Authorizations and FUE Costs: How Role Design Determines Your License Base
In S/4HANA Cloud, the assigned authorization, not actual usage, determines a user's license type. Assigning a colleague a role that includes Advanced authorization counts that person as an Advanced User, regardless of whether they ever call that function. Role scope is therefore not just a security concern. It is a direct governance moment for the FUE base and, by extension, for your contract price.
1. Authorization-Based Classification: How It Works
The core principle of authorization-based classification follows the Role-Based Access Control (RBAC) model. Every user is assigned roles, and each role maps to an FUE type. The highest authorization a user holds across all their roles determines that user's FUE type. This is the critical difference from usage-based classification.
Usage-based would mean: SAP measures which transactions a user actually executes and classifies them accordingly. The FUE result would reflect real system activity.
Authorization-based means: SAP measures what a user could do, specifically which authorizations their roles contain. Whether those authorizations are ever exercised has no bearing on the classification.
S/4HANA Cloud operates on the authorization-based model. The implication is immediate: roles scoped broader than actual need generate FUE costs that are not justified by usage.
PCE Metering (Private Cloud Edition) amplifies this mechanism. SAP triggers measurement monthly and automatically. Whatever authorization is registered in the system flows into the metering results every month and therefore into the contractual compliance assessment. Role quality is no longer just an annual audit checkpoint. It is a monthly governance moment.
2. What PCE Metering Measures and When
The PCE metering flow follows a defined architecture. The customer system delivers metering data to LAW (License Administration Workbench), user IDs are hashed before transmission, SAP processes the data, and makes it available in the SAP for Me dashboard under "License Utilization for Private Cloud."
The metering cycle is monthly. This means any role change that takes effect after the cutoff date of a metering run will not appear in the results until the following month. If you plan to manage FUE costs through role optimization, you need to know your metering cutoff and time optimizations to complete before the next run.
A practical note: PCE Metering has known quality boundaries that SAP continues to address. Discrepancies between automated metering and STAR reports are documented. The recommendation is to regularly validate metering results against your own internal calculations and document deviations rather than accepting them silently.
For ongoing governance: the PCE Metering dashboard should be reviewed monthly. Is FUE consumption within the expected range? Are there outliers that point to newly assigned roles or changed authorization structures? These questions are part of a structured authorization governance moment.
3. Role Creep: How Gradual Authorization Growth Drives FUE Costs
Role creep is the gradual expansion of authorizations beyond the licensed scope. It is not a deliberate process. It is the result of everyday decisions: a Self-Service User receives an additional role because they occasionally need to approve something. A Core User gets access to a transaction that technically requires Advanced, because it was "just for a one-time task." These assignments accumulate over months and years.
The result is structurally problematic. Users are measured at a higher FUE type than their work profile justifies. FUE headroom is consumed without any conscious decision being made. The authorization governance moment becomes a silent license cost driver.
A pattern that occurs frequently in practice: Self-Service Users who accumulate additional roles over time that, in combination, add up to Core-level authorization. Metering counts them as Core Users, even though the original license plan assumed Self-Service. The FUE difference between Self-Service (0.033) and Core (0.2) is 0.167 FUE per user. Across 50 affected users, that is 8.35 FUE charged against the contractually agreed FUE pool, with no active decision driving it.
The most reliable countermeasure is technical: consistently scope roles to the authorization level that is actually needed, rather than erring on the side of a broader profile. Organizational processes that validate every role assignment against the license type complement this protection.
4. STAR Analysis: Capabilities and Limitations
The STAR analysis (S/4HANA Trusted Authorization Review) is an SAP tool for analyzing the authorization structure in your system. It shows which authorizations are assigned and provides the data foundation for reviewing FUE types and identifying optimization potential.
One important limitation applies: STAR results show assigned authorizations, not actual usage. Raw STAR data can therefore reflect inflated FUE counts when authorizations are assigned but never used. Sharing that data without review can create grounds for compliance actions that are not justified by the actual usage situation.
The recommended approach is:
- Run the STAR analysis internally
- Cross-reference the results with actual usage logs and usage tracking from SAM4U
- Optimize authorizations: remove transactions that are assigned but consistently unused
- Use only the optimized data foundation as the basis for negotiations or submissions
SAM4U's Authorization Simulation (available from Q4/2025) goes further by allowing you to simulate authorization changes and assess their impact on total FUE requirements before changes are actually implemented. This is a valuable tool for quantifying the expected FUE effect before initiating a role cleanup.
