SAP Security for AI Agents: Identity, Access and Accountability
Your SAP security model was built around people. Now you need to work out what happens when an AI agent can access data, initiate actions or transact across systems. Traditional questions about identity, permissions, segregation of duties and auditability suddenly have a new kind of user to account for.
Across three days, explore how security and governance need to evolve as AI moves into business processes. Learn from Queensland's Department of Transport and Main Roads on threat modelling, Under Armour on what RISE's shared-responsibility model means for customers, and Tait Communications on roles, authorisations and audit evidence. Put the principles into practice through an incident simulation, and leave with a stronger framework for controlling what agents can do, understanding who remains accountable and giving auditors the evidence they need.
What Would You Do? An Interactive SAP Risk and Security Simulation
DEEP DIVE · 90 MINColleen Hebbert (SAP) and Gaurav Singh (Under Armour)
A simulation, not a lecture. Teams work live through access violations, auditor challenges and an unfolding incident. Bring your GRC and audit people and do it together.
Paul Hesford (Queensland Department of Transport and Main Roads) and Phil Burgess (SAP)
How TMR used process-level threat modelling, clear accountabilities and a business-led incident exercise to prepare for agentic AI risk.
SAPinsider APAC 2026 · Innovation Vanguard finalistSAP Best Tech Awards 2026 · Intelligent ERP finalistJames Pearson, Tait Communications
How Tait is turning its first subsidiary onboarding into a repeatable model for roles, authorisations and audit evidence across its global finance environment.
Gaurav Singh, Under Armour
Why Under Armour treated security as a Phase Zero decision, and what RISE's shared-responsibility model still leaves with the customer.
Norman Alimagno, Go Global Business Services (JG Summit Holdings)
Control at the point of change rather than the point of reporting.
Phil Burgess and Colleen Hebbert, SAP
Business process threat modelling, process intelligence and SAP Enterprise Threat Detection. Why technical alerts disconnected from business consequence don't help you.
Gaurav Singh, Under Armour
The uncomfortable audit of what your programme actually covers.
SAP TechEd curriculum
How agent identities change authentication, lifecycle management and access across SAP landscapes.
SAP TechEd curriculum
How to give agents scoped permissions, runtime controls, human approval and observability across SAP and third-party systems.
SAP TechEd curriculum
How to establish ownership, runtime controls and central visibility as agents, models and MCP servers spread across the business.
A clearer view of the gaps in your current control model, and the questions you need to answer about agent identity, access and accountability.
SAP security lead · GRC manager · Internal audit · Process owners
Pre-conference 17 Nov · Main conference 18–19 Nov · ICC Sydney · Agenda and timings subject to change