bp Sphere
bp Sphere is the operating layer for enterprise understanding, judgment, execution, and learning.
bp Sphere does not replace SAP, Ariba, ServiceNow, Foundry, Databricks, AWS, Azure, or hyperscaler AI. It connects them, understands them, reasons across them, governs decisions across them, and progressively turns fragmented enterprise work into replayable, evidence-backed operating judgment.
How to use this page
- Use Overview and Why for first-time orientation.
- Use How It Thinks and Operating Model when the team asks how Sphere actually works.
- Use Architecture and Technology + Data when the room asks how this fits with SAP, Ariba, Foundry, Databricks, AWS, and Azure.
- Use By Function and Functional Packs to connect the platform story to P2P, O2C, R2R, FP&A, Treasury, and ST&S.
- Use Roadmap to explain why bp should invest over time even with strong existing platforms.
Technology + data alignment
This tab translates the technology pack into language the functional team can use confidently.
Where Sphere fits
| Layer | bp foundation | Sphere role |
|---|---|---|
| Core systems | SAP, Ariba, BlackLine, treasury platforms, Endur | Orchestrates decisions across them |
| Cloud runtime | AWS + Azure | Runs inside those guardrails |
| Data estate | UDP, Databricks, Palantir, ERP data, market feeds | Consumes and federates instead of replacing |
| Identity | Entra ID, IAM, workload identities | Turns permissions into named operational accountability |
| Governance | Existing controls and audit obligations | Makes them operational through replay, evidence, and policy runtime |
What to say
- Sphere operates inside bp’s architecture. It does not try to replace it.
- Sphere uses the existing data estate in a federated way rather than demanding one giant replatforming move.
- Sphere turns policy, evidence, replay, and human approval into an operating layer rather than after-the-fact controls.
- Sphere makes the enterprise work better across SAP, Ariba, ServiceNow, Foundry, Databricks, AWS, and Azure.
Current implementation status
The latest platform updates add governed chat, assistant portability, token economy, policy fail-closed behavior, replay determinism, runtime adoption audit, learning promotion, autonomy demotion enforcement, case-state propagation, and observability readiness.
Implemented in code
Experience Orchestration Layer
Surface available - Shared decision objects render across desktop, mobile, and chat surfaces.
/ui/mission/p2p, /ui/mobile-cockpit, /ui/enterprise-chat
Governed Chat Interface
Surface available - Chat resolves role, mission, case, evidence, policy, action contract, replay, and feedback.
/ui/enterprise-chat
Workforce Intelligence Integration Fabric
Surface available - Assistant registry, connector packages, certification, compliance mappings, identity resolution, failover drills, and workforce coordination APIs.
/ui/workforce-intelligence-fabric, /ui/assistant-operations-center
Token Economy Control Plane
Surface available - LLM calls are routed, cached, denied, downgraded, or escalated before spend occurs; token value is attributed to decisions.
/ui/ai-cost-usage, /api/iaf/decision-intelligence/token-economy/decision
Guardrail Policy Engine
Surface available - Policy evaluation fails closed in production posture; non-fail-closed failures route to escalation instead of silent execution.
/ui/policy-registry, /ui/control-plane
Decision Replay + LLM Determinism
Surface available - Execution seed, prompt/context hash, evidence hash, policy version, and replay records are persisted and validated.
/ui/decision-journey, /ui/single-decision-audit, /ui/decision-replay-studio
Production bindings still external
- SAP/SOR phase 2-3: RFC/OData reads, CDC streams, governed write-back, and master-data sync require customer credentials and agreed write boundaries.
- Live Entra tenant/Graph sync and vendor assistant connector credentials are external deployment bindings.
- Production OTEL/SLO alerting requires environment configuration and failure-mode drills in dev/prod.
- Agent de-stubbing and route-level adoption breadth continue as capability migration work, not platform architecture gaps.
Latest Runtime Capability Update
Every Introduction tab is now grounded in the same current runtime baseline: Continuous Finance Command Center, Continuous Close digital twin, CLI runtime proof, provenance badges, governed chat, WIIF assistant portability, Token Economy controls, fail-closed policy enforcement, deterministic replay, signed evidence, runtime adoption audit, skill learning promotion, autonomy demotion enforcement, case-state propagation, and observability readiness.
How to read “Status”: “Surface available” and “Endpoint available” mean the named surface or endpoint is implemented and registered in this build — they are not real-time health probes. Open any surface for its own ● live / ◐ seeded provenance badge; production SOR connectivity stays fail-closed until BP credentials and feeds are supplied.
Experience Orchestration Layer
Surface available - Shared decision objects render across desktop, mobile, and chat surfaces.
/ui/mission/p2p, /ui/mobile-cockpit, /ui/enterprise-chat
Governed Chat Interface
Surface available - Chat resolves role, mission, case, evidence, policy, action contract, replay, and feedback.
/ui/enterprise-chat
Workforce Intelligence Integration Fabric
Surface available - Assistant registry, connector packages, certification, compliance mappings, identity resolution, failover drills, and workforce coordination APIs.
/ui/workforce-intelligence-fabric, /ui/assistant-operations-center
Token Economy Control Plane
Surface available - LLM calls are routed, cached, denied, downgraded, or escalated before spend occurs; token value is attributed to decisions.
/ui/ai-cost-usage, /api/iaf/decision-intelligence/token-economy/decision
Guardrail Policy Engine
Surface available - Policy evaluation fails closed in production posture; non-fail-closed failures route to escalation instead of silent execution.
/ui/policy-registry, /ui/control-plane
Decision Replay + LLM Determinism
Surface available - Execution seed, prompt/context hash, evidence hash, policy version, and replay records are persisted and validated.
/ui/decision-journey, /ui/single-decision-audit, /ui/decision-replay-studio
Continuous Finance Runtime
The hero story is now “if BP closed the books right now, what would the financial statements look like?” The runtime combines actuals, forecast accruals, provisions, reconciliations, controls, evidence, confidence, and replay.
CLI Proof Path
Architects can run bp-now, bp-close-now, bp-financial-position, bp-digital-twin, bp-runtime, and bp-provenance to prove the runtime without the UI.
The CLI is intentionally self-disclosing: the runtime query is live; the workshop baseline is seeded and marked.
Provenance Badges
● live API query · ◐ seeded BP-shaped baseline · ◇ model/estimate with basis · ◆ deterministic policy/replay path.
Production SOR connectivity remains fail-closed until BP credentials and feeds are supplied.