🔍 Read the full analysis: SAP Monitoring Security: A Read-Only Approach To Capacity Ledger Integration on Rymvard
Get monitors, keyboards and dev gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TL;DR

Rymvard says its early-access capacity ledger collects SAP infrastructure data through read-only interfaces and does not write to SAP. Its described integration has been tested against a simulator representing 200 hosts, not a customer landscape, and no customer deployments or outcomes are identified.
Rymvard says its early-access capacity ledger can collect infrastructure and landscape information from SAP environments using read-only connections, with no writes to SAP. The company describes fixed limits on the data it reads and says the integration was tested against a simulator rather than a customer system, leaving real-world deployment results unreported.
A small collector at each site communicates with the SAP Host Agent over HTTPS. Rymvard says the collector permits four operations: ListInstances, ListDatabases, GetDatabaseStatus and GetComputerSystem, and refuses other operations. A separate connection reads selected HANA monitoring views using a monitoring account over TLS. That process is limited to six fixed SELECT queries, a 60-second window per system and no more than eight systems at a time.
Rymvard also says it reads landscape information through the read-only interfaces of SAP Focused Run, ServiceNow, SAP Solution Manager via its System Landscape Directory, and SAP LaMa. The company says nothing is written to SAP. It has not supplied independent testing, a security audit or customer deployment results in the information describing the product.
The ledger’s matching rules are designed to avoid filling gaps with unsupported assumptions, according to Rymvard. An instance is associated with the system already running on its host; a system not declared elsewhere is recorded as a development system with 0.5 confidence and reported, rather than assigned to a customer. A guessed value does not replace a declared one, and an instance no longer listed by the Host Agent on its host is removed from the ledger.
SAP Monitoring Security: A Read-Only Approach to Capacity Ledger Integration
Rymvard describes a capacity ledger that gathers SAP infrastructure data through restricted read-only interfaces. The stated design limits what it can read; customer deployment evidence has not been reported.
“Nothing is ever written to SAP.”
Rymvard says the collector uses named operations and fixed HANA queries. These are company-described controls, with no independent audit or customer validation identified.
What the integration is designed to read
The described access model combines a site collector, a constrained HANA monitoring connection, and read-only landscape sources. Rymvard says the product does not write data to SAP.
Four named operations
A small collector communicates with SAP Host Agent over HTTPS. It permits ListInstances, ListDatabases, GetDatabaseStatus, and GetComputerSystem, and refuses other operations.
Fixed query boundaries
A monitoring account connects over TLS to selected views. Rymvard says access is limited to six fixed SELECT queries, a 60-second window per system, and up to eight systems at once.
Read-only interfaces
Named sources include SAP Focused Run, ServiceNow, SAP Solution Manager through its System Landscape Directory, and SAP LaMa.
How uncertainty is handled
Rymvard says matching rules are intended to avoid filling gaps with unsupported assumptions. Classification remains explicit when a system is not declared elsewhere.
Keep instances with their host
An instance is associated with the system already running on its host. If the Host Agent no longer lists an instance on that host, Rymvard says it is removed from the ledger.
Report, don’t guess
A system not declared elsewhere is recorded as a development system with 0.5 confidence and reported, rather than assigned to a customer. An inferred value does not replace a declared one.
From SAP sources to a capacity ledger
This is the flow Rymvard describes for collecting and organizing estate information.
Connect
Site collector reaches SAP Host Agent over HTTPS using named operations.
Read
Selected HANA monitoring views are queried through a TLS connection.
Match
Declared system and host information guide the ledger’s associations.
Report
Uncertain classifications are flagged instead of assigned by assumption.
Simulator testing, not customer validation
Rymvard says it has no SAP system of its own and tested the connection against a simulator modeled on Host Agent and HANA monitoring responses for a 200-host landscape.
What the description establishes
The product is described as running in early access. Screens are said to show the product using an illustrative estate.
The example is explicitly not identified as a customer, site, or outcome. Pricing is arranged with early-access partners; standard prices are not published.
What remains unconfirmed
No customer deployments, live-estate performance, or operational outcomes are identified. Independent security testing or an audit is not reported.
The description also leaves retention, stored-record encryption, audit logs, update procedures, interface changes, and source outages unspecified.
Questions to resolve before deployment
The stated controls describe an intended access model. They do not by themselves establish security, compatibility, reliability, or planning value in a live customer landscape.
Does Rymvard write data to SAP?
