| Status | |
| Owner | |
| Stakeholders | The business stakeholders involved in making, reviewing, and endorsing this decision. Type @ to mention people by name |
| LeanIX Link | SAP Ariba Sourcing , SAP Ariba Procurement, Ariba CIG |
SAP Ariba is a cloud-based procurement and supply chain management solution that enables organizations to digitally transform their sourcing, procurement, contract management, and supplier collaboration processes. As part of the SAP Business Network, Ariba facilitates seamless integration between buyers and suppliers, promoting transparency, efficiency, and compliance across procurement operations.
In the context of enterprise architecture, SAP Ariba serves as a strategic component for automating and optimizing the Source-to-Pay (S2P) lifecycle. It supports integration with ERP systems (such as SAP S/4HANA or other third-party platforms) through standardized APIs and middleware, ensuring data consistency and process alignment across financial, operational, and procurement domains.
This document defines the architectural scope of the Ariba solution within the SyWay program, focusing on the deployment and integration of Ariba as the central platform for their sourcing, procurement, contract management, and supplier collaboration processes.
The scope includes:
List down out of scope items if applicable.
| Description | Rationale |
|---|---|
| Brownfield | Ariba is brownfield system and the landscape will be used for both Production support and SyWay Release 4 |
| Landscape | 3 Tier landscape for Syway project: Supplemental, Test, PRD. Will coexist with current Ariba BAU landscape |
| SSO | As part of SyWay project, a common authentication mechanism (e.g., SAML) will be adopted |
| SSL will be configured for Ariba to encrypt all traffic | Based on SyWay implementation approach, all data in transit must be encrypted. |
| Provision users in Ariba Sourcing based on IAG | The purpose of this integration is to automate the provisioning, update, and deprovisioning of user accounts and authorizations in Ariba via IAG, ensuring that access remains controlled, compliant, and aligned |
| Term | Description |
|---|---|
| Parent Realm | Use for Strategic Procurement and supplier enablement activities. Acts as a central Hub to :
|
| Child Realm | Use for Operational Procurement activities only (Guided Procurement). Can represent subsidiaries / regions / Business units . Acts as subordinate structure to :
|
| Upstream | Refer to all pre-purchase activities as Sourcing / Strategic Sourcing / Supplier Collaboration / Spend Visibility |
| Downstream | Refer to all procurement execution as Purchasing and Ordering (incl. catalog management) / Receipt processing/ Spend Management and reporting. |
| Supplemental Realm | Refer to an additional realm to :
|

It is a cloud-based platform that connects buyers, suppliers, and partners to streamline procurement, supply chain, and collaboration processes.
SAP Ariba Sourcing is a SAAS strategic sourcing solution that enables organizations to manage sourcing events such as RFIs, RFPs, and auctions in a centralized and collaborative platform. It helps procurement teams identify the best suppliers, negotiate optimal terms, and drive cost savings.
SAP Ariba Procurement is a cloud-based procurement solution designed to help organizations manage their purchasing processes more efficiently. It’s part of the SAP Ariba suite, which focuses on source-to-pay processes.
Ariba Cloud Integration Gateway (CIG)
The Ariba Cloud Integration Gateway (CIG) is SAP’s standardized integration platform that simplifies and accelerates the connection between SAP Ariba and external systems. It provides a unified framework for integrating Ariba with SAP ERP Platforms, Third party applications or Middleware platforms.
CIG acts as a bridge between Ariba’s cloud services and on-premise or cloud-based ERP systems, enabling seamless data exchange for processes such as purchase order creation, invoice submission, goods receipt, and supplier onboarding.

Icertis
Icertis is a contract lifecycle management (CLM) platform that helps organizations manage contracts digitally from creation to execution and compliance. It’s widely used by enterprises to improve visibility, reduce risk, and ensure compliance across all types of contracts.The "Ariba connector for Icertis" refers to the Icertis Contract Intelligence (ICI) for SAP Ariba integration, which extends SAP Ariba's procurement capabilities with Icertis's advanced contract lifecycle management (CLM) features. This integration synchronizes data between the two platforms, allowing users to manage contracts from sourcing through to payment, leveraging AI and automation for tasks like contract authoring, risk assessment, and compliance tracking.
Keelvar
Keelvar is a strategic sourcing and procurement automation platform that uses AI and optimization technology to help organizations run more efficient sourcing events and manage supplier negotiations.
The SAP Cloud connector acts as a reverse invocation proxy to establish network connection between SAP RISE systems and Ariba Cloud Integration Gateway (CIG). Due to its reverse invoke capabilities, the network traffic originates from SAP Cloud connector to SAP Ariba CIG and once the link as been established, data can be exchanged between SAP RISE systems and Ariba. HTTPS or RFC protocols are used between SAP Cloud Connector and S/4HANA, and HTTPS protocol is used between Cloud Connector and SAP Ariba CIG.
A 2 tier landscape will be adopted for SAP cloud connector: non-PRD and PRD. The non-PRD cloud connector will be shared across all non-PRD landscape.

