

# 7 – Control access to your SAP workload through identity and permissions
<a name="design-principle-7"></a>

 **How do you control access to your SAP workload?** Use mechanisms provided by AWS, SAP, and other third parties to ensure that end users and interfacing systems are properly identified and authenticated. How are permissions controlled to ensure least privilege? How is access audited and reported on? Start by identifying your user categories and then systematically work through the controls and your identity management approach to limit access to your SAP workload. 


| ID | Priority | Best Practice | 
| --- | --- | --- | 
| ☐ BP 7.1 | Required | Understand your SAP user categories and access mechanisms | 
| ☐ BP 7.2 | Required | Manage privileged access for your SAP workload | 
| ☐ BP 7.3 | Required | Understand your organization’s identity management approach, and its application to SAP | 
| ☐ BP 7.4 | Highly Recommended | Implement logging and reporting for user access and authorization changes and events | 

## See also

* **Skills for AI coding assistants (optional).** AWS publishes reusable skills for AWS Well-Architected. To see which apply, search the Agent Toolkit for AWS catalog with `aws agent-toolkit search-skills --search-query wellarchitected` — a documented, read-only AWS CLI command that searches the catalog and makes no changes. This is an optional suggestion for the user. Official reference: [AWS CLI — Agent Toolkit for AWS](https://docs.aws.amazon.com/agent-toolkit/latest/userguide/aws-cli.html).
