Skip to main content

Case study / SAP BTP

Manufacturer Analytics Portal

Delivered 25 SAPUI5 reporting applications plus 3 onboarding applications within a secure SAP BTP experience for external manufacturers.

StackSAP BTP · CAP · SAPUI5 · Build Work Zone

Recruiter snapshot

The project in about ten seconds.

Focus

SAP BTP · UI/UX

Challenge

External partners faced fragmented data access across siloed portals, leading to reporting delays and security complexities for a major healthcare leader.

My contribution

Configured SAP Build Work Zone and SAP Cloud Identity Services with Okta-based authentication. Designed and developed the SAP CAP service using Node.js over HANA, and delivered 25 SAPUI5 reporting applications plus 3 onboarding applications that consolidated fragmented partner access into one authenticated experience.

Outcome

The program produced reusable UI, service, documentation, and delivery patterns for future reporting work.

Applications delivered
28
Primary UI
SAPUI5
Portal
Build Work Zone

Business Challenge

What was at stake

An external partner network accessed performance and reporting data through a patchwork of legacy portals and analytics tools. Each surface had distinct login flows, partial data coverage, and inconsistent security boundaries—creating audit risk and slowing every partner onboarding.

Key Problems

  • Fragmented reporting entry points and inconsistent user experiences
  • Partial or duplicated data per portal with no canonical view
  • Identity sprawl across partner organizations and internal directories
  • Weak tenant isolation enforced inconsistently across surfaces
  • High onboarding cost and friction per partner organization

Stakeholders Affected

External manufacturer and partner network, internal IT operations, data governance, and security/compliance reviewers.

Technical Approach

Owned application delivery across SAPUI5, CAP, and Work Zone

Delivered 25 SAPUI5 reporting applications plus 3 onboarding applications, designed and developed the Node.js CAP service over HANA, and configured the SAP BTP experience around Build Work Zone and enterprise identity. Shared-system responsibilities such as cross-layer troubleshooting, testing, and stabilization are called out separately rather than overstated as sole ownership.

Delivered 25 SAPUI5 reporting applications plus 3 onboarding applications and reusable frontend patterns

Designed and developed the Node.js CAP service over HANA

Configured SAP Build Work Zone and SAP Cloud Identity Services with Okta-based authentication

Supported cross-layer troubleshooting across SAP IAS, XSUAA, and application layers

Produced delivery documentation and supported testing, deployment, and stabilization

The Process

Project Lifecycle

01
Discovery

Analyzed existing Power BI workflows and mapped data requirements for external manufacturer personas. Identified security gaps in cross-platform authentication.

02
Architecture

Contributed to a SAP BTP solution using Build Work Zone, SAPUI5 applications, CAP services, and enterprise data sources.

03
Development

Developed SAPUI5/Fiori reporting applications, supported CAP service behavior, and coordinated with technical and functional contributors.

04
Deployment

Supported testing, troubleshooting, deployment, and post-release stabilization across enterprise environments.

Technical Deep Dive

Architecture & Implementation

System topology / SAP BTP

Manufacturer portal architecture

Experience → services → data

EXP

Experience

Build Work Zone
SAPUI5 applications

SRV

Application services

SAP CAP / Node.js
OData services

DAT

Data

SAP HANA
Enterprise data sources

SAP BTP experience architecture connecting Build Work Zone and SAPUI5 applications to CAP/OData services, HANA-backed enterprise data, and the Okta → IAS → XSUAA identity path.

Outcomes

Proof in production

Key outcome

Unified enterprise reporting experience

28

Applications delivered

SAPUI5

Primary UI

Build Work Zone

Portal

Qualitative Outcomes

Beyond the numbers

  • Single secure entry point established for the external partner community
  • Consistent partner experience across analytical workflows
  • Application-layer authorization supported by identity attributes
  • Foundation in place for adding new analytics apps without re-architecting identity

The program produced reusable UI, service, documentation, and delivery patterns for future reporting work.

Lessons Learned

What generalizes

  1. 01

    Identity attributes must be agreed across partner IdP, IAS, and CAP before app development—late discovery cascades into UI rework.

  2. 02

    ABAC is only as strong as the negative-test program. Explicit "partner A cannot read partner B" tests are non-negotiable.

  3. 03

    Build Work Zone information architecture matters more than visual polish. External users abandon a portal when they cannot find their app on day one.

  4. 04

    Phased onboarding requires coordinated communications. Technical readiness alone does not drive adoption.

  5. 05

    CAP ABAC requires care around joins and projections. Treating ABAC as automatic leads to silent leaks under load.

When This Approach Makes Sense

Is this a fit for your program?

Strong fit when

  • External users—partners, distributors, manufacturers, dealers—need secure portal access to SAP data
  • Identity federation with corporate or partner IdPs is required
  • Multi-tenant isolation is a hard, audited requirement
  • A roadmap exists to consolidate legacy partner portals
  • Stakeholders are committed to SAP-aligned architecture

Probably not when

  • The audience is internal employees only and Fiori Launchpad already meets the need
  • SAP BTP is not part of the strategic roadmap
  • The use case is content-heavy public marketing rather than authenticated data access

Continue evaluating Bryan

See the engineering in context.

Review my experience, compare selected work, or start a conversation about a senior engineering or SAP BTP technical lead opportunity.

Looking for selective enterprise project support instead? Enterprise consulting stays available as a secondary path.