Optional Section if application requires a network design.
Ariba will have 3 realms: Supplemental, Test and Production. Each realm will have the following modules: Sourcing, Procurement Parent, Procurement Child (one for each S/4HANA) and CIG. Ariba is also brownfield system and the landscape will be used for both Production support and SyWay Release 4. Additional landscape information can be found in instance plan document .
Modules / Tier | Supplemental | Test | Prod |
|---|---|---|---|
Ariba Sourcing | 745255310-SS-T | 744368466-T | 744368466 |
| Ariba Procurement Parent | 745255310-SS-T | 744368466-T | 744368466 |
| Ariba Procurement Child (BAU) | N/A | 744368466-CHILD1-T | 744368466-CHILD1 |
| Ariba Procurement Child (SyWay) | 745255310-SS-1-T | TBC | TBC |
| Ariba Business Network | AN11228658404-T | AN11204137717-T | AN11204137717 |
| Ariba CIG | AN11228658404-T | AN11204137717-T | AN11204137717 |
The landscape path will be modified based on 2 phases:

SAP Ariba solutions are thin client solutions. Cloud solution customers (users) access the solution through a browser and use HTML and JavaScript for presentation. The client browser communicates with the Web server tier using HTTPS over any connection to the Internet. SAP Ariba solutions support various browsers on Windows and Mac platforms. The login page indicates the browsers supported.
System | Users | Access Method |
|---|---|---|
Ariba | Business users | Web |
Support users | Web |
See below list of URL access to the Ariba instances:
| Application | Region | SBX | DEV | INT | UAT | PAR | TRG | PROD |
|---|---|---|---|---|---|---|---|---|
| Ariba - Sourcing | EU | - | Supplemental (745255310-SS-T) | Test | Supplemental (745255310-SS-T) | PRD (744368466) | ||
Ariba - Procurement Parent | EU | - | Supplemental (745255310-SS-T) | Test | Supplemental (745255310-SS-T) | PRD (744368466) | ||
| Ariba - Procurement Child | EU | - | Supplemental-EU (745255310-SS-1-T) | Test-EU | Supplemental-EU (745255310-SS-1-T) | PRD-EU | ||
| US | - | Supplemental-US | Test-US | Supplemental-US | PRD-US | |||
| CN | - | Supplemental-CN | Test-CN | Supplemental-CN | PRD-CN | |||
| Ariba Network | EU | - | Supplemental (AN11228658404-T) | Test (AN11204137717-T) | Supplemental (AN11228658404-T) | PRD | ||
List down all URL and access details.
Authentication is performed using the standard SyWay approach. Each user has an Entra-ID and a global user ID. The end to end Single Sign On is accomplished with SAML 2.0.
SAP Ariba utilizes Role-Based Access Control (RBAC) to manage user access. This means that user permissions are assigned based on their job within the organization. Each group corresponds to a specific set of tasks or responsibilities within the SAP Ariba platform.

Authorization checks related to procurement activities are performed in S/4 HANA using RBAC and then pushed to Ariba.
In Ariba, users can be restricted based on templates specific to a country. A sourcing template is created with the relevant attributes and fields, and access is assigned only to users from the same country. For example, users from the UK or Belgium will be mapped to their respective country's sourcing template.
The sourcing template can also be linked to multiple projects, with each project being assigned to a user as the project owner.
For Ariba Buyer/Supplier, the access design follows the same custom groups, tailored to specific business needs.
Addtional details can be found in Security Approach document..
SAP Ariba provides X.509 certificate-based authentication. SAP Ariba stores private keys for its certificates in a secured and hardened key management infrastructure. In certain environments, this is further protected by a FIPS 140-2 Level 2 Hardware Security Module (HSM).
SAP Ariba solutions apply encryption-at-rest solutions at different layers to mitigate different types of threats pertaining to unauthorized access. These include:
Cloud services are deployed to multiple data centers throughout the world. The data centers are geographically located in regional pairs. Data is replicated between the regional pairs so that data remains in the region of deployment.
An SaaS IV system is scalable to an arbitrarily large number of customers because the number of servers and instances on the back end can be increased or decreased as necessary to match demand. As a result, scaling resources does not require any rearchitecting of the applications, so changes and fixes can be rolled out to thousands of tenants as easily as for a single tenant.
SAP Ariba solutions are powered by high-performance servers and utilize a network infrastructure designed for scalability, reliability, and security. SAP Ariba solutions implement an n-tier network architecture that physically segments Web, application, and data tiers. The communication protocols used between the systems are TCP/IP-based. The Cloud Engineering Services team constantly monitors and maintains all systems. Redundant load balancing and security firewall devices are inserted between each tier of SAP Ariba solutions.
SAP Ariba Procurement schedules data backup at regular intervals. The backups are replicated to a secondary site, from where they can be restored in case of a disaster.
When there is an inadvertent data destruction, within the primary data center, the data is recovered using the data that was last backed up.
SAP Ariba Procurement schedules jobs to execute an automated backup of customer’s data. Additionally, a backup of the log files is automatically taken at 15-minute intervals.
As part of the RPO, when SAP Ariba Procurement restores the data and restores the system, the loss of data would be a maximum of 15 minutes.
The data backups that SAP Ariba Procurement maintains are retained in an encrypted format for a period of 14 days. SAP Ariba Procurement follows best practices and ensures that all the necessary steps are taken to prevent data failure to the best of its capability.
Cadence. SAP operates monthly updates (standard), immediate updates for critical fixes, and quarterly releases (usually on Feb-May-Aug-Nov).
What’s New & release calendars is available in following link. Teams to track feature deliveries and maintenance windows.
Major upgrades. SAP provides ≥ 4 weeks’ advance notice of major upgrades; SyWay reviews impact and coordinates any required readiness actions as documented in System upgrade plan.
Release information can be found on SAP Note 3453776 - SAP Ariba Release Information and Release Schedule:
