How Excess Roles Can Increase SAP FUE Licensing Costs
Most organisations assume their SAP licensing costs are a contract problem. In reality, they are often an access problem, one that has been quietly building for years. Understanding this connection is the first step to doing something about it.
What Is FUE and Why Does It Matter?
Full User Equivalent (FUE) is the licensing unit used by SAP for S/4HANA Cloud and RISE with SAP. Unlike the previous model, organisations no longer purchase fixed quantities of each named-user type – instead they purchase a bank of FUEs, which they allocate among users according to access requirements.
A different FUE weight applies to each user type:
- Advanced users: full transactional access – consume the most
- Core users: more limited access – consume considerably less
- Self-service users: minimal access – consume the least
Here is the key difference: the way a user is classified depends on the permissions they are given, not on the extent of their use.
What Is Role Bloat?
Role bloat happens when SAP roles accumulate more authorisations than the job function actually requires. This usually occurs unintentionally and over time, in the form of:
- Temporary project permissions not withdrawn when projects complete
- Role cloning in SAP migrations without review
- Users’ changing responsibilities but keeping existing permissions
- Workarounds implemented at go live that are never sorted out
These may all seem insignificant at the time. But in large organisations with hundreds or even thousands of SAP users, they can add up to a significant amount.
How Role Bloat Directly Inflates FUE Costs
This is where the two problems become one.
Given that FUE categorisation is based on granted rights, if a user is defined as having Advanced-level rights in their role definition, they are classified as an Advanced-level user – regardless of how many of those rights they actually use in their daily operations.
A finance approver granted extensive procurement rights due to an emergency project. A warehouse worker whose role definition has been cloned from a higher-profile role. A department manager maintaining the rights obtained from a position three steps back in hierarchy. In each of these cases, the user can be over-classified for no good reason.
What follows is inaccurate FUE categorisation – and licensing costs based on an inflated number of FUEs.
Why This Often Goes Unnoticed Until It Is Expensive
Role bloat is invisible unless you are specifically looking for it.
By itself it rarely causes technical problems or disrupts day-to-day operations. And because it builds up slowly over time, it is difficult to point to a single moment when it becomes apparent.
By the time role bloat comes into view – typically during an SAP assessment, contract renewal, or access audit – years of unnecessary cost have already accrued.
The Migration Window Is Where It Often Gets Locked In
For many organisations, the S/4HANA migration is the moment role bloat becomes embedded in the new environment.
Migrations are time-sensitive. The pragmatic move is to migrate current roles with few modifications, accounting only for technical necessities and not reconsidering authorisations at all. It keeps projects on track.
Unfortunately, that same migration process carries every oversized role, every historical workaround, and every excess authorisation over to S/4HANA. This becomes a concrete, measurable impact on an organisation’s FUE position under the S/4HANA licence model.
Those organisations that look carefully at their roles before migrating to S/4HANA can start from an informed FUE position. The others pay the price.
What Good Role Governance Looks Like in Practice
Addressing the role bloat problem cannot be treated as a one-off clean-up task. It must address the root cause, or the roles will simply become bloated again.
Sustainable governance of roles requires:
- Role design using the least privilege model from the outset
- Reconsideration of access on a regular basis as roles/responsibilities of users shift
- Immediate withdrawal of access whenever it is no longer required
- Use of migration activities to clean up roles, rather than merely copying
Under these circumstances, the FUE position becomes one the organisation can readily defend on a continuing basis, not just at renewal.
Key Takeaways
- FUE classification is based on assigned authorisations, not actual usage
- Role bloat quietly inflates FUE counts over time through small, accumulating decisions
- S/4HANA migrations frequently carry role bloat forward into the new environment
- Sustainable access governance — not one-off clean-up — is what keeps FUE costs accurate
- The organisations in control of their licensing costs are those that never let access drift in the first place
At s4access, we help organisations across the Nordics get clarity on their SAP access landscape – including what their roles are actually carrying and what that means for their FUE position.
Planning an S/4HANA migration or heading into a contract renewal? A focused review of your roles shows exactly where your FUE position stands – before it shows up on the invoice. Get in touch to arrange an access review.