CAPELLA AFEPCapella Agentic Full-Stack Engineering Platform for SAPAsk CAPELLA

CURRENT RELEASE CONTROL PATH / CAPELLA AFEP 0.7.4

Mission Control

Follow the current nine-stage product path from intent through structured pre-SFC validation, ERCC, SFC, authorization, governed execution, backend/Fiori delivery and evidence. This is a released control-path model—not live runtime state. The verified historical SAP case remains separate below.

REPLAY / PRODUCT DEMONSTRATIONNO LIVE SAP ACTIVITYNO LIVE AUTHORIZATIONNO EXECUTION ACTION

Current release control path

CAPELLA AFEP 0.7.4

Released product structure for evaluating a governed FullStack mission from intent through backend, Fiori and runtime evidence. Stage state is descriptive release capability, not live runtime telemetry.

d9c02ef163c5ff0cfd2e7efcfdd20daa82dbfa57
Release state RELEASEDRuntime state NOT ASSERTED
Current platform stages
9
Current Context
Mission-scoped and inspectable
Engineering Task Contract
ERCC / frozen and hash-bound
Pre-SFC validation
Structured findings
Needs Review
Explicit evidence or authority gaps only
Stage record
Status / timing / summary / evidence
Current ContextCAPELLA AFEP 0.7.4 / RELEASED
Mission lifecycle stateREFERENCE PATH / NO LIVE MISSION ASSERTED

Released product structure for evaluating a governed FullStack mission from intent through backend, Fiori and runtime evidence. Stage state is descriptive release capability, not live runtime telemetry.

Needs Review is shown only for an explicit evidence or authority gap; it is never inferred from missing live data.

CAPELLAERCCSFCGOVERNA4LayerSAPOBSERVATORY

Intent: CAPELLA AFEP holds authority. Boundary — Captures and bounds engineering intent without granting downstream authority.

Stage 01 / 9 · Guided · CURRENT RELEASE CONTROL PATH

Intent

Status
RELEASED CAPABILITY
Timing
Mission start
Summary
Capture objective, scope and constraints.
Evidence
Released 0.7.4 Mission Control structure

An engineer expresses the objective, constraints and expected outcome. CAPELLA starts a mission record and keeps the intent distinct from qualification, authorization and execution.

What entered
Human engineering objective
What left
Bounded mission intent
What was not proven
No generation, qualification, authorization, execution or SAP activity is implied.
Next authority
CAPELLA orchestration / pre-SFC validation

CAPELLA does not hide the failure path

Normal path and blocked path are both product behavior.

These scenarios use supported product states only. They are demonstrations, not fabricated incidents.

STALE AUTHORIZATION

The executable identity changed after approval.

Owner
GOVERN
Why CAPELLA stopped
Approval was bound to the previous execution configuration.
What CAPELLA will not do
Reuse stale approval or silently widen authorization.
Safe next action
Re-freeze the executable identity and require fresh authorization.
SAP/BTP write occurred?
NO
PLATFORM_BLOCKED

Deployment evidence exists, but runtime authentication/execution proof is unavailable.

Owner
SAP/runtime boundary
Why CAPELLA stopped
Runtime verified cannot be inferred from deployment, AppIndex or service registration.
What CAPELLA will not do
Represent PLATFORM_BLOCKED as VERIFIED.
Safe next action
Capture authoritative runtime proof when the platform allows it.
SAP/BTP write occurred?
NO ADDITIONAL WRITE CLAIMED
UNCERTAIN OUTCOME

Execution activity exists without authoritative target-state proof.

Owner
SAP readback / Observatory
Why CAPELLA stopped
Activity is not a verified delivery outcome.
What CAPELLA will not do
Blindly retry or call operation pass a verified outcome.
Safe next action
Perform authoritative readback before claiming delivery.
SAP/BTP write occurred?
UNKNOWN UNTIL READBACK
PROVIDER CAPABILITY UNAVAILABLE

A required provider capability or system carrier is unavailable.

Owner
A4Layer/provider boundary
Why CAPELLA stopped
Capability availability is not execution authority.
What CAPELLA will not do
Silently degrade LIVE to REPLAY.
Safe next action
Report the blocked provider state and keep the mission non-executing.
SAP/BTP write occurred?
NO

Operator Truth

Mission Control separates current state, approvals, operations, delivery and evidence.

APPROVALS are human/GOVERN decisions only. OPERATIONS are machine lifecycle activity. DELIVERY is verified outcome only. EVIDENCE is proof of what was observed.

CURRENT STATE

where the mission actually is now

Machine operation pass is never presented as verified delivery outcome.

