| Status | |
| Owner | |
| Stakeholders | |
| LeanIX Link |
User provisioning (IdM) and Emergency access management (EAM) designs are not finalized for Blackline. This document will be updated after the designs are finalized. |
| Description | Rationale |
|---|---|
| Single Sign-On (SSO) | As part of SyWay project, a common authentication mechanism (e.g., SAML) is adopted for ease of access and unified user experience. |
| Users must access BlackLine using HTTPS. | As part of SyWay standards, all data in transit must be encrypted. |
| Data stored in BlackLine must be encrypted. | As part of SyWay standards, all data at rest to be encrypted. |
| BlackLine must have appropriate data protection. | BlackLine performs data backups regularly so that point in time recovery can perform to recover data. Additional, backups must be replicated to another site to protect against a site disaster. |
SAP Account Substantiation and Automation by Blackline solution is be used to automate account reconciliations, centralizing period-end tasks, and enforcing internal controls.
Financial Close BlackLine SaaS instance is provisioned for Syensqo. This solution leverages Blackline Core and Blackline Connector S/4HANA add-ons to integrate S/4HANA and Blackline application. Blackline is also configured to perform SAML SSO with Syensqo's Entra ID.
![]()
| Region | Cloud Provider | Disaster Recovery Region |
|---|---|---|
| Frankfurt, Germany | St. Ghislain, Belgium |
The BlackLine landscape consists of 2-tiers: Non-Production and Production. The non-PRD system is integrated with all non-PRD S/4HANA instances.
Following are the URLs for BlackLine instances:
BlackLine is a SaaS application and can be accessed by users over the internet via HTTPS using their web browser. No Syensqo infrastructure or application is required to access BlackLine.
User must have their IDs created and assigned with the correct role before they can login to BlackLine.
BlackLine is configured to perform SAML SSO with Syensqo Entra ID. The use of SSO is mandatorily enforced via configuration, and users cannot bypass SSO to log in with a password.
Data in transit is encrypted using secure TLS protocols (v.1.2 or greater) with 2048-bit keys.
The following controls are implemented to ensure data security:
Blackline is covered by standard availability SLA for SAP Cloud Services - 99.7%
Blackline does not have a transport tool. Users will need to replicate configurations manual from non-PRD to PRD.
Blackline performs the following monitoring:
Blackline system availability can be monitored via Trust Blackline.
Blackline tenants allocates 2GB of storage per users and monitors the usage for the whole instance.
Blackline has implemented high availability throughout its environment to prevent single points of failure.
It has the following DR targets:
BlackLine conducts disaster recovery tests on an annual basis.
BlackLine does backups of Production and non-Production instances daily from 9pm to 1am Pacific Standard Time. Backups are retained for 30 days and this can be increase to a maximum of 90 days by opening a support ticket.
Users can request for their Blackline instance to be restored using the daily backups for the last 30 days
Blackline maintenance schedule can be found in Trust Blackline. Syensqo BlackLine tenants are deployed to the following regions: