PASS
bp Technology + Data Alignment
bp Sphere operates as the governed finance decision, control, evidence, and accountability runtime inside bp guardrails.
PASS
Yalla, Nexus, LaunchPad, UDP, OneData, KDO, Purview, identity, TDR
Tenant data products with owner, steward, custodian, certification, lineage
FBT controls referenced in bp tenant overlay
Positioning boundary
Positioned as
- Decision Runtime
- Data Runtime consumer
- Governance Runtime
- Identity-aware Runtime
- Transformation Runtime
Not positioned as
- A replacement for UDP, OneData, Foundry, Databricks, SAP, Nexus, Yalla, Purview, or bp identity platforms.
- A standalone AI platform that creates competing data, governance, or integration layers.
Runtime principle
- Generic runtime capabilities live in platform code.
- bp constructs live in tenant configuration.
- Production connectivity binds to bp-approved systems.
Latest platform capabilities now available
Current system update: the architecture now includes governed chat, WIIF assistant portability, token economy routing, fail-closed policy enforcement, deterministic replay, signed evidence, runtime seam adoption audit, skill learning promotion, autonomy demotion enforcement, shared case-state propagation, and observability readiness.
| Capability | Status | Runtime proof | Surface / endpoint |
|---|---|---|---|
| Experience Orchestration Layer | Surface available | Shared decision objects render across desktop, mobile, and chat surfaces. | /ui/mission/p2p, /ui/mobile-cockpit, /ui/enterprise-chat |
| Governed Chat Interface | Surface available | Chat resolves role, mission, case, evidence, policy, action contract, replay, and feedback. | /ui/enterprise-chat |
| Workforce Intelligence Integration Fabric | Surface available | Assistant registry, connector packages, certification, compliance mappings, identity resolution, failover drills, and workforce coordination APIs. | /ui/workforce-intelligence-fabric, /ui/assistant-operations-center |
| Token Economy Control Plane | Surface available | LLM calls are routed, cached, denied, downgraded, or escalated before spend occurs; token value is attributed to decisions. | /ui/ai-cost-usage, /api/iaf/decision-intelligence/token-economy/decision |
| Guardrail Policy Engine | Surface available | Policy evaluation fails closed in production posture; non-fail-closed failures route to escalation instead of silent execution. | /ui/policy-registry, /ui/control-plane |
| Decision Replay + LLM Determinism | Surface available | Execution seed, prompt/context hash, evidence hash, policy version, and replay records are persisted and validated. | /ui/decision-journey, /ui/single-decision-audit, /ui/decision-replay-studio |
| Externally Verifiable Evidence | Surface available | Evidence bundles are signed with asymmetric verification and can be checked through the verify endpoint. | /ui/evidence, /api/iaf/decision-intelligence/evidence/verify |
| Runtime Adoption Audit | Endpoint available | Agents/workflows are audited for identity, policy, evidence, replay, value, token, and learning seam adoption. | /api/iaf/decision-intelligence/runtime-adoption-audit |
| Skill-Binding Learning Promotion | Endpoint available | Skill learning overlays require evidence, confidence, and runtime effect before promotion into runtime metadata. | /api/iaf/decision-intelligence/skill-learning-overlays/{id}/validate |
| Autonomy Demotion Enforcement | Endpoint available | Telemetry demotion guidance writes supervisory state, event logs, and owner review queue items. | /api/iaf/decision-intelligence/autonomy/demotions/enforce |
| Shared Case-State Propagation | Endpoint available | One case resolution updates analyst state, supervisor state, value records, replay reference, and CFO rollup readiness. | /api/iaf/decision-intelligence/case-state/{case_id}/rollup |
| Observability Readiness | Endpoint available, env-bound | Production telemetry posture exposes OTEL endpoint status, Prometheus/failure-mode surfaces, and SLO targets. | /api/iaf/decision-intelligence/observability/readiness |
External production bindings still required
These are deployment dependencies, not hidden platform architecture gaps.
- SAP/SOR phase 2-3: RFC/OData reads, CDC streams, governed write-back, and master-data sync require customer credentials and agreed write boundaries.
- Live Entra tenant/Graph sync and vendor assistant connector credentials are external deployment bindings.
- Production OTEL/SLO alerting requires environment configuration and failure-mode drills in dev/prod.
- Agent de-stubbing and route-level adoption breadth continue as capability migration work, not platform architecture gaps.
bp architecture alignment
Maps bp constructs to neutral bp Sphere runtime capabilities, with the implementation boundary explicit.
| bp construct | Decision runtime | Boundary | Required from bp | Workshop proof |
|---|---|---|---|---|
| Yalla golden path | Deployment and platform operations runtime | bp-specific deployment path is tenant configuration; core runtime remains platform-neutral. | Approved hosting pattern, namespaces, service accounts, pipeline standards, SRE/SLO expectations. | Runtime topology and operator surfaces show deployable services, health, recovery, and release gates. |
| Nexus registry | Agent Registry Runtime | Generic agent inventory fields are platform-level; Nexus IDs/status are bp tenant overlay metadata. | Nexus registration schema, naming rules, lifecycle states, duplicate-check process. | Agent cards expose owner, risk class, MCP/A2A status, LaunchPad status, red-team status, TDR readiness, and replay coverage. |
| AI LaunchPad | AI Governance Runtime | LaunchPad gates are bp-specific policy states attached to generic governance lifecycle. | Risk triage, approval gates, AI inventory fields, data sensitivity taxonomy, model/use-case acceptance criteria. | AI Governance Registry maps every use case and agent to owner, risk class, approval gate, evaluation posture, and audit trail. |
| UDP + OneData | Enterprise Data Runtime | Data runtime models data products and certified datasets generically; UDP/OneData labels are bp tenant overlay. | Data domains, product catalog, owner/steward/custodian mappings, certification levels, marketplace metadata. | Certified Data Catalog and Data Product Marketplace show source -> bronze -> silver -> gold -> decision lineage. |
| FIM + Finance Data Office | FIM-Native Finance Context Layer | FIM remains BP's curated finance backbone; bp Sphere consumes FIM products for decisions, controls, evidence, and governed action. | FIM product access, FDO owner/steward metadata, ADH/HWG lineage, quality dimensions, refresh cadence, row-level security rules. | FIM Context Layer shows source ERP -> FDF/ADH/HWG -> FIM product -> quality checks -> bp Sphere decision -> evidence pack -> governed write-back. |
| Foundry Key Domain Objects | KDO + Semantic Authority Manager | Object manager is generic; bp KDO names and semantic-authority ownership are tenant-scoped. | Canonical KDO list, object owners, source-system authority, lineage rules, quality thresholds. | Object lineage shows SAP/Ariba/Databricks/Foundry -> KDO -> agent -> decision -> action -> replay. |
| Purview monitoring + red-team testing | Evaluation and Compliance Runtime | Evaluation metrics are platform-level; Purview sinks and bp red-team statuses are tenant metadata. | Monitoring sink, red-team criteria, prompt/tool-injection policies, evaluation thresholds. | Evaluation Runtime tracks quality, hallucination, tool-call accuracy, policy compliance, cost, latency, and red-team readiness. |
| Identity governance | Identity Governance Runtime | OIDC/OAuth/RBAC/ABAC concepts are platform-level; bp IdP, entitlement, and recertification specifics are tenant-scoped. | IdP integration path, app registration, consent, entitlement rules, recertification cadence, privileged access controls. | Identity page shows user identity, agent identity, entitlements, access certification, SoD, MFA, and drift handling. |
| Technical Design Review | Design Review and Readiness Runtime | TDR workflow is a tenant-specific design authority overlay over generic approval workflow. | TDR template, architecture review gates, security review gates, data design authority workflow, exception process. | TDR Readiness view maps architecture, APIs, data, controls, observability, recovery, evaluation, and approval state. |
Enterprise Data Runtime
bp Sphere consumes certified data products and preserves source-to-decision lineage. It does not replace UDP or OneData.
