョニング — SAP Community (Technology Blog Posts by SAP)
- SAP Business Data Cloud: Secure by Design and Intelligent by Default — SAP Community (Technology Blog Posts by SAP)
- Securing Data Journey with SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
- Provisioning of Business Data Cloud : SAP Analytics Cloud — SAP Community (Technology Blog Posts by SAP)
- #SITREC2025 - 🗣️Desbravando o Futuro com SAP Analytics e Business Data Cloud — SAP Community (Recife Blog Posts)
- SAP Business Data Cloud : Expert-Guided Implementation series — SAP Community (Technology Blog Posts by SAP)
- New era of data and analytics : SAP Business Data Cloud (BDC) — SAP Community (Enterprise Resource Planning Blog Posts by Members)
- Analytics Evolution : From Traditional Business Content to SAP BDC Intelligent Applications — SAP Community (Technology Blog Posts by SAP)
- Unleashing a New Era in Data & Analytics with SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
- Datasphere - Populating Dynamic Default Values in Analytical Model Variables — SAP Community (Technology Blog Posts by Members)
- Deployment Readiness: SAP Datasphere & SAP Analytics Cloud — SAP Community (Technology Blog Posts by SAP)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.