SAP expert series, part 1

SAP Technical Architecture in Depth

Product generations, the runtime that turns a screen entry into a committed document, the ABAP Dictionary, enhancement points, landscapes, authorizations, logging, archiving, and what changes on HANA and S/4HANA.

10

Numbered tables

3 diagrams

1. Product generations

Table SA-1SAP ERP generations relevant to DoD programs
GenerationTechnical baseDatabaseWhat it means for a DoD system
R/3 4.xSAP BasisAny supported databaseWhere LMP and the DLA modernization began in the early 2000s.
ERP 6.0 (ECC 6.0) with enhancement packagesNetWeaver 7.0x to 7.5 Application Server ABAPOracle, DB2, SQL Server, MaxDB, later HANAThe release family the DoD SAP systems were built and fielded on. Enhancement packages switch on new functions through business functions (SFW5).
Business Suite on HANANetWeaver 7.4 or 7.5HANASame application and tables as ECC with the database replaced. Navy ERP moved to HANA in the cloud in 2019.
S/4HANAABAP platformHANA onlySimplified data model with the Universal Journal. The target of Army convergence planning.

SAP announced in 2020 that mainstream maintenance for Business Suite 7, which includes ERP 6.0, runs to the end of 2027 with optional extended maintenance to the end of 2030. An Army article in 2025 cites the pending end of service life of its current ERP systems as a driver for modernization.

2. From screen to committed document

An SAP transaction spans several screens. Each screen is a dialog step and may run in a different work process, and each dialog step ends with its own database commit. SAP therefore cannot rely on one database transaction to keep a document consistent. It uses the SAP logical unit of work: changes are collected during the dialog and written together by an update work process after the user saves.

Figure SA-1Life of a posting: dialog steps, update task, and the documents written
update requeston errorDialog: the user or interface works through screensUpdate: the document is writtenResult: what exists in the databaseDialog step 1Screen inputWork process AOwn database commit at theendDialog step 2Checks, derivations, fundscheckMay run in work process BSaveNumber assigned from NRIVUpdate modules registeredCOMMIT WORKEnqueue locksHeld across dialog stepsPassed to the update taskReleased when the updateendsAuthorization checksAUTHORITY-CHECK attransaction start andbefore saveFailures shown in SU53V1 updateUpdate work processAll inserts in onedatabase transactionAll or nothingV2 and collectiveupdateStatistics and infostructuresRuns after V1 succeedsUpdate failureEntry stays in VBHDR andVBMODExpress mail to the userDocument number isconsumed with no documentFI documentBKPF, BSEGFAGLFLEXA or ACDOCAFM documentFMIFIIT, FMIOIFMIT, FMAVCTCO documentCOBK, COEPCOSP, COSSChange and status logsCDHDR, CDPOSJEST, JCDSWorkflow log
Table SA-2Runtime behavior and its audit consequence
MechanismHow it worksAudit or operations consequence
Number assignmentThe document number is drawn from the number range table NRIV at save, before the update runs. Buffered number ranges hand out blocks of numbers to each application server.Gaps in document numbers are normal. A gap is not evidence of a deleted document. Legal gap-free numbering needs unbuffered ranges.
Update taskFunction modules registered with IN UPDATE TASK run together in an update work process. If one fails, the whole V1 update rolls back.A failed update leaves no partial document. Failed requests sit in SM13 until reprocessed or deleted. Review SM13 at period end.
Enqueue locksLogical locks sit in a lock table in memory, not in the database. They block a second user from the same document or master record.Orphaned locks block postings and interfaces. SM12 shows them.
Integrated updateOne business event posts to FI, FM, CO, and logistics in the same update.The ledgers agree by construction when the update succeeds. Differences come from configuration, direct postings to one ledger, or repair programs.
Background processingJobs run the same programs without a user. Job definition, start condition, and log are kept in TBTCO and TBTCP.The job log is the evidence that a scheduled control ran, such as an interface load or the depreciation run.
Batch inputA session replays screen input from a file.Sessions in error stay in SM35. Unprocessed sessions are unrecorded transactions.

3. The ABAP Dictionary

Every table, field, and value list is defined in the ABAP Dictionary. Knowing its layers is what lets an analyst read an unfamiliar table, including a custom one.

