AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

Threat-First SAP Analytics Architecture (the T in GSTACK)

Threat-First SAP Analytics Architecture (the T in GSTACK) — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-06

What is Threat-First SAP Analytics Architecture (the T in GSTACK)?

The threat tree walks every SAP analytics flow through four steps — asset classification, trust boundaries from ECC to external share, STRIDE-light per boundary, and blast-radius scoring — producing a one-page document per flow.

The 4-step threat tree on SAP analytics flows

Apply to every critical data flow on the engagement. Output is a 1-page-per-flow document.

Step 1 — Asset inventory

What data does this flow carry? Classification levels:

  • Public — counts, KPIs at country level, anonymized buyer-persona
  • Internal — country-grouped revenue, partner relationships, named-customer logos
  • Confidential — per-customer transactional, individual employee, payroll, MNPI
  • Restricted — PII identifying natural persons, health data, payment card data

The higher the classification, the smaller the acceptable blast radius.

Step 2 — Trust boundaries

Walk the flow from origin to consumption. At each transition, draw a boundary:

  • ECC source → Datasphere replication (boundary: SAP RFC trust)
  • Datasphere → BDC Iceberg lakehouse (boundary: lakehouse object-store ACLs)
  • BDC → SAC live model (boundary: SAC role + space)
  • SAC story → embedded export to Office (boundary: SAC export policy)
  • SAC story → shared to external auditor (boundary: SAC public link)

At each boundary, name what the attacker would have to compromise to cross it.

Why it matters

  • Data classification (public, internal, confidential, restricted) sets the acceptable blast radius before any control is designed — the higher the classification, the smaller that radius must be.
  • Each trust-boundary transition (ECC to Datasphere, Datasphere to BDC Iceberg, BDC to SAC live model, SAC to external auditor) names exactly what an attacker would need to compromise to cross it.
  • STRIDE-light applied per boundary surfaces SAP-specific attack vectors — S-User reuse, RLS bypass via SAC drill-through, a Joule agent inheriting service-account scope.

Key points

  • Apply per data flow, not per project — each flow gets a 1-page threat tree.
  • 4 steps: asset inventory · trust boundaries · STRIDE-light per boundary · blast-radius scoring.
  • SAP analytics-specific boundary list: ECC→Datasphere, Datasphere→BDC, BDC→SAC, SAC→export, SAC→public link.
  • Output: a [GSTACK · threat-model · Pn] line per finding, fed into engagement risk register.
  • Pairs with ownership-map (C306) — every finding gets a named owner.
  • Once a Joule agent or grounding pipeline sits in the flow, add an LLM-inference boundary — its Spoofing leaf is prompt injection, its Information-disclosure leaf is grounding retrieval bypassing row-level security.
  • Score blast radius on a third factor when a leaf feeds an actionable agent: is the downstream action reversible — a self-propagating disclosure via an agent's own write action outranks a static leak.
  • Fix grounding-bypass leaks at the data-product layer (Datasphere DAC), not inside Joule Studio — a Joule-only fix leaves every other consumer of the same data product still exposed.

Terms used on this page

Trust boundary
A point in the architecture where attacker-controlled input meets privileged code or data.
STRIDE
Microsoft threat-classification framework: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
Data classification
Tagging of data with a sensitivity level (public/internal/confidential/restricted) used to scope acceptable blast radius.
Asset inventory
The first step of any threat model — what are we protecting? Skip this and the rest is theatre.
LLM-inference boundary
The trust-boundary type introduced once a flow includes an LLM call — the point where governed data crosses into a prompt, with its own Spoofing (prompt injection) and Information-disclosure (grounding leakage) failure modes.
Grounding retrieval
The document- or database-grounding step in SAP's orchestration service that fetches context before an LLM call; historically runs under a service identity, which can silently bypass the requesting user's own row-level security unless explicitly configured otherwise.
Reversibility factor
A third scoring dimension added to blast-radius rank once a threat-tree leaf feeds an actionable agent: whether the downstream action the agent can take is reversible, since an irreversible action compounds a disclosure into a self-propagating incident.

Sources

  1. Microsoft STRIDE
  2. OWASP Threat Modeling Cheat Sheet
  3. SAP Datasphere Security Guide
  4. SAP Analytics Cloud Security Configuration
  5. SAP Datasphere — official product page
  6. Leveraging SAP Architecture Center for SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  7. The Challenges You Face and How SAP Business Data Cloud Helps — SAP Community (Data Professionals Blog posts)
  8. Managing Parent-Child Hierarchies in SAC: A Datasphere-Driven Approach — SAP Community (Technology Blog Posts by Members)
  9. Key figure / column based security in Datasphere — SAP Community (Technology Blog Posts by Members)
  10. SAP Business Data Cloud and Datasphere News in March — SAP Community (Technology Blog Posts by SAP)
  11. SAP Analytics Cloud in Business Data Cloud Achieves IBCS Re-Certification until February 2028! — SAP Community (Technology Blog Posts by SAP)
  12. Beyond Row-Level Security: Implementing Widget-Level Custom Authorization in SAP Analytics Cloud — SAP Community (Technology Blog Posts by Members)
  13. Currency Conversion in SAP Datasphere: The Next Level — SAP Community (Technology Blog Posts by Members)
  14. SAP Business Data Cloud for the Business Analyst: turning raw data to trusted and actionable insight — SAP Community (Data Professionals Blog posts)
  15. SAP Business Data Cloud and Datasphere News in February — SAP Community (Technology Blog Posts by SAP)
  16. Deep Dive into SAP Datasphere Object Store of BDC: Benefits, Architecture and implementation — SAP Community (Technology Blog Posts by Members)
  17. SAP Business Data Cloud and Datasphere News in January — SAP Community (Technology Blog Posts by SAP)
  18. Leveraging SAP Architecture Center for SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  19. SAP Business Data Cloud - Consolidated Error Messages in SAC Story Designer — SAP Community (Technology Blog Posts by SAP)
  20. Connecting SAP Analytics Cloud to Databricks model serving endpoint — SAP Community (Technology Blog Posts by SAP)
  21. Authorization setup for SAC Import Model from S4 ABAP CDS Views — SAP Community (Tooling (+ SAP Build) Blog Posts)
  22. Rewiring of SAP Datasphere to SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  23. Data masking, data scrambling and data anonymization in Business Data Cloud with SAP Datasphere — SAP Community (Technology Blog Posts by SAP)
  24. Datasphere (DSP) and SAC data and metadata versioning / backup and restore — SAP Community (Technology Blog Posts by Members)
  25. Authorization setup for SAC Live Model from S4 ABAP CDS Views — SAP Community (Tooling (+ SAP Build) Blog Posts)
  26. SAP Datasphere & Google BigQuery: 3 Integration Strategies Before Zero Copy via BDC Connect Arrives — SAP Community (Technology Blog Posts by SAP)
  27. Empowering SAP Datasphere users with SAP Business Data Cloud innovations — SAP Community (Technology Blog Posts by SAP)
  28. SAP PaPM Cloud Universal Model: Pushing and Pulling data to and from SAP Analytics Cloud — SAP Community (Financial Management Blog Posts by SAP)
  29. Planning your transition paths to SAP Business Data Cloud (data architecture miniseries) — SAP Community (Technology Blog Posts by SAP)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →