Technology - SAP

SAP AI Agent Hub — Governance or Discovery?

I asked a client last month how many AI agents were running across their SAP landscape. Nobody in the room had a number. Not the CIO, not the lead architect, not the SAP account team sitting across the table.

That answer used to be forgivable. It is not anymore. Every AI project I have touched this year has the same shape — pilots multiply faster than anyone tracks them, and by the time someone asks what all these agents actually do, the honest answer is a shrug.

SAP’s answer to that shrug is the AI Agent Hub. Before you build a governance strategy around it, you need a straight answer to one question: is this real governance, or is it an inventory list with a compliance badge stuck on the front? I have spent enough time in it now to tell you.

🔗 Foundation posts

This post connects to SAP Business AI Platform (BAIP) — BTP, BDC and AI Explained — the Agent Hub is the Govern layer of that platform. It also connects to SAP LeanIX — Enterprise Architecture Management, since the Hub runs directly inside LeanIX. Neither is required reading — this post is self-contained, and both are worth a look for more depth.

The agent sprawl problem

Gartner’s numbers explain why this landscape got out of control so fast. The average Fortune 500 company had fewer than 15 AI agents in 2025. By 2028, Gartner expects that number to pass 150,000.

Most of those agents will not come from one clean rollout. They will come from a Copilot Studio flow someone in HR built without telling IT, a Joule skill a consultant configured mid-project, and an MCP server a developer wired up to test an idea that quietly made it into production.

This is what people mean by shadow AI. It is not malicious — it is just what happens when building an agent gets easy and tracking one stays hard. Gartner’s own research backs this up: only 13% of organisations believe they currently have appropriate AI-agent governance in place.

📌 Key takeaway

The problem the Agent Hub solves is not “AI is risky.” It is “nobody can currently answer which agents exist, what they touch, and who approved them.” That is an inventory problem before it is a policy problem.

What SAP AI Agent Hub actually is

SAP AI Agent Hub is the governance layer of the SAP Business AI Platform — the three-layer model SAP introduced at Sapphire 2026, sitting alongside Context (unified business data) and Build (Joule Studio 2.0). It is not a new product bolted onto BTP. It runs inside SAP LeanIX, and that placement tells you SAP’s real intent — LeanIX was built for enterprise architecture management, and SAP is treating AI agents as architecture, not as some separate category needing separate tools.

The confusion I hear most often on client calls: is this the same as Joule Studio? It is not. Joule Studio is where you build agents — the develop-and-deploy plane. The Agent Hub is where you find out what already exists — the govern plane. It sits above every build platform, including Joule Studio, and tracks agents regardless of where they were built.

That distinction matters because the Hub is also vendor-agnostic. It uses the Agent-to-Agent (A2A) protocol — the open interoperability standard Google created and later donated to the Linux Foundation, with SAP as one of the founding members among 50-plus contributing technology partners, not a co-creator of the core spec — to discover and govern agents across vendor platforms, not just SAP’s own. That is the right design decision. Nobody’s SAP landscape is SAP-only anymore.

Diagram on white background showing SAP Business AI Platform split into a Build layer, where Joule Studio creates agents, workflows and apps, and a Govern layer, where the Agent Hub tracks every agent regardless of where it was built

Discovery — building the agent inventory

Before you can govern anything, you need to know it exists. The Hub’s discovery layer auto-scans across SAP AI Core, Microsoft Copilot Studio, Google Vertex AI / Agentspace and — via a dedicated integration — ServiceNow, pulling every agent, LLM and MCP server it finds into a single structured registry. AWS Bedrock discovery is on the roadmap rather than live everywhere yet, so check your own tenant’s release notes before assuming full coverage.

Asset typeWhat it meansWhy it matters for governance
AI AgentAn autonomous or semi-autonomous process performing a task on someone’s behalfThe unit you approve, monitor and eventually retire
LLMThe underlying model an agent or app callsMultiple agents can share one model — risk needs tracking at both levels
MCP ServerThe connection point an agent uses to reach tools, data or other systemsWhere an agent actually touches business data — the highest-risk layer

This is where the “it’s just discovery” criticism has some truth to it. On its own, an inventory is a spreadsheet with better branding. What makes it governance is what SAP layers on top — architecture context. Every discovered agent gets mapped to the business capability, process and application it touches, using the same graph LeanIX already builds for your SAP landscape.

That context is the actual differentiator. A list of 40,000 agents tells you nothing on its own. A list of 40,000 agents mapped to “this one reads vendor master data in MM” tells you exactly where to look first.

Diagram on white background showing agents, LLMs and MCP servers from SAP, Microsoft, Google and AWS platforms flowing into a single AI registry, mapped to business context

The governance lifecycle

Once an agent is discovered, it moves through a lifecycle SAP designed to mirror how architecture decisions already get made in most SAP shops — nothing ships without a review.

StageWhat happens
ProposedAn agent is registered — discovered automatically, or submitted ahead of a new build
EvaluatedA risk rating is assigned and compliance mapping runs against defined policy rules
ApprovedPasses review and receives a verification badge that gates production use
ActiveRunning in production, monitored against defined KPIs and observability metrics
RetiredDecommissioned and removed from active use — the record is kept for audit

The verification badge is the mechanism that actually has teeth. Without it, an unverified MCP server or agent cannot be called in a production runtime that respects the Hub’s policy. That is the difference between a dashboard that tells you something is wrong and a gate that stops it happening.

