FarrenioFarrenio
SAP Basis operations

Your Basis team is too small for the landscape it runs

Most teams cover a dozen SIDs with four people and a SAPGUI window per system. Farrenio puts SM50, SM37, ST22, ST04 and the rest in one browser tab, and flags the disk filling before users feel it.

  • First metrics inside an hour
  • Outbound-only, no firewall change
  • Credentials envelope-encrypted, PIN-gated
Built for productionChecking status…
MFA-gated reveal 92-perm RBAC Multi-tenant GDPR-aware SOC2-aligned audit
Use cases

Who this is actually for

One production system or forty across a dozen customers. The operating model is the same and only the tenancy changes.

SAP coverage

The transactions your team already lives in

Twelve Basis transactions, mapped to where they live in the stack, from the ABAP dispatcher down to the HANA indexserver and the OS. One web console, cross-system search, every action on the audit trail.

Application server

The ABAP dispatcher, its work processes, sessions and the enqueue lock table.
SM50
Work processes
DIA/BTC/UPD/ENQ/SPO state per instance, catching PRIV mode and runaways before the queue backs up
SM66
Global WP overview
One work-process table across the whole cluster, not one instance at a time
SM04
User sessions
Active users and orphaned sessions per application server
SM12
Enqueue locks
Lock-table entries and orphaned locks, drillable by user or object

Workload, jobs & diagnostics

Batch, runtime errors, the system log and where response time actually goes.
SM37
Background jobs
Released / active / cancelled jobs cross-system, with job logs and long-runner trends
ST22
ABAP dumps
Runtime errors with short text, frequency and trend analytics
ST03
Workload
Dialog response-time breakdown by task type, top transactions and top users
SM21
System log
Filtered syslog tail across every SID at once

Database, host & connectivity

The HANA / anyDB layer, the operating system, and the RFC links between systems.
ST04
Database monitor
HANA & anyDB health, cache ratios and expensive statements
DB02
Space & growth
Tablespace and HANA volume pressure with fill forecasting
SM59
RFC destinations
Connection and authorization probes on your RFC / gateway links
OS
Host layer
CPU, memory, disk, inode and sapcontrol, read via the agent
Adding 4 more transactions next quarter. Vote on the roadmap after sign-in.
How it works

Nothing gets opened on your SAP hosts

The question every Basis lead asks first, answered plainly: one Python daemon runs on the host, reads what it is allowed to read, and pushes outbound over HTTPS. There is no inbound listener and nothing to open on your perimeter.

Install once, per system

One Python daemon per SID, under its own unprivileged service account rather than <sid>adm. Each collector is isolated, so one failing source never takes the others down with it.

It dials out, never in

The agent polls for its config and pushes metrics on 443. No firewall change, no NAT rule, no exposed port on a production SAP box.

Credentials are envelope-encrypted

RFC and HANA credentials are encrypted under a key issued per agent, never returned in plaintext on a read, and unlocked only behind a PIN or a fresh TOTP code, with every reveal on the audit trail.

See it work

From install to audit-ready, in one console

Scroll the four steps a landscape goes through with Farrenio. The panel keeps pace.

Farrenio Collector Management: live agent fleet, version distribution and update queue
Deploy

Get an agent reporting the same afternoon

A three-step wizard hands you an install script and a scoped token. The agent dials out and starts streaming while you watch. No firewall change, no inbound port.

Farrenio SAP Systems: health, trends and Basis transactions across the landscape
Monitor

Search the whole landscape in one query

SM50, SM37, ST22, DB02 and SM21 indexed across every SID. "Which system has the long-running job?" is one search with the answer attached, rather than twelve SAPGUI logons.

Farrenio Alerts: active rules with unhandled, open and 24h counts
Alert

The right person hears about it first

Per-metric, per-customer thresholds. Escalation ladders by severity and fans out to Slack, Teams, PagerDuty and email. Any alert can be promoted to an incident workflow.

Farrenio Security and Access: RBAC, auto-block and live 24h audit volume
Secure

Every privileged action on the record

Ninety-two permissions across eight roles, PIN- or MFA-gated token reveal, auto-block on credential-stuffing, and an audit trail carrying operator, IP and outcome behind every action.

Solutions

Four things a Basis team does every week

Roll out collectors, watch the landscape, control who can touch what, and route what breaks to whoever is on call.

Farrenio Collector Management: live agent fleet, version distribution and update queue
Fleet & Deployment

Get a new SID reporting the same afternoon

Onboarding a system is usually a ticket, a firewall request and a week of waiting. Here it is a wizard that hands you an install script and a scoped token, then the agent dials out and starts streaming while you watch.

  • Three-step wizard: pick system → configure → deploy
  • HANA SYSTEMDB + tenant out of the box
  • Per-collector freshness dots, so a stalled source is visible
  • Adopt existing agents, no duplicate registrations
ROI

What this is worth in hours

Based on benchmark workflows from teams running 6–25 SAP systems. Your mileage will vary, so we ship live dashboards you can measure it with yourself.

~6 h
per Basis admin / week
reclaimed from SAP GUI

Cross-system SM50 / SM37 / ST22 queries take seconds instead of opening one GUI window per SID.

<60 s
agent install → live data
time-to-first-metric

A single Python daemon, no firewall changes, no inbound ports. Heartbeat shows up immediately.

