Manufacturer Analytics Portal
Delivered 25 SAPUI5 reporting applications plus 3 onboarding applications within a secure SAP BTP experience for external manufacturers.
For Decision-Makers
Executive Summary
Configured SAP Build Work Zone and SAP Cloud Identity Services with Okta-based authentication. Designed and developed the SAP CAP service using Node.js over HANA, and delivered 25 SAPUI5 reporting applications plus 3 onboarding applications that consolidated fragmented partner access into one authenticated experience.
Business Challenge
What was at stake
An external partner network accessed performance and reporting data through a patchwork of legacy portals and analytics tools. Each surface had distinct login flows, partial data coverage, and inconsistent security boundaries—creating audit risk and slowing every partner onboarding.
Key Problems
- Fragmented reporting entry points and inconsistent user experiences
- Partial or duplicated data per portal with no canonical view
- Identity sprawl across partner organizations and internal directories
- Weak tenant isolation enforced inconsistently across surfaces
- High onboarding cost and friction per partner organization
Stakeholders Affected
External manufacturer and partner network, internal IT operations, data governance, and security/compliance reviewers.
Technical Approach
Enterprise UI delivery within a multi-layer SAP BTP solution
Developed 25 SAPUI5 reporting applications plus 3 onboarding applications and reusable UI patterns while delivering the CAP service, Build Work Zone configuration, identity integration, documentation, testing, and cross-team coordination.
Developed 25 SAPUI5 reporting applications plus 3 onboarding applications and reusable frontend patterns
Designed and developed the Node.js CAP service over HANA
Worked with identity attributes used by application authorization
Supported troubleshooting across SAP IAS, XSUAA, and application layers
Contributed documentation, testing, deployment, and stabilization support
The Process
Project Lifecycle
Analyzed existing Power BI workflows and mapped data requirements for external manufacturer personas. Identified security gaps in cross-platform authentication.
Contributed to a SAP BTP solution using Build Work Zone, SAPUI5 applications, CAP services, and enterprise data sources.
Developed SAPUI5/Fiori reporting applications, supported CAP service behavior, and coordinated with technical and functional contributors.
Supported testing, troubleshooting, deployment, and post-release stabilization across enterprise environments.
Technical Deep Dive
Architecture & Implementation
Built on SAP BTP, this architecture enables secure, multi-tenant access...
Outcomes
Proof in production
Key outcome
Unified enterprise reporting experience
25 Reporting Apps + 3 Onboarding Apps
Applications
SAPUI5
Primary UI
Build Work Zone
Portal
Qualitative Outcomes
Beyond the numbers
- Single secure entry point established for the external partner community
- Consistent partner experience across analytical workflows
- A more consistent reporting experience across analytical workflows
- Application-layer authorization supported by identity attributes
- Foundation in place for adding new analytics apps without re-architecting identity
The program produced reusable UI, service, documentation, and delivery patterns for future reporting work.
Lessons Learned
What generalizes
- 01
Identity attributes must be agreed across partner IdP, IAS, and CAP before app development—late discovery cascades into UI rework.
- 02
ABAC is only as strong as the negative-test program. Explicit "partner A cannot read partner B" tests are non-negotiable.
- 03
Build Work Zone information architecture matters more than visual polish. External users abandon a portal when they cannot find their app on day one.
- 04
Phased onboarding requires coordinated communications. Technical readiness alone does not drive adoption.
- 05
CAP ABAC requires care around joins and projections. Treating ABAC as automatic leads to silent leaks under load.
When This Approach Makes Sense
Is this a fit for your program?
Strong fit when
- External users—partners, distributors, manufacturers, dealers—need secure portal access to SAP data
- Identity federation with corporate or partner IdPs is required
- Multi-tenant isolation is a hard, audited requirement
- A roadmap exists to consolidate legacy partner portals
- Stakeholders are committed to SAP-aligned architecture
Probably not when
- The audience is internal employees only and Fiori Launchpad already meets the need
- SAP BTP is not part of the strategic roadmap
- The use case is content-heavy public marketing rather than authenticated data access
Next step
Planning an SAP BTP portal for external users?
If your program involves federation, multi-tenant isolation, or consolidating legacy partner entry points, share a short brief and I'll respond with how a similar engagement would be structured.
Not sure how to engage? See engagement options.
Practical delivery
Related services
This case study maps to the services below. For engagement models, fit criteria, and how programs start, see Work With Me.