Skip to main content
SAP BTPCAPSAPUI5Build Work Zone

Manufacturer Analytics Portal

Delivered 25 SAPUI5 reporting applications plus 3 onboarding applications within a secure SAP BTP experience for external manufacturers.

For Decision-Makers

Executive Summary

Configured SAP Build Work Zone and SAP Cloud Identity Services with Okta-based authentication. Designed and developed the SAP CAP service using Node.js over HANA, and delivered 25 SAPUI5 reporting applications plus 3 onboarding applications that consolidated fragmented partner access into one authenticated experience.

Business Challenge

What was at stake

An external partner network accessed performance and reporting data through a patchwork of legacy portals and analytics tools. Each surface had distinct login flows, partial data coverage, and inconsistent security boundaries—creating audit risk and slowing every partner onboarding.

Key Problems

  • Fragmented reporting entry points and inconsistent user experiences
  • Partial or duplicated data per portal with no canonical view
  • Identity sprawl across partner organizations and internal directories
  • Weak tenant isolation enforced inconsistently across surfaces
  • High onboarding cost and friction per partner organization

Stakeholders Affected

External manufacturer and partner network, internal IT operations, data governance, and security/compliance reviewers.

Technical Approach

Enterprise UI delivery within a multi-layer SAP BTP solution

Developed 25 SAPUI5 reporting applications plus 3 onboarding applications and reusable UI patterns while delivering the CAP service, Build Work Zone configuration, identity integration, documentation, testing, and cross-team coordination.

Developed 25 SAPUI5 reporting applications plus 3 onboarding applications and reusable frontend patterns

Designed and developed the Node.js CAP service over HANA

Worked with identity attributes used by application authorization

Supported troubleshooting across SAP IAS, XSUAA, and application layers

Contributed documentation, testing, deployment, and stabilization support

The Process

Project Lifecycle

01
Discovery

Analyzed existing Power BI workflows and mapped data requirements for external manufacturer personas. Identified security gaps in cross-platform authentication.

02
Architecture

Contributed to a SAP BTP solution using Build Work Zone, SAPUI5 applications, CAP services, and enterprise data sources.

03
Development

Developed SAPUI5/Fiori reporting applications, supported CAP service behavior, and coordinated with technical and functional contributors.

04
Deployment

Supported testing, troubleshooting, deployment, and post-release stabilization across enterprise environments.

Technical Deep Dive

Architecture & Implementation

Architecture & Implementation

Built on SAP BTP, this architecture enables secure, multi-tenant access...

Outcomes

Proof in production

Key outcome

Unified enterprise reporting experience

25 Reporting Apps + 3 Onboarding Apps

Applications

SAPUI5

Primary UI

Build Work Zone

Portal

Qualitative Outcomes

Beyond the numbers

  • Single secure entry point established for the external partner community
  • Consistent partner experience across analytical workflows
  • A more consistent reporting experience across analytical workflows
  • Application-layer authorization supported by identity attributes
  • Foundation in place for adding new analytics apps without re-architecting identity

The program produced reusable UI, service, documentation, and delivery patterns for future reporting work.

Lessons Learned

What generalizes

  1. 01

    Identity attributes must be agreed across partner IdP, IAS, and CAP before app development—late discovery cascades into UI rework.

  2. 02

    ABAC is only as strong as the negative-test program. Explicit "partner A cannot read partner B" tests are non-negotiable.

  3. 03

    Build Work Zone information architecture matters more than visual polish. External users abandon a portal when they cannot find their app on day one.

  4. 04

    Phased onboarding requires coordinated communications. Technical readiness alone does not drive adoption.

  5. 05

    CAP ABAC requires care around joins and projections. Treating ABAC as automatic leads to silent leaks under load.

When This Approach Makes Sense

Is this a fit for your program?

Strong fit when

  • External users—partners, distributors, manufacturers, dealers—need secure portal access to SAP data
  • Identity federation with corporate or partner IdPs is required
  • Multi-tenant isolation is a hard, audited requirement
  • A roadmap exists to consolidate legacy partner portals
  • Stakeholders are committed to SAP-aligned architecture

Probably not when

  • The audience is internal employees only and Fiori Launchpad already meets the need
  • SAP BTP is not part of the strategic roadmap
  • The use case is content-heavy public marketing rather than authenticated data access

Next step

Planning an SAP BTP portal for external users?

If your program involves federation, multi-tenant isolation, or consolidating legacy partner entry points, share a short brief and I'll respond with how a similar engagement would be structured.

Not sure how to engage? See engagement options.

Practical delivery

This case study maps to the services below. For engagement models, fit criteria, and how programs start, see Work With Me.