<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BMC Software | Blogs</title>
	<atom:link href="https://blogs.bmc.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://s7280.pcdn.co</link>
	<description></description>
	<lastBuildDate>Thu, 16 Jul 2026 15:42:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://s7280.pcdn.co/wp-content/uploads/2016/04/bmc_favicon-300x300-36x36.png</url>
	<title>BMC Software | Blogs</title>
	<link>https://s7280.pcdn.co</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Agentic Orchestration in the Enterprise: What It Is and How It Relates to Workload Automation</title>
		<link>https://s7280.pcdn.co/agentic-orchestration-vs-workload-automation-enterprise/</link>
		
		<dc:creator><![CDATA[BMC Software]]></dc:creator>
		<pubDate>Thu, 16 Jul 2026 12:09:45 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55974</guid>

					<description><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-1024x512.png" class="attachment-large size-large wp-post-image" alt="AIOps Innovation Man Tablet Data" decoding="async" fetchpriority="high" srcset="https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-1024x512.png 1024w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-300x150.png 300w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-768x384.png 768w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-810x405.png 810w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-1140x570.png 1140w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-24x12.png 24w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-36x18.png 36w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-48x24.png 48w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700.png 1400w" sizes="(max-width: 810px) 100vw, 810px" />AI agents are entering production environments — taking actions, making decisions, coordinating with humans and automated systems in ways that didn’t exist two years ago. The question for enterprises is how the autonomous work these agents do fits into the execution discipline that already runs the business. Agentic orchestration is the answer many enterprises are […]]]></description>
										<content:encoded><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-1024x512.png" class="attachment-large size-large wp-post-image" alt="AIOps Innovation Man Tablet Data" decoding="async" srcset="https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-1024x512.png 1024w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-300x150.png 300w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-768x384.png 768w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-810x405.png 810w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-1140x570.png 1140w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-24x12.png 24w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-36x18.png 36w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700-48x24.png 48w, https://s7280.pcdn.co/wp-content/uploads/2023/01/AIOps-Innovation-Man-Tablet-Data_1400x700.png 1400w" sizes="(max-width: 810px) 100vw, 810px" /><p>AI agents are entering production environments — taking actions, making decisions, coordinating with humans and automated systems in ways that didn’t exist two years ago. The question for enterprises is how the autonomous work these agents do fits into the execution discipline that already runs the business. Agentic orchestration is the answer many enterprises are moving toward: a coordination layer that governs how autonomous agents operate within business processes, alongside the automated systems and human operators those processes already involve.</p>
<h2>What is agentic orchestration?</h2>
<p>Agentic orchestration is the coordination of AI agents, automated systems, and human reviewers within governed business processes. Unlike traditional workload automation, which executes predefined sequences of tasks, <a href="/content/bmc/language-masters/en/it-solutions/agentic-orchestration.html">agentic orchestration</a> coordinates work that combines rules-based execution with the judgment of AI agents, with consistent policy enforcement and visibility across both.</p>
<p>The orchestration layer doesn’t dictate every step. It provides the goals, defines what agents are allowed and not allowed to do, and gives them the tools and information they need to do their work. But it’s the agents themselves that figure out how to reach the goal within those limits. The result is a system where individual agents have room to make judgments — but the rules they operate under, the visibility into what they’re doing, and the accountability for what results stay under enterprise control. This combination is what makes agentic systems durable enough for production environments, where business workflows have to run reliably, prove auditable, and meet enterprise standards.</p>
<p>Most enterprises don’t introduce agentic orchestration as a replacement for what they already run. They add it to the orchestration layer they’ve been using for workload automation across applications, data pipelines, and cloud services — extending that layer to govern AI agents alongside the work it already coordinates.</p>
<h2>How does agentic orchestration work?</h2>
<p>Agentic orchestration begins with a defined goal — process a support ticket, execute a financial close, investigate a security alert — and a set of agents, automated systems, and human reviewers available to do the work. Different agents typically take different roles: A triage agent might categorize an incoming request; a research agent might pull information from internal systems or external sources; an executor agent might call an API to take a specific action. Each agent uses a defined set of tools that the orchestration layer makes available to it. The orchestration layer routes work to the right agent, gives the agent the context it needs, and tracks the state of the overall effort.</p>
<p>When an agent receives a piece of the work — investigate this anomaly, resolve this ticket — it typically breaks down the goal into a sequence of steps and works through them, adjusting the plan as it encounters new information or unexpected conditions along the way. The agent retains what’s happened across those steps — what it’s tried, what’s worked, what data it’s gathered — so that each action builds on what came before rather than starting from scratch. In more complex processes, agents also collaborate directly: one agent may delegate a subtask to another with the right specialization, or multiple agents may work different parts of a problem in parallel. The orchestration layer manages these interactions, tracking which agent is responsible for what and ensuring the overall process stays coherent as work moves among them.</p>
<p>When one stage of work is complete, the next stage usually involves a handoff — to another agent, to an automated system, or to a human for review or approval. The orchestration layer manages these transitions, carrying the relevant context forward, enforcing the policies that apply to the work in question, and recording every decision, tool call, and outcome at each step.</p>
<p>Some systems use this history to refine agent behavior over time. But whether or not learning is in scope, the audit trail is the foundation for accountability — it’s what makes governed autonomy possible at the scale production requires.</p>
<h2>How does agentic orchestration relate to AI orchestration and AI agents?</h2>
<p>Agentic orchestration is sometimes confused with related concepts. Here are the two distinctions that matter most.</p>
<h2>How does agentic orchestration differ from AI orchestration?</h2>
<p>AI orchestration is sometimes used as a catch-all term, but in practice it usually refers to something specific: coordinating the steps required to run AI models. A typical example is a fraud-detection system: A transaction comes in, the system enriches it with relevant history, and then an AI model scores the transaction for risk and a second model checks the customer’s recent behavior. The two scores get combined into a single assessment, and the result is sent to a downstream system. AI orchestration is what choreographs that sequence — what runs when, what data flows where, what triggers each model. The platforms that do this are built around the lifecycle of the AI models themselves: when they’re invoked, how their inputs and outputs connect to surrounding systems, and how their performance is tracked.</p>
<p>Agentic orchestration coordinates something different. The actors aren’t models running predefined steps, they’re autonomous agents pursuing goals — making judgments, choosing actions, working alongside automated systems and human reviewers inside a business process. Where AI orchestration manages a sequence of model calls, agentic orchestration coordinates and governs the actors themselves — agents whose paths aren’t fully defined in advance, because some of what they do gets decided as they go.</p>
<p>The two often coexist. The fraud-detection pipeline might be coordinated by AI orchestration, while the agent that detects a fraud pattern and initiates an investigation — pulling case history, contacting the customer, escalating to a human reviewer — operates within agentic orchestration. Both layers may run inside the same enterprise control plane, but they’re solving different problems: how an AI model should run as part of a larger flow of work, versus how autonomous agents should be governed as they do their work.</p>
<p>How does agentic orchestration relate to individual AI agents<strong>? </strong></p>
<p>An AI agent is an autonomous actor — typically a large language model connected to a set of tools, given a defined goal to pursue, and able to take actions in the world to make progress toward that goal. Agents perceive their situation, decide what to do, and act through the tools they’ve been given. Each agent is typically specialized — built for a defined scope of work, with a defined set of tools, and a defined role within a larger process.</p>
<p>Agentic orchestration is the layer above the agents, managing the system the agents operate inside. The orchestration layer provides the goal to be achieved, allocates tasks among the available agents, determines which tools each agent can use, enforces the policies the work has to follow, manages handoffs between agents and other systems, and keeps track of what’s happened so the work stays coherent as it moves from step to step. It also records actions and decisions for visibility and accountability.</p>
<p>A single agent can complete a task. Multiple agents can complete related tasks in sequence or in parallel. Agentic orchestration is what coordinates those tasks — and the agents performing them — into a coherent, governed business process. It’s the layer that helps ensure the work as a whole completes reliably, transparently, and within the limits the enterprise has set.</p>
<h2>How does agentic orchestration relate to traditional workload automation?</h2>
<p>Agentic orchestration is best understood as an extension of the decades-old practice of workload automation — the next stage in the evolution of enterprise execution control.</p>
<h2>The lineage from batch workload automation to agentic orchestration</h2>
<p>That evolution has a recognizable shape. Enterprise execution began as batch workload automation — scheduled jobs running on predictable cycles, with dependencies managed across multiple systems. It expanded into application and <a href="/content/bmc/language-masters/en/it-solutions/data-pipeline-orchestration.html">data pipeline orchestration</a>, coordinating workflows across the mix of systems most enterprises now run, including on-premises servers and multiple cloud environments. It grew to handle event-driven systems and cloud-native services, where work was triggered by signals rather than schedules. More recently, it has come to cover AI-powered workflows — where machine-learning models and AI-driven automation participate in business processes alongside everything else. Agentic orchestration is the next step: extending the execution layer to also coordinate autonomous agents that reason, plan, and act within the same business processes.</p>
<p>What carries forward is not just terminology but specific practices. The capabilities that mature workload automation platforms have developed over decades — dependency management across heterogeneous systems, SLA enforcement, retry and recovery logic, audit traceability, exception handling, observability across long-running workflows — are exactly the capabilities agent-driven workflows require to run reliably in production. The disciplines that make a financial close reliable when it consists of <a href="/content/bmc/language-masters/en/it-solutions/job-scheduling.html">scheduled batch jobs</a> are the same disciplines that make it reliable when it consists of a mix of scheduled jobs and AI-driven exception handling. The underlying execution layer doesn’t need to be rebuilt for agentic workflows; it needs to be extended to them.</p>
<h2>What changes with agent-driven execution</h2>
<p>What is genuinely new is the kind of work being coordinated. Traditional workload automation governs largely deterministic execution: predefined steps that follow defined rules and produce predictable outcomes. In general, the same job, run with the same inputs under the same conditions, should produce the same result. Agentic systems introduce non-deterministic execution: agents make judgments based on context, and similar situations can lead to different actions depending on the conditions the agent observes. Agents also introduce challenges that have no direct workload-automation precedent: the quality of the plans agents construct, the reliability of the reasoning behind their decisions, and the management of the memory and awareness that they carry across steps all require forms of oversight that traditional execution platforms were never designed to provide. Many production business processes now combine both. A financial close has dozens of deterministic steps (data extraction, scheduled reporting, file transfers) and a growing number of non-deterministic ones (anomaly investigation, AI-assisted exception handling, reprioritization when something upstream is late). Supply chain operations, customer service workflows, and IT remediation increasingly look the same way.</p>
<p>Mixed-execution processes are why agentic orchestration is best understood as an extension of the existing execution layer rather than as a separate AI-specific one. When agent-driven work is governed in one place and the deterministic work it coordinates with is governed somewhere else, the business process as a whole can end up with fragmented governance. Even if both systems enforced similar policies, the process crossing between them would have two separate audit trails to reconcile, two separate observability surfaces to integrate, and two separate state-management systems to keep in sync.</p>
