| Status | Approved |
| Owner | |
| Stakeholders | |
| LeanIX Link |
The purpose of this document is to describe the architecture of BlackLine application and the systems it will be integrating with.
Out of Scope:
- Since BlackLine is a SaaS aaplication, network and infrastructure architecture will be considered as out of Scope.
- Information related to product documentation and can be found online will not be documented here.
Key Decisions and Requirement
| Description | Rationale |
|---|---|
| Single Sign-On (SSO) | As part of SyWay project, a common authentication mechanism (e.g., SAML) will be adopted for ease of access and unified user experience. |
| Users must access BlackLine using HTTPS. | As part of SyWay standards, all data in transit must be encrypted. |
| Data stored in BlackLine must be encrypted. | As part of SyWay standards, all data at rest to be encrypted. |
| BlackLine must have appropriate data protection. | BlackLine performs data backups regularly so that point in time recovery can perform to recover data. Additional, backups must be replicated to another site to protect against a site disaster. |
Application Architecture
Overview
SAP Account Substantiation and Automation by BlackLine solution will be used to automate account reconciliations, centralizing period-end tasks, and enforcing internal controls. This solution will leverage BlackLine Core and BlackLine Connector S/4HANA add-ons to integrate S/4HANA and Blackline application. BlackLine is also configured to perform SAML SSO with Syensqo's Entra ID.
Hosting Details
| Region | Cloud Provider | Disaster Recovery Region |
|---|---|---|
| Frankfurt, Germany | Belgium |
System Landscape
BlackLine landscape will consist of 2-tiers: Non-Production and Production. The non-PRD system will be integrated with all non-PRD S/4HANA instances.
Following are the URLs for BlackLine instances:
- Non-Production: https://sapsyensqo.sbeu3.blackline.com
- Production: https://sapsyensqo.eu3.blackline.com
Application Security
User Access
BlackLIne is a SaaS application and can be accessed by users over the internet via HTTPS using their web browser. No Syensqo infrastructure or application is required to access BlackLine.
User must have their IDs created and assigned with the correct role before they can login to BlackLine.
Authentication
BlackLIne is configured to perform SAML SSO with Syensqo Entra ID. The use of SSO is mandatorily enforced via configuration, and users cannot bypass SSO to log in with a password.
Communication Security
Data Security
Other Controls
System Landscape
Development Environment
Project Test Environment
Quality Environment
Production Environment
Operation Architecture
Change and Configuration Management
Transport Management
Release Management
Monitoring
Application Monitoring
System Monitoring
Sizing
High Availability
Disaster Recovery
Backup/Restore
Maintenance Plan
Service Introduction
Application Category
Support Team
Skill required
Checklist
Exceptions
See also
Change log
Workflow history
| Title | Last Updated By | Updated | Status | |
|---|---|---|---|---|
| There are no pages at the moment. | ||||