Identity and access control is the piece still rolling out at the time of writing — agents get a unique identity through SAP Cloud Identity Services, tied into the same authentication layer as your human users. I cover that properly, along with the EU AI Act compliance angle, in SAP Cloud Identity Services for AI Agents — The Two Models. It deserves its own space rather than a rushed paragraph here.

Diagram on white background showing the SAP AI Agent Hub governance lifecycle — Proposed, Evaluated, Approved, Active, Retired — with a verification badge required before an agent reaches Approved status

Human oversight — where people stay in the loop

Governance tooling is only as good as the humans who use the levers it gives them. Three oversight patterns show up repeatedly in how organisations actually run the Hub, and they are not interchangeable.

PatternHow it worksBest for
Approval gateAn agent cannot reach Active status without a named human sign-off at the Evaluated stageHigh-risk agents touching finance, HR or customer data
Continuous KPI monitoringAgent stays active automatically but is measured against defined business outcomes in real timeLower-risk agents where speed matters more than pre-approval friction
Post-hoc audit trailAgent runs freely; the full decision and action history is reviewed on a regular cadenceExploratory or low-blast-radius agents in non-production environments

💡 Practical tip

Do not default every agent to the approval gate pattern. I have watched governance programmes collapse under their own weight because every agent, regardless of risk, went through the same heavyweight review. Match the pattern to the blast radius, not to institutional habit.

There are two layers of enforcement working underneath these patterns, and it is worth knowing both exist. Joule Studio governs whether an agent action should happen from a business policy perspective. Underneath that, SAP has been co-developing an open-source runtime called OpenShell with NVIDIA, which enforces policy at the infrastructure level — filesystem and network isolation for agents with shell, file or API access. NVIDIA formalised this in late September 2026 as the Open Agent Safety Platform, pairing OpenShell with a second component, Sentry, and more than 100 supporting partners. Application-level rules alone cannot contain an agent that can touch the operating system directly. You need both layers.

What the Hub does not do

⚠️ Warning — do not oversell this to your steering committee

The Agent Hub records metadata, lifecycle state and policy compliance. It does not evaluate whether an agent behaves safely under adversarial conditions, it does not detect conflicts between two agents operating on the same data from different platforms, and it does not intercept a live autonomous action in progress. It is a system of record, not a runtime firewall.

This matters because governance tooling gets sold — fairly or not — as a solved problem. It is not. The Hub answers “what exists and was it approved.” It does not answer “is this specific action, right now, the correct one.” Keep that distinction in front of whoever signs off your AI Center of Excellence charter, or you will end up with a false sense of security dressed up as a compliance dashboard.

At a glance — SAP AI Agent Hub

ConceptOne-line summary
SAP AI Agent HubThe governance layer of SAP Business AI Platform — a vendor-agnostic command centre for AI agents, LLMs and MCP servers
Built on SAP LeanIXRuns inside LeanIX Application Portfolio Management — agents are treated as architecture, not a separate category
DiscoveryAuto-scans SAP AI Core, Microsoft, Google, AWS and ServiceNow into one structured registry
A2A protocolGoogle’s open interoperability standard, now under Linux Foundation governance — SAP is a founding member among 50+ partners, letting the Hub govern non-SAP agents too
Governance lifecycleProposed → Evaluated → Approved → Active → Retired
Verification badgeGates production use — unverified agents and MCP servers cannot run where the Hub’s policy applies
Joule Studio vs Agent HubJoule Studio is the build plane. The Agent Hub is the govern plane. They are not the same tool
Identity & access controlRolling out via SAP Cloud Identity Services — gives every agent a unique, auditable identity
What it does not doDoesn’t test adversarial safety, catch cross-agent conflicts, or intercept live actions in real time

What to take away

The honest answer to the governance-or-discovery question is that it starts as discovery and earns the word governance through what SAP layers on top — architecture context, a real lifecycle with a gate that has teeth, and oversight patterns you actually control. Strip any of those three away and you are back to a spreadsheet.

The real value is not the inventory itself. It is turning “who approved this agent to touch invoice data” from an unanswerable question into a two-click lookup. That is what makes scaling past a handful of agents survivable, instead of a governance incident waiting for an auditor to discover it.

Treat the Hub as the floor, not the ceiling. It tells you what exists and whether it was approved. Whether it was the right call is still your job.

🔗 Related posts on this site

SAP Business AI Platform (BAIP) — BTP, BDC and AI Explained — the three-layer platform the Agent Hub sits inside; read this first if you have not already.

SAP Joule Studio — How Intent-Based Development Works — Joule Studio is the build plane the Hub governs; this post covers what gets built there.

SAP Cloud Identity Services for AI Agents — The Two Models — how every discovered agent gets its own auditable identity, the layer underneath the Hub’s governance lifecycle.

SAP LeanIX — Enterprise Architecture Management — the Hub runs inside LeanIX; this post covers the platform it is built on.

MCP — Model Context Protocol Explained — MCP servers are one of the three asset types the Hub inventories and governs.

Published on rakeshnarayan.com — Articles

URL: https://rakeshnarayan.com/articles/sap-ai-agent-hub-governance-or-discovery/