Figure SA-2ABAP Dictionary objects, using company code as the example
typed byused bypart ofincludedDomain BUKRSTechnical type CHAR 4Value table T001Conversion routine, if anyFixed values, if anyData element BUKRSSemantic meaningField labels: Company CodeF1 help documentationSearch helpChange document flagTable field BSEG-BUKRSPosition in the tableKey flagForeign key to T001Reference field for amountsTable BSEGCategory: cluster in ECC,transparent in S/4HANADelivery class ATechnical settings: buffering,logging, size categoryStructure COBLCoding blockNo data of its ownIncluded in BSEG, EKKN,KBLP, MSEGCustomer include CI_COBLView V_T001Database, projection, help,or maintenance viewMaintenance views drive SM30Search help C_T001F4 value listElementary or collectiveLock object EFBKPFGenerates ENQUEUE_ andDEQUEUE_ function modulesLogical lock on a document

A field gets its technical type from a domain and its meaning from a data element. The same data element is reused in every table that carries the field, which is why field names repeat across the system.

Table SA-3ABAP Dictionary object types
ObjectWhat it definesHow to use it in analysis
DomainData type, length, value range, conversion routineThe conversion routine explains why a value looks different on screen and in the database. Example: ALPHA pads document numbers with leading zeros. WBS elements are stored as an 8-digit internal number and shown as an external ID.
Data elementMeaning, labels, documentation, search helpSearch the data element in SE11 and use the where-used list to find every table that holds that field.
Transparent tableA table that exists one-to-one in the databaseCan be queried and joined directly.
Cluster and pooled tableSeveral logical tables stored together in one physical tableIn ECC, BSEG sits in cluster RFBLG and cannot be joined in database SQL. Read it through the application or use the index tables.
StructureA field list with no stored dataStructures such as COBL show which account assignment fields travel together.
Append structureCustomer fields added to a standard table without modifying itCustom fields on standard tables usually start with ZZ or YY.
Customer includeA named slot SAP reserves for customer fields, such as CI_COBLFields added to CI_COBL appear on every line item table that includes the coding block.
ViewA join or projection, or a maintenance dialog over tablesMaintenance views are how configuration is entered through SM30.
Lock objectThe definition of a logical lockExplains which key is locked when a document is in use.
Table SA-4Table delivery classes and what they imply
ClassContentTransported between systemsChange evidence
AApplication data: master data and documentsNoChange documents and the document itself
CCustomizingYes, by transport requestTransport log, and table logging when switched on
GCustomizing protected against SAP upgradesYesTransport log
EControl tables with customer namespacesYesTransport log
SSystem tablesWith SAP deliveriesSAP notes and upgrades
LTemporary dataNoNone

Table logging needs two switches: the logging flag in the technical settings of the table and the profile parameter rec/client. Logged changes are written to DBTABLOG and read with SCU3.

4. Where programs change standard behavior

A DoD SAP system is standard software plus configuration plus custom development. Custom objects are often called RICEFW: reports, interfaces, conversions, enhancements, forms, and workflows. The table below lists the places where behavior can differ from the standard, in the order an analyst should check them.

Table SA-5Configuration and enhancement points
PointWhat it doesWhere to lookTypical DoD use
CustomizingSettings in configuration tablesSPRO, table views in SM30Document types, number ranges, account determination, release strategies, FM update profile
Account determinationDecides the G/L account for automatic postingsOBYC for materials, VKOA for sales, AO90 for assets, table T030Mapping stock movements and receipts to DoD chart of accounts posting accounts
Validation and substitutionRules that reject or overwrite field values at postingGGB0, GGB1, OB28, OBBHForcing a business area or blocking invalid fund and account combinations
FM derivationDerives funds center, commitment item, and functional area from other fieldsFMDERIVE, trace with FMDERIVATIONANALYSISDeriving the commitment item from the G/L account or material group, as the GFEBS procedures describe
Document splittingSplits lines so every document balances by fund or segmentSplitting configuration, tables FAGL_SPLINFO and FAGL_SPLINFO_VALBalanced books by fund in the new G/L
Customer exits and BAdIsSAP-provided hooks for custom codeSMOD, CMOD, SE18, SE19Interface checks, extra authorizations, custom derivations
Coding block extensionAdds customer account assignment fieldsCustomer include CI_COBL, transaction OXK3Carrying standard line of accounting elements that have no SAP field
Custom programs and tablesObjects in the Z and Y namespacePackage assignment in TADIR, source in SE38Trial balance extracts, status of funds reports, interface loaders
ModificationsChanges to SAP source codeModification browser SE95Should be rare. Each one needs re-testing at every upgrade.

5. Landscapes, clients, and change control

  • A production system is reached only through a transport route from development and quality assurance. Direct changes in production are blocked by the client setting in SCC4 and the system change option.
  • Workbench requests carry programs and dictionary objects. Customizing requests carry table entries from one client.
  • Each transport request records its owner, objects, and import history in E070, E071, and the transport logs.
  • Solution Manager adds change request management, test management, and system monitoring on top of the transport system.
  • Sandbox, training, and pre-production copies are created by client copy or system copy. Copies of production data carry the same sensitivity as production.
  • An emergency or firefighter account gives temporary elevated access with a log of every action. Auditors ask for the list of firefighter sessions and their reviews.

6. Authorization concept

SAP checks authorization in program code. A check names an authorization object and field values. The user passes if any role assigned to the user contains a matching authorization.

Table SA-6Building blocks of SAP authorizations
ElementMeaningExample
Authorization objectA group of up to ten fields checked togetherF_BKPF_BUK: accounting document by company code
Activity field ACTVTWhat the user may do01 create, 02 change, 03 display, 06 delete, 77 pre-enter (park)
Organizational levelA field maintained once per role and applied to every object in itCompany code, FM area, plant, purchasing organization
Single roleMenu plus authorizations, generated into a profileBuilt in PFCG
Derived roleCopy of a master role with different organizational levelsOne purchasing role per command
Composite roleA bundle of single rolesA job position
S_TCODEThe object checked when any transaction startsLists the transaction codes a user may start
Table SA-7Authorization objects that matter most for financial controls
ObjectControlsWhy it is sensitive
F_BKPF_BUK, F_BKPF_KOA, F_BKPF_BLAPosting by company code, account type, and document typeWho can post manual journals
F_BKPF_BUPPosting period authorization groupWho can post to closed or special periods
F_KNA1_BUK, F_LFA1_BUK, F_LFA1_APPCustomer and vendor master dataWho can create or change a payee
F_REGU_BUK, F_REGU_KOAPayment program actionsWho can propose, run, and release payments
F_FICB_FKR, F_FICA_FCD, F_FICA_FSG, F_FICA_FPGFM area, funds center, fund group, commitment item groupWho can post and view budget by organization and fund
F_FMBU_ACC, F_FMBU_DOCBCS budget entry by budget address and document typeWho can load, transfer, or return budget
M_BEST_BSA, M_BEST_EKO, M_BEST_EKG, M_BEST_WRKPurchase orders by document type, purchasing organization, group, plantWho can obligate
M_BANF_FRG, M_EINK_FRGRelease codes for requisitions and purchase ordersWho can approve and certify
M_MSEG_BWA, M_MSEG_WWAGoods movements by movement type and plantWho can receive
M_RECH_WRK, M_RECH_AKZInvoice verification and tolerance acceptanceWho can enter invoices and override match differences
K_CSKS, K_ORDER, K_KA03Cost centers, orders, cost element planningCost object maintenance
A_S_ANLKL, A_B_ANLKLAsset master and asset postings by classWho can capitalize and retire
S_TABU_DIS, S_TABU_NAMTable maintenance and displayDirect table access bypasses application controls
S_DEVELOP, S_PROGRAM, S_TRANSPRTDevelopment, program execution, transportsCode changes and debug-change access in production
S_USER_GRP, S_USER_AGRUser and role administrationWho can grant access
S_RFC, S_ICFRemote function calls and web servicesWhat interface accounts can execute
S_BTCH_JOB, S_BTCH_NAMBackground jobs and the user a job runs underRunning programs under another identity

Object names are standard SAP. Each program decides which checks and organizational levels it uses.

Table SA-8Segregation of duties conflicts usually tested first
Function AFunction BRisk
Maintain vendor master (XK01, XK02, FK02)Enter vendor invoice or run payments (FB60, MIRO, F110)Create a payee and pay it
Create purchase order (ME21N)Post goods receipt (MIGO)Order and confirm receipt of goods that never arrived
Post goods receipt (MIGO)Enter invoice (MIRO)Complete a three-way match alone
Enter journal (FB50, FV50)Post parked journal (FBV0) for the same documentPrepare and approve an adjustment
Load or transfer budget (FMBB)Create obligations (ME21N, FMZ1)Fund and spend without independent control
Maintain customer master (XD01)Post incoming payments or credit memos (F-28, FB75)Misapply or write off receivables
Maintain asset master (AS01)Post asset transactions (ABAVN, ABUMN)Conceal loss or transfer of property
Develop programs (SE38)Import transports to production (STMS)Unreviewed code in production
Administer users (SU01)Administer roles (PFCG)Self-granted access
Open posting periods (OB52)Post documentsBackdated postings