<p>Coherent enterprise execution requires consistent governance across the whole process, for both operational and architectural reasons. A consistent governance layer reduces the cost of keeping connected systems in sync, helps policy changes propagate predictably, and produces a more coherent audit trail when the result has to be explained to an auditor, a regulator, a board, or an internal investigator.</p>
<h2>How is agentic orchestration governed at enterprise scale?</h2>
<p>Governance is what makes agentic orchestration different from agent experimentation. An AI agent operating in isolation can be unreliable in ways that are tolerable for a prototype; an agent operating inside a business process has to meet the same standards of reliability, accountability, and auditability as anything else running in production. Governance in this context isn’t a single capability. It’s a set of practices that together make autonomous execution safe enough to scale.</p>
<p>Five capabilities form the practical core:</p>
<p><strong>Dependency control:</strong> Agent-driven work, like every other kind of enterprise work, has dependencies — on data being available, on upstream processes completing, on downstream systems being ready to receive results. The orchestration layer manages these dependencies across both deterministic and agent-driven steps, ensuring that an agent doesn’t act on stale data, that a downstream system isn’t asked to process incomplete inputs, and that the sequence of work — wherever the rules permit flexibility — still completes in a coherent order.</p>
<p><strong>Policy enforcement:</strong> Every agent operates within defined constraints: what data it can access, what actions it can take, what thresholds require human review, what kinds of decisions it can make autonomously and which it must escalate. These policies are defined when agents are authored and enforced at runtime, not left to be implemented inconsistently by individual agents or development teams. Policy enforcement is what allows the enterprise to extend autonomy to agents without ceding control over what they do with it.</p>
<p><strong>Observability:</strong> Production-grade agentic orchestration requires visibility into what’s happening across the full process — agent work and deterministic work alike. For agent work, that means tracking not just whether an agent completed its task but what actions it took, what tools it called, what AI model invocations it made, what data it accessed, and what outcomes resulted. For deterministic work, the requirements are the ones workload automation has long handled: job completion, dependency resolution, SLA performance, exception handling. Across mixed-execution processes, the orchestration layer has to bring these two kinds of observability together, because the signals each generates are different and the operations teams running the process need a single coherent view. The orchestration layer integrates those signals so operations teams can see the whole process at once, not just its individual parts.</p>
<p><strong>Exception handling:</strong> Real business processes encounter conditions their designers didn’t anticipate — data that’s late, systems that are unavailable, situations that fall outside an agent’s defined scope. Exception handling in agentic orchestration combines retry and recovery logic familiar from workload automation with judgment-driven response from agents themselves, governed by clear escalation paths to human reviewers when the situation requires it. The result is a process that can absorb variability without losing its coherence.</p>
<p><strong>Auditability:</strong> Every action taken by every agent — and every decision the orchestration layer makes about how to coordinate that action — is recorded with the context required to reconstruct what happened and why. Auditability is what makes governed autonomy demonstrable to regulators, auditors, and internal stakeholders. It’s also what makes systematic improvement possible: the <a href="/content/bmc/language-masters/en/it-solutions/audit-trail-lineage.html">audit trail</a> is the data from which patterns of agent behavior, process performance, and recurring exceptions can be understood and addressed.</p>
<p>These five capabilities have to operate consistently across both deterministic and agent-driven execution — and across the points where the two interact. Coherent governance has to span the boundary between the two, not just hold on either side.</p>
<h2>What are the core components of an agentic orchestration system?</h2>
<p>A working agentic orchestration system typically combines several components, each with a defined role. The specifics vary by platform, but the underlying architecture is increasingly consistent across mature implementations.</p>
<p><strong>Agents:</strong> The autonomous actors that perform individual units of work. Each agent has a defined scope — what kinds of tasks it handles, what tools it uses, what models it relies on, what decisions it can make on its own. Specialization is the norm; a system might include a triage agent, a research agent, an investigation agent, and an executor agent, each tuned for the work it’s meant to do.</p>
<p><strong>Planning and reasoning:</strong> The capability that allows an agent to break down a goal into steps, decide what to do next based on what it knows, and adjust its approach as conditions change. Planning and reasoning are what distinguish an agent from a script — they’re what make it possible for the agent to pursue a goal rather than just execute a sequence.</p>
<p><strong>Multi-agent coordination and delegation:</strong> The mechanisms by which work gets allocated and handed off among agents within a process. One agent may delegate a subtask to another agent with the right specialization, or multiple agents may work different parts of a problem in parallel. This is distinct from the control plane’s broader routing role — it’s the coordination among agents themselves, within the structure the control plane provides.</p>
<p><strong>Control plane:</strong> The layer that routes work across the system, manages state (what’s happened so far, where each piece of work currently sits, what context needs to be carried forward), enforces policies, and coordinates handoffs between agents, automated systems, and human reviewers. This is the orchestration layer proper. It’s where the rules of engagement are enforced and where the audit trail is generated.</p>
<p><strong>Tool registry:</strong> The central reference that defines what tools are available to which agents, with the appropriate access controls. Agents can access enterprise systems, APIs, data sources, and other resources through this registry, rather than through direct integrations that have to be configured for each agent. The registry is what makes governance manageable at scale: changes to access policies, new tools, or revoked permissions propagate consistently across the system rather than having to be applied agent by agent. The Model Context Protocol (MCP) — now backed by major AI vendors and governed by the Linux Foundation — enables agents to discover and connect to tools across systems, giving the registry a common interface rather than requiring custom integrations for each tool an agent needs to use.</p>
<p><strong>Shared state and memory:</strong> The context preserved across the multiple steps that make up a coordinated process. An agent that takes the second action in a sequence needs to know what happened in the first; a downstream reviewer needs to see what the agent has already done. Shared state is what makes coordination across agents possible at all.</p>
<p><strong>Human-in-the-loop mechanisms:</strong> Defined points at which humans participate in agent-driven processes — for review, for approval of consequential decisions, for handling exceptions the system can’t resolve on its own. These mechanisms aren’t a fallback for failure; they’re a structural component of the system, designed in from the start.</p>
<p><strong>Audit and observability layer:</strong> The layer that captures the actions, decisions, and outcomes of every agent and every coordination event, in a form that’s query-able and retainable for compliance and operational analysis.</p>
<p>Together, these components form a system that can coordinate agent-driven work alongside everything else an enterprise runs, under coherent governance, with the visibility production requires.</p>
<h2>What are common enterprise use cases?</h2>
<p>Enterprise work increasingly combines deterministic, rules-based execution with adaptive, judgment-driven response. Below are three common examples — processes where <a href="/content/bmc/language-masters/en/it-solutions/ai-governance-for-production-ai-workflows.html">governance</a> has to span the boundary between scheduled work and AI-driven response.</p>
<p><strong>Financial close and reconciliation:</strong> A <a href="/content/bmc/language-masters/en/it-solutions/finance-automation/financial-close.html">financial close</a> consists of dozens of scheduled, rules-based steps — data extractions, reconciliations, validation routines, reports. It also requires judgment when something doesn’t reconcile, when an anomaly appears, when an exception has to be investigated and resolved before the close can complete. Agentic orchestration coordinates AI agents that handle the exception-investigation work alongside the scheduled jobs that handle the predictable work, with full auditability across both.</p>
<p><strong>Supply chain and operational continuity:</strong> <a href="/content/bmc/language-masters/en/it-solutions/supply-chain-orchestration.html">Supply chain operations </a>depend on scheduled coordination across procurement, inventory, logistics, and fulfillment systems. They also depend on adaptive response when something goes wrong — a delayed shipment, an inventory shortage, a routing change that affects downstream commitments. Agentic orchestration handles the coordination across the systems agents need to work with and gives agents the latitude to assess disruption signals, propose responses, and coordinate adjustments across the affected systems, all within policy boundaries set by the operations team.</p>
<p><strong>IT operations and incident response:</strong> Modern IT environments combine deterministic automation (scheduled maintenance, automated patching, defined remediation playbooks) with situations that require judgment (incident triage, anomaly investigation, novel failure modes). Agentic orchestration coordinates AI-driven triage and investigation with the deterministic remediation playbooks already in place, escalating to human operators when the system reaches the limits of what it can resolve on its own. The result is faster response without loss of operational control.</p>
<h2>What challenges does agentic orchestration introduce?</h2>
<p>The challenges enterprises encounter when adopting agentic orchestration tend to be as structural as they are technological. They’re not only about whether the technology works; they’re about whether the organization has the architecture and discipline to deploy it responsibly.</p>
<p><strong>Multi-agent coordination:</strong> Coordinating multiple agents across a complex process is harder than coordinating a single agent. Keeping track of what’s happened across multiple agents working in parallel gets more involved. Handoffs have to be defined clearly. The temptation to let agents communicate freely with each other has to be balanced against the need for the orchestration layer to maintain coherent visibility into what’s happening.</p>
<p><strong>Observability across mixed execution:</strong> Producing a single coherent view across deterministic and agent-driven work requires the orchestration layer to make sense of two very different kinds of operational data: the predictable status updates that scheduled jobs generate, and the more varied signals that agent-driven work produces. Operations teams used to monitoring scheduled jobs have to extend their mental model to include those new signals — confidence levels, alternative paths the agent considered, decisions the agent escalated for human review.</p>
<p><strong>Integration with existing systems:</strong> Agents typically need access to enterprise data and tools that were designed for human users or for system-to-system automation, not for autonomous agents. Integrating agents into existing environments — without bypassing the governance those environments enforce — requires careful work, particularly around identity, access control, and audit logging.</p>
<p><strong>Operational discipline:</strong> The biggest challenge is often cultural. Operations teams used to deterministic systems sometimes treat agent-driven work as inherently less trustworthy, and either over-constrain it (eliminating the value of autonomy) or under-constrain it (creating governance gaps). Building the right practices for mixed-execution processes is mostly a matter of clear policy and experience — but it takes time, and it benefits from platforms that make those practices easier to enforce.</p>
<p>None of these challenges is unique to agentic orchestration as a category; they’re variants of challenges that enterprise execution has always involved. What’s new is the need to apply them to a kind of work that wasn’t prevalent in production environments a few years ago.</p>
<p>Control-M, BMC’s enterprise orchestration platform, the <a href="/content/bmc/language-masters/en/it-solutions/job-scheduling-workload-automation.html">workload automation</a> and <a href="/content/bmc/language-masters/en/it-solutions/workflow-orchestration.html">workflow orchestration</a> disciplines it has run for decades to coordinating agentic execution in enterprise environments. It holds agents to</p>
<p>In BMC’s view, the future of orchestration is not about AI agents or any other new technology. It’s about orchestrating the work — all the work, of agents, applications, data pipelines, and people — under coherent governance and through a single execution layer.</p>
<p>More on Control-M’s agentic orchestration capabilities is available <a href="/content/bmc/language-masters/en/it-solutions/agentic-orchestration.html">here</a>.</p>
<p>Control-M is named a Leader in the 2025 Gartner<sup>® </sup>Magic Quadrant™ for Service Orchestration and Automation Platforms. Eighty percent of the Forbes Global 100 — across financial services, manufacturing, healthcare, retail, telecommunications, and the public sector — use BMC to coordinate the systems their businesses depend on.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Turning Innovation into Trusted Action with Control-M</title>
		<link>https://blogs.bmc.com/turning-innovation-into-trusted-action-with-control-m/</link>
		
