Set up a SAP data source and use it with an agent
This walkthrough configures one SAP data source from an empty form to a working request, then attaches it to an agent. You work through the tabs of the data source in order, so that by the end you have set every part of it and seen it answer a request.
The worked example answers the request: Which vendors have the largest open
purchase orders, by value?. Answering it requires the orchestration engine to
look up vendors, read purchase-order values, and rank them, which exercises
most of what a data source does.
Prerequisites
-
You have access to the SAP Data Sources tool in Neptune DXP - Open Edition.
-
The SAP system you will access is connected as a remote system and has been ingested into a catalog.
-
An AI model is configured in the Model tool in Naia Agent Studio. See Models.
-
An API authentication is configured for the connection, for the authentication step.
-
A development package is available to save the data source in.
Procedure
Create the data source
On the General tab you name the data source and connect it to the SAP system it will access.
-
In the Cockpit, go to SAP Data Sources.
-
Create a new SAP data source.
Result: The Create SAP Data Sources dialog opens.
-
In Name, enter a name, for example
Open purchasing. -
In Description, enter what the data source is for, for example
Answers queries about open purchase orders and vendors. -
In SAP System, select the connected system to query.
-
In Package, select the development package the data source belongs to.
-
Select Create.
Result: The data source now has an ID and is connected to the selected SAP system.
Write the system instructions
The instruction tells the data source how to behave when it answers a request. It is free text, and it is where you state the defaults and rules the orchestration engine should follow, such as which context to assume or how to present an answer.
-
Open the Instructions.
-
Enter the instruction the orchestration engine should follow, for example:
You answer queries about open purchase orders and vendors for {{username}}. Report amounts with their currency, and when ranking vendors, rank by value.An instruction can include variables in the
{{variableName}}format, which the orchestrastion engine fills in when it answers. As you type, autocomplete offers the available variables. System variables such as{{username}},{{name}},{{language}}, and{{currentTime}}are always available, and you can use your own custom variables in the same format. -
Save the instruction.
Saving an instruction creates a new version and sets it as the active one. Earlier versions are kept, so you can revise the instruction without losing the previous wording.
Configure the orchestration engine
The Engine Configuration tab sets which models the data source uses and how the orchestration engine plans, caches, reads data, and validates. . In the AI section, select the models the data source uses. The models offered are those configured in the Model tool in Naia Agent Studio, selected by development package and by output type, and both must support tool calling.
-
AI Model: the primary model, which handles complex requests. This is the only mandatory model on the tab.
-
Lightweight model: a secondary model for simpler requests, at lower cost and latency.
-
In the Planning section, leave Plan Cache on. With it on, the orchestration engine reuses a previously planned request for a similar new request instead of planning from scratch, which is faster. It is safe to leave on: if no cached plan is close enough, the orchestration engine plans the request normally.
-
Leave Cache Similarity Threshold at its default of
0.85. This is the minimum similarity, from 0 to 1, a new request must have to a cached plan before that plan is reused. Raise it to reuse a plan only for very close queries; lower it to reuse plans more readily. The Cache Overview shows how many plans are cached and reused, and lets you clear the cache. -
In the Data Access section, set LLM Data Access. This is the central control over how much of the SAP data the AI model may see:
-
Always: the AI model may read actual result values to interpret them.
-
Ask User (default): the AI model works from metadata only, and the orchestration engine requests one-off consent when a request cannot be answered without reading values.
-
Never: metadata only, with no consent requests.
For the scenario, leave it at Ask User.
Always, and consenting under Ask User, sends the values in question to the selected model, which can be a hosted third-party model. Use Always only where that is acceptable for the data involved. See Data security and governance.
-
-
Also in the Data Access section, set Result Retention. It governs how much of a result a run keeps once stored, the shape of the data only or the full result with SAP values, and is separate from LLM Data Access. See Data security and governance.
