How it works

How the export becomes documentation you can check.

A read-only ABAP report exports your custom code and the context around it. From that export, CodeGraphAI builds an evidence graph, re-checks every relationship and every citation, and generates the documentation. This page walks through each step: what it produces, and where its limits are.

01The export

One read-only report, installed in about 5 minutes.

It reads code, dictionary definitions and configuration. It reads no transactional data and no user names, and it changes nothing: its only output is the export files, written to a directory you choose.

What the export reads
WhatIn detail
Custom source codePrograms and includes (reports, module pools, user-exit includes), classes and interfaces (every include), function groups and their function modules, enhancement implementations and CDS view sources.
ABAP Dictionary definitionsThe structure, not the table contents: customer tables, views, structures, appends, data elements, domains with fixed values and table types. Also the definitions of the SAP tables your code uses.
The SAP where-used indexBoth directions: who calls your code from SAP, and what your code references.
TransactionsCustomer transaction codes with their program, screen, parameters and text.
ScreensFlow logic and field names.
Background jobs that run customer programsJob name, step, program, variant name, number of runs in the period (default 90 days), last run date, periodic flag and statuses. No user names.
Process configuration (customizing)IDoc process codes; IDoc partner profiles (included by default; one checkbox leaves them out, see the stated limit below); payment methods and payment medium formats; customer DMEE trees; CMOD projects; classic and new BAdI implementations; table maintenance dialogs (SM30); the SAP modification log (names of modified SAP objects only).
TextsObject, package and message texts: in the selected language, then the master language, then English.
InventoryEvery customer object of the selection, of all object types, flagged with whether its content was exported.

Stated limit: IDoc partner profiles are included by default and contain partner numbers (customer, vendor and bank numbers). One checkbox, “Include IDoc partner profiles”, leaves them out. The documentation never writes partner numbers. An optional field, “Extra config tables (content)”, reads only the tables you add to it; it is empty by default.

What it never reads or changes

  • SAP standard source code. The one exception is described below.
  • User names. Author, scheduler, changed-by and every other user-name column are removed from every file. The object inventory has no user column either. Source code is exported as written, so a comment can still contain a name or an SAP user ID; before any AI step, personal data in comments and string literals is redacted.
  • Transactional data. It never reads orders, invoices, postings or similar data.
  • Your database. The report contains no database INSERT, UPDATE, MODIFY, DELETE or COMMIT.

The one exception

The user-exit includes that you list on the selection screen are read, because they hold customer code inside SAP frames. In the synthetic demo system, the user-exit include MV45AFZZ is documented like any other custom code:

MV45AFZZ calls ZSD_ORDER_STATUS_UPDATE GRAPH:CALLS CODE:mv45afzz.abap:18 — in update task, in form USEREXIT_SAVE_DOCUMENT

Authorizations of the user who runs the export
Authorization objectAccess
S_DEVELOPDisplay
S_TABU_NAM / S_TABU_DISDisplay
S_DATASETWrite, for the output directory
S_GUIOnly for a download to a PC folder

Product: Tables the user may not display are skipped and logged.

Installing and running it

Installation
About 5 minutes: create, paste, save, activate. It is a local object (package $TMP), so no transport is needed.
Output
The export files, written to a server directory (AL11) or a PC folder that you choose.
In the background
A system with a few thousand custom objects takes minutes. A manifest and a log record what was exported, what was skipped and why.
Releases
The pilot ran on a productive SAP S/4HANA system. The report is syntax-checked for ABAP 7.40 SP08, 7.50 and 7.55. Release-dependent parts (CDS, DMEE, BAdI tables) are read dynamically and skipped with a log entry when they do not exist. Ask us about your release.
Selection
By default, all customer objects (Z*, Y*). You can add your own namespace (for example /ABC/*) and narrow the selection by package.

What leaves your system

02The evidence graph

Every relationship points to the line or row that proves it.

One relationship per evidence site, stored with how it was detected, the file, the line and a confidence tier. Each one is re-verified automatically.

One catalogue line, two pieces of evidenceZSD_ORDER · Calls to other code

LZSD_ORDERU01 calls BAPI_SALESORDER_CREATEFROMDAT2 GRAPH:CALLS CODE:lzsd_orderu01.abap:33 — in function ZSD_ORDER_CREATE, recorded in the SAP where-used index EXPORT:cg_xref_cross.tsv:2

The code line

33CALL FUNCTION 'BAPI_SALESORDER_CREATEFROMDAT2'34  EXPORTING35    order_header_in = is_header

The where-used row

cg_xref_cross.tsv, line 2

direction
from_custom
type
F
name
BAPI_SALESORDER_CREATEFROMDAT2
include
LZSD_ORDERU01

Stored with every relationshiphow it was detectedfilelineconfidence tier

Each relationship is labeled with how it was established
Confidence tierHow the relationship was established
ResolvedResolved against the export or the SAP where-used index.
Configuration or dictionaryTaken from configuration or the ABAP Dictionary.
Name onlyMatched by name only.