APPROVALS

human/GOVERN decisions only

Machine operation pass is never presented as verified delivery outcome.

OPERATIONS

machine lifecycle activity

Machine operation pass is never presented as verified delivery outcome.

DELIVERY

verified outcomes only

Machine operation pass is never presented as verified delivery outcome.

EVIDENCE TIMELINE

proof of what was observed

Machine operation pass is never presented as verified delivery outcome.

FullStack delivery detail

Progressive detail behind the nine-stage path.

The expanded lifecycle covers backend and Fiori delivery without creating fake authority layers.

intent/contextERCCSFC compilequalificationSAP preflighttyped mutation manifest freezecanonical physical artifact identityGOVERN SAP-write authorizationcarrier/A4Layer executionSAP generationactivationATCbackend readbackservice publicationindependent publication verificationOData validationBACKEND_VERIFIEDFiori deployment authorizationUI5 validationUI5 buildBSP deploymentdeployment reconciliationdeployed-content/readback verificationAppIndex/descriptor/service validationruntime outcome classificationObservatory/evidence finalization

VERIFIED SAP CASE 01

Governed managed RAP realization

A validated managed RAP mission moved through SFC 0.13.1 qualification, explicit human authorization, A4Layer 1.0.0 execution, SAP realization, SAP readback and ATC with 0 findings.

CAPELLA_MULTI_OBJECT_NAMING_CORRECTED_LIVE_REALIZATION_R1
Historical mission state COMPLETEClaim state VERIFIED

This eight-stage verified case is preserved from its original evidence. ERCC is not inserted because the published mission evidence does not establish that ERCC was used.

Historical evidence lineage

Eight evidenced stages. No ERCC retrofit.

Each stage states what happened, which authority owned it, what evidence exists and what was not proven in the original 14-object managed RAP realization.

  1. 01 · CAPELLA AFEP

    Engineering intent

    A person expresses the engineering goal: create a governed SAP RAP application. CAPELLA freezes this as a bounded managed RAP create mission. Nothing is generated, qualified or executed yet — this stage only fixes the objective. CAPELLA holds coordination authority; SFC owns the next step.

    Claim VERIFIED · Not proven This stage does not prove any code was generated, qualified or executed. It only proves the mission objective was bounded.

  2. 02 · CAPELLA AFEP

    CAPELLA orchestration

    CAPELLA coordinates operator workflows, status, approvals, delivery surfaces and evidence continuity so the mission stays visible end to end. It keeps the work moving between authorities without becoming any of them. The next authority is SFC, which compiles and qualifies the delivery candidate.

    Claim DECISION · Not proven No separate orchestration artifact is published. This stage is an architectural decision, not verified mission evidence.

  3. 03 · SFC 0.13.1

    SFC qualification

    SFC 0.13.1 compiles the managed RAP candidate and qualifies it against the current banked release. Compilation and qualification completed before any SAP-write authorization existed. A qualified candidate is still not an approved write — Govern owns the next gate.

    Claim VERIFIED · Not proven Qualification does not prove the change is safe to run — it proves the candidate compiled and qualified before authorization.

  4. 04 · Govern

    Govern / human approval

    Govern applies the hash-bound human approval gate before any SAP-write execution. A person authorizes the exact qualified execution request; the approval is bound by hash so what is approved is exactly what runs. Govern does not execute against SAP — it authorizes a bounded execution intent.

    Claim VERIFIED · Not proven Approval here does not prove SAP accepted the change. It proves a human explicitly authorized the exact qualified request.

  5. 05 · A4Layer 1.0.0

    A4Layer execution

    A4Layer 1.0.0 carries the authorized delivery intent into bounded SAP execution. The authorized carrier executed without transferring SAP authority to CAPELLA or SFC. A4Layer performs the approved work; it does not decide whether SAP accepts it.

    Claim VERIFIED · Not proven A4Layer running does not prove the outcome is correct. Correctness is decided by SAP and verified at readback.

  6. 06 · SAP

    SAP realization

    SAP determines authorization, realized object state, activation and runtime truth. In the verified mission, SAP realized the exact expected 14-object set and remained final runtime truth. If SAP had rejected the change, SAP's decision would stand and be recorded as evidence.

    Claim VERIFIED · Not proven This does not prove SAP writes occurred during the 0.6.1 release process — those were zero. It proves this bounded mission realized its expected object set.

  7. 07 · SAP / Observatory

    Readback + ATC

    SAP readback verified the realized state against the expected object set, and ATC completed with 0 findings. Readback and ATC turn an outcome into evidence: until the realized state is verified, an outcome is not yet proof.

