AGENTIC DEVELOPMENT INSIDE SAP

Your agents.
Your SAP.
Your rules.

Give your AI agents the means to act inside your SAP system. From code to operations, with the authorizations and traceability your teams expect.

  • 01 Inside SAP
  • 02 Native authorizations
  • 03 Audit trail
  • 04 Your MCP client

01 / THE PLATFORM

One platform.
Three pillars.

Klystron connects your MCP client to the SAP application server. Native tools to act, a team of agents to deliver, shared knowledge to improve. Each pillar is detailed below.

01PILLAR

Native SAP tools.

The MCP server is written in ABAP and runs inside your system. Code, dictionary, CDS and RAP, ATC and ABAP Unit checks, transports, roles and diagnostics, exposed as typed tools. Every object is also a file in SAP’s format, ready for Git.

The server inside SAP
02PILLAR

A team of agents.

A plugin for your MCP client. Agent teams per scenario, from development to incidents; domain skills that carry the SAP procedures and expose to each agent only the tools of its mission.

The agentic plugin
03PILLAR

Shared knowledge.

The Central Hub turns field findings into verified, signed documentation redistributed to participating systems. You choose your contribution scope.

The Central Hub

02 / USE CASES

Real work.
In the real system.

Read the context. Propose a change. Verify it. Four scenarios; the first will be replayed from a real session, code included.

SESSION · MCP CLIENT + KLYSTRON PLUGIN · FEATURE-PIPELINE TEAMSESSION REPLAY · COMING ON SERVER V2
DURATION
[DURATION]
TURNS
[N]
TOOL CALLS
[N]
OBJECTS DELIVERED
[N] · package ZIPP
YOU

“Implement the IPP protocol (RFC 8011) in NetWeaver, in pure ABAP, with no external dependency: a client able to query a printer and send a job. Package ZIPP, unit tests, transport.”

ORCHESTRATOR
feature-pipeline

Four-phase plan. No existing object under ZIPP: the Understand phase covers the release, the available HTTP classes and IPP’s binary encoding.

ANALYST
skill sap-abap-dev

Checks the target package, the release’s HTTP client classes and the locks. Gate criterion: package created, no conflict.

abap_read_packageabap_code_searchabap_where_used
DEVELOPER
skills sap-abap-dev · sap-ddic

Creates the headers, then writes the sources: IPP attribute encoder and decoder, HTTP client, Get-Printer-Attributes and Print-Job operations. Mass activation.

abap_write_class_headerabap_write_file zcl_ipp_codec.clas.abapabap_write_file zcl_ipp_client.clas.abapabap_activate_objects
QA
skill sap-quality

Runs the encoder’s unit tests against reference frames, then ATC. Gate criterion: tests green, no priority 1 error.

abap_write_file zcl_ipp_codec.clas.testclasses.abapabap_run_unit_testsabap_run_atc
RELEASE
skill sap-transports

Checks the locks, simulates the release, exports. The package files are pushed to the public repository.

abap_read_transportsap sync zipp/
  1. Understand
  2. Build
  3. Validate
  4. Deliver
Replay the session The code on GitHub · [ORG]/[REPO] Files in SAP formats, one folder per package. System identifiers removed. Links go live when the session is published.

03 / HOW IT WORKS

The entry point is
inside your system.

Three mechanisms, in the order of the pillars: the server that exposes the tools, the agents that use them, the hub that builds on what they learn.

3.1 / PILLAR 01

The server inside SAP.

An ICF service exposes the tools. Execution, checks and log stay on the SAP side.

YOUR AI ENVIRONMENT WORKSTATION OR CI
YOUR AGENT MCP client + Klystron plugin Agent teams, domain skills. It reads and writes the repository files.
YOUR GIT REPOSITORY
zsd_pricing/one folder = one package
zcl_discount.clas.jsonheader · SAP format
zcl_discount.clas.abapsource
zcl_discount.clas.testclasses.abaptests
zsd_price.tabl.jsontable · SAP format
zi_sd_price.ddls.acdsCDS view
zi_sd_price.bdef.abdlRAP behavior
zsd_price_var.vari.jsonKlystron format
Your SAP objects, as files, on your side. Version, review, open merge requests. Alongside abapGit and your pipelines.
MCP / HTTPS
Typed tool calls
DESERIALIZEWrite a file: checked, written if the fingerprint matches, read back, activated.
SERIALIZERead a package: its objects become files, one fingerprint per file.
Results, explained refusals, log
YOUR SAP SYSTEMABAP APPLICATION SERVER
klystron.The MCP server, in ABAP, behind an ICF service.
Typed tools
Bounded actions
THE REPOSITORYCustomer objects Z / Y
Classes, interfaces, programsTables, domains, data elementsCDS viewsRAPFunction modulesVariantsPFCG rolesTransports

Every object has a file name and a format: the one SAP publishes, ABAP File Formats, where it exists; a Klystron format in the same convention otherwise, distinguishable by its version (formatVersion 900). Serialization is SAP’s own: transformations generated from the ABAP types, canonical JSON identical to the SAP handler’s.

AuthorizeSAP roles / PFCG
ExecuteNative SAP services
LogSLG1 log

Explicit permissions.

A defined scope for each domain and activity. Reading, changing and executing are separate permissions, checked on the server.

A clear contract.

Typed inputs and outputs, in the vocabulary of the files. The agent knows what to send, what to expect and why a request is refused.

Safe writes.

Syntax check before anything is saved; fingerprint and conditional write against concurrent overwrites; read-back after writing.

No middleware.

The AI model remains your client’s: the choice of provider and the data sent to it are governed by your policy.

3.2 / PILLAR 02

The agentic plugin.

A plugin for your MCP client: agent teams, domain skills, and the server’s tools.