		<dc:creator><![CDATA[April Hickel]]></dc:creator>
		<pubDate>Tue, 14 Jul 2026 09:58:04 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55967</guid>

					<description><![CDATA[<img width="810" height="463" src="https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1.png 810w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-768x439.png 768w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-48x27.png 48w" sizes="(max-width: 810px) 100vw, 810px" />Enterprise technology is moving quickly, but our customers are focused on a very practical question: how do we put new capabilities to work in ways the business can trust?  That question is at the center of our July Control-M release. But more broadly, it reflects a shift we are seeing across the market. Increasingly, enterprises are realizing […]]]></description>
										<content:encoded><![CDATA[<img width="810" height="463" src="https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1.png 810w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-768x439.png 768w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/07/Blog-Image-4-Turning-Innovation-1-48x27.png 48w" sizes="auto, (max-width: 810px) 100vw, 810px" /><p><span data-contrast="auto">Enterprise technology is moving quickly, but our customers are focused on a very practical question: how do we put new capabilities to work in ways the business can trust?</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">That question is at the center of our July Control-M release. But more broadly, it reflects a shift we are seeing across the market. Increasingly, enterprises are realizing that innovation alone is not enough. What matters is how consistently and reliably that innovation is executed. This is why orchestration is becoming the control plane for modern enterprise operations.</span><span data-ccp-props="{}"> </span></p>
<h2>Helping customers put innovation to work</h2>
<p><span data-contrast="auto">The new Control-M release reflects the operational realities our customers are navigating every day. As AI, automation, and cloud services become more central to business execution, teams need orchestration that helps them move new capabilities into production with more confidence and less complexity.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">That starts with practical AI: capabilities that help teams plan workflows faster, monitor with more insight, and get answers without chasing them across tools. It also means strengthening the governance and usability that make those capabilities dependable in daily operations.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">On the governance side, enhanced change management and ITSM interoperability bring workflow changes into the governed processes that the rest of the enterprise already depends on. As automation expands, governance has to expand with it.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<h2>Turning innovation into trusted action</h2>
<p><span data-contrast="auto">Several updates in this release bring that idea to life. They make AI more useful inside day-to-day operations, give agents a governed way to interact with enterprise workflows, expand the technologies Control-M can orchestrate, and strengthen the visibility and history teams rely on when they need to understand what happened and why.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">A key example is the </span><a href="/it-solutions/agentic-orchestration.html">Control-M MCP Server</a><span data-contrast="auto">. MCP, the Model Context Protocol, is becoming an important way for AI agents to connect with enterprise systems. With Control-M MCP Server, agents have a governed path into Control-M: a way to trigger workflows, check status, and investigate issues without bypassing the security, auditability, and policy controls customers already trust us to enforce. That is what matters as AI moves from experimentation into business-critical operations.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">Innovation also must connect to the systems where work happens. In this release, we are continuing to expand Control-M&#8217;s reach across AI, data, cloud, and enterprise applications, including </span><a href="/it-solutions/control-m-integrations.html#&amp;sortCriteria=recommended&amp;category=mp"><span data-contrast="none">integrations</span></a><span data-contrast="auto"> with </span><b><span data-contrast="auto">Azure AI Foundry, Dataiku, AWS RDS, Oracle Data Transform, SAP CPI, Azure VMSS</span></b><span data-contrast="auto">, and more on the way. Every new integration helps reduce custom scripting and speed up onboarding of new technologies, bringing more of the environment into a single orchestration framework. Without that layer, teams are left stitching together scripts and point solutions that make execution harder to scale, govern, and trust.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">Once that work is in motion, trusted action depends on history, visibility, and accountability. That is why we are extending </span><b><span data-contrast="auto">Control-M Archive Service to Control-M self-hosted customers</span></b><span data-contrast="auto">. </span><a href="/documents/datasheets/control-m-archive-service.html"><span data-contrast="none">Archive Service</span></a><span data-contrast="auto"> gives teams a managed, more secure way to retain workflow history for audit, compliance, troubleshooting, and operational investigation. We are also introducing a refreshed user experience for Archive Service, making historical data faster to search, easier to navigate, and more useful when teams need answers quickly.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><b><span data-contrast="auto">Bringing innovation into real operations</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Taken together, practical AI, governed agent access, broader integrations, and extended Archive Service support all point in the same direction: helping customers bring new innovation into real operations with the trust, visibility, and control their businesses depend on.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">For Control-M, that means continuing to make orchestration smarter, better governed, more connected, and easier to use across the environments customers choose to run, so they can adopt what is next with confidence.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">As enterprises accelerate adoption of AI, automation, and cloud, the question is no longer what to adopt but how to run it reliably at scale. Control-M continues to evolve as the orchestration layer that turns innovation into trusted, business-ready execution, so organizations can move forward with confidence.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:300}"> </span></p>
<p><span data-teams="true">To learn more about the latest release, join our webinar, &#8220;<strong><a href="/webinars/control-m-smarter-orchestration-and-workflow-archiving.html">What’s New in Control‑M: Smarter Orchestration and a New Approach to Workflow Archiving.</a>&#8220;</strong></span></p>
<p><em>“While the announcement introduces a broad set of AI-powered capabilities, including workflow creation, operational copilots, self-hosted AI support, and Model Context Protocol (MCP) integration, the more important story is BMC&#8217;s continued investment in Control-M as an orchestration control plane capable of coordinating deterministic automation, event-driven workflows, data pipelines, and emerging AI agents under a common governance framework.” – <strong>Dan Twing, President and COO, Enterprise Management Associates (EMA)</strong></em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Don’t Let “Inherent Mainframe Security” Make You Complacent About Mythos</title>
		<link>https://blogs.bmc.com/mainframe-security-claude-mythos/</link>
		
		<dc:creator><![CDATA[Matt Whitbourne]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 11:06:52 +0000</pubDate>
				<category><![CDATA[Security & Compliance Blog]]></category>
		<category><![CDATA[Mainframe Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55957</guid>

