ServiceNow · Zendesk · Jira · S/4HANA

A scene can read the systems your customers run

By default a scene reads what is in your own workspace. It can also read what is in theirs: the S/4HANA instance behind their firewall, the ticket queue your desk works in, the historian on their plant network.

Most of it is a connection your customer authorises once, the same way they connect anything else. For the systems with no door out, a node goes inside their network instead. Either way you are not the one holding their credentials, and the answer comes back to the screen your engineer already had open.

support.yourcompany.comyour desk
INCIDENT · SECOND LEVEL
Goods receipt fails on posting
Raised by the customer's AP team
“Every goods receipt against a scheduling agreement dies with the same message. Nothing changed on our side.”
M8 082 — Balance in transaction currency
the scene underneath itwhat ran
Diagnose the posting failurethe customer's systems
01read the ticketthe subject, the message number, the customer it belongs to
02find the failed postingswhich documents, against which agreement, since when
03read the change historywho touched that agreement and the tax setup, and when
04compare against one that worksthe same posting on an agreement that still goes through
asked before continuingRead the custom field on the agreement header? It is in the customer's own namespace, not the standard one.
05read the custom fieldapproved by the engineer, one table, read only
what comes backThe change that broke it, the setting it depends on, and the working agreement it was compared against. Written into the ticket your engineer already had open.

The steps a run of this kind takes. No timings or findings are shown here, because the ones worth printing are the ones measured on a real system.

Who asks for this

Three companies describe the same afternoon

Each one has people who spend it reading a system that belongs to somebody else.

ServiceNow → S/4HANA

The second-level engineer

Logs into the customer's instance, finds the document, compares it against the config that was supposed to govern it, checks whether the field they added is the thing that broke it, writes it up. An hour, per ticket, and the next customer's instance is different.

Jira → SuccessFactors

The consultant on day three

Still mapping the landscape by hand: which tables were extended, what the interfaces do, where the exceptions live. The engagement was sold on the advice that comes after this part.

MQTT → the work order

The service desk for the machine

The line stops, the telemetry that would have shown it coming sits on the customer's own network, and the work order gets written from a phone call instead.

Access

Two ways in, and the install is the rarer one

Connect it. An instance URL and a service key for their S/4HANA, a communication user, or the ticket system's own consent screen. Your customer authorises it once and it is an asset in the scene, the same shape as every other integration we ship. Nothing is installed and nothing is opened. This is how most of them start and how most of them stay.

Or put a node inside. For the systems with no door out: the ERP behind the firewall, the historian on the plant network, the database with no public endpoint. One binary, 45 MB, no runtime and no toolchain on the machine it runs on. It keeps a read-only copy of what it may see and dials outward, so nothing on their side is opened towards it, and the read path is the ABAP data-preview endpoint, so there is no database login in the chain to hand over, lose or rotate. We have run one in a production tenant since August.

What nobody has to agree to a port opened towards the node a database user created for us a credential held by you, or by us
one customerwhat this scene can read
S/4HANAservice key · purchase orders, goods receipts, change historyconnected
Account determinationtables in the customer's own namespacevia node
Scanned documentsmatched back to their recordsvia node
Their ticket queueconsent screen · the incident, and the note written backwrite · asks
Everything not on this list is not reachable, including by us. The customer edits the list, not you.
Evidence

Reading the system is not the slow part any more

Three numbers off live systems, each measured once. We would rather show you the run than the number.

17 minuteschange history

12.4 million rows of it, read end to end. The engineer looking for the one row that matters opens four transactions instead.

114,484scanned documents

112 GB of them, matched back to the records they belong to: 98.7% of purchase orders, 99.9% of requisitions.

3 orderssold below cost

Surfaced by one rewritten statement. The source endpoint caps statements at about 255 characters and has no window functions; the local copy has both.

What you keep

Your keys, your data, your name on the screen

Your model contracts are tried first and ours sit underneath at list price if you want the fallback. The data and the traces are yours, and we do not train on them. Writes stop and ask, the way step 05 above did. Every run is recorded and reviewable, including the ones that got nowhere, so a wrong answer is something you open rather than a score you have to trust.

Billing

There is no price on this page

Nobody is buying a subscription here, so there is no subscription revenue for us to take a share of and the self-serve terms we publish are not the ones that fit. What this costs is built from the specifics: how many people it serves, whether the node sits in one network or three hundred, and what your agreement has to say.

Common questions

What gets asked in the security review

Do you need access to our customers' systems?

Not from you. The customer authorises the connection themselves, or installs the node if the system has no door out, and either way they decide what goes on the list. You never hold their credentials.

What about customers who will not connect anything?

Then this does not help them. There is no version of reading a system that works without a way in, and we would rather say so here than in month three.

Does this replace our ticketing?

No. It feeds what you already run. The incident arrives where it always did and the note goes back to the same place.

Who is the data processor?

Where we operate the servers, you sign a data-processing agreement with us and your customers sign theirs with you. On your own servers the data never reaches us.

Does our name or yours appear?

Yours. Your sign-in, your domain, your screens. Which consent screens carry which name is part of the setup rather than something you inherit.

Can we run it on our own servers?

Yes. It is the same instance configuration on your machines: you take the server, the database and the vault.

Start

Bring a ticket nobody could close

A real one, from a real customer instance. That is a better first meeting than a demo of ours.