| Status | |
| Owner | |
| Stakeholders | |
| LeanIX Link |
This document will describe the high-level architecture of the Signavio application.
Out of Scope:
| Description | Rationale |
|---|---|
| Configure SSO for Signavio | As part of SyWay project, a common authentication mechanism (i.e. SAML) will be adopted for ease of access and unified user experience. The use of SSO is also enforced via configuration. |
| Users must access Signavio using HTTPS | Based on SyWay implementation approach, all data in transit must be encrypted. |
Signavio is deployed at Syensqo to model, analyze, and optimize business processes. Its primary use case is to document business processes using BPMN 2.0 and assists identifying areas for process improvement. The Process Manager and Process Collaboration Hub modules are activated in Syensqo's Signavio tenant.
Signavio is integrated with LeanIX so that application and business process data is replicated between the two systems as shown below. Signavio also publishes selected business processes to SAP Cloud ALM so that these can be used to organise Integration and User Acceptance Testing scopes. Signavio is also configured to perform SAML SSO with Syensqo's Entra ID.
Business process replication from Signavio to LeanIX is planned to be activated after SyWay design phase is completed and the processes are more stable (estimated Q1 2026). |
| Region | Region ID | Data Center ID | Infrastructure Provider |
|---|---|---|---|
Germany: Frankfurt | XAF | EU10 | AWS |
Since Signavio is a tool to model business process, only a single productive instance has been deployed in Syensqo.
Signavio is a SaaS application and can be accessed by users over the internet via HTTPS using their web browser. No Syensqo infrastructure is required to access Signavio, and no application needs to be deployed into Syensqo equipment.
When users login for the first time using SSO, Signavio will automatically create a user ID with read-only access and assign a Collaboration Hub license to that user.
Signavio is configured to perform SAML SSO with Syensqo Entra ID. The use of SSO is mandatorily enforced via configuration, and users cannot bypass SSO to log in with a password.
Effective authorizations are determined by the combination of a user's permissions to data inside the application (e.g. process models, dictionary objects), and the license assigned to the user.
Authorisations to documents (such as process models) and dictionary objects (such as IT Systems, Executables, etc.) are controlled via custom Groups. The following Groups exist:
The license assigned to a user also controls the functionality to which a user has access. The following license types exist:
Effective authorizations are determined by the combination of a user's Group assignment and License assignment. For example, auto-provisioned users are assigned the Users group and Collaboration Hub license, thus providing read-only access to all models via the Collaboration Hub. Editing of models is prevented by the lack of a license that permits editing.
SAP uses TLSv1.2 to encrypt customer data during transmission outside of the SAP-controlled network.
The following controls are implemented to ensure data security:
Signavio's System Availability SLA is 99.7% (documented in SAP Trust Center - Service Level Agreement for Cloud Services).
Signavio's availability can be monitored through SAP for Me portal using:
Signavio is deployed across multiple availability zones with the following SLA:
SAP performs full backups with the following schedule to meet SAP's recovery point objective.
| Backup Tier | Frequency | Retention Period |
|---|---|---|
| T1 | Hourly | 8 Days |
| T2 | Daily | 35 Days |
| T3 | Every Sunday | 120 Days |
SAP has defined two windows for Signavio maintenance:
The definition of regular maintenance windows does not mean that maintenance outages will actually occur in each window.
SAP is continuously improving and expanding the capabilities of Signavio. The following links provide more information on releases: