Most organizations treat SAP licensing and SAP security as different departments with different meetings. RISE quietly merged them. When your license position is driven by how users are classified — and classification is driven by their roles and their actual activity — the people who understand access are the people who understand your license exposure. They just haven't been asked.
What FUE classification is actually measuring
The RISE model groups users into tiers by the nature of their access and use — broadly, from the most capable down to the lightest touch. Without getting into the commercial weeds, the shape looks like this:
| Tier | Roughly who lands here |
|---|---|
| Advanced | Users with broad, powerful, or development-grade access across processes |
| Core | Users doing substantive operational work within defined processes |
| Self-Service | Light users — occasional, narrow, request-and-view interactions |
The critical thing: a user's tier isn't a static label somebody typed in. It's a consequence of their access and behavior. Give someone a role broader than their job needs, and you may have quietly pushed them into a higher tier — the same over-provisioning that shows up as a security finding shows up again as a licensing one.
An over-provisioned user is a security risk and a licensing cost. The role that's too broad for their job is the same role that lifts them into a heavier FUE tier. Fix the access and you improve both positions at once — but only if you can see the connection.
Why this is hard to do by hand
Classifying a landscape of thousands of users by tier is not a spreadsheet you want to maintain manually. Roles change, people move teams, activity shifts over quarters, and the mapping from "what access does this person have and use" to "what tier does that imply" is a lot of careful, consistent judgment applied at scale.
Done once a year by hand, it's stale before it's finished — and worse, it's inconsistent, which is precisely the thing that falls apart under scrutiny. When a licensing review arrives, "we think it's about right" is not a position; "here is every user, their tier, and the basis for it" is.
What the agent does — and doesn't
The FUE Analysis Agent reads role and activity data and classifies each user by tier, consistently and across the whole landscape. It turns a vague, dreaded exercise into a current, evidence-backed picture you can actually defend.
Note what's absent from that list: it doesn't change licenses, reassign users, or touch your SAP system. It's read-only. Its job is to give you a clear, current, consistent view — and to make the link between an access decision and its tier consequence visible, so that when you tighten a role for security reasons, you can see the licensing effect too.
You'll notice this article quotes no dollar figures. That's on purpose. Precise savings claims depend on your specific commercial terms, and a number invented for a web page is worse than useless in a real negotiation. The agent gives you your classification and the basis for it — the defensible facts — not a fabricated headline.
The strongest position in any licensing conversation is the one you can show your working for. "Here is every user, their tier, and why" beats any estimate — and it's the same access data your security team already lives in.
The bottom line
RISE turned user classification into a place where security and licensing meet. The access hygiene that keeps you audit-clean is the same hygiene that keeps your FUE position tight — and the data lives in one place. An agent that classifies every user by tier, consistently and continuously, gives you a defensible position ahead of a licensing review, without touching your system and without inventing numbers you'd have to walk back later.
Know your FUE position before the review does
See the FUE Analysis Agent classify your users by tier from real role and activity data — a defensible, evidence-backed position, read-only, on your infrastructure.
Frequently asked questions
What is FUE in SAP RISE?
Under RISE, users are measured in Fixed User Equivalents (FUE) and grouped into tiers — broadly Advanced (broad or development-grade access), Core (substantive operational work), and Self-Service (light, occasional access). Your license position is driven by how users are classified into these tiers.
How is a user's FUE tier determined?
By the nature of their access and actual use — what their roles let them do, and what they actually do. That means classification is driven by the same role and activity data your security team already owns.
Is FUE a licensing problem or a security problem?
Both. RISE merged them: license exposure is driven by access classification, so the people who understand access also understand license exposure. Over-provisioned access is simultaneously a security risk and a recurring licensing cost.
How does an AI agent optimize FUE licensing?
It classifies each user by FUE tier from role and activity data, surfaces over-licensed users, and can indicate where restricting access would move a user to a lower tier — so you walk into a licensing review with a defensible, evidence-backed position.
Does FUE analysis change my SAP system?
No. The FUE agent is read-only — it reads role and usage data to classify and recommend. Any role change to move a user's tier is proposed for your team to review and apply.