Onboarding Guide

Technical setup for the FinOptory Managed Service · As of: August 2026

This guide describes the steps to get started with the FinOptory Managed Service. Setup is carried out together with your FinOptory consultant and typically takes four weeks.

Timeline

Week 1

Access & Documents

Weeks 2 and 3

Analysis

Week 4

Onboarding

From Week 5

Service Delivery

Overview

1. S-User Setup

FinOptory requires an S-User with read permissions on the SAP for Me portal (me.sap.com) to continuously monitor and analyse your SAP contract data, licence consumption, cloud infrastructure and billing. Without this access, data-driven contract management is not possible.

Access is provided via a dedicated S-User under your SAP customer number, created and managed by your Super Administrator or Cloud Administrator. FinOptory receives read-only access exclusively. Write actions (creating cases, ordering licences, modifying system data) are deliberately excluded. Data processing is governed by the Data Processing Agreement (DPA) between you and FinOptory.

Permission Level

FinOptory recommends granting permissions at the Global level. This ensures that all SAP contracts under your customer number are fully captured, including cross-contract dependencies such as volume discounts, term overlaps and consolidation potential.

If you wish to use the FinOptory Managed Service for selected contracts only, permissions can be restricted to the Installation level. In this case, you grant permissions only for the relevant SAP installation numbers.

SAP for Me Portal

Permission Purpose
Display Order InformationView contract data, orders and terms
Access License Utilization (OnPrem, Cloud, Private Cloud)Monitor FUE consumption and licence utilisation
Manage Invoices and PaymentsReview invoices and payment status
Access Compliance DocumentsView contract documents and compliance records
Manage cloud creditsMonitor BTP credit consumption and quotas

SAP Cloud Products

Permission Purpose
Display Cloud DataView cloud system landscape, availability and provisioning status
Display Service RequestTrack existing cloud service requests

Installation and System Management

Permission Purpose
Display System DataView system landscape and installation data
Manage Shared Hardware & Cloud MeasurementsView hardware and infrastructure metrics of the cloud environment

Case Management

Permission Purpose
Display all CasesView all support cases under your customer number

Reports

Permission Purpose
Service Reports and FeedbackAccess SLA reports and service evaluations
Display Security AlertsView security notifications and recommendations
Display Support Situation ReportingTrack support evaluations and trends
Manage Alert(s) in SAP EarlyWatch AlertMonitor system health and performance analyses
Display/Manage SAP Readiness Check AnalysisView upgrade readiness and system checks

Summary: 15 Permissions

Category Count
SAP for Me Portal5
SAP Cloud Products2
Installation and System Management2
Case Management1
Reports5
Total15

Step-by-Step: Creating the S-User

  1. Open SAP for Me and sign in with your administrator S-User (me.sap.com)
  2. Navigate to User Management (menu: Users & Contacts > User Management)
  3. Create a new S-User: click Create User and enter the contact details of the FinOptory consultant provided by us
  4. Assign permissions: go to the Authorizations tab and grant the 15 permissions from the tables above
  5. Select the permission level: choose Global (recommended) or the desired installation numbers
  6. Save and activate: the new S-User will receive an activation email from SAP

After setup, share the S-User ID (format: S00XXXXXXXXX) with us. FinOptory will verify access and confirm successful setup.

Notes on the S-User

Dedicated access: Your administrator creates a separate S-User for FinOptory. Existing S-User credentials are not shared.

Permissions with Manage in the name: Some SAP permissions include the word Manage (e.g. Manage Invoices and Payments), even though FinOptory only requires read access. SAP's permission structure does not provide a separate display-only permission for these areas. FinOptory uses these permissions exclusively for reading. During onboarding, we will document the usage boundaries together with you.

Adjustments: If your SAP landscape has specific requirements (e.g. Customer Centre of Expertise with multiple customer numbers), we will align the permission structure individually during onboarding.

2. SAP API Integration

FinOptory synchronises data from your SAP landscape automatically via official SAP APIs. This replaces manual data maintenance for system landscapes, BTP consumption, entitlements and subaccount structures. Synchronisation runs daily and automatically.

Available Connections

Connection Data
Cloud ALMCloud services and technical systems from your system landscape
BTP ConsumptionCloud credit consumption and monthly costs per subaccount
BTP EntitlementsService quotas, plan assignments and utilisation
BTP AccountsSubaccount hierarchy including directories, regions and production classification

Creating a Service Key (BTP APIs)

All three BTP connections (Consumption, Entitlements, Accounts) use the same service key. It only needs to be created once.

