Resource

2026

Agent Definition Canvas

A reusable structure for defining an ETM4S4 agent’s purpose, skills, authority, controls and measures.

Complete this canvas before writing the implementation prompt. Keep each statement testable.

1. Identity

  • Name and version
  • Owner
  • Agent type: control-plane, domain or assurance
  • SAP Activate phases
  • Status: concept, pilot, approved, suspended or retired

2. Outcome

  • What transformation result should improve?
  • Who receives the result?
  • What current problem or delay does it address?
  • What measurable baseline exists?

3. Mission and boundaries

  • What tasks are inside scope?
  • What is explicitly outside scope?
  • What events trigger the agent?
  • When must it stop or escalate?

4. Skills and knowledge

  • Which durable professional skills are required?
  • Which process packs—such as Lead-to-Cash, Procure-to-Pay or Design-to-Operate—apply?
  • Which SAP product, industry, country and client skills apply?
  • Which sources are authoritative, and who owns them?

5. Tools and permissions

  • Which repositories and systems may it read?
  • Which artifacts may it create or update?
  • Which actions are reversible?
  • Which tools require independent policy checks or approval?

6. Human–agent responsibilities

  • Who initiates, contributes context, reviews, decides, executes and verifies?
  • Which decisions always remain human?
  • Which conflicts require independent challenge?

7. Evidence and controls

  • What provenance accompanies an output?
  • Which deterministic rules and policy checks apply?
  • How are separation of duties and least privilege maintained?
  • How are exceptions, overrides and incidents handled?

8. Evaluation and operation

  • What representative and adverse cases will be tested?
  • Which quality, risk, adoption, cost and value measures apply?
  • What constitutes an unacceptable failure?
  • What changes trigger reevaluation?
  • How can the agent be suspended or retired?

9. Dependencies

  • Which agents provide inputs or receive outputs?
  • Which shared knowledge, identity, policy and observability services are required?
  • What happens when a dependency is unavailable?