Migrating from SAP IdM
SAP has announced the end of mainstream maintenance for SAP Identity Management at the end of 2027. For the move, Nova takes over the data from an export file using the “Migration Workbench” (Nova System Migration Workbench, NSMW). Nova needs no connection to SAP IdM for this, nor a fixed export format: an AI writes a suitable parser for each file. Administrators find the workbench under “Administration › Migration Workbench”.
What Nova takes over
| In Nova | Matched by | Taken over |
|---|---|---|
| Identities | email address | name, department, phone, location, status, start date, salutation, title, manager; further fields as custom attributes |
| Entitlements | ID | name, description, colour, risk |
| Business roles | ID | name, description, colour, contained entitlements |
| Assignments | email and role | one entitlement or one business role per assignment, by ID or name |
Nova displays custom attributes once they are defined under “Administration › Identity Management › Custom Fields”.
The workbench writes to Nova only. It creates no accounts in target systems and triggers no provisioning; newly created entitlements are not linked to any target system. It does not take over accounts, organisational units, approval workflows or passwords.
Procedure
- Upload. Administrators upload the export file via “New migration”: CSV, Excel, JSON, XML or fixed-width text, at most 10 MB. Nova stores it with the migration.
- Generate the parser. In the workbench chat, administrators describe the file or take over the suggestion “Read the file in and map all fields automatically.” The AI receives an excerpt and writes a parser for the whole file. Nova asks it for an explanation of the mapping, including a table of source column and Nova field, and shows it in the chat; “Parser script” shows the code. The instructions to the AI require multi-values that SAP IdM exports separated by “|” to be split per value.
- Dry run. As soon as the AI delivers a parser, Nova applies it to the whole file and checks every record against the current data without changing identities, entitlements or assignments; “Dry-run” repeats this at any time. If the parser fails, Nova passes the error message back to the AI up to two times. The AI receives the result of the last dry run with the next message.
- Review the preview. The “Dry-run preview” counts per object type what would be created, updated or skipped and what is faulty. Clicking a number filters the list. Skipped and faulty rows state their reason, such as a missing email address, an invalid date or an unknown role; for identities to be updated, the preview shows the changes field by field. Administrators request corrections in the chat or set them under “Options”.
- Run. “Run” opens “Run migration” with the counts per object type; individual object types can be deselected. Nova then writes in the background in a single database transaction: if it fails, the data stays unchanged.
- Final report. “Import finished” shows the counts per object type and, under “Not imported”, the faulty records with their reason.
- Roll back. As long as the migration has the status “Activated”, its card offers “Roll back”. Nova first states how many records it will delete and restore. Using a journal, Nova deletes what the migration created, together with the assignments attached to these objects, and restores the stored previous values of changed records. Entitlements that the migration added to business roles that already existed stay there. This takes effect in Nova only. Afterwards the migration can be run again.
Options
- “Mode”: the default is “Create only” – Nova skips whatever already exists in Nova. “Create & update” updates existing records; for identities, empty fields in the file do not overwrite existing values.
- “On error”: the default is “Skip row” – Nova writes the records without errors. With “Abort migration”, Nova writes nothing as soon as one record is faulty.
- Further switches remove leading and trailing whitespace, treat empty cells as missing, convert role IDs to upper case and skip duplicates within the file; all are on by default. A date-format hint is passed to the AI.
AI and data
Only generating the parser requires AI (“Local” or “Cloud”); dry run, run and roll-back work without it. The AI receives an excerpt of the file, the chat messages and the result of the last dry run – in “Cloud” mode, this includes personal data from the first rows of the export. Nova runs the parser in a separate, restricted process; only Nova itself writes to the database, after its own checks. See Overview and modes.
Logging and retention
- Audit log: upload, changes to name and options, start and completion of the run with the counts per object type and the records written (up to 5,000 listed individually), roll-back with the records undone, deletion.
- Provisioning log: entries per affected identity, both for the run and for the roll-back.
- Every dry run and every run remains stored as a run of the migration, as does the chat with the AI.
- An activated migration can only be deleted once it has been rolled back. Until deletion, the uploaded file also remains stored in Nova.
The steps after the upload can also be started from the admin chat; running, rolling back and deleting require a confirmation there, see AI guardrails.