					<description><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png.png 700w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" />Anthropic’s Claude Mythos has put mainframe security teams on notice. As a frontier AI model capable of autonomously identifying and chaining vulnerabilities at machine speed, Mythos represents a new class of risk for z/OS environments, dramatically accelerating the ability of adversaries to exploit any weakness present in the environment. While Mythos is the most visible […]]]></description>
										<content:encoded><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png.png 700w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/06/SecurityThreatDirector700x400.png-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" /><p>Anthropic’s Claude Mythos has put mainframe security teams on notice. As a frontier AI model capable of autonomously identifying and chaining vulnerabilities at machine speed, Mythos represents a new class of risk for z/OS environments, dramatically accelerating the ability of adversaries to exploit any weakness present in the environment. While Mythos is the most visible example today, it represents a broader trend toward increasingly capable AI systems that are transforming vulnerability discovery and exploitation across the enterprise.  Traditional assumptions about the inherent security of the mainframe overlook operational risks such as misconfigurations, expired certificates, unmonitored privileged sessions, and delayed threat detection. To be Mythos-ready, organizations need to take active, end-to-end measures to reduce their attack surface and detect threats in real time.</p>
<p><strong>Why Claude Mythos poses a threat to the enterprise</strong></p>
<p>By acting as an autonomous agent capable of independent, multi-step actions, Mythos can identify and link multiple security flaws into a <a href="https://www.isaca.org/resources/news-and-trends/industry-news/2026/claude-mythos-is-redefining-the-cyberthreat-landscape" target="_blank" rel="noopener">programmatic chain of exploitation</a>. As a result, time-to-exploit can collapse from weeks or months to hours or days, making vulnerability discovery and exploitation effectively simultaneous. These capabilities lower technical barriers and enable motivated actors with modest resources to perform multi-step exploitation that historically required elite specialists. Mythos has already found <a href="https://www.bbc.com/news/articles/crk1py1jgzko" target="_blank" rel="noopener">thousands of high-severity vulnerabilities</a> across major operating systems and web browsers, including one vulnerability that had been present in a system for 27 years.</p>
<p>Global leaders are taking this threat seriously. Canadian Finance Minister François-Philippe Champagne described Mythos as an <a href="https://www.bbc.com/news/articles/crk1py1jgzko" target="_blank" rel="noopener">“unknown unknown”</a> that warrants the attention of all finance ministers. Bank of England Governor Andrew Bailey has said his institution is carefully examining what it means for the <a href="https://www.bbc.com/news/articles/crk1py1jgzko" target="_blank" rel="noopener">risk of cybercrime</a>.</p>
<p><strong>Project Glasswing is a temporary measure at best</strong></p>
<p>Formed in response to the risk of Mythos weaponization, <a href="https://www.bbc.com/news/articles/crk1py1jgzko" target="_blank" rel="noopener">Project Glasswing</a> is a narrow, defensive consortium led by Anthropic with more than 50 member organizations. The group’s intention is to use Mythos to find and patch vulnerabilities in critical software while the model remains withheld from general availability. While Project Glasswing aims to give security teams time to reorganize their defenses, this window <a href="https://www.securityweek.com/mythos-ready-security-csa-urges-cisos-to-prepare-for-accelerated-ai-threats/" target="_blank" rel="noopener">won’t hold forever</a>, and its partners may not be able to fix all vulnerabilities in time.</p>
<p>In fact, reporting indicates that an unauthorized group has already <a href="https://gizmodo.com/some-unknown-group-is-reportedly-using-claude-mythos-without-permission-2000749327" target="_blank" rel="noopener">accessed Mythos</a> through a data breach at an AI training startup combined with contractor access to Anthropic’s systems, demonstrating that access restrictions alone cannot be relied upon. Rivian CISO Mike Johnson has warned that <a href="https://www.securityweek.com/mythos-ready-security-csa-urges-cisos-to-prepare-for-accelerated-ai-threats/" target="_blank" rel="noopener">“by the end of the year, Mythos-level capabilities will be in the hands of any attacker.”</a></p>
<p>Organizations can’t rely solely on rollout restrictions imposed by AI developers. Mainframe security teams have to work proactively to reduce the risks posed by Mythos.</p>
<p><strong>Why platform strength isn’t enough</strong></p>
<p>The mainframe has traditionally offered security advantages such as physical isolation, proprietary architecture, and granular access controls. But unless this platform strength is complemented with the right operational security capabilities, including automation, monitoring, and lifecycle management, that strength won’t translate into real-world security outcomes.</p>
<p>To actively protect the mainframe end-to-end, mainframe security teams must address risks including:</p>
<ul>
<li><strong>API-based threats</strong><strong>:</strong> Attackers can hijack trusted API connections between distributed systems and the mainframe, exploiting machine-to-machine authentication to reach mainframe data directly.</li>
<li><strong>Identity-based threats</strong><strong>:</strong> Credential theft, insider threats, and privilege escalation, already among the most common attack vectors across platforms, are turbocharged by AI-driven phishing and social engineering; machine identities including service accounts and API keys represent an additional and often under-protected attack surface.</li>
<li><strong>Software supply chain attacks</strong><strong>:</strong> Third-party involvement in breaches <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener">doubled in a single year</a>. Compromised mainframe development tools, vendor software, and shared CI/CD pipelines all represent potential entry points.</li>
<li><strong>Lateral movement</strong><strong>:</strong> Once a distributed system is compromised, existing trusted connections including database links, shared credentials, and network pathways can be used as a stepping stone to the mainframe.</li>
</ul>
<p>Operational gaps such as expired or misconfigured certificates, unmonitored privileged sessions, outdated software versions, and manual security processes can make these threats more exploitable. As AI-driven attack capabilities continue to evolve, staying current on supported <a href="https://community.bmc.com/s/topic/0TO3n000000WJUMGA4/bmc-ami-security">BMC AMI Security</a> software versions and adopting new protections quickly becomes increasingly important.</p>
<p><strong>Preparing Mainframe Security for AI-Accelerated Threats</strong></p>
<p>AI-accelerated threats increase the cadence of attacks, expand the scope of vulnerability discovery across hybrid environments, and compress the time available for security teams to respond. As Mythos-level capabilities proliferate, ISACA, a global, independent non-profit association focused on digital trust, calls for organizations to adopt continuous exposure management. With this approach, security teams correlate findings with runtime topology and business criticality in real time to close the operational gaps that advanced threats exploit.</p>
<p>This shift also reflects what organizations such as <a href="/customers/fnts.html">FNTS</a> are seeing in the field: compliance reporting alone is no longer enough. Security teams need operational security capabilities that provide continuous visibility, real-time monitoring, and rapid response across the hybrid enterprise. In the Mythos era, organizations must move beyond periodic audits and static controls to actively detect, investigate, and contain threats before automated attacks can escalate</p>
<p>BMC AMI Security helps close these operational gaps across key threat categories facing the mainframe:</p>
<ul>
<li><strong>Delivering faster forensic investigations </strong>with <a href="/it-solutions/bmc-ami-mainframe-security.html">real-time visibility and session auditing</a><strong>: </strong><a href="/it-solutions/bmc-ami-command-center.html" target="_blank" rel="noopener">BMC AMI Command Center for Security</a> provides an affordable mainframe-native SIEM for immediate visibility into z/OS security incidents. <a href="/it-solutions/bmc-ami-datastream.html">BMC AMI Datastream</a> streams mainframe security events into enterprise SIEMs in real time, eliminating the mainframe security silo and enabling coordinated detection of lateral movement across the hybrid environment. <a href="/it-solutions/bmc-ami-security-session-monitor.html">BMC AMI Security Session Monitor</a> delivers continuous auditing of application and data access to detect session-level anomalies before they escalate. Together, these capabilities turn enriched, real-time security data into the speed of response that the Mythos era demands.</li>
</ul>
<ul>
<li><strong>Protecting against API-based threats</strong> with <a href="/it-solutions/bmc-venafi-integration-certificate-management.html">certificate lifecycle management</a>: Certificate-based authentication provides stronger protection against API-based threats than API keys alone, but only if certificates are kept current and correctly configured. As certificate lifetimes shorten toward 47 days by 2029, manual certificate management creates an unacceptable operational risk. BMC AMI’s integration with enterprise certificate infrastructure automates certificate lifecycle management across the hybrid environment, preventing vulnerabilities resulting from expired or misconfigured certificates.</li>
<li><strong>Protecting against identity-based threats</strong> with <a href="/it-solutions/bmc-ami-mainframe-security.html">behavioral monitoring, MFA</a>, and privileged access controls: As threats accelerate, organizations must be able to identify stolen credentials and rogue users immediately before an automated attack can escalate. BMC AMI User and Entity Behavior Analytics (UEBA) monitors both human and machine identities under an assumed-breach posture, using AI-driven behavioral baselining to detect anomalies such as unusual login times, abnormal data access, and anomalous query patterns that signal credential misuse. <a href="/it-solutions/bmc-ami-enterprise-connector-for-okta.html">MFA support via Okta</a> extends enterprise authentication standards to mainframe access. Privileged Access Management further reduces risk by enforcing controlled, auditable access to critical systems, commands, and sensitive data.</li>
<li><strong>Protecting against supply chain attacks</strong> with DevSecOps integration and file integrity monitoring: BMC AMI <a href="/it-solutions/bmc-ami-devx-code-pipeline.html">DevSecOps integration</a> supports code signing and hashing verification, ensuring that mainframe deployments carry the same supply chain security controls as distributed systems. File Integrity Monitoring (FIM) capabilities detect and remove malware from recovery sites during restoration, with change management controls providing a full forensic audit trail of what was deployed, when, and by whom.</li>
<li><strong>Reducing exploitable gaps with AI-driven penetration testing and exposure assessment: </strong>Traditional periodic testing is no longer sufficient against autonomous, AI-accelerated threats. AI/ML penetration testing helps organizations identify vulnerabilities across LLMs, APIs, applications, identities, and hybrid infrastructure before attackers can chain them together into real-world exploits, enabling security teams to proactively remediate weaknesses and strengthen operational resilience.</li>
</ul>
<p><strong>Limiting the blast radius: Zero Trust and resilience</strong></p>
<p>As mainframe teams work to strengthen their security posture against Mythos-enabled attacks, they must also ensure the resilience to mitigate the impact of any incident that does occur. The Cloud Security Alliance (CSA) advises organizations to verify and enable mitigating controls such as <a href="https://www.securityweek.com/mythos-ready-security-csa-urges-cisos-to-prepare-for-accelerated-ai-threats/" target="_blank" rel="noopener">segmentation, egress filtering, Zero Trust architectures, and phishing-resistant MFA</a> to limit post-exploitation impact.</p>
<p>AMI Security provides essential capabilities to address these requirements.</p>
<ul>
<li><a href="/it-solutions/bmc-ami-enterprise-connector-for-illumio.html"><strong>BMC AMI Enterprise Connector for Illumio</strong></a> brings the mainframe into enterprise Zero Trust with automatic micro-segmentation, restricting lateral movement even when a distributed system has been compromised.</li>
<li><a href="/it-solutions/bmc-ami-mainframe-security.html"><strong>Immutable Cloud Vaults</strong></a> prevent data tampering and ensure forensic recovery. Transaction logs are streamed continuously off-platform—even to on-premises object storage—to enable no-data-loss recovery even if the mainframe environment is compromised.</li>
<li><a href="/it-solutions/bmc-ami-mainframe-security.html"><strong>Automated Forward Recovery</strong></a> restores lost transactions post-attack, supporting the tight recovery windows required under frameworks such as DORA.</li>
</ul>
<p><strong>What AI-resilient security means in practice</strong></p>
<p>While Mythos may be the first widely discussed example of autonomous AI-driven cyber exploitation, it is part of a broader wave of increasingly capable models that are accelerating the pace of cybersecurity risk. This makes established best practices even more critical. The <a href="https://www.gov.uk/government/organisations/ai-safety-institute" target="_blank" rel="noopener">UK AI Security Institute</a> has noted it cannot confirm whether Mythos Preview would be able to attack well-defended systems, reinforcing that strong, active defenses remain the most effective response.  As autonomous AI models continue to emerge and proliferate, organizations must shift from static audits to continuous, real-time defense, with active management of certificates, identities, sessions, and supply chain integrity across the full hybrid environment.</p>
<p>However the Mythos story evolves, it’s clear that mainframe teams will continue to see new types of threats and rising risk. By strengthening security across your mainframe attack surface with end-to-end technologies and operational capabilities, you can protect your organization more effectively against whatever the future holds.</p>
<p>Explore how <a href="/it-solutions/bmc-ami-mainframe-security.html">BMC AMI Security</a> helps identify vulnerabilities, monitor privileged activity, and reduce exposure before threats become incidents.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>You&#8217;re moving to SAP S/4HANA. Is your execution ready?</title>
		<link>https://blogs.bmc.com/you-are-moving-to-sap/</link>
		
