How it works

Learn the client's SAP, then resolve it safely.

It starts with an assessment that maps how that client's SAP actually works into a knowledge graph. The agents reason over that graph, and every action they propose is gated by policy before anything happens. Tessera federates across your systems rather than replacing them.

Learning loop · resolved outcomes make the model smarter CONNECT Your SAPS/4HANA and ECC ServiceNowincidents Identityroles and access Knowledge & controlsSharePoint · runbooks queried in place in your tenant no data to a model LEARN Client knowledge a living model of how your SAP actually works built in the assessment compounds with every fix REASON Agents read the ticket in its full context propose a specific, reversible action with cited evidence and a confidence score they recommend. they do not decide. GOVERNANCE GATE Your rules decide every action is checked against your policies decided by risk level a person approves anything higher-risk nothing risky runs on its own ACT Auto-resolve Assist and log Human approval Block and escalate Where you see it Command center Copilot Reports and audit GOVERNANCE AND AUDIT · spans every stage Every action on the record · Your access controls and separation of duties · Per-client isolation · Watch-only before it acts · Reversible, with a kill switch
01 · Integration

Federated access to your SAP, ServiceNow, identity, and company knowledge sources (SharePoint, runbooks, process and controls). Data is queried where it lives and copied only when necessary, within your residency controls.

02 · Knowledge

A model of how your SAP works, with per-client memory that grounds every recommendation in your own history.

03 · Agent runtime

Config-driven agents with a risk-tiered action model and human-in-the-loop approval queues.

04 · Experience & control

Command center, copilot surfaces, assessment reports, governance and audit dashboards, and cost attribution.

Knowledge graph

A ticket carries its full context.

Incidents, IDocs, orders, configuration, partners, plants, error signatures, and business KPIs live in one semantic model. So when a delivery block arrives, an agent already knows the order, the partner, the interface, the recurring signature, and the KPI it threatens, instead of rediscovering it.

Built during the assessment and deepened with every fix: a per-client model of your SAP and resolution memory that compounds over time.

ErrorSigVKM block Incident IDoc Order Partner Plant KPIDSO Playbookcandidate
representative graph fragment · O2C credit-block signature
Governance by design

An agent proposes. Policy decides.

A language model is good at reading a messy ticket and reasoning toward a fix. It is the wrong thing to trust with a production change on its own. So every action an agent proposes passes through a deterministic policy engine before anything happens.

Reason

Agent proposes

The agent reads the ticket and graph context and proposes a specific action with a confidence score and cited evidence.

Evaluate

Policy engine

Deterministic rules check it:

  • action on the allowlist
  • segregation of duties
  • environment permitted
  • confidence above threshold
Gate

Decision

Auto-resolve, require human approval, or block and escalate, by risk tier. Every decision is recorded with its inputs and the rules applied.

The policy engine is deterministic and is not overridable by model output or prompt content.

Governance

Safe to put in your client's production.

Action is gated by risk. Higher risk means more oversight, never less. This is what lets an SI put agents near production SAP at all.

RiskWhat the agent doesExamples
LowAuto-resolve within allowlistPassword reset, known IDoc reprocess
MediumAct and logJob restart, queue clear
HighRequire human approvalRole change, credit release
CriticalBlock and escalateProduction config, security grants
  • Human-in-the-loop approval queues, with shadow mode before any execution
  • Role- and attribute-based access, with segregation of duties enforced
  • Source attribution and confidence on every recommendation
  • Immutable audit of every agent decision and human approval
  • Per-agent and global rollback and kill switches
  • Per-client data isolation; one client's knowledge is never shared with another
The runtime

What makes agents safe to deploy.

Swipe to explore
Connectivity

Reaches your systems

Federated access to your SAP, ServiceNow and identity systems, querying data where it lives.

Memory

Knowledge that stays

Every validated resolution becomes reusable, versioned, and attributable, isolated to each client tenant.

Execution

Acts within limits

Calls SAP through supported interfaces, never beyond the allowlist. Where SAP publishes no interface for an action, a thin custom adapter over the standard SAP function is reviewed and transported by your own team.

Verification

Proves the fix landed

After every change the source system is read again, independently. Unverified is treated as unresolved, so a write is never mistaken for a resolution.

Evidence

A record per ticket

The agent sequence and timings, the policy decision, the approver, the interfaces called, and the tables read and written. Exportable for audit.

Landscape

Meets the estate you have

S/4HANA on-premise and private cloud with custom adapters, public cloud on released APIs, and ECC behind the same adapter pattern. Scope is established from what your system actually exposes, not from its release number.

Deployment

Where you need it

SaaS, private cloud, or fully isolated for regulated estates, one control surface everywhere.