-
In the Validation section, leave Validate Requests on, so each planned operation is checked against the SAP metadata before it runs. This catches malformed requests earlier, at the cost of an extra check per step.
-
Leave Reflection Mode at Inline, a light re-check folded into planning. Choose Step to re-verify after every step, which is the safest and slowest, or None for the fastest, with no extra verification.
-
In the Tracing section, leave Agent Trace Detail and Run Log File at their defaults. They set how much of each run is recorded for later review. See Data security and governance.
-
Save the data source.
Add execution authentication
The orchestration engine runs its SAP calls as a user, not anonymously, so the SAP system applies its own authorizations to every call on top of what the data source grants. You set which user on the Authentication tab, per system role.
-
Go to the Authentication tab.
-
Select Add.
Result: The Execution Authentication dialog opens.
-
In Role, select the system role this authentication applies to, for example Default. The roles are Default, Local, Development, Integration, and Test.
-
In API Authentication, select the pre-configured API authentication to use.
-
Confirm the dialog, then save the data source.
Grant SAP services and operations
The SAP Services tab scopes the data source. You grant it access to specific services and operations, drawn from the catalog. An agent using the data source can reach only what you grant here, which is the main control over what it can do against SAP. See Data security and governance.
To make a large catalog navigable, you can display the services by service or semantically, and search by keyword or by describing what you want.
-
Go to the SAP Services tab.
-
Find the services the scenario needs. For open purchase orders and vendors, search for the purchasing and vendor capabilities, for example by entering
open purchase ordersorvendors. -
Grant the data source access to a service.
-
Within the granted service, grant access to the operations the queries need, such as reading purchase orders and looking up vendors.
Grant a service its value-lookup operations too, such as the search help that resolves vendor names. These let the orchestration engine turn names in a request into the codes SAP needs, and codes in a result back into names. Without them, a request that names an entity may not be answerable. -
Save the data source.
Test a request in the Playground
The Playground runs a single request against the data source, so you can see how the orchestration engine handles it: the plan it builds, any consent it needs, and the result. It tests one request in isolation. In normal use, an agent sends the requests.
-
Go to the Playground tab.
-
In Query, enter the request:
Which vendors have the largest open purchase orders, by value? -
To plan from scratch rather than reuse a cached plan, select Skip plan cache.
-
Select Send.
Result: The Agentic Activity section shows the orchestration engine searching, planning, and executing against SAP.
-
If the data source uses Ask User data access and the request needs to read values, respond to the consent request when the orchestration engine asks. Being asked is expected behavior: it keeps values out of the AI model until you allow it.
-
When the run finishes, review the result. Agentic Activity is replaced by the Cache Hits and the Final Execution Plan, which show whether a cached plan was used and the exact steps the orchestration engine ran. The Final Execution Plan is where you confirm the plan is correct or diagnose a wrong answer.
Attach the data source to an agent
Once the data source answers the request correctly in the Playground tab, attach it to an agent in Naia Agent Studio. The agent then accesses the data source as part of a conversation.
-
In Naia Agent Studio, open the agent.
-
Go to the agent’s Connectivity tab.
-
Add the SAP data source as a connection.
-
Save the agent.
The agent can now access the data source in a conversation. It handles the conversation and its history, and sends each request to the data source, which plans and executes it against SAP.
Results
You now have a working SAP data source, configured end to end:
-
It is connected to your SAP system and saved in a development package.
-
It answers with your chosen AI model, following the instruction you set.
-
It can reach only the services and operations you granted, and reads only as much data as LLM Data Access allows.
-
It runs against SAP as the authenticated user, so SAP applies its own authorizations to every call.
-
It returned a correct answer to the test request in the Playground tab.
-
It is attached to a configured agent from Naia Agent Studio, which can access it in a conversation.
With that in place, a user can ask the agent, in natural language, Which vendors
have the largest open purchase orders, by value?, and get back a ranked list of
vendor names with formatted amounts, drawn live from SAP and governed by the data
source. No integration was built for that request query.