THE PLUGIN · MCP CLIENT SIDETHE SERVER · INSIDE SAP
LEVEL 1 · SCENARIOSThe agent teamsOne team per business scenario: an orchestrator, specialized agents, a phased workflow with gate criteria.
feature-pipeline teamS/4HANA migration teamrole-mining teamincident-triage teamrap-factory teamenterprise-harness teambasis team
LEVEL 2 · SAP PROCEDURESThe domain skillsOne domain per skill: instructions, triggers, guards on destructive actions and a focused tool catalog.
sap-abap-devsap-ddicsap-rap-cdssap-qualitysap-transportssap-rolessap-role-miningsap-migration-s4sap-incident-triagesap-notessap-basissap-sysopssap-integrationsap-rap-factorysap-feature-pipelinesap-enterprise-harness
LEVEL 3 · KLYSTRON SERVER INSIDE SAPThe native toolsThe MCP server exposes the typed tools; authorizations, execution and log stay on the SAP side (see 3.1).
Authorize · PFCGExecute · native servicesLog · SLG1Objets ABAP, DDIC, CDS, RAPTransportsATC · ABAP UnitJobs, dumps, logs

Why this stack. Loading every SAP tool into an agent’s context wastes context and says nothing about ordering rules or risks. Skills bring the procedure and a restricted tool catalog; each agent only reaches the domains its mission needs; SAP controls frame the execution.

EXAMPLE · FEATURE-PIPELINE TEAM

Understand → Build → Validate → Deliver.

An orchestrator holds the gate criteria; each agent hands verifiable evidence to the next.

  1. 01 / UNDERSTAND

    The analyst · skills sap-abap-dev, sap-transports

    Understand.

    Explores the repository, dependencies and scope of the change.

    GATE CRITERIONTarget package verified, caller impact assessed, no lock collision.
  2. 02 / BUILD

    The developer · skills sap-abap-dev, sap-ddic

    Build.

    Changes ABAP objects, prepares tests and checks activation.

    GATE CRITERIONAll modified objects activated, with no syntax error.
  3. 03 / VALIDATE

    The QA agent · skill sap-quality

    Validate.

    Runs ABAP Unit and ATC, then links the results to the change.

    GATE CRITERIONABAP Unit tests green, no priority 1 ATC error, no dump.
  4. 04 / DELIVER

    The release agent · skill sap-transports

    Deliver.

    Checks locks and prepares the transport under the delivery rules.

    GATE CRITERIONRelease simulation successful, transport request exported cleanly.
3.3 / PILLAR 03

The Central Hub.

A loop: what one customer learns comes back to all the others.

  1. 01 / AT EACH CUSTOMERThe agents document.

    Findings, incidents, release quirks: every mission leaves documentation behind.

  2. 02 / TO THE HUBThey share it.

    Signed, encrypted contributions, within the scope you chose.

  3. 03 / AT THE HUBThe hub consolidates.

    Triage, reproduction on reference systems, human review, signed publication.

  4. 04 / BACK TO EVERY CUSTOMER ↻The knowledge comes back.

    Business documentation, known limits and verified solutions, for the teams and their agents. Then the loop starts again.

The hub is optional: the native SAP tools work without it. Sharing is enabled as you need it.

04 / WHY NOW

AI moves forward.
So does your codebase.

Teams need to modernize code, prepare the transition and keep systems running. Our approach: give agents practical access to the system, within a framework SAP teams can examine.

THE TRANSITION IS ALREADY HERE
2027→ 2030

One timeline.
Years of code.

Mainstream maintenance for core Business Suite 7 applications ends in late 2027; optional extended maintenance runs through the end of 2030.

SAP maintenance strategy
AN ECOSYSTEM GAINING NEW TOOLS

The protocol opens the door.
The product does the work.

MCP connects your agents to SAP. Klystron gives them the tools, the method and the knowledge to act.

SAP on the agentic evolution

05 / THE RIGHT QUESTIONS

Let’s get practical.

Data, rights, hosting and its place in your toolchain.

Do we need an intermediary server?

No. The MCP server is written in ABAP and runs inside the SAP application server, behind an ICF service. You then connect your MCP client. The agent and its model keep their own hosting and network requirements.

What data is sent to the AI model?

Results your MCP client sends to the model may contain code or system data. A server inside SAP does not mean the model is local. The client, AI provider, authorized domains and accessible data are part of the pilot scope.

Which permissions does the agent use?

The SAP identity used by the client, the applicable native permissions and the server’s authorizations by domain and activity. Any technical account must be explicitly authorized. Validate the pilot scope with the account that will actually be used.

Is the hub required to use the SAP tools?

You can use the native SAP tools independently of the Central Hub. Enable knowledge exchange as needed, with an explicit configuration and contribution scope.

Does the Central Hub control my agents remotely?

The Central Hub shares verified knowledge. Agents work in their own environment, under your system’s SAP controls. The hub collects contributions, coordinates reproduction and review, then distributes signed documentation. Your teams retain control of execution and shared data.

Does this replace abapGit or Joule?

Klystron provides tooled access to the system through MCP, plus agents and skills to use it. Your assistant remains responsible for reasoning; abapGit and your pipelines remain your versioning and delivery tools, and the files in SAP formats fit into them. Connection options depend on the MCP client you choose.

How does Klystron fit into my SAP landscape?

Deployment is scoped to your release, components and use cases, on ECC or S/4HANA. A development or test pilot validates scenarios and permissions with your teams. Production rollout follows your change management and operations processes.

How do we start a pilot?

Choose a release, a domain and a measurable scenario: an ABAP test, findings analysis or a role proposal.

06 / LET’S START WITH A REAL USE CASE

Your system has potential.
Give it an agent.

One system. One scope. One first use case.