Step A: Entitle the Service (Global Account Admin required)

  1. Open the SAP BTP Cockpit and navigate to the Global Account (top level, not subaccount)
  2. Go to Entitlements > Entity Assignments
  3. Select the subaccount where the instance should be created
  4. Click Configure Entitlements > Add Service Plans
  5. Search for cis or Cloud Management
  6. Select the central plan > Add Service Plans > Save

Step B: Create Service Instance

  1. Navigate to the subaccount > Services > Service Marketplace
  2. Search for Cloud Management Service
  3. Click Create > plan central > provide a name > Create

Step C: Create Service Key

  1. Go to Services > Instances and Subscriptions
  2. Find and click the instance in the Instances tab
  3. Service Keys tab > Create Service Key > provide a name > Create
  4. Click View and copy the full JSON
  5. Paste the JSON in the FinOptory setup wizard (Settings > SAP Connections > Add Connection)

The JSON contains clientid, clientsecret, url (token URL) and endpoints (API base URL). FinOptory extracts all fields automatically.

Creating a Service Key (Cloud ALM)

Cloud ALM requires its own service key in the Cloud ALM subaccount:

  1. Open the SAP BTP Cockpit and navigate to the Cloud ALM subaccount
  2. Go to Services > Service Marketplace
  3. Search for SAP Cloud ALM API (or calm)
  4. Click Create > select plan Landscape Management > Create
  5. Instances and Subscriptions > click on the instance > Service Keys > Create Service Key
  6. Copy the full JSON and paste it into FinOptory

Cloud ALM must be provisioned and activated in your BTP landscape before the API service is available in the marketplace.

Setup in FinOptory

Via the setup wizard in Settings > SAP Connections > Add Connection:

  1. Select the connection type (Cloud ALM, BTP Consumption, Entitlements or Accounts)
  2. Paste the full service key JSON
  3. Review the extracted fields (Token URL, API Base, Client ID, Secret)
  4. Test the connection

Once successfully configured, the connection synchronises automatically on a daily basis.

Troubleshooting

Error message Service not found in Marketplace: The service may not be entitled for your subaccount. Add the central plan for Cloud Management under Entitlements > Configure Entitlements.

No Create button visible: You need the Subaccount Administrator role. Your Global Account Administrator can assign this role.

Cloud Management not available: Your BTP contract may not include this service. Clarify entitlement with your SAP Account Executive.

3. FinOptory Report and System Access

FinOptory uses the existing ABAP report Z_FINOPTORY_EXTRACT to analyse your ECC and S/4HANA systems. FinOptory provides the current version as a transport. Your SAP Basis administrator imports it into the agreed collector system and configures the approved RFC connections to the source systems.

Because FinOptory performs the analysis as a Managed Service, we require the same dedicated FinOptory dialog user in every ECC or S/4HANA system and client to be analysed. SAP GUI sign-in to each of these systems is part of this step. The customer imports the transport, configures the user and connections, and assigns the minimum role. FinOptory then performs the data collection.

Available Data Modules

  • Measurement and system inventory: mandatory module with users, licence classification and official measurement evidence
  • Authorisations: roles, profiles, assignments and reference users
  • Authorisation catalogue: SU24 proposals plus object and transaction catalogues
  • Organisational levels: descriptions for company codes, plants and other organisational units
  • Usage: authorisation trace and transaction usage where approved by the customer

What You Provide

  1. Import of the transport provided by FinOptory into the agreed collector system
  2. The same dedicated FinOptory dialog user and SAP GUI sign-in in every ECC or S/4HANA system and client to be analysed
  3. Approved type 3 RFC connections from the collector to the source systems. A separate technical RFC user without dialog access can be used according to your security policy
  4. One role, identical in the collector system and in every source system and client
  5. A joint connection and test run before the first data transfer

One Role, Identical in Every System

The FinOptory user is granted the same role in the collector system and in every source system: dialog access to start the report, plus RFC access for cross-system execution. The same role also carries the authorization for a targeted dialog analysis directly in the system, whenever an anomaly requires it. The user is personally assigned to a single FinOptory consultant, never shared, and every activity is traceable via the Security Audit Log and STAD. One exception stays system-specific: the SM59 destination in S_ICF is maintained only in the system that delivers results to FinOptory, and stays empty everywhere else.

Authorization Matrix for Download

Manifest 2026-08-10.1 · Report 1.15.3 · one role, all authorization objects and values by module

The CSV lists every line with object, field, value and purpose, plus one column per module: x = required, opt. = only for agreed usage (background job, offline transfer, older releases, Digital Access).

Important: S_TABU_DIS does not replace S_TABU_NAM. The SAP standard checks S_TABU_DIS and S_TABU_NAM with OR logic. Z_FINOPTORY_EXTRACT additionally requires S_TABU_NAM itself and otherwise skips every dataset with a warning, regardless of S_TABU_DIS. SAP_ALL is never required.