0
lost incidents
every action audit-trailed

Tiered audit retention: 365 days for auth and role events, 180 for the rest. Every login, every config change, every sapcontrol command.

Calculate your ROI

Plug in your estate and see your numbers

SAP systems in your landscape8systems
Across PRD / QAS / DEV / sandbox, every SID counts
Basis admins on your team3admins
Engineers actively running SM50 / SM37 / ST22 every week
Fully-loaded admin cost80€/h
€/hour incl. salary + overhead, adjusted to your local rate
Hours saved / year
1,056
≈ 22 h / week
Labour value / year
€84,480
@ €80/h fully-loaded
Payback
1.3 mo
Business tier · €9,000/yr
Year-1 ROI
9.4×
Net €75,480 reclaimed
Like what you see?
We'll size a tier to your landscape, with no commitment.
The traditional way

SAP GUI · 12 windows · per-SID hops

  • Open GUI, pick SID, run SM50, screenshot
  • Repeat for QAS, DEV, sandbox…
  • No history, no cross-SID search
  • Audit trail = your memory + Confluence page
The Farrenio way

One web console · all systems · audit-logged

  • Cross-SID search across SM50 / SM37 / ST22 in one query
  • Live WebSocket updates, no manual refresh
  • Every command logged with user, IP, before/after state
  • Mobile-friendly, so you can triage from your phone if it pages you
Security

Built like a fortress,
delegated like a SaaS.

Permissions, audit, and brute-force protection aren't bolted on. They are the spine of every endpoint and every UI surface.

  • 92 permissions across 8 roles, every checkbox enforced at the API layer
  • Role-permission edits logged with full diff (granted / revoked / by whom)
  • Privilege-escalation refused at the boundary and audited as denied attempts
  • Auto-block on 10 failures in 5 min OR ≥3 distinct emails
  • Allowlist exempts known-good probes and office IPs
  • JWT revoked on role / email / customer change
  • Token reveal requires PIN or fresh TOTP, via a one-shot verification JWT
Audit event types captured
14 types
login_successlogin_failedlogin_blockedmfa_failedrole_changedrole_permissions_updatedauth_block_createdauth_block_removedauth_allowlist_createdauth_allowlist_removeduser_inviteduser_password_resetescalation_deniedrole_change_denied
Each event carries actor, target, IP, user-agent, and the action's full delta, retained 365 days for auth and role events and 180 for the rest.
AWS Reseller · Cloud Services

An AWS Reseller and Cloud Services provider

Farrenio acts as an AWS Reseller and Cloud Services provider, supporting customers throughout their cloud adoption, optimization and operational journey. We help organizations leverage Amazon Web Services for:

  • Infrastructure modernization
  • SAP workloads on AWS, RISE-aligned where it makes sense
  • Migration projects · landing zones · account vending
  • Cloud operations · monitoring · incident response
  • Cost optimization · rightsizing · reserved-capacity strategy
From the blog

Written by people who run these systems

Kernel patching, HANA signals, S/4HANA on AWS. Deep-dives written from the Basis work itself rather than by the marketing team.

All posts
FAQ

What Basis leads ask us first

Does the agent need inbound network access to my SAP hosts?
No. The agent is outbound-only. It polls Farrenio over HTTPS for its config and pushes metrics the same way. No new firewall rules, no exposed ports on your SAP boxes.
Where do the SAP credentials live, and who can read them?
The agent authenticates to SAP using credentials in its local config on your host. Those values are envelope-encrypted using a Fernet key issued per agent, itself encrypted under the platform key, so the database holds no plaintext. Reads never return a password; revealing one requires a PIN or a fresh TOTP code, and every reveal is audit-logged. You can also manage the config entirely on the host and never enter a credential in the UI.
What happens to my data, and is this multi-tenant?
Yes, but every customer's data is scoped by tenant ID at the MongoDB query level. RBAC is enforced server-side on every endpoint, and audit logs are per-tenant, retained 365 days for auth and role events and 180 for the rest.
Can I bring my own SSO?
Google OAuth and MFA (TOTP with backup codes) ship today. SAML / OIDC enterprise SSO is on the roadmap for the Enterprise plan. Talk to us about your IdP and we will scope the timeline with you.
Do you support S/4HANA and classic NetWeaver?
Both. The collectors talk to sapcontrol, RFC and HANA SQL, protocols that haven't changed across versions. Tested against ECC 6.0, S/4 1909+, and HANA 2.0 SPS04+.
How do you handle credential stuffing and password attacks?
Per-IP and per-email rate limiting, automatic blocking after 10 failures in 5 minutes or 3 distinct emails from one IP, an allowlist for known-good sources, and PIN- or MFA-gated reveal for sensitive tokens. Every blocked attempt is audit-logged with the source IP, the reason and the expiry.
Can my service desk see alerts without touching production?
Yes. The "service_desk" role is read-only on alerts and incidents, with no SAP transaction access, no config changes and no token reveal. Granular 92-permission RBAC means you can carve out exactly what each team sees.
How long does a proof of concept take?
A 30-minute call to scope. We typically have one production SID streaming live metrics within an hour of agent install, and the rest of the landscape follows as fast as you can roll out the package.
Something else on your mind?
Farrenio

See it against your own SIDs

Thirty minutes to scope it, about an hour to get your first production SID streaming. No commitment past that.

MFA-gated 92-perm RBAC Multi-tenant 180–365d audit 99.9% SLA