		<dc:creator><![CDATA[Jennifer Margules]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 14:02:32 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=52032</guid>

					<description><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-1024x512.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="Blue-screen-with-numbers-and-analytics" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-1024x512.jpg.optimal.jpg 1024w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-300x150.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-768x384.jpg.optimal.jpg 768w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-810x405.jpg.optimal.jpg 810w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-1140x570.jpg.optimal.jpg 1140w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-24x12.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-36x18.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-48x24.jpg.optimal.jpg 48w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics.jpg.optimal.jpg 1400w" sizes="auto, (max-width: 810px) 100vw, 810px" />SAP mainstream maintenance for ECC ends December 31, 2027. Moving to S/4HANA protects your ERP investment, but only if the business processes around SAP keep running. Control-M is the enterprise orchestration layer that coordinates SAP and non-SAP workflows so execution stays reliable through the change. The countdown is real. For the estimated 17,000 organizations still […]]]></description>
										<content:encoded><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-1024x512.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="Blue-screen-with-numbers-and-analytics" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-1024x512.jpg.optimal.jpg 1024w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-300x150.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-768x384.jpg.optimal.jpg 768w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-810x405.jpg.optimal.jpg 810w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-1140x570.jpg.optimal.jpg 1140w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-24x12.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-36x18.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics-48x24.jpg.optimal.jpg 48w, https://s7280.pcdn.co/wp-content/uploads/2022/05/Blue-screen-with-numbers-and-analytics.jpg.optimal.jpg 1400w" sizes="auto, (max-width: 810px) 100vw, 810px" /><p>SAP mainstream maintenance for ECC ends December 31, 2027. Moving to S/4HANA protects your ERP investment, but only if the business processes around SAP keep running. <a href="/it-solutions/control-m-for-sap.html">Control-M</a> is the enterprise orchestration layer that coordinates SAP and non-SAP workflows so execution stays reliable through the change.</p>
<p>The countdown is real. For the estimated 17,000 organizations still running ECC, that deadline is no longer a distant milestone. It&#8217;s a planning problem that needs an answer now.</p>
<p>The move to S/4HANA is more than just a technical upgrade. It&#8217;s a shift from stable, system-centric operations to dynamic, interconnected processes that span cloud services, data platforms, and external partners. Your SAP investment only delivers value when everything around SAP works, and that&#8217;s specifically where migration risk hides.</p>
<h2>Why does S/4HANA migration increase execution risk?</h2>
<p>Most transformations involve a dual-run period, where ECC and S/4HANA operate in parallel while teams work toward cutover. During that window, a single financial close or order-to-cash cycle can span SAP, data platforms, cloud services, and non-SAP applications, each with its own dependencies and timing.</p>
<p>When those workflows are managed in siloed tools, three problems surface fast:</p>
<ul>
<li><strong>Cross-system dependencies break down.</strong> Processes that depend on coordinated handoffs between SAP and connected systems fail in ways that aren&#8217;t obvious until they hit business outcomes.</li>
<li><strong>Visibility fragments.</strong> Teams lose a unified view of what&#8217;s running, what&#8217;s blocked, and what&#8217;s at risk.</li>
<li><strong>Recovery becomes manual.</strong> Disconnected tools mean more effort and more chances for late or failed processes.</li>
</ul>
<p>The work that looks stable inside SAP can still collapse across the systems SAP depends on.</p>
<h2>How Control-M protects your SAP investment</h2>
<p>SAP runs your core business processes. But when those processes span systems, coordination breaks down. Control-M is the enterprise orchestration layer that ensures reliable, end-to-end execution across SAP and dependent systems. It&#8217;s not a better SAP scheduler, but the layer that governs the full business workflow.</p>
<p>During migration, Control-M orchestrates workflows across ECC and S/4HANA simultaneously, manages parallel execution, and coordinates cutover, reducing disruption risk. After go-live, it keeps financial close, data movement, and cross-platform workflows running as coordinated processes rather than disconnected jobs. And as legacy SAP automation tools reach end of support, Control-M consolidates automation into one governed control plane with unified SLA tracking and audit-ready visibility.</p>
<p><strong>What results have organizations seen?</strong></p>
<ul>
<li><strong>REWE digital</strong> shifted its entire distribution system to Control-M with zero downtime. At 23:59 on go-live, the original vendor&#8217;s tool ran its last workflow. One minute later, Control-M launched all workflows across every fulfillment center.</li>
</ul>
<ul>
<li><strong>Coop</strong> manages 107 SAP instances and 140,000 job runs a day with only three administrators.</li>
</ul>
<ul>
<li><strong>Snam</strong> reduced workflow errors by 40 percent after consolidating data and application workflows in Control-M.</li>
</ul>
<p>These gains are the difference between a migration that protects the business and one that puts it at risk.</p>
<h2>Protect the investment before the deadline</h2>
<p>The 2027 deadline is about protecting the processes your business runs on. Modernization increases complexity, and complexity left ungoverned becomes operational risk.</p>
<p>Control-M ensures those processes continue to run reliably through the change. SAP manages the core. Control-M makes sure the full business service executes on time and within policy, across every system involved.</p>
<p>If you&#8217;re planning your move to S/4HANA, see how <a href="/it-solutions/control-m.html?vu=control-m">Control-M</a> can ease and accelerate your migration.</p>
<h2>Frequently asked questions</h2>
<h4>When does SAP ECC maintenance end?</h4>
<p>SAP provides mainstream maintenance for ECC 6.0 (enhancement packages 6–8) until December 31, 2027. Many organizations are choosing a migration path now to avoid rising costs and a compressed timeline.</p>
<h4>Why is S/4HANA migration considered risky?</h4>
<p>The main risk isn&#8217;t SAP itself. It&#8217;s execution across connected systems. During dual-run periods, coordinating workflows with fragmented tools leads to broken dependencies, lost visibility, and manual recovery.</p>
<h4>How is Control-M different from SAP-native scheduling?</h4>
<p>SAP-native tools manage jobs within SAP. Control-M coordinates the full business process across SAP and non-SAP systems, mapping dependencies, enforcing SLAs, and providing unified visibility across the entire workflow.</p>
<h4>Do we have to replace our existing tools to use Control-M?</h4>
<p>No. Control-M acts as a unifying orchestration layer without forcing a rip-and-replace. It consolidates fragmented automation over time, which is especially valuable as legacy SAP automation reaches end of support.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why Modernize Orchestration Alongside Your SAP S/4HANA® Migration</title>
		<link>https://blogs.bmc.com/orchestration-s4hana-migration/</link>
		
		<dc:creator><![CDATA[Jennifer Margules]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 13:31:03 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=53632</guid>

					<description><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-1024x512.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="3-people_computer_abstract-codes" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-1024x512.jpg.optimal.jpg 1024w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-300x150.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-768x384.jpg.optimal.jpg 768w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-810x405.jpg.optimal.jpg 810w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-1140x570.jpg.optimal.jpg 1140w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-24x12.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-36x18.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-48x24.jpg.optimal.jpg 48w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes.jpg.optimal.jpg 1400w" sizes="auto, (max-width: 810px) 100vw, 810px" />Modernizing your orchestration platform during an SAP S/4HANA migration protects existing automation investments, closes integration gaps across hybrid landscapes, and creates a governed control plane for AI workflows. Doing both together reduces dual-run risk and helps critical business processes run reliably through change and after go-live. SAP runs the core processes that keep a business […]]]></description>
										<content:encoded><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-1024x512.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="3-people_computer_abstract-codes" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-1024x512.jpg.optimal.jpg 1024w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-300x150.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-768x384.jpg.optimal.jpg 768w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-810x405.jpg.optimal.jpg 810w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-1140x570.jpg.optimal.jpg 1140w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-24x12.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-36x18.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes-48x24.jpg.optimal.jpg 48w, https://s7280.pcdn.co/wp-content/uploads/2021/03/3-people_computer_abstract-codes.jpg.optimal.jpg 1400w" sizes="auto, (max-width: 810px) 100vw, 810px" /><p>Modernizing your orchestration platform during an SAP S/4HANA migration protects existing automation investments, closes integration gaps across hybrid landscapes, and creates a governed control plane for AI workflows. Doing both together reduces dual-run risk and helps critical business processes run reliably through change and after go-live.</p>
<p>SAP runs the core processes that keep a business moving: financial close, order flows, supply chain, and reporting. But those processes rarely stay inside SAP. They reach into data platforms, cloud services, mainframes, and dozens of non-SAP applications. When you migrate from ECC to S/4HANA, the systems your workflows depend on shift too, and the coordination between them gets more fragile.</p>
<p>That&#8217;s the part many migration plans overlook. Teams focus on the ERP move itself, then assume their existing automation will behave the same way in the new environment. It usually doesn&#8217;t. New complexity (multi-cloud execution, longer dependency chains, parallel ECC and S/4HANA operation) changes how workflows perform. The result is missed SLAs, manual recovery, and the kind of late-night escalations no one budgets for.</p>
<p>This post explains why your orchestration platform deserves attention at the same time as your S/4HANA migration, not after it. You&#8217;ll learn how modernizing both together protects what you&#8217;ve already built, supports emerging AI-driven work, and keeps business processes running predictably through one of the biggest transitions your organization will face.</p>
<h2>Why modernize SAP orchestration during migration?</h2>
<p>A migration to S/4HANA is rarely a clean, single-day switch. Most organizations run ECC and S/4HANA in parallel for a stretch, coordinating cutover and validation across both. That dual-run period is where execution risk spikes. You&#8217;re managing timing, dependencies, and handoffs across two ERP environments plus everything connected to them, often with disconnected tools and a lot of manual effort.</p>
<p>Modernizing orchestration at the same time gives you a single control plane to manage that complexity. Instead of stitching together SAP-native schedulers and siloed point tools, you coordinate end-to-end business processes across ECC, S/4HANA, and dependent systems from one place. You see what&#8217;s running, what&#8217;s blocked, and what&#8217;s at risk before it affects the business.</p>
<p>Treating orchestration as a separate, later project tends to backfire. Execution coordination is hardest to fix once fragmentation is already entrenched. Addressing it during the migration, when you&#8217;re already redefining how work runs, means you build the new environment on a stable foundation rather than retrofitting one under pressure.</p>
<h2>The forcing function: legacy automation reaching end of support</h2>
<p>There&#8217;s a practical reason this conversation is happening now. Legacy SAP automation tools are reaching end of support, which pushes many organizations into a replacement decision they can&#8217;t defer. Rather than swapping one siloed scheduler for another, this is the moment to adopt an enterprise-wide orchestration layer that consolidates SAP and non-SAP execution under unified control, without rebuilding the same workflows in a tool that only understands SAP.</p>
<h2>Protect the automation investments you&#8217;ve already made</h2>
<p>Here&#8217;s the concern that keeps IT leaders up at night during a migration: years of carefully built automation suddenly at risk. You&#8217;ve invested time and budget into workflows that span SAP, data pipelines, file transfers, cloud services, and homegrown applications. Moving to a SAP-specific tool often means rebuilding much of that from scratch, which adds cost, delay, and risk to an already demanding project.</p>
<p>Modernizing with an enterprise orchestrator preserves that work. <a href="/it-solutions/control-m.html?vu=control-m">Control-M</a> brings your existing non-SAP automation and your new S/4HANA workflows into the same control plane, so you extend what you&#8217;ve built rather than recreate it. With more than 100 native <a href="/it-solutions/control-m-integrations.html#&amp;product_interest=396588812&amp;sortCriteria=recommended&amp;category=mp">integrations</a> covering AWS, Azure, Google Cloud, Oracle, Informatica, Kubernetes, Databricks, Apache Airflow, and many more, the workflows surrounding SAP keep running while the ERP environment changes underneath them.</p>
<p>The financial logic is straightforward. SAP S/4HANA migration projects already carry significant investments across planning, licensing, resources, and implementation. Folding orchestration modernization into the same program reduces the number of follow-on upgrade projects later, and the savings can be redirected elsewhere in the business. Investment protection isn&#8217;t only about preserving old work. It&#8217;s about getting more value from the project you&#8217;re already funding.</p>
<h2>AI agents need governed orchestration, not free rein</h2>
<p>SAP is moving fast into AI-assisted operations. SAP Joule and intelligent agents built on the SAP Business Technology Platform (BTP) can generate decisions, trigger actions, and interact with APIs across systems. That&#8217;s powerful, but business value doesn&#8217;t come from isolated intelligent components acting on their own.</p>
<p>Agent-driven workflows are dynamic, cross-platform, and sensitive to compliance requirements. They need a structured, observable, and accountable layer to sequence execution, enforce SLAs, and maintain an audit trail of what ran, when, and with what outcome. Without that governance, AI activity becomes another source of risk rather than a source of value.</p>
<p>This is where orchestration earns its place in your future architecture. Control-M orchestrates event-driven and AI workflows within governed business services, so intelligent systems operate inside guardrails instead of around them. If you&#8217;re audited tomorrow, you can show what executed and whether it met policy. As more AI enters production, accountability becomes essential rather than optional.</p>
<h2>The migration challenges that orchestration solves</h2>
<p>The more established an organization is in SAP ECC, the harder the transition tends to be. A few recurring challenges show up across nearly every migration:</p>
<ul>
<li><strong>Accumulated integrations.</strong> Over years, companies have built up a growing web of integrations with their SAP systems. Managing all of them during a migration pulls focus away from the project itself and creates more places for things to break.</li>
</ul>
<ul>
<li><strong>Complex landscapes.</strong> Many organizations run multiple ERPs, add-ons, non-SAP systems, and custom scripting. If any associated job or process breaks during migration, operations can grind to a halt, costing real time and money.</li>
</ul>
<ul>
<li><strong>Clean core pressure.</strong> SAP&#8217;s clean core strategy moves custom logic and integrations out of the ERP and into the surrounding landscape. Without a capable orchestration layer to manage those externalized workflows, teams end up with new coordination gaps where the old customizations used to be.</li>
</ul>
<ul>
<li><strong>No plan for ongoing automation.</strong> Teams often keep running automation the way they always have. During migration, that lack of forward thinking leads to gaps as workflows move to S/4HANA.</li>
</ul>
<p>Each of these comes down to the same root issue: execution that spans systems without coordinated, end-to-end control. A modern orchestration layer addresses all three by mapping dependencies, sequencing execution, and giving teams one view across the whole process lifecycle.</p>
<h2>How Control-M supports your S/4HANA migration</h2>
<p>As an SAP-certified solution, Control-M creates and manages SAP ECC, S/4HANA, and BW jobs, plus data archiving, and supports any application in the SAP ecosystem. It connects to SAP through the SAP-certified BC-XBP interface, and both the self-hosted and SaaS versions are SAP Certified for Integrations with RISE with SAP S/4HANA Private Cloud. Here&#8217;s what that delivers in practice:</p>
<ul>
<li><strong>Reduced project time and cost.</strong> Pre- and post-migration automation keeps operations smooth and consolidates modernization into one program, cutting the number of follow-on upgrade projects.</li>
</ul>
<ul>
<li><strong>Reduced integration complexity.</strong> Control-M provides a complete integration view across SAP and non-SAP systems, so data flows and dependencies stay coordinated through the transition.</li>
</ul>
<ul>
<li><strong>End-to-end visibility and governance.</strong> Real-time monitoring, SLA management, and full execution traceability give teams the control and audit readiness modernization demands.</li>
</ul>
<ul>
<li><strong>Scalability and stack alignment.</strong> Control-M scales with the business and sets a clean foundation for the innovation projects that follow migration.</li>
</ul>
<h2>Proof that this approach works</h2>
<p>Two examples show what reliable orchestration looks like during high-stakes change.</p>
<p>When <a href="/customers/rewe-digital-gmbh.html"><strong>REWE digital</strong></a> migrated its mission-critical distribution systems, the cutover was seamless. At 23:59 on go-live, the previous automation tool ran its last workflows. One minute later, at 00:00, Control-M launched every workflow, managing orders to all fulfillment centers across the company&#8217;s markets. The entire distribution system shifted with zero downtime, no small feat when thousands of supermarkets depend on it.</p>
<p><a href="/forms/how-coty-streamlines-business-processes-with-control-m.html"><strong>Coty</strong></a>, one of the world&#8217;s largest beauty companies, uses Control-M to automate and orchestrate its most critical business processes. By consolidating onto a single orchestration platform, Coty streamlined execution across its environment and sustained high process reliability. This is clear evidence that unifying fragmented automation pays off in day-to-day operations, not just at cutover.</p>
<h2>Build the foundation before you need it</h2>
<p>A migration to S/4HANA succeeds only when workflows run reliably, make daily work better for business users, and support what the enterprise wants to build next. Your ERP can be perfectly migrated and still fall short if the processes around it stumble.</p>
<p>Modernizing orchestration alongside your S/4HANA migration protects the automation you&#8217;ve already invested in, simplifies the integrations that make migration risky, and prepares your environment for AI-driven work that needs governance to be safe. The organizations that handle both together don&#8217;t just survive the transition. They come out of it with a stronger foundation for everything that follows.</p>
<p>To see how Control-M can de-risk your S/4HANA migration and strengthen your broader SAP workflows, visit the <a href="/it-solutions/control-m-for-sap.html">Control-M for SAP</a> website.</p>
<h2>Frequently asked questions</h2>
<h3>Why should I modernize orchestration during an SAP S/4HANA migration instead of after?</h3>
<p>Migration is when execution risk is highest, because you&#8217;re often running ECC and S/4HANA in parallel and coordinating cutover across connected systems. Modernizing orchestration at the same time gives you one control plane to manage that complexity. Waiting until after means retrofitting coordination once fragmentation is already entrenched, which is harder and costlier.</p>
<h3>How does Control-M protect existing automation investments?</h3>
<p>Control-M brings your existing non-SAP workflows and new S/4HANA jobs into a single control plane, so you extend what you&#8217;ve built instead of rebuilding it in an SAP-only tool. With more than 100 native integrations, the automation surrounding SAP keeps running while the ERP environment changes.</p>
<h3>What does the end of support for legacy SAP automation mean for my migration plan?</h3>
<p>It forces a replacement decision you can&#8217;t postpone. Rather than swapping one siloed scheduler for another, you can use the moment to consolidate SAP and non-SAP execution into one enterprise orchestration layer, reducing tool sprawl and avoiding a rebuild later.</p>
<h3>Is Control-M certified to work with SAP and RISE with SAP?</h3>
<p>Yes. Control-M is an SAP-certified solution that manages SAP ECC, S/4HANA, and BW jobs through the SAP-certified BC-XBP interface. Both the self-hosted and SaaS versions are SAP Certified for Integrations with RISE with SAP S/4HANA Private Cloud.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Revolutionizing SAP® Data Flow: Advanced Orchestration and Monitoring Solutions</title>
		<link>https://blogs.bmc.com/revolutionizing-sap-data-flow/</link>
		
		<dc:creator><![CDATA[Jehangir Khan]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 09:43:23 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=54058</guid>

					<description><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400.jpg.optimal.jpg 700w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-300x171.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-24x14.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-36x21.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-48x27.jpg.optimal.jpg 48w" sizes="auto, (max-width: 700px) 100vw, 700px" />Data plays an integral role in the success of modern businesses. In an SAP ecosystem, data must flow across multiple inbound and outbound sources. To make things even more complicated, gathering and processing data, and then delivering insights, often requires orchestration of data and applications across multiple SAP and non-SAP systems. And as companies enact […]]]></description>
										<content:encoded><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400.jpg.optimal.jpg 700w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-300x171.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-24x14.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-36x21.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2019/06/Accelerating-Code-Delivery-507065943-700x400-48x27.jpg.optimal.jpg 48w" sizes="auto, (max-width: 700px) 100vw, 700px" /><p>Data plays an integral role in the success of modern businesses. In an SAP ecosystem, data must flow across multiple inbound and outbound sources. To make things even more complicated, gathering and processing data, and then delivering insights, often requires orchestration of data and applications across multiple SAP and non-SAP systems. And as companies enact plans to migrate from legacy SAP systems to SAP S/4HANA<sup>®</sup>, failure of critical SAP data flows can bring those digital transformation and modernization efforts to a screeching halt. Missing business modernization deadlines could have long-lasting ramifications, including additional maintenance costs and less-inclusive approaches.</p>
<p>Without a solid data orchestration strategy to ease the process, SAP data orchestration can get difficult quickly. Orchestrating and monitoring data flow within SAP systems is challenging due to factors like integration complexity, data quality, performance, and scalability issues. Monitoring data workflows through multiple SAP and non-SAP systems can also create a range of difficulties, from a general lack of workflow visibility to the inability to address dataflow failures in a timely manner. In addition, SAP data engineers must manage complex environments with multiple integrations and interoperability, often while trying to keep up with frequent changes in business requirements and technologies. All this work, and the troubleshooting required to find data and job failures, leads to more time and money being spent to get everything back on track.</p>
<h2>How Control-M Can Help</h2>
<p><a href="/it-solutions/control-m.html">Control-M</a> provides the workflow orchestration capabilities to help organizations streamline their SAP dataflows in parallel with their migration to SAP S/4HANA. As an SAP-certified solution, Control‑M orchestrates non‑SAP and SAP workflows (including SAP ECC, S/4HANA, and SAP BW jobs) within a single platform. It provides out-of-the-box visibility to all enterprise workflows and their dependencies across SAP and non-SAP source systems and de-risks the transition to SAP S/4HANA.</p>
<p>With unified scheduling and automation of workflows with both SAP and non-SAP systems, Control-M can help organizations greatly reduce time to value, complexity, and the requirement for specialized knowledge. It can also be used for all other enterprise jobs, services, processes, and workflows. That lets businesses using SAP build, orchestrate, run, and manage all their enterprise jobs from a consolidated, integrated platform. In addition, Control-M easily adapts to changing business and technology requirements, ensuring that data processes remain consistent across systems and platforms and aligned with organizational goals. And as resources fluctuate, Control-M can help allocate them effectively, optimizing system capability usage and reducing bottlenecks.</p>
<p>Control-M can serve as a comprehensive platform because of its many integrations. The solution can support all SAP versions and job types. It also supports many other enterprise workflows and has more than 100 native integrations with popular tools, including Amazon Web Services (AWS), Azure, and Google Cloud (and many of their components), Oracle, Informatica, SQL, Red Hat, Kubernetes, Apache Airflow, Hadoop, Spark, Databricks, UiPath, OpenText (Micro Focus), Alteryx, and many more.</p>
<p>Robust data orchestration is crucial to the success of your SAP workflows, especially when they include both SAP and non-SAP systems. Complexity can increase quickly, making it difficult to keep up and hard to manage, and ultimately, leading to missed service level agreements (SLAs). With Control-M, organizations can cut through complexity and have full visibility and control of their application and data workflows.</p>
<p>If you’re interested in learning more about how Control-M can help you with SAP dataflows and much more, check out our <a href="/it-solutions/control-m-for-sap.html">website</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Real-Time Compliance: Prove What Ran, What Data Was Used, and Whether It Was Compliant</title>
		<link>https://blogs.bmc.com/proving-real-time-compliance/</link>
		
		<dc:creator><![CDATA[BMC Software]]></dc:creator>
		<pubDate>Mon, 08 Jun 2026 14:26:54 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55940</guid>

					<description><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png 700w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" />AI is changing where risk shows up—and making it harder to prove you’re in control. TL;DR AI agents, APIs, and automated workflows are scaling faster than the controls designed to govern them. Fewer processes involves people, but most controls still assume they do. Policies exist. Monitoring exists. But control rarely happens at the moment work […]]]></description>
										<content:encoded><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png 700w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" /><p><em>AI is changing where risk shows up—and making it harder to prove you’re in control.</em></p>
<h2>TL;DR</h2>
<p>AI agents, APIs, and automated workflows are scaling faster than the controls designed to govern them. Fewer processes involves people, but most controls still assume they do.</p>
<p>Policies exist. Monitoring exists. But control rarely happens at the moment work runs.</p>
<p>That’s the gap.</p>
<p>If you can’t prove—right now—what executed, what data was used, and whether it followed policy, you don’t have real-time compliance. You have delayed reporting.</p>
<h2>What Do We Mean by “Real-Time Compliance”?</h2>
<p>Practically speaking, it’s pretty simple: Can you tell me—right now—what ran, what data it used, and whether it followed policy? If you can’t answer that without digging through logs or pulling reports later, it’s not real-time.</p>
<p>Real-time compliance means control is applied as work runs—not before on paper, and not after in an audit. And the proof is created at the same time, automatically.</p>
<p>If you have to reconstruct what happened after the fact, you’re not operating in real time. You’re piecing together history.</p>
<h2>The Real Problem: Control Isn’t Applied Where Work Happens</h2>
<p>Most organizations aren’t missing controls. You likely already have:</p>
<ul>
<li>IAM to define who can access what</li>
<li>Security tools to detect issues</li>
<li>Governance frameworks to set policies</li>
</ul>
<p>The problem is that these systems don’t actually control what happens when work runs across workflows, data pipelines, or AI systems. As a result, gaps show up in production:</p>
<ul>
<li>Machine-driven activity grows, but enforcement isn’t consistent</li>
<li>Data pipelines move faster, but validation gets weaker</li>
<li>AI systems follow policies on paper, but not always in practice</li>
</ul>
<p>And when someone asks, “Are we compliant right now?” you still can’t answer in real time. It can take hours, days, or even weeks.</p>
<h2>A Quick Litmus Test: Is Control Enforced?</h2>
<p>If you’re accountable for risk and compliance, there’s a simple way to pressure-test your current state: Check the boxes where you can prove control <em>at execution</em>—not just in policies or audit reports.</p>
<h2>Machine &amp; AI execution</h2>
<ul>
<li>You can list every non-human identity running production workflows</li>
<li>You can trace every AI-driven action to a system and dataset</li>
<li>Policies are enforced <em>before execution</em>, not just logged afterward</li>
</ul>
<p>If not, machine activity is happening outside enforceable control—and you can’t reliably audit it.</p>
<h2>Data and AI pipelines</h2>
<ul>
<li>Every production pipeline includes enforced validation checkpoints</li>
<li>You can prove lineage from source to output</li>
<li>AI systems cannot run on unapproved or external data</li>
</ul>
<p>If not, decisions are being made on data you can’t fully trust or defend.</p>
<h2>Compliance proof</h2>
<ul>
<li>You can generate evidence in real time without manual effort</li>
<li>Audit trails are system-generated, not assembled afterward</li>
<li>You can answer “are we compliant right now?” with actual data</li>
</ul>
<p>If not, compliance is reactive and hard to defend under scrutiny.</p>
<p><strong>The takeaway: </strong>If you can’t check every box in a category, control in that area isn’t enforced at execution. And if you see gaps across categories, you’re not preventing risk, you’re discovering it after the fact.</p>
<h2>Where Real-Time Compliance Breaks Down</h2>
<p>In most environments, the issue is that controls aren’t applied where the work actually runs.</p>
<p>Here’s where it typically breaks down:</p>
<h3>1. Identity control stops with people</h3>
<p>IAM works well for humans, but most production activity now isn’t driven by people. It’s service accounts, APIs, automated workflows, and AI agents doing the work. These identities often aren’t consistently governed, aren’t tied to enforceable policies at runtime, and aren’t monitored at the point of action. So, while access may be controlled, execution isn’t.</p>
<h3>2. Data pipelines outrun your controls</h3>
<p>Pipelines are built to move fast. Controls are often layered around them, not inside them. That leads to validation being optional, policies being applied inconsistently, and outputs being built on unverified inputs. So, you might have lineage—but not trust in the outcome.</p>
<h3>3. AI governance stops at definition</h3>
<p>Most organizations have started defining model policies, access controls, and governance frameworks. But they don’t control how AI actions are triggered, what data is actually used, and how decisions propagate through systems. So, policy exists, but enforcement doesn’t.</p>
<h2>What It Takes to Prove Compliance</h2>
<p>At some point, this becomes a practical question: <em>Can we prove what happened, as it happened?</em> To do that, control has to move closer to execution, where works runs.</p>
<p>That means having a layer that:</p>
<ul>
<li>enforces policy before execution</li>
<li><a href="/blogs/resilient-data-pipelines/">validates data as it moves</a></li>
<li>governs AI workflows like any other production process</li>
<li>captures evidence as part of execution—not afterward</li>
</ul>
<p>When that exists, questions like these are easier to answer:</p>
<ul>
<li>What ran across our environment in the last 24 hours?</li>
<li>Which workflows used unvalidated data?</li>
<li>Where were controls bypassed?</li>
<li>Which AI-driven actions violated policy?</li>
<li>Are we compliant right now?</li>
</ul>
<p>If you can’t answer these questions quickly, control is assumed—not enforced.</p>
<h2>What Real-Time Compliance Requires</h2>
<p>Frameworks like the EU AI Act and NIST AI RMF aren’t asking for more documentation.</p>
<p>They’re asking for <em>provable behavior.</em> To meet that bar, four things need to be true:</p>
<h3>1. Controls are enforced at execution</h3>
<p>Non-compliant workflows don’t run. Policies apply consistently. Every execution records whether it passed or failed control.</p>
<h3>2. Data and decisions are traceable</h3>
<p>Every output can be traced back to its data sources, transformations, and execution path. Across systems, not just within tools.</p>
<h3>3. Compliance is continuous</h3>
<p>You don’t check compliance periodically. You can see what’s running, under which policies, in real time.</p>
<h3>4. Evidence is generated automatically</h3>
<p>Audit trails aren’t reconstructed. They’re created as part of execution. If compliance depends on reconstructing events, it won’t hold up under real pressure.</p>
<h2>What This Looks Like in the First 90 Days</h2>
<p>Achieving real-time compliance isn’t a multi-year transformation. It starts with visibility into where control breaks down, and then quickly moves to enforcing control at execution.</p>
<h3>Days 0–30: Visibility</h3>
<ul>
<li>Identify critical workflows</li>
<li>Surface unmanaged machine and AI activity</li>
<li>Map where execution happens outside control</li>
</ul>
<p><em>Outcome:</em> You know where compliance can’t be proven right now.</p>
<h3>Days 30–60: Enforcement</h3>
<ul>
<li>Bring high-risk workflows under orchestration</li>
<li>Introduce policy checkpoints</li>
<li>Apply validation to key pipelines</li>
</ul>
<p><em>Outcome:</em> High-risk execution is now governed at runtime.</p>
<h3>Days 60–90: Proof</h3>
<ul>
<li>Automate evidence generation</li>
<li>Establish continuous compliance baselines</li>
<li>Link workflows, data, and outcomes</li>
</ul>
<p><em>Outcome:</em> You can prove compliance as work runs, not after.<strong> </strong></p>
<h2>Common Questions Security &amp; Risk Leaders Ask</h2>
<h3><span style="font-size: 16px;">1. How do we find where controls are being bypassed?</span></h3>
<p>You need visibility into execution, not just policy definitions. That usually means <a href="/blogs/workflow-orchestration/">centralizing orchestration</a> and making workflow execution observable across systems.</p>
<h3>2. How do we keep AI agents within bounds?</h3>
<p>By enforcing controls at runtime: identity, data access, and allowed actions. Every action must pass through those controls, not just inherit policy.</p>
<h3>3. How do we add human approvals without slowing everything down?</h3>
<p>By applying them selectively. Most workflows run automatically. Only exceptions or high-risk actions trigger human approval in real time.</p>
<h3>4. How do we prove what happened without manual reconstruction?</h3>
<p>By capturing execution as it happens: inputs, transformations, model activity, outputs. All in a single, time-sequenced record.</p>
<h2>Final Thoughts: The Mental Shift That Matters</h2>
<p>Compliance used to be about documentation. Now it’s about <em>provable execution</em>. The question isn’t “Do we have policies?” It’s “Can we prove they were enforced when work actually ran?”</p>
<p>That’s where an <a href="/blogs/soap-control-plane-ai/">AI control plane</a> approach starts to matter.</p>
<p>Platforms like <a href="/it-solutions/control-m.html" target="_blank" rel="noopener">Control‑M</a> bring execution, control, and evidence together, so you can:</p>
<ul>
<li>Enforce policy at execution, not after the fact</li>
<li>Validate data before it’s used</li>
<li>See exactly what ran, how it ran, and what it produced</li>
<li>Capture audit evidence automatically, as part of runtime</li>
</ul>
<p>When that’s in place, everything tightens up: Work runs under control, activity is visible in real time, policies are applied consistently, and compliance is provable without reconstruction.</p>
<p><strong>Final takeaway:</strong> If you’re trying to move from “we think we’re compliant” to “we can prove it right now,” it starts with enforcing control where execution happens.</p>
<p><a href="/it-solutions/ai-governance-for-production-ai-workflows.html" target="_blank" rel="noopener">How to operationalize AI governance to control risk and compliance in production</a></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SOAP as the Control Plane for AI: Why Everything Runs—And Still Isn’t Under Control</title>
		<link>https://blogs.bmc.com/soap-control-plane-ai/</link>
		
		<dc:creator><![CDATA[BMC Software]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 15:01:36 +0000</pubDate>
				<category><![CDATA[Workload Automation Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55932</guid>

					<description><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png 700w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" />TL;DR AI isn’t the hard part anymore. Operationalizing AI is. Most AI projects stall because no one really has control over how the whole thing behaves in production. Pipelines run. Workflows exist. But they’re stitched together across tools, scripts, and “somebody who knows how it works.” What you have isn’t a system. It’s coordination by […]]]></description>
										<content:encoded><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png" class="attachment-large size-large wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1.png 700w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2026/06/All-DB2-DBAs-497452519-700x400-1-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" /><h2>TL;DR</h2>
<p>AI isn’t the hard part anymore. Operationalizing AI is.</p>
<p>Most AI projects stall because no one really has control over how the whole thing behaves in production.</p>
<p>Pipelines run. Workflows exist. But they’re stitched together across tools, scripts, and “somebody who knows how it works.” What you have isn’t a system. It’s coordination by coincidence.</p>
<p>A SOAP is the layer that turns all of that into something you can actually run and rely on.</p>
<h2>Why So Many AI Projects Stall — and What’s Missing in the Middle</h2>
<p>The model works. The use case is valid. And then it stalls. Not because the model failed, but because everything around it starts to break.</p>
<p>The problem shows up in the middle:</p>
<ul>
<li>data isn’t where it needs to be</li>
<li>steps don’t run in the right order</li>
<li>systems drift out of sync</li>
</ul>
<p>Individually, those pieces exist. Together, they don’t behave like a system. That’s why “we got it working” rarely turns into “this runs reliably in production.”</p>
<p>There’s a layer that’s supposed to hold all of this together. In most environments, it doesn’t exist as a single system. It’s spread across schedulers, pipelines, scripts, and a lot of tribal knowledge.</p>
<p>When you actually pull that together into something coherent, it’s what’s referred to as a <a href="/blogs/soaps-service-orchestration-automation-platforms/">Service Orchestration and Automation Platform (SOAP)</a>.</p>
<h2>Is SOAP Just Rebranded Orchestration?</h2>
<p>It sounds like it. Most teams already have plenty of orchestration. And yet the common experience is: everything runs but it still doesn’t feel under control.</p>
<p>That’s because <a href="/blogs/workflow-orchestration/">orchestration</a> is built to execute workflows—even across systems—but it doesn’t inherently give you control over how those workflows behave at the system level.</p>
<p>The problem is that real systems don’t stay in boundaries. Workflows interact. Dependencies cross tools. Upstream delays ripple. AI steps behave inconsistently. So you end up here: everything ran, but the outcome is still wrong.</p>
<p>That’s not an execution failure. It’s a control failure. That’s the shift:</p>
<ul>
<li>Orchestration defines how the workflow is supposed to run across systems.</li>
<li>SOAP is what actually keeps those workflows running correctly across the environment.</li>
</ul>
<p>You don’t feel that difference when you’re building a pipeline. You feel it when:</p>
<ul>
<li>that pipeline connects to everything else</li>
<li>something upstream is late</li>
<li>something downstream quietly breaks</li>
<li>and no single tool can explain what actually happened</li>
</ul>
<p>In practice, this is where platforms like <a href="/it-solutions/control-m.html" target="_blank" rel="noopener">Control‑M</a> show up—not as “another orchestrator,” but as the layer that coordinates workflows across data, applications, and AI so they behave like a system.</p>
<p><strong>Takeaway: </strong>It’s not more orchestration. It’s the layer that makes everything already orchestrated actually behave predictably.</p>
<h2>What a Control Plane Has to Get Right</h2>
<p>Once you think in terms of a SOAP as the control plane, the question shifts pretty quickly from: “how do we run this workflow?” to “what does it take to keep this thing behaving under real conditions?”</p>
<p>In practice, there are a few things a control plane needs to get right if it’s going to hold up in production:</p>
<h3>1. It actually has to run reliably</h3>
<p>Not just once. Not just in a clean path. Across:</p>
<ul>
<li>cloud + onprem</li>
<li>internal systems + external APIs</li>
<li>workloads that don’t all behave the same way</li>
</ul>
<p>AI makes this harder, not easier. Latency varies. Dependencies drift. Retries don’t always help. At some point, you realize the pipeline is only as reliable as the least predictable thing in it.</p>
<h3>2. It has to understand what depends on what</h3>
<p>This is the one most teams feel immediately. Something upstream is delayed, and you don’t find out until something downstream fails—or worse, runs with bad data.</p>
<p>Without system-level awareness, you’re always reacting. With it, you can actually see what’s at risk, what’s impacted, and what needs attention now.</p>
<h3>3. It has to explain what’s going on</h3>
<p>This is where things usually fall back to people. Someone knows how the workflow works, why it fails in weird ways, and what “normal” looks like. And everyone else is stuck asking them.</p>
<p>A control plane starts to pull that knowledge into the system itself:</p>
<ul>
<li>what this workflow does</li>
<li>what changed</li>
<li>what likely caused the issue</li>
</ul>
<p>Not magic. Just enough context to stop everything from being a guessing game.</p>
<p><strong>Takeaway: </strong>You’re no longer just running workflows. You’re running a system where behavior is visible, dependencies are understood, and issues are explainable. That’s what lets <a href="/it-solutions/ai-workflow-orchestration.html" target="_blank" rel="noopener">AI pipelines</a> move from “it works” to something you can actually rely on.</p>
<h2>What This Looks Like When It Actually Works</h2>
<p>This is where the control plane idea stops being conceptual and starts showing up in real workflows.</p>
<h3>1. When a “quick change” isn’t a scramble anymore</h3>
<p>You get the request: “Can we refresh this dashboard with updated projections today?”</p>
<p>Without a control plane, that usually turns into a scramble—figuring out which pipelines are involved, coordinating across a few teams, manually triggering jobs, and then watching closely to see what breaks.</p>
<p>With a control plane, that same request is already understood as a workflow. The dependencies are mapped, the execution path is known, and the change can be applied in one place without chasing it across tools.</p>
<p>The difference isn’t just speed. It’s that the work becomes predictable and repeatable instead of reactive.</p>
<h3>2. When AI actually makes it to production</h3>
<p>Moving revenue forecasting models, fraud analysis pipelines, or <a href="https://www.bmc.com/it-solutions/supply-chain-orchestration.html" target="_blank" rel="noopener">supply