Governed AI for SAP teams

The AI ABAP developer inside your SAP

It builds ABAP, diagnoses incidents and writes advisory reports through the official ADT, on S/4HANA and on-prem 7.x alike. A full agent, not autocomplete.

  • On-prem
  • Official ADT
  • Claude verified
  • Full audit log
  • Deletion disabled
makion · Specification → Development → Code review
Specificationread-only in SAP

Here is the client's brief for the credit-limit check. credit-limit-brief.docx

  1. Read the brief, cross-checked against the live system
  2. Versioned spec created:SPEC-0142 v1Goal · Scope · R1–R6 · Acceptance criteria
Developmentwrites · dev system only

Implement SPEC-0142 v1.

  1. Reuse first:ZCL_FI_CREDIT_UTILfound · reused, not rewritten
  2. Team standard applied: naming · error handling · Clean ABAP
  3. sap_locksap_set_source· cleaner, 45 rules
  4. sap_syntax_checkpassed · ATC clean · ABAP Unit passed
  5. sap_activatesap_unlock
Code reviewread-only

Review the change against our standard.

  1. Reviewed against the same standard · findings ordered Critical / Major / Minor
Done
ObjectZCL_FI_ORDER_CHECK
TransportDEVK900342
Wherein your SAP
Engine: Claude · your key · your server
Problem

Where other AI stops

Plenty of AIs can now touch your SAP. None of them are governed: no roles, no approval gate, no audit, no team standards. And none run on your 7.x / ECC.

You've been here before.

01

Blind chat, endless clipboard

Out of the box a chat only edits text, so you shuttle code through the clipboard. Wired to SAP via MCP it writes and activates with no roles, no gate, no audit.

02

Cloud-only, metered by SAP

Joule and the official ADT MCP route model choice through SAP and meter it in AI Units — a per-consumption bill you cannot forecast before the run. And SAP scopes Joule for Developers to S/4HANA Cloud Private Edition 2021+.

03

Fear of breaking production

Letting a “smart automaton” loose in a live system without guarantees is simply not acceptable. The boundary has to live in the tooling.

How it runs

One agent, inside your SAP

A desktop app plus a server you host. The server holds the MCP broker, your AI account and the ADT connection. Every tool call is checked against the role before it reaches SAP.

Makion architecture The desktop app connects to your server, which holds the MCP broker, your AI account credentials and the ADT connection to your SAP. Your server calls your own AI provider — Claude (verified), with Gemini, Codex, Kimi, Grok and DeepSeek selectable (results vary by model) — using your key; Makion never sees your code. YOUR INFRASTRUCTURE no data path Your AI provider Desktop app chat, roles, orchestrator Your server MCP broker checks every call against the role your AI account: your key or subscription Official ADT REST connection Your SAP makion.dev (vendor)
tool calls over the official ADT, checked by the broker prompts to your own AI account Makion the vendor: no data path
Three products, one agent

Build, support, advise

The same governed AI and the same official ADT channel. All three come with the licence — you don't buy them separately. Every role outside Development is read-only at the tool level.

writes · dev systems only

Development

Implements a requirement end to end: ABAP, CDS / RAP / Fiori, Adobe Forms, S/4HANA migration, unit tests and ATC. The only product that writes to SAP.

What you get: a finished, activated change made your way.

Read the full
read-only

Support

Diagnoses incidents over the same ADT channel: dumps, jobs, logs, IDocs, RFC queues. No RFC SDK, no S-User.

What you get: root cause and the next action in minutes, with nothing touched.

Read the full
read-only

Consult

Writes advisory deliverables from the real system and code: assessment, authorization review, interface inventory, delivery report, Migration Map.

What you get: engagement-grade documents you can hand a client.

Read the full
Secure by design

Built so production stays safe

“What if it breaks production?” It won't. That is built into the design.

Read the full
  • Read-only is a tool boundary.Read-only roles are never handed the write tools.
  • The broker checks every call.A call outside the role's set never reaches SAP.
  • Deletion permanently disabled.sap_delete_object is in no role and has no switch.
  • Two-person gate.In autonomous mode a person approves, then separately confirms the apply.
Makion vs the rest

How Makion compares

Seven rows that matter most. The full fifteen-row table is on the compare page.

CriterionMakionSAP's AIKiro / Q + ADT MCPCopilot · Cursor
Where it runsYour serverSAP cloud (BTP AI Hub)Developer laptopIn the editor
BillingYour own AI accountPer token (AI Units)Agent tier + overagePer-tool subscription
Roles as a tool boundaryPer-role read / write tool allow-listAll-or-nothing
Two-person gateIrreversible actions queued for human approval
Central audit logServer-side, every action loggedClient-side onlyClient-side only
Project memoryVersioned specs · your standards · reuse-first
Old ECCOfficial ADT — 7.40+, no release lockJoule: S/4HANA PCE 2021+Depends on the MCP serverDoesn't touch the system
Read the full table
Who it's for

Who Makion is for

People who write ABAP and answer for a live system.

Indie and freelance developers

ABAP developers and consultants who want to describe a task in words and have Makion carry it out, review it or investigate it in their system.

IT teams at an SAP customer

Several developers need a single instance, isolated by “developer × project”, each with their own SAP connection.

Consulting firms

Who need one development standard across the whole team and work on client on-prem / ECC systems without handing their SAP system to a third-party SaaS.

Get started

Put Makion inside your SAP

Your SAP, your standards, your terms. Makion reads, writes, activates and creates DDIC inside the system. Deletion is off the table and unattended runs wait behind a two-person gate.

On-prem. Your SAP and credentials stay on your infrastructure. Makion never sees your code.

Several developers or a client rollout? Teams & enterprise