| Data product | Domain | Certification | Ownership | Sources | Quality | SLA | Agents | Decisions | Lineage |
|---|---|---|---|---|---|---|---|---|---|
Journal Data Productjournal_product | Finance | Gold | Finance Data Owner R2R Data Steward / UDP Custodian | SAP S/4HANA ACDOCABKPFBSEGCFIN | 94 | Gold certified before CFO consumption; event plus daily reconciliation | Journal Risk AgentClose Readiness AgentControl Assurance Agent | Escalate JournalAdjust Close ReadinessRequest Support | SAP S/4HANA ACDOCA/BKPF -> UDP bronze/silver/gold -> KDO Journal -> Decision Runtime |
Invoice Data Productinvoice_product | Procurement | Gold | Procurement Data Owner P2P Data Steward / UDP Custodian | SAP ECCSAP S/4HANAAriba | 91 | Near-real-time event feed; daily duplicate and lineage certification | Duplicate Invoice AgentPayment Timing AgentEvidence Agent | Approve InvoiceHold PaymentRequest Evidence | SAP ECC/S4 + Ariba -> UDP bronze/silver/gold -> KDO Invoice -> Decision Runtime |
Counterparty Credit Productcounterparty_product | Customer | Silver | Credit Risk Data Owner O2C Data Steward / UDP Custodian | Customer MasterAccounts ReceivableTreasuryExternal RatingsMarket Feeds | 88 | Daily certification with intraday market-risk refresh | Credit Exposure AgentCollections AgentTreasury Risk Agent | Increase LimitReduce LimitRequire Collateral | Customer master + AR + market feeds -> UDP silver -> KDO Counterparty -> Credit Decision Runtime |
Treasury Liquidity Producttreasury_product | Treasury | Gold | Treasury Data Owner Liquidity Data Steward / UDP Custodian | Bank APIsCash systemsFX systemsTreasury workstations | 92 | Intraday liquidity refresh; daily gold certification | Liquidity Intelligence AgentWorking Capital AgentCFO Cockpit | Prioritize PaymentRebalance CashEscalate Covenant Risk | Bank/cash/FX systems -> UDP gold -> KDO Cash Position -> Treasury Decision Runtime |
Control Evidence Productcontrol_product | Controls | Gold | SOX Control Owner Control Steward / Audit Evidence Custodian | Control registryPolicy registryEvidence vaultApproval workflow | 93 | Evidence lineage available for every governed decision | Control Assurance AgentEvidence Agent | Block TransactionEscalate Control FailureApprove Override | Policy/control/evidence registries -> UDP gold -> KDO Control -> Decision Runtime |
KDO + Semantic Authority Manager
The ontology becomes decision-oriented by linking objects to owners, sources, policies, controls, and decisions.
| KDO | Semantic authority | Authoritative sources | Policies | Controls | Quality | Decisions |
|---|---|---|---|---|---|---|
| Invoice | Procurement Data Owner P2P Data Steward / UDP Custodian | SAP ECCSAP S/4HANAAriba | Three Way MatchDuplicate Payment ControlApproval Authority | SOX AP ControlSOD Payment Control | CompletenessAccuracyFreshnessDuplicationTraceability | Approve InvoiceHold PaymentRequest EvidenceEscalate Supplier Risk |
| Journal | Finance Data Owner R2R Data Steward / UDP Custodian | SAP S/4HANACFINBlackLine | MaterialityJournal ApprovalSegregation of Duties | SOX Journal ControlManual Journal Review | CompletenessAccuracyFreshnessLineageEvidence Coverage | Post JournalEscalate JournalRequest SupportAdjust Close Readiness |
| Vendor | Procurement Data Owner Supplier Master Steward / SAP/Ariba Custodian | SAP Vendor MasterAriba SupplierCyber Risk Feed | Supplier OnboardingBank VerificationSanctions Screening | Vendor Master ControlSupplier Cyber Control | CompletenessDuplicationBank ValiditySanctions Freshness | Approve SupplierBlock SupplierRequest Master Data Remediation |
| Contract | Legal / Procurement Owner Contract Steward / Contract Repository Custodian | Ariba ContractsDocument RepositoryLegal CLM | Contract CoverageMilestone BillingPrice Variance | Contract Compliance Control | Clause ExtractionEffective DateCoverageVersion Lineage | Validate ContractRequest EvidenceEscalate Leakage |
| Cost Center | Finance Data Owner Management Reporting Steward / ERP Custodian | SAP ControllingOrganization Hierarchy | Cost Center OwnershipPosting Authority | Coding ControlApproval Matrix | Owner ValidityHierarchy FreshnessPosting Eligibility | Approve CodingRoute ApprovalEscalate Miscode |
| Asset | Asset Operations Owner Asset Integrity Steward / Maximo / SAP Asset Custodian | MaximoSAP Asset AccountingServiceNow | Asset CriticalityMaintenance ApprovalCapitalization | Asset Integrity ControlMaintenance Evidence Control | CriticalityLocationMaintenance FreshnessAccounting Linkage | Escalate Asset RiskApprove Work OrderRequest Inspection Evidence |
| Counterparty | Credit Risk Data Owner Credit Data Steward / UDP Custodian | Customer MasterTreasuryExternal RatingsMarket Feeds | Credit LimitCollateral RequirementSanctions Screening | Credit Exposure ControlTreasury Counterparty Control | CompletenessTimelinessRating FreshnessExposure Traceability | Increase LimitReduce LimitRequire CollateralBlock Exposure |
| Control | SOX Control Owner Control Steward / Control Registry Custodian | Control RegistryPolicy RegistryAudit Findings | SOXSODAuthority Matrix | Control EffectivenessAttestation | Owner ValidityTest FreshnessEvidence Completeness | Block TransactionEscalate FailureApprove Override |
| Policy | Policy Owner Policy Steward / Policy Repository Custodian | Policy RegistrySharePointAuthority Matrix | Version ControlApproval Workflow | Policy Enforcement Control | VersionEffective DateApproval Status | Evaluate PolicySimulate PolicyEscalate Conflict |
| Decision | Decision Owner Runtime Governance Steward / Replay Custodian | Decision RuntimeEvidence RuntimePolicy Runtime | Human AccountabilityReplay RequiredEvidence Required | Decision Audit ControlOverride Control | Evidence CompletenessPolicy CoverageReplayability | ApproveRejectEscalateReplay |
AI Governance / Nexus Registry
Agent governance is visible as LaunchPad, Nexus, MCP, A2A, red-team, and TDR metadata on top of the generic agent registry.