5. Role Optimization Before the Metering Cycle
Role optimization has no effect if it is completed after the metering cutoff. The authorization governance moment follows a clear time logic: optimizations that take effect before the monthly metering run improve the result for that month. Optimizations completed afterward apply only in the following month.
In practice, this means: if you are planning a role cleanup, you need to know when the next metering run is scheduled and time implementation accordingly. A quarterly role review as an operational standard is therefore worthwhile, not just as good practice, but as a structural requirement for optimizations to actually show up in metering results.
Three questions should guide each quarterly review:
- Are there users whose assigned roles result in a higher FUE type than their work profile requires?
- Are there roles that contain Advanced authorizations even though the majority of usage is at Core or Self-Service level?
- Have any new role assignments been made since the last review that were not validated against license type?
These questions can be answered systematically with SAM4U Enhanced Usage Tracking. The tool identifies specific downgrade opportunities and makes the FUE effect of a reclassification visible.
6. A Practical Timeline: What Needs to Be Cleaned Up and When
A structured governance rhythm for the authorization governance moment looks like this:
Monthly: Review the PCE Metering dashboard in SAP for Me. Validate FUE consumption against internal calculation. Document any anomalies.
Quarterly: Run a self-audit with SAM4U. Check role assignments against FUE types. Identify role creep patterns. Initiate optimizations and complete them before the next metering cutoff. Document results.
At SAP upgrades and releases: Review classification changes. SAP adjusted role-to-user-type mappings in 2025. Certain transactions may now require a higher FUE type than before. Every release is therefore an opportunity to validate the current role-to-user-type mapping against your contract baseline.
12 months before renewal: Build a license optimization analysis. Which FUE types are actually needed? What pool size is realistic for the next contract term? This analysis is the negotiating foundation for renewal. Building it only after the SAP offer arrives means negotiating with weaker information.
Before enhanced audits: Run the STAR analysis internally, cross-reference with usage logs, optimize authorizations. Only then use that data foundation for discussions with SAP.
Frequently Asked Questions
What is authorization-based classification in S/4HANA?
Authorization-based classification means a user's FUE type is determined by the roles and authorizations assigned to them, not by their actual system usage. The highest authorization in a user's role combination determines their FUE type.
What is the difference from usage-based classification?
In a usage-based model, the actual scope of transactions a user executes would serve as the basis for the license type. S/4HANA Cloud uses the authorization-based model instead: assigned authorization overrides actual usage.
How often does PCE Metering run?
PCE Metering runs monthly, triggered automatically by SAP. Role optimizations must therefore be completed before the respective metering cutoff to take effect in the current month.
What is role creep and how does it occur?
Role creep is the gradual expansion of authorizations beyond the licensed scope. It typically results in users being measured at a higher FUE type than their actual work activity requires. The cause is usually the assignment of additional roles without validating the license type implication.
What is the STAR analysis and how should I use it?
The STAR analysis (S/4HANA Trusted Authorization Review) is an SAP tool for analyzing the authorization structure. It shows which authorizations are assigned. Important: always cross-reference raw STAR data internally with usage logs and optimize authorizations before using that data foundation for any external purpose.
How does role optimization affect FUE requirements?
Every user who can be downgraded from Advanced to Core saves 0.8 FUE. From Advanced to Self-Service, that is 0.967 FUE. From Core to Self-Service, it is 0.167 FUE. Across larger user populations, these savings add up to a substantial lever for shaping the contract baseline at the next renewal.
Related Articles
- SAP License Management and Maturity Model: Pillar Overview: Authorization-based classification in the broader context of license governance
- Named User and FUE: The Two Worlds of SAP Licensing: Fundamentals and conversion weights in detail
- USMM, LAW, and SAM4U: The SAP License Measurement Toolkit: How metering data is collected, consolidated, and used for governance
Next Steps
If you want to address the authorization governance moment in a structured way, start with an inventory of your current role structure and its FUE implications. The Contract Check provides a structured starting point: it captures the license base, reviews classification gaps, and surfaces optimization potential in the authorization area. Fixed price: EUR 7,900. Four weeks. Clarity for one contract.
To schedule an initial conversation, reach out to Bernhard Mändle: Book a meeting
Next Steps
Would you like your SAP contracts reviewed for deadlines, clause risks, and available commercial levers?
This article is part of our topic hub on SAP license management and maturity model. To have one specific contract assessed, the FinOptory Contract Check delivers a structured basis within four weeks.
Last updated: July 2026