Start here

The pages in reading order.

Ten minutes of reading before the first scan: which role you need, where requests go, and what each finding means.

Before the first scan

  1. Getting started without being a developer: install Node.js, run npx btp-lens, answer four questions.
  2. Permissions: Space Auditor is enough, and what happens when a role is missing.
  3. Privacy: where requests go, what is kept and what is never kept.
  4. Frequently asked questions: safe with a production login, will SAP know, can I share the report.

Reading the report

  1. The sample report: what the overview, the findings and the apps pages show.
  2. Rules: every rule with its evidence, remediation and references, and how the risk score is computed.

Guides and posts

The first guides and posts are in review. They will be listed here as they are published.

All posts