| Agent | Owner | Business owner | Risk | Skills | MCPs | Policies | Supervisor | Evidence | Escalation | LaunchPad | Nexus | MCP / A2A | Red team / TDR / Evaluation |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Duplicate Invoice Agentagent-p2p-duplicate-invoice | P2P Control Owner | P2P Process Owner | High | invoice matchingevidence resolutionpayment hold drafting | SAP MCPAriba MCP | Duplicate Payment ControlApproval Authority | P2P Supervisor | invoicePOGRpayment history | P2P Supervisor -> Controller | Conditional approval for workshop | NEXUS-PENDING-BP-001 | Compliant adapter contract Registered handoff map | Prompt/tool injection scenarios defined Ready for BP template mapping baseline complete |
Journal Agentagent-r2r-journal-risk | Controller | R2R Process Owner | High | journal anomaly detectionmateriality assessmentevidence validation | SAP MCPBlackLine MCP | MaterialityJournal ApprovalSOD | Controller | journal linesupporting documentapproval record | Controller -> Group Controller | Conditional approval for workshop | NEXUS-PENDING-BP-002 | Compliant adapter contract Registered handoff map | Evidence-gated unsafe action tests defined Ready for BP template mapping baseline complete |
Control Assurance Agentagent-control-assurance | SOX Owner | Controllership Owner | High | control matchingSOD detectionattestation routing | Control MCPEvidence MCP | SOXSODAuthority Matrix | SOX Owner | policycontrol testapproval trail | SOX Owner -> Internal Audit | Conditional approval for workshop | NEXUS-PENDING-BP-003 | Compliant adapter contract Registered control escalation map | Authority bypass tests defined Ready for BP template mapping baseline complete |
Enterprise Controls / Controllership Runtime
bp control scale is tenant context, not platform code. The runtime uses it to explain control coverage and value cases.
Scale references
- FBT controls: 3,124
- SOX controls: 1,005
- Non-SOX controls: 2,119
- SOD population: 5,868
Finance volumes
- Manual journals / quarter: 30,000
- IC transactions / quarter: 300,000
- Procurement invoices: 2,750,000
- Procurement invoice value: $62,000,000,000
Command center
- Financial Stewardship
- SOX and non-SOX Controls
- SOD Population
- Manual Journal Risk
- Intercompany Risk
- Procurement Invoice Controls
- AI Controls
- Human Accountability
Control Registry Drilldowns
Duplicate Invoice Control and peer controls expose policy, risk, evidence, owner, type, and status.
| Control | Owner | Policy | Risk | Evidence | Type | Status |
|---|---|---|---|---|---|---|
Duplicate Invoice Controlduplicate_invoice_control | P2P Control Owner | Duplicate Payment Control | Duplicate payment or fraud loss | invoicePOGRpayment history | preventive | active |
Journal Approval Controljournal_approval_control | Controller | Journal Approval | Unsupported material journal | journal linesupporting documentapproval record | preventive | active |
SOD Payment Controlsod_payment_control | SOX Owner | Segregation of Duties | Creator and approver conflict | user identityrole assignmentapproval trail | preventive | active |
Identity Governance Runtime
User and agent access is shown as entitlements, role/attribute policy, recertification, SoD, and fail-closed controls.
