BUILT IN FROM DAY ONE
Security & Trust for SAP Business One
MyWave was built for complex, regulated industries from the beginning. Enterprise-grade security has been foundational to our approach from Day One, not an afterthought.
In clear language, here are the reasons why you can trust MyWave to deliver agentic transformation in your customer’s business or your own business.
Zero
business records ever pass through the MyWave Innovation Hub
3
things ever leave the customer perimeter, all outbound
1
place a credential meets an agent: at import, on the customer's side
For Customers
You own and operate the infrastructure. MyWave holds no standing access and no business data.
For Partners
Your access is whatever the customer grants, visible in their admin screens, and revocable without touching the agent.
For SAP
The agent loop runs inside the customer's landscape. SAP Business One is reached through the Service Layer, and SAP AI Core is a supported model path.
Five things that are true of every MyWave deployment.
01. An agent is a definition, not a data container.
What leaves the MyWave Innovation Hub is instructions, policies and connector configuration. Never business records.
02. The deployment lives on your side.
Conversations, credentials, the database and the audit trail all sit inside your own perimeter.
03. Only three things ever cross that perimeter.
A licence check at start-up, the model call, and usage counts that carry none of what the agent worked on.
04. Business data reaches the model, and only the model.
It gets there as the result of a tool call, shaped by a response template the builder controls, field by field.
05. Nothing routes through MyWave or a partner at runtime.
Neither has a component in the request path once the agent is running. Access exists only where you grant it.
What happens to an agent when it moves from the MyWave Innovation Hub into your environment?
The MyWave Innovation Hub™ is where an agent is written. It is not where the agent runs, and it is not in the path of a running agent.
A fleet of agents is not redundancy. It is fifty points of failure with fifty sets of credentials, and most organizations cannot even inventory the ones they have. Fewer than half of companies can list the agents they are running. (SAP News Center, August 2026)
We concentrated the governance, not the risk. The agent's authority is scoped process by process in the policy you wrote. Every response is checked before it leaves. Compliance-critical processes run as deterministic workflows, exactly as designed.
You already trust one general ledger for the same reason. One gate is not a weakness in an audit. It is the only thing an auditor has ever trusted.
"Isn't one agent a single point of failure?"
Gartner's autonomy tiers run observe, advise, act with approval, act autonomously. We support all four, and you set the tier process by process rather than once for the whole company.
Probabilistic where the work is full of exceptions and the agent should weigh the case in front of it. Deterministic where the process has to run identically every time. Same skills, same policy, same trail.
Autonomous within policy. And only within it.
Probabilistic where it thinks.
Governed in everything it does.
Some processes are full of exceptions, and the agent should weigh the case in front of it. Others have to run identically every time, because compliance depends on it.
You choose per process. Autonomous within policy where judgment helps. Deterministic workflows where prescription matters. Same skills, same governance, either way.
Gartner's autonomy tiers run observe, advise, act with approval, act autonomously. We support all four, and you set the tier process by process.
The plain-language policy is both the auditable control document and the runtime configuration
Every response checked against written policy by deterministic enforcement outside the model
One agent holds the full context of a case from first message to final transaction