7. Evidence the system keeps

Table SA-9Logs and where they are stored
EvidenceTablesRead withRetention concern
Who posted a document and howBKPF fields USNAM, TCODE, CPUDT, CPUTMFB03, SE16NKept with the document until archived
Changes to documents and master dataCDHDR, CDPOSFB04, XK04, report RSSCD100Kept until archived or deleted by a housekeeping job
Status changes on orders, projects, earmarked fundsJEST, JCDSStatus display in the objectOnly if change documents are active for the status profile
Approval stepsWorkflow tables such as SWWWIHEAD, release fields on EBAN and EKKOWorkflow log, ME53N, ME23NWorkflow logs are often purged first
Configuration table changesDBTABLOGSCU3Only for tables with logging switched on
TransportsE070, E071, transport logsSTMS, SE09Permanent unless cleaned up
Security eventsSecurity audit log filesSM20File-based. Retention is an operations setting.
User and role changesChange documents for users and rolesSUIMKept until archived
Interface messagesEDIDC, EDID4, EDIDSWE02, BD87IDocs are archived or deleted on a schedule. Agree the schedule with audit retention needs.
Job runsTBTCO, TBTCP, job logs, spoolSM37, SP01Job logs and spool are deleted after days or weeks by default
AttachmentsSRGBTBREL, SOOD, content repositoryServices for object in the documentDepends on the content server

Archiving

  • Data archiving moves closed documents out of the database into archive files through archiving objects. Examples: FI_DOCUMNT for accounting documents, MM_EKKO for purchasing documents, MM_MATBEL for material documents, IDOC for IDocs, CHANGEDOCU for change documents.
  • Archiving runs in SARA. Archived data stays readable through the archive information system when an archive infostructure exists.
  • An extract or replication taken after archiving will not contain the archived documents. A universe of transactions for an open audit period must be taken before archiving, or must read the archive.
  • Residence times are configuration. They should be set against record retention rules, which for federal financial records run for years after the period.

8. HANA and S/4HANA architecture

Figure SA-3S/4HANA layers and the simplified data model
User experienceApplication serverSAP HANA databaseFiori launchpadTiles from catalogs and groupsTransactional, analytical, andfact sheet appsSAP GUI and Web GUIClassic transactions remainSome are replaced or redirectedAPIs and integrationOData and SOAP servicesIDoc and BAPI still supportedAnalytics clientsAnalysis for Office, analyticscloud tools, BW queriesGatewayFront-end serverPublishes OData servicesEmbedded or hub deploymentABAP platformBusiness logic, authorization checks, posting interfacesCDS views define the virtual data model, for example I_JournalEntryItemCode pushdown: aggregation runs in the databaseEmbedded analyticsAnalytical queries on CDS viewsNo separate warehouse load foroperational reportsACDOCAOne line item table forG/L, CO, assets, materialledgerMATDOCMaterial documentsStock computed on readFMIOI, FMIFIIT, BCSFunds Management tablescarry overCompatibility viewsBSIS, BSIK, GLT0, COSP,MKPF, MSEG as viewsOld reads still work
Table SA-10What HANA and S/4HANA change technically
TopicECC on a row databaseHANA and S/4HANA
StorageRow store on disk with secondary indexesColumn store in memory with compression. Aggregates are computed on request.
Totals and index tablesStored and updated with every postingRemoved. Same-named compatibility views read the line items.
Cluster tablesBSEG in cluster RFBLGTransparent tables
Reporting modelABAP reports, Report Writer, BW extractsCDS views expose a virtual data model. Analytical apps read line items directly.
ExtractionDelta extractors and trigger-based replicationCDS-based extraction and replication. Table-level replication still works.
User interfaceSAP GUIFiori launchpad plus SAP GUI. Access is granted through business catalogs as well as roles.
Custom codeReads of standard tables in any formMust be checked. Code that relied on implicit sort order or wrote to removed tables needs remediation.
Business partnerSeparate vendor and customer mastersBusiness partner is the leading object, synchronized to LFA1 and KNA1.
Field lengthsMaterial number 18, amounts 13 digits plus 2 decimalsMaterial number up to 40, amounts up to 23 digits

USNI News reported in August 2019 that Navy ERP moved about 72,000 users at six commands to SAP HANA in the cloud, and that a report that had taken five to six hours then ran in about 30 minutes.

Sources

  1. SAP NetWeaver documentation: work processes and the application server
  2. SAP News: maintenance commitment for Business Suite 7 and S/4HANA (February 2020)
  3. SAP Press: S/4HANA Finance and the universal journal
  4. SAP Community: ECC tables after migration to S/4HANA Finance
  5. USNI News: six Navy commands on cloud-based Navy ERP (August 2019)
  6. Army.mil: EBS-C goes live for ammunition (July 2025)

Educational reference. Standard product tables and public sources only. Not an official DoD, DFAS, SAP, or Oracle publication.