    Claim VERIFIED · Not proven Zero ATC findings for this bounded mission does not prove zero findings for arbitrary future work.

  8. 08 · Observatory

    Observatory / evidence

    Observatory records the authoritative engineering execution and evidence, and the bounded mission closed PASS with ATC 0 findings. The evidence is classified VERIFIED — supported by current authoritative CAPELLA evidence — with its boundary stated explicitly.

    Claim VERIFIED · Not proven The evidence record does not establish unrestricted autonomous SAP engineering. It is one bounded verified outcome.

Historical mission completion

This is what CAPELLA means by a governed engineering outcome.

  • Engineering intentqualified
  • SFC 0.13.1qualification passed
  • Governhuman authorization preserved
  • A4Layer 1.0.0bounded execution carried
  • SAPrealization + runtime truth
  • ATC0 findings
  • Observatoryevidence preserved
Outcome
14-object bounded SAP realization
Qualification
SFC 0.13.1
Authorization
explicit human approval
Execution
A4Layer 1.0.0
SAP
realized + readback
ATC
0 findings
Claim
bounded verified outcome

Boundary This verified case does not establish unrestricted autonomous SAP engineering. It does not claim unrestricted RAP delivery, a clean test environment, or SAP writes during the 0.6.1 release process.

The CAPELLA engineering contract

One layer never inherits another’s authority.

These invariants are CAPELLA product behaviour, consistent with the published authority model and claim taxonomy — not marketing slogans.

  • Generation is not qualification

    Generated managed RAP content is a candidate, not a qualified result. SFC 0.13.1 compiles and qualifies it before it can move toward a SAP-write authorization.

    Verify
  • Qualification is not authorization

    A qualified execution request still cannot become a SAP write on its own. Govern applies a hash-bound human approval bound to that exact request.

    Verify
  • Authorization is not execution

    Human approval authorizes a bounded execution intent. A4Layer 1.0.0 is the separate carrier that performs the approved execution.

    Verify
  • Execution is not SAP authority

    A4Layer carries approved intent into SAP without inheriting SAP authority. SAP determines authorization, realized object state, activation and runtime truth.

    Verify
  • Activity is not a verified outcome

    Durable run activity and lifecycle telemetry exist, but measured effectiveness does not. The public experience separates verified, demonstrated, experimental and planned.

    Verify
  • An outcome is not evidence until it is verified

    SAP readback and ATC verify the realized state against the expected object set. The verified mission recorded a 14-object realization with ATC 0 findings.

    Verify
  • AI intelligence is not engineering authority

    AI contributes across the engineering lifecycle, but SFC still qualifies, Govern still authorizes, A4Layer still executes and SAP still decides.

    Verify

Product category

CAPELLA AFEP — Agentic Full-Stack Engineering Platform for SAP.

CAPELLA is the engineering control plane between AI-assisted engineering intent and governed SAP outcome. It does not replace SAP authority. Supporting category: Governed Engineering Control Plane for SAP.

  • AI can generate.
  • Agents can reason.
  • MCP can expose tools.
  • Workflow engines can orchestrate.
  • SAP can authorize and execute.

CAPELLA's product role is to connect these concerns into a governed engineering lifecycle without allowing one layer to silently inherit the authority of another.

Architectural differentiation by product category. Non-CAPELLA cells use neutral descriptions, not assumption-based checkmarks.
DimensionAI copilotLLM / agentWorkflow automationLow-code / app builderCAPELLA AFEP
Generates engineering suggestionsYesYesNot inherent to the categoryProduct-dependentYes — as one stage, not the outcome
Deterministic qualification boundaryNot inherent to the categoryNot inherent to the categoryRequires external controlsProduct-dependentSFC 0.13.1 compiles and qualifies before authorization
Explicit human authorization boundaryProduct-dependentRequires external controlsRequires external controlsProduct-dependentGovern hash-bound approval before any SAP write
Separate execution authorityNot inherent to the categoryNot inherent to the categoryProduct-dependentProduct-dependentA4Layer 1.0.0 carrier, separate from generation and compilation
SAP remains final runtime authorityNot addressed by the categoryNot addressed by the categoryNot addressed by the categoryProduct-dependentSAP determines authorization, realized state and runtime truth
Evidence lineage and claim classificationNot inherent to the categoryNot inherent to the categoryProduct-dependentProduct-dependentObservatory records evidence; every public claim carries a class

After the replay

See the full evidence, or ask CAPELLA about the mission.

Inspect verified evidence