← All insights

News analysisLens: United States3 min read

The most valuable enterprise agents may never leave the transaction system. SAP's Joule rollout makes that bet

SAP is rolling out Joule Work this month and counts more than 200 Joule Agents that run inside its deterministic business workflows. The architecture matters more than the agent count.

Listen to this article · 5 min

AI-generated narration of the full article.

A handwritten accounting ledger with columns of figures, in La Madre duotone, beside the words Where rules live
Photo: rawpixel (CC0)

The safest place for an enterprise agent may be the one place most agent architectures avoid: inside the system of record.

The common design runs the other way. An agent reads data through an API, reasons about it somewhere else, and writes a result back. Every hop is a place where business rules, permissions and audit trails have to be rebuilt, and every rebuilt rule is a copy that can drift from the original.

SAP’s keynote at SAP Connect on October 7 is the strongest public bet yet on the alternative.

Rules that do not have to be copied

When an agent proposes a purchase order inside the procurement application, the same approval limits, segregation of duties and posting checks apply as when a person does it. Nothing has to be re-implemented in an orchestration layer, because the agent never leaves the place where those rules already run.

The audit trail follows the same logic. In finance and procurement, an auditor’s first question is who changed what, when and under which authority. If the agent’s action is a normal transaction in the system of record, it lands in the same log as everyone else’s. We saw the same principle in Snowflake’s accounts payable system, which keeps deterministic steps deterministic.

Meaning comes along too. A purchase order, a cost center or a vendor block means something precise in an ERP. An agent working on those objects does not have to reconstruct their meaning from documents, much as an ontology did the work in Databricks’ Genie One for funds.

What SAP actually put on the table

SAP says Joule Work is rolling out this month as a new interface for AI, so people ask for outcomes in natural language instead of learning SAP’s screens, and that it reaches all of its more than 400 million users. It counts more than 20 Joule Assistants and more than 200 Joule Agents across finance, procurement, supply chain, HR and customer experience, and targets more than 400 agents by year end.

The architectural claim is explicit: the agents run inside deterministic application workflows, with the same data, rules and audit trails as the business application. SAP contrasts that with a language model on its own, which gives the most likely answer rather than a verified one. A knowledge graph and SAP Business Data Cloud give the agents a mapped view of SAP’s fields, tables, APIs and data products, with business logic attached.

SAP cites Novartis piloting sourcing agents for bid analysis, and reports productivity gains of more than 20% in its own HR, finance and procurement functions. Both are SAP’s own claims. Measure on your own processes before planning around them.

Where the agent's controls come from

Inside the system of record

  • Approval limits
  • Segregation of duties
  • Posting checks
  • Audit trail
  • Business object meaning

Inherited by the agent, not rebuilt

Beyond the ERP boundary

  • CRM
  • Email
  • Supplier portal
  • Other SaaS

Identity, policy and logging must be designed again

An agent inside the transaction system borrows controls that already work. The moment a process leaves it, those controls have to be rebuilt.

Where the argument stops

The thesis holds for transactional work inside one system. It weakens at the edges.

Many real processes span the ERP, a CRM, email and a supplier portal. An agent that stays inside SAP is safe within SAP; the moment it acts elsewhere, the integration, identity and policy questions return, and someone has to decide which platform governs the agent beyond the boundary.

Lock-in grows with every agent built on a vendor’s application logic. That can be a fair trade for the controls gained, but it should be made on purpose and counted when platforms are compared.

And a deterministic workflow only guards what it models. If an approval limit is configured wrong, an agent will respect the wrong limit faster than any person would. Before agents inherit authorizations, approval limits and posting rules, those settings deserve a review, along with a clear answer to how an agent’s action will appear in the audit log: which identity, which agent, which request.

That is the practical shape of SAP’s bet. Inside the system that already knows the rules, agents can be both useful and controlled. The harder design work starts at the edge of that system, where most end-to-end processes actually live.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case