Authentication
- bp IdP / Entra-compatible OIDC
- OAuth 2.0
- MFA
- Reduced sign-on
Authorization
- RBAC
- ABAC
- Data classification
- Action permissions
- Agent workload identity
Governance
- Entitlement assignment
- Access recertification
- Immediate removal on role change
- Privileged access controls
- Access drift detection
- SoD runtime
Integration Contract Runtime
Every integration declares owner, target, frequency, quality SLA, path, and failure mode.
| Contract | Source | Target | Schema | Frequency | Quality SLA | Rules | Owner | Escalation | Latency | Retries | Failure mode |
|---|---|---|---|---|---|---|---|---|---|---|---|
sap_to_udp_journal | SAP S/4HANA | UDP Journal Data Product | journal_id, company_code, account, amount, currency, poster, approver, evidence_ref | Event + batch reconciliation | Gold certified before CFO consumption | balanced journalvalid company codeapproval present | Finance Data Owner | R2R Data Steward | near-real-time | 3 with DLQ | fail closed for high-materiality journals |
ariba_to_udp_invoice | Ariba + SAP | UDP Invoice Data Product | invoice_id, supplier_id, PO, amount, tax, match_status, evidence_ref | Near-real-time events + daily certification | Duplicate and lineage checks before agent action | supplier validPO/GR linkageduplicate check | Procurement Data Owner | P2P Data Steward | under 5 minutes | 3 with DLQ | agent recommends evidence request only |
identity_to_runtime_entitlements | bp Identity Governance Platform | bp Sphere Identity Runtime | principal_id, roles, attributes, expiry, certification_status | JIT + recertification feed | Fail-closed on missing entitlement | not expiredrole certifiedSOD clear | Identity Platform Owner | Access Governance Owner | real-time for login; daily recertification | 2 then deny | deny privileged action |
OneData Alignment
Maps bp Sphere to OneData strategy, architecture, delivery, management, analytics, controls, and people dimensions.
| OneData dimension | bp Sphere support |
|---|---|
| Strategy & Planning | Maps finance missions to data products, owners, KPIs, and transformation value. |
| Architecture & Design | Keeps UDP/OneData as data authority and positions bp Sphere as decision runtime consumer. |
| Data Delivery | Consumes certified products through contract-managed APIs/events/MCPs. |
| Data Management | Shows owner, steward, custodian, quality, lineage, certification, and consumers. |
| Analytics & AI | Connects governed data products to agents, evaluations, evidence, and decisions. |
| Policy & Controls | Links KDOs and data products to policies, controls, and evidence packs. |
| People & Culture | Maps human ownership, supervision, role evolution, training, and adoption readiness. |
Evaluation + Transformation Runtime
Evaluation and Quantum-style transformation readiness are tracked as operating model capabilities, not slideware.
Evaluation metrics
- Accuracy
- Relevance
- Task success
- Tool-call accuracy
- Redundant calls
- Planning quality
- Reasoning coherence
- Hallucination rate
- Policy compliance
- Override rate
- Escalation rate
- Cost
- Latency
Evaluation gates
- No production promotion without evaluation baseline
- No write-back without policy and evidence tests
- No high-risk agent without red-team scenarios
- No autonomous action outside approved scope
Transformation runtime
- Deployments
- Hypercare
- Training
- Role Mapping
- Data Cleansing
- Business Readiness
- Parallel Run
- Adoption
- Go-Live Risk
- Training Risk
- Data Risk
- Control Risk
- Headcount Impact
- Cycle Time Impact
- Control Impact
- Automation Impact
Quantum Go-Live Readiness
Answers whether the transformation is ready for go-live and what remains conditional.
Go-live readiness
- Score: 86
- Status: READY WITH CONDITIONS
Blockers
- production tenant app registration
- final BP-owned data contracts
- formal LaunchPad approval
Next actions
- confirm identity consent
- map UDP product owners
- complete TDR evidence pack
Implementation sequencing
Prioritizes workshop credibility first, then runtime contracts, then production integration.
Tier 1
- Enterprise Alignment & Readiness page
- AI Governance / Nexus Registry columns on agent inventory
- Certified Data Runtime + Data Product Marketplace
- KDO + Semantic Authority Manager
- Controllership Command Center using BP scale references
Tier 2
- Identity Governance Runtime
- Integration Contract Runtime
- Evaluation Runtime
- TDR Readiness Workspace
Tier 3
- Quantum Transformation Runtime
- Purview monitoring sink
- LaunchPad and Nexus production integration
- Yalla deployment package