Rymvard says nothing is written to SAP and describes restricted read-only interfaces. No independent audit confirming that behavior is reported.
How was the integration tested?
Against a simulator emulating Host Agent and HANA monitoring views for 200 hosts. No customer system used for validation is identified.
Is the product available?
Rymvard describes early access, with pricing agreed directly with participating partners. Customers and standard prices are not identified.
What happens when classification is uncertain?
An undeclared system is recorded as development with 0.5 confidence and reported. Inferred values do not overwrite declared information.
Evidence to look for next
Useful next evidence would include customer deployments across varied SAP configurations, documented checks of read-only boundaries, collector performance under real workloads, and measured reliability of the matching rules. Rymvard has not specified a launch date, customer announcement, or further milestone.
Limits on SAP Production Access
Monitoring tools that connect to production infrastructure can create concerns about both operational changes and exposure of sensitive information. Rymvard’s stated design addresses those concerns by restricting the collector to named read operations, constraining HANA queries and keeping the SAP connection read-only. These controls describe the product’s intended access model; they do not, by themselves, establish that a deployment is secure or has no operational risk.
Data location and visibility may also matter to organizations operating across jurisdictions or serving multiple customers. Rymvard says detailed records remain in the country where they were measured, while customer names are visible only to planners and administrators. Those statements offer a picture of the company’s handling rules, but the available description does not specify retention periods, encryption at rest, access logging, or how the rules are enforced and verified.
The ledger is intended to help capacity planners understand system and infrastructure estates without writing back to SAP. That could make it relevant to organizations seeking consolidated capacity information, but its practical value, compatibility across varied landscapes and effect on planning decisions remain unconfirmed until customer use and results are documented.
As an affiliate, we earn on qualifying purchases.
Simulator Testing, Not Customer Validation
Rymvard says it has no SAP system of its own. It built and tested the connection against a simulator that responds like the SAP Host Agent and HANA monitoring views for a 200-host landscape. The company says the product is running and that displayed screens come from the product using an illustrative estate. It explicitly says the example does not represent a customer, site or outcome.
That distinction matters: simulator testing can show how software behaves against modeled responses, but it does not establish performance or reliability in a live customer environment. Rymvard describes the product as being in early access; it does not name partners, report installations or provide measured results. The company says pricing is agreed with early-access partners and does not publish standard prices.
“Nothing is ever written to SAP.”
— Rymvard
As an affiliate, we earn on qualifying purchases.
Live Deployment Evidence Is Pending
Customer use has not been documented in the product description. Rymvard says the system was tested against a simulator for a 200-host landscape, but does not provide results from a live SAP estate, identify early-access customers or report operational outcomes. It is also unclear whether independent security testing has been completed.
The described controls do not answer every deployment question. The company does not detail its audit-log procedures, retention schedule, encryption for stored records, update process, or the permissions required for each landscape interface. The information also does not establish how the product behaves when a source is unavailable, returns inconsistent data or changes its interface. These matters remain unconfirmed, rather than evidence that a particular control is absent.
As an affiliate, we earn on qualifying purchases.
Early-Access Validation Ahead
Rymvard says the product is available in early access, with pricing arranged directly with participating partners. The next useful evidence would be customer deployments showing whether the stated read-only boundaries hold in varied SAP configurations, how the collector performs under real workloads and whether the ledger’s matching rules produce reliable records.
No launch date, customer announcement or further product milestone is specified. Organizations considering the product would need to obtain details from Rymvard about security review, deployment requirements, data handling and support, then assess those against their own SAP environment and policies.
As an affiliate, we earn on qualifying purchases.
Key Questions
Does Rymvard write data to SAP?
Rymvard says nothing is written to SAP. It describes restricted read-only access to the SAP Host Agent, HANA monitoring views and landscape tools. No independent audit confirming that behavior is reported.
How was the SAP integration tested?
Rymvard says it tested the connection against a simulator that emulates the SAP Host Agent and HANA monitoring views for a 200-host landscape. It does not identify a customer system used for validation.
Is Rymvard available to customers?
The company describes the product as running in early access. It says pricing is agreed with early-access partners and does not publish prices or identify customers in the product information.
What happens when the system classification is uncertain?
Rymvard says an undeclared system is recorded as a development system with 0.5 confidence and reported, rather than assigned to a customer by assumption. It also says inferred values do not overwrite declared ones.
Source: Rymvard
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
