Most teams cover a dozen SIDs with four people and a SAPGUI window per system. Farrenio puts SM50, SM37, ST22, ST04 and the rest in one browser tab, and flags the disk filling before users feel it.
One production system or forty across a dozen customers. The operating model is the same and only the tenancy changes.
Run SM50, SM37, ST22 and RFC checks from one console, with no Windows GUI.
See SAP operationsRead-only alert monitoring with escalation tracking and audit-grade history.
Inspect alertsMulti-tenant by design. Per-customer RBAC and isolated audit trails.
Multi-tenant modelMFA-gated reveal, 92-permission RBAC, tiered audit retention, SOC2-aligned.
Review the security modelTwelve Basis transactions, mapped to where they live in the stack, from the ABAP dispatcher down to the HANA indexserver and the OS. One web console, cross-system search, every action on the audit trail.
The question every Basis lead asks first, answered plainly: one Python daemon runs on the host, reads what it is allowed to read, and pushes outbound over HTTPS. There is no inbound listener and nothing to open on your perimeter.
One Python daemon per SID, under its own unprivileged service account rather than <sid>adm. Each collector is isolated, so one failing source never takes the others down with it.
The agent polls for its config and pushes metrics on 443. No firewall change, no NAT rule, no exposed port on a production SAP box.
RFC and HANA credentials are encrypted under a key issued per agent, never returned in plaintext on a read, and unlocked only behind a PIN or a fresh TOTP code, with every reveal on the audit trail.
Scroll the four steps a landscape goes through with Farrenio. The panel keeps pace.


A three-step wizard hands you an install script and a scoped token. The agent dials out and starts streaming while you watch. No firewall change, no inbound port.

SM50, SM37, ST22, DB02 and SM21 indexed across every SID. "Which system has the long-running job?" is one search with the answer attached, rather than twelve SAPGUI logons.

Per-metric, per-customer thresholds. Escalation ladders by severity and fans out to Slack, Teams, PagerDuty and email. Any alert can be promoted to an incident workflow.

Ninety-two permissions across eight roles, PIN- or MFA-gated token reveal, auto-block on credential-stuffing, and an audit trail carrying operator, IP and outcome behind every action.
Monitoring, automation, the HANA database and the move to S/4HANA on AWS. Each has a page of its own.
Roll out collectors, watch the landscape, control who can touch what, and route what breaks to whoever is on call.

Onboarding a system is usually a ticket, a firewall request and a week of waiting. Here it is a wizard that hands you an install script and a scoped token, then the agent dials out and starts streaming while you watch.
Based on benchmark workflows from teams running 6–25 SAP systems. Your mileage will vary, so we ship live dashboards you can measure it with yourself.
Cross-system SM50 / SM37 / ST22 queries take seconds instead of opening one GUI window per SID.
A single Python daemon, no firewall changes, no inbound ports. Heartbeat shows up immediately.
Tiered audit retention: 365 days for auth and role events, 180 for the rest. Every login, every config change, every sapcontrol command.
Permissions, audit, and brute-force protection aren't bolted on. They are the spine of every endpoint and every UI surface.
Farrenio acts as an AWS Reseller and Cloud Services provider, supporting customers throughout their cloud adoption, optimization and operational journey. We help organizations leverage Amazon Web Services for:
Kernel patching, HANA signals, S/4HANA on AWS. Deep-dives written from the Basis work itself rather than by the marketing team.
SAP BasisA walk through the platform: what it watches across ABAP, HANA, the instance and the host layer, how the collector connects outbound-only over HTTPS, the path from alert to SLA evidence, the automation it runs, the 92-permission access model, and what it does not do.
SAP on AWSDesigning SAP HA across two AWS Availability Zones: HANA System Replication modes and operation modes, a Pacemaker cluster with the SAPHana agents and AWS fencing, overlay IPs and Route 53, and ENSA2 for the ASCS, plus why an untested cluster is not HA.
Security & ComplianceHow SAP Security Patch Day works, what note priorities (HotNews to Low) and CVSS mean, applying fixes via SNOTE / SPAM / kernel, using System Recommendations to find what applies, and a risk-based cadence auditors accept.

Thirty minutes to scope it, about an hour to get your first production SID streaming. No commitment past that.