Your SAP Basis administrator confirms the role with STAUTHTRACE for each release and selected module. On systems below SAP_BASIS 7.02, S_RFC RFC_TYPE = FUNC is not yet available and the trace shows the FUGR fallback on the entire function group instead. SAP_ALL, development, transport, RFC administration and change permissions are not required for the FinOptory user.

4. Digital Access User Analysis (optional)

Digital Access is measured by documents created rather than by named users. For ongoing contract governance, FinOptory therefore analyses which document volumes were caused by selected interface, RPA or technical users. This connects automations and integrations with their actual SAP usage.

FinOptory uses the same dedicated FinOptory user provided in Step 3. Reports are executed in the system and client where the documents were created. Central execution from another SAP system does not replace these local report runs.

Reports by System Type

Additional Permissions

Digital Access needs no additional user and no additional role. Whatever is required per system and client on top is listed in the authorization matrix from step 3, in the Digital Access column.

5. Contract Documents

We need your SAP contract documents for the contract analysis. The more complete the documentation, the more precise the analysis and the faster the start.

Document Priority Note
SAP Order FormsRequiredCloud ERP, BTP, SuccessFactors, Ariba, Concur
Amendments and addendaRequiredAll contract changes since the original agreement
Price listsRecommendedCondition sheets, discount agreements
On-Premise licence overviewIf availableExisting on-premise licences prior to Cloud ERP migration
SAP invoicesRecommendedLast 12 months, for reconciliation with contract values
Cloud SLA / OLAIf availableService level agreements with SAP

Submission: Upload directly in the FinOptory platform (PDF, DOCX, XLSX), or by email to your FinOptory consultant. Contract documents are AI-indexed and assigned to the corresponding contract units.

6. Platform Access and Roles

FinOptory uses a role-based permission model on two levels: tenant-wide and per contract. Setup is carried out together with your FinOptory consultant.

Roles

Role Permission
ViewerRead-only access to all data
EditorCreate, edit and delete data; no access to settings
AdminFull access including settings, user management and integrations

Sign-In

The default sign-in method is email and password. MFA can be activated per tenant (disabled, optional or required). Single Sign-On via Microsoft Entra ID can optionally be configured (see Step 7).

Contract Access

For each contract in FinOptory, it is defined separately which users have access and with which role. You can, for example, grant a colleague Viewer access to a specific contract without them being able to see other contracts.

Setup

  1. FinOptory creates your tenant and invites your first Admin user
  2. Your Admin invites further users (Settings > Users > Invite User)
  3. For each contract, access is configured per user

7. Microsoft Entra ID (optional)

Your employees sign in to FinOptory with their Microsoft work account, without an additional password. FinOptory receives the sign-in, the user's name and their email address. Email and password sign-in remains available alongside.

What You Provide

  • A one-time approval of FinOptory by an administrator of your Microsoft environment. We send you the approval link.
  • The email domains that should use Single Sign-On, for example yourcompany.com.

Process

  1. Your administrator opens the approval link and confirms FinOptory for your organisation.
  2. We enable your domains as soon as the approval is in place.
  3. Your employees enter their company email address at sign-in and are redirected to Microsoft.

After That

Your Microsoft environment lists FinOptory as an approved application. There you decide which users or groups may use FinOptory, and you end access whenever you no longer need it. On request, users from your domain automatically receive a FinOptory account with a role you define (Viewer, Editor or Admin) on their first login.

8. AI Integration (optional)

FinOptory provides an interface (Model Context Protocol) through which AI tools such as ChatGPT or Google Gemini can directly access your contract data. This allows you to query contract content in natural language without opening the FinOptory platform.

How It Works

The integration uses OAuth 2.0 for authentication via api.finoptory.ai. You create an OAuth Client once in the FinOptory settings and enter the credentials in ChatGPT (as a Custom GPT) or Gemini (as a Gem). The connection is then permanently active.

Available Functions

Function Description
Contract searchSearch contract documents and clauses in natural language
Document retrievalRetrieve the full content of a document for analysis
DomainsList available knowledge areas in your tenant

Setup

  1. In FinOptory: Settings > MCP Service > Create OAuth Client
  2. Note down the Client ID and Client Secret securely (the secret is shown only once)
  3. In ChatGPT or Gemini: create a Custom GPT / Gem and enter the OAuth credentials
  4. Authorise the connection (one-time sign-in to FinOptory)

Detailed instructions for ChatGPT and Gemini are available after login in the FinOptory platform under Settings > MCP Service.

Support

Setup is carried out together with your FinOptory consultant. For questions about technical configuration, please reach us at support@finoptory.ai.

SAP®, SAP for Me®, SAP Cloud ERP® and SAP BTP® are registered trademarks of SAP SE. Microsoft® and Entra ID® are registered trademarks of Microsoft Corporation.