Unresolved points are listed, never forced into the graph

What static analysis cannot resolve appears as an unresolved point in Coverage:

  • dynamic calls
  • dynamic SQL
  • targets outside the export
  • statements that could address either a database table or an internal table

Unresolved point

CALL FUNCTION gv_fm in ZWM_PICK_LABEL: the function name is computed at run time. Listed in Coverage, never guessed.

CODE:zwm_pick_label.abap:32

Absence statements say what stays invisible

A sentence such as “no code updates this table” is written only after checking, and it always states what the check cannot see.

Checked first

  • database statements
  • where-used rows
  • names in the source

What stays invisible, for example

  • dynamic names
  • code outside the export
  • SAP standard code
  • a stale where-used index

The evidence graph, drawn

From a transaction to the table it writes, every hop cited.

  1. TCODEZWM_LABELPrint picking labels

    STARTSEXPORT:cg_transactions.tsv:15

  2. PROGZWM_PICK_LABEL

    CALLS, IN UPDATE TASKCODE:zwm_pick_label.abap:40

    Unresolved point

    CALL FUNCTION gv_fm: the function name is computed at run time. Listed in Coverage, never guessed.

    CODE:zwm_pick_label.abap:32

  3. FMZSD_ORDER_STATUS_UPDATE

    WRITESGRAPH:WRITESCODE:lzsd_orderu04.abap:8

  4. TABLEZSD_ORDER_LOG
CODE:lzsd_orderu04.abap:8checked

Lines 8 to 10 of include LZSD_ORDERU04

8UPDATE zsd_order_log  SET status = iv_status9      aedat = sy-datum10  WHERE vbeln = iv_vbeln.

LZSD_ORDERU04 updates ZSD_ORDER_LOG

GRAPH:WRITESSCHEMA:DDIC:ZSD_ORDER_LOG

A slice of the evidence graph of a synthetic demo system. Every solid line is a recorded relationship; the dashed line marks an unresolved point, listed rather than recorded. One path is lit.lit pathunresolved point (CALL FUNCTION gv_fm): listed, never guessed

03Verification

Every relationship and every citation is checked again.

Two checks run on what was built, and there is no AI in this step. The web app shows the citation check next to each citation.

Every relationship

Graph verifier

Replays every relationship against its cited source line or exported row.

Every tag

Citation auditor

Re-checks every tag on every catalogue page. It is a deterministic script, not an AI.

Next to each citation

In the web app

The app shows the result of the check next to each citation: checked, or a warning.

Every factual line carries a citation

Five tags and one marker, each with one meaning.

CODE
The exact line of your ABAP or CDS source, numbered as in the ABAP editor (SE80).
GRAPH
A recorded relationship in the evidence graph, for example this program reads that table. It is always paired with the code line or exported row it came from.
SCHEMA
The ABAP Dictionary definition: a table, field, data element, domain or message.
EXPORT
A specific row of an exported file: configuration, the SAP where-used index, the transaction or job list, or the object and package inventory.
INFERRED
A deduction or a stated limit, clearly marked as not evidence.
SME-REVIEW-REQUIRED
A question for your subject-matter expert when evidence is insufficient. It is never filled in by guessing.
Source of include LZSD_ORDERU01, numbered as in SE80, with cited lines marked and line 55, INSERT zsd_order_log FROM ls_log., highlighted.
Source drawer. In the web app, a citation opens the source at its line, so a reader can check it too. Screens from a synthetic demo system. Full size

Stated limit: Re-verification proves that each citation points to real evidence that matches it. It does not prove that a business interpretation is correct. That is why Validation Packages end with sign-off by your subject-matter expert.

04Pilot figures

The pilot, in figures.

Automated analysis of a productive SAP S/4HANA system.Note 1 The notes under the figures say what each one covers, and what it does not.

313,202

lines of ABAP analyzed

2,387

custom objects inventoriedNote 2

13,480

relationships with verified evidenceNote 3

0

failures when re-verifying each relationshipNote 4

1 day

from export to documentationNote 5

Where the 13,480 relationships come from

12,739from a line of ABAP / CDS codecited as CODE
535from an exported configuration rowcited as EXPORT
206from the SAP where-used indexcited as EXPORT
13,480relationships, 0 failures

Plus: 14,571 ABAP Dictionary facts (tables and fields).

Code and configuration, connected

  • 84 payment methods
  • 55 payment formats
  • 7 DMEE trees
  • 19 implemented BAdIs
  • 9 CMOD projects
  • 4 IDoc message types
  • 327 BAPI calls
  • 83 maintenance dialogs
  • 4,867 SAP modification log entries

05What it produces

Four things built from the same evidence.

The catalogue and the process map are generated without AI. Validation Packages and Ask AI use AI, only with your recorded authorization. The roles that write and review Validation Packages run on Anthropic Claude or on OpenAI; the verified Spanish translations of Validation Packages, and Ask AI, use OpenAI.

  • Built without AI

    A cited catalogue, one page per object

    • Module, dictionary and index pages (transactions, jobs, entry points, enhancements and exits, configuration, SAP modifications, interfaces and SAP dependencies), an object inventory and a coverage register.
    • Every factual line is cited. It states what the code and the configuration do and where, never business purpose.
    • Plain Markdown pages with wiki-links, which can also be built as a static website for offline reading. Ask us whether the files are part of your engagement.
  • Built without AI

    A process map, proposed from the evidence

    • A deterministic algorithm groups the custom code into business processes. Every hand-written object belongs to exactly one process.
    • Each process is anchored on what starts it (transactions, jobs, configuration, SAP callers) and ranked into tiers A, B and C.
    • Names come from texts recorded in SAP. The grouping is a proposal, not a statement of business purpose.
  • AI, with your recorded approval

    Validation Packages your experts sign off

    • One business domain or process end to end, in eight fixed sections, from the overview to the validation checklist.
    • Three automated gates run before an expert sees it, and the runner cannot skip or waive a gate.
    • Your subject-matter expert confirms the points marked SME-REVIEW-REQUIRED and signs off, which publishes the document.
    1. Documentation Validator
    2. Validation Triad
    3. Citation Auditor
    4. Expert sign-off
  • AI, off by default

    Ask AI, answered with numbered evidence

    • Questions in plain language, in any language. The answer comes in English or Spanish.
    • Ask AI cites numbered evidence and cannot add evidence of its own. Each item is re-checked by the citation auditor and linked to its source line.
    • An answer with no evidence is labeled “unverified”. Ask AI stays off until your authorization is recorded.

    Answers are generated and may be incomplete; the linked code is the reference.

    The app says so too.

06Refresh

After each release, run the export again.

There is no live connection to SAP. A refresh is a new export, built and verified separately before it goes live.

  1. Run the export again.

    After a release, you run the same read-only report and hand over the new archive.

  2. Rebuilt and re-audited.

    The graph, the catalogue and the process map are regenerated, and every citation is re-audited. The new version is built and verified separately, in both languages.

  3. Switched over, with a way back.

    The previous version is archived and can be rolled back. User accounts, approvals and Validation Packages are kept across refreshes.

Stated limit: Validation Packages are not rewritten automatically. A Validation Package that is regenerated must pass the gates again.

The subscription covers this: refresh after every release, AI included, plus support.

How to start

07The CodeGraph method

One method, applied to SAP.

CodeGraphAI for SAP is built on CodeGraph, a technology-agnostic method for evidence-based documentation of software systems.

The five phasesMethod

  1. Source ingestion. The evidence graph, with the evidence recorded on every relationship.

  2. Domain documentation. Validation Packages with three gates: Documentation Validator, Validation Triad (Defender, Challenger and Judge) and Citation Auditor.

  3. Reference layer. For SAP, the cited catalogue: one page per object, generated without AI.

  4. Process discovery. For SAP, the process map: custom code grouped into business processes, without AI.

  5. Vault assembly. For SAP, the catalogue assembled as plain Markdown pages with wiki-links, which can also be built as a static website.

Its core practices

  • Evidence is recorded when each relationship is created.
  • The graph is queried through fixed templates.
  • The parts that write documentation are kept separate from the parts that check it.
  • Gaps are stated honestly, as SME-REVIEW-REQUIRED questions for your expert.

Method: “CodeGraph” on its own names only the method. The product is CodeGraphAI for SAP.

What the method needs, and what it is for SAP
The method needsFor SAP
A source export with stable line numbersThe read-only report, which keeps SE80 numbering
A parser or extractor for the language, emitting objects and relationships with source, file, line and confidenceAn ABAP extractor plus a graph builder
Schema definitions of the databaseThe ABAP Dictionary
Optionally, a compiler cross-reference for the most reliable relationshipsThe SAP where-used index
The configuration or wiring that starts codeTransactions, jobs, IDoc, payment, BAdI and CMOD
A graph store, a deterministic cited catalogue generator, a graph verifier and a citation auditorThe evidence graph, the catalogue, the verifier and the auditor described on this page
AI roles with gates for the business documents, plus human expert reviewValidation Packages and sign-off by your subject-matter expert

Beyond SAP. Today SAP is the method’s only implementation. Have another technology? The same method applies to any codebase once a parser for its language is built.

A guided demo with our team: the web app, the evidence graph and a cited catalogue page.