Agents and A2A

A data source does not interface directly to users. An agent does, and it uses the data source to answer the SAP part of a conversation. That conversation can start inside Neptune DXP - Open Edition or from an external system.

The request path

Every request passes through the same layers, each with one job:

Caller

A person in a Neptune DXP - Open Edition chat, or an external orchestrator such as SAP Joule.

Agent

Owns the conversation and its history. It decides when to access the data source and how to present the answer. You build it in Naia Agent Studio.

Data source

Governs and answers one SAP request. It plans the request, runs it as the user, and returns the result.

SAP system

Runs the operations and applies its own authorizations.

Wherever the caller is, the data source is the point where SAP access is governed. See Data security and governance.

How the agent reaches the data source

You attach a data source on the agent’s Connectivity tab, in its SAP data sources panel. The agent reaches it over A2A, exposed as the access_sap tool, and calls it like any other tool in a conversation. See Attach the data source to an agent.

For a request that takes a long time, switch on Run tasks in background for the data source so the user can keep chatting while it runs. This uses the agent background-tasks feature.

The agent’s own model has a data-access setting of its own, separate from the data source’s, so set both. See Data security and governance.

A2A and external callers

The caller does not have to be inside Neptune DXP - Open Edition. An agent can be exposed over the agent-to-agent (A2A) protocol, so other agents and orchestrators can call it, including SAP Joule. A request that arrives over A2A follows the same path: the agent accesses its data source, and the data source governs the SAP access exactly as it does for a local chat.

Exposing an agent over A2A, and registering an external agent to call, are set up in Naia Agent Studio, not in the AI Context Hub: on the agent’s Connectivity tab, and as an external (A2A) agent. Inbound callers authenticate with the methods the agent card advertises, including OAuth 2.0 client credentials.

Connecting SAP Joule to an agent is an agent-level setup, comprising a BTP destination, the Joule Studio CLI, and a capability definition, and does not touch the AI Context Hub. A separate guide covering it is available from Neptune on request. When the Joule-facing agent has a data source attached, Joule reaches SAP through it, governed by the data source.