AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

Secure-by-Default for SAP Analytics Delivery (the S in GSTACK)

Secure-by-Default for SAP Analytics Delivery (the S in GSTACK) — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-06

What is Secure-by-Default for SAP Analytics Delivery (the S in GSTACK)?

Secure-by-default is a pattern library, not a principle — every default (RLS on, public sharing off, watermarked exports, TLS on every RFC) pairs with a named override path and a gate that catches deviations at write time.

The pattern library

Each pattern is a one-liner default that a consultant applies on every Datasphere / BDC / SAC / BW/4HANA engagement, plus the gate that catches the override.

Datasphere

Datasphere
PatternDefaultOverride requires
Row-level securityON for every fact viewsign-off + reason in model.security filter off reason
Consumption roleconsume-only (no edit on production view)architect explicit grant
Public sharingOFFdata-classification re-review
Federated source PIIdata-mask layer requiredInfoSec review
Audit-log on view readONnone — never off

Business Data Cloud (BDC)

Business Data Cloud (BDC)
PatternDefaultOverride requires
Iceberg writesstaged with provenance metadata (table + commit)architect sign-off + post-write audit-log entry
Joule enterprise agentguard-rails: data-scope = caller's session roleInfoSec review for elevated scope
Cross-tenant joinDENYper-tenant explicit grant + data-classification re-review
Lakehouse object-store ACLleast-privilege, principal-awareplatform-team approval

SAP Analytics Cloud (SAC)

SAP Analytics Cloud (SAC)
PatternDefaultOverride requires
Story workspaceprivate until reviewedstory-publish approval
Embedded exportwatermarkedexport-policy sign-off
Public linkOFFdata-owner approval + expiry stamp
Live connection rolesleast-privilege, scoped to datasetarchitect grant
Drill-through to federated sourceRLS verified at every hopre-test on every model edit

Why it matters

  • Row-level security defaults ON for every Datasphere fact view; turning it off requires sign-off and a reason logged in the model's security-filter field — not a silent choice.
  • SAC story workspaces default private until reviewed and embedded exports default watermarked — publication and export both require explicit sign-off to override.
  • The gate contract catches overrides at write time via pre-commit hooks for code-defined controls and postbuild audits — not at audit time, months later.

Key points

  • Default = safe path. Override = explicit cost + sign-off.
  • Pattern library covers Datasphere · BDC · SAC · BW/4HANA — four products, ~20 default patterns.
  • Every pattern carries a gate: pre-commit / postbuild / live-origin probe.
  • Audit ledger captures overrides, not heroics. Trail of consent ≠ trail of guesses.
  • Maps to canonical skill `security-best-practices`. Refresh quarterly.
  • Two new agentic defaults belong in the library: narrowest tool grant by default (not broadest available), and a human checkpoint default for any write-capable agent until an adversarial test on that specific capability has passed.
  • A capability extension that reuses an existing gated pattern's shape (e.g. another 'gated write scope') still needs its own adversarial test if its blast radius differs — reusing the pattern's form without its test coverage is scope creep in disguise.
  • Record override history and adversarial-test cadence in SAP AI Agent Hub's AI Governance Assistant rather than a parallel spreadsheet only the consulting team can read.

Terms used on this page

Choice architecture
The structure of options presented to the user, designed so the safe path is the default. Coined by Thaler/Sunstein.
Pre-commit hook
Audit gate that runs locally before a commit lands — catches overrides at write time, not audit time.
Postbuild audit
Audit gate that runs after the build produces an artefact — catches content-level overrides like SAC story public links.
RLS
Row-level security — restricts which rows a user can see in a query, typically based on attributes of the user (country, role, employer).
Narrowest tool grant
The secure-by-default pattern for agentic AI: an agent's default tool/scope grant is the minimum its stated task requires, with any broader grant treated as an explicit, sign-off-gated override.
Adversarial-test-passed flag
A recorded, dated result confirming a specific agent capability was tested for manipulation (prompt injection, out-of-policy action) before being enabled — the artefact a pre-commit hook can check for before allowing a tool-grant expansion.
Scope creep (agentic)
Extending an agent's capability by reusing an existing gated pattern's shape without re-running the adversarial test for the new capability's actual blast radius — looks like reuse, functions like an ungated expansion.

Sources

  1. NIST Secure Software Development Framework (SSDF)
  2. SAP Datasphere Authorization Concept
  3. SAP Analytics Cloud Security Configuration
  4. SAP Datasphere — official product page
  5. SAP BW/4HANA — Help Portal
  6. The Challenges You Face and How SAP Business Data Cloud Helps — SAP Community (Data Professionals Blog posts)
  7. Key figure / column based security in Datasphere — SAP Community (Technology Blog Posts by Members)
  8. SAP Analytics Cloud in Business Data Cloud Achieves IBCS Re-Certification until February 2028! — SAP Community (Technology Blog Posts by SAP)
  9. CDS View Linkage between Outbound Delivery, ODO, Warehouse Order & Warehouse Task — SAP Community (Enterprise Resource Planning Blog Posts by SAP)
  10. SAP Business Data Cloud - Consolidated Error Messages in SAC Story Designer — SAP Community (Technology Blog Posts by SAP)
  11. Planning & Analytics (P&A) is an essential part of SAP Business Data Cloud (SAP BDC) — SAP Community (Technology Blog Posts by SAP)
  12. Session 1 Recap & Highlight - SAP BDC The Future of Intelligent Data Architectures 🚀 — SAP Community (Enterprise Architecture Blog Posts)
  13. [Portuguese] SAP Business Data Cloud: Sessões de Expert-Guided Implementation — SAP Community (Technology Blog Posts by SAP)
  14. UPDATE: SAP Datasphere and SAP Analytics Cloud Availability via SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  15. Accelerate Business Value with SAP Business Data Cloud — SAP Community (Max Success Plan Blog Posts)
  16. Easily Find the Link between Deliveries ↔ Freight Orders – Thanks to a CDS View — SAP Community (Supply Chain Management Blog Posts by Members)
  17. SAP Business Data Cloud : Cybersecurity, Compliance and Data Protection — SAP Community (Technology Blog Posts by SAP)
  18. This Is the Way: Rethinking Analytics Orchestration with REST in SAP Datasphere — SAP Community (Technology Blog Posts by Members)
  19. SAP Business Data Cloud : SAP Analytics Cloud のプロビジョニング — SAP Community (Technology Blog Posts by SAP)
  20. SAP Business Data Cloud: Secure by Design and Intelligent by Default — SAP Community (Technology Blog Posts by SAP)
  21. Securing Data Journey with SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  22. Provisioning of Business Data Cloud : SAP Analytics Cloud — SAP Community (Technology Blog Posts by SAP)
  23. #SITREC2025 - 🗣️Desbravando o Futuro com SAP Analytics e Business Data Cloud — SAP Community (Recife Blog Posts)
  24. SAP Business Data Cloud : Expert-Guided Implementation series — SAP Community (Technology Blog Posts by SAP)
  25. New era of data and analytics : SAP Business Data Cloud (BDC) — SAP Community (Enterprise Resource Planning Blog Posts by Members)
  26. Analytics Evolution : From Traditional Business Content to SAP BDC Intelligent Applications — SAP Community (Technology Blog Posts by SAP)
  27. Unleashing a New Era in Data & Analytics with SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  28. Datasphere - Populating Dynamic Default Values in Analytical Model Variables — SAP Community (Technology Blog Posts by Members)
  29. Deployment Readiness: SAP Datasphere & SAP Analytics Cloud — SAP Community (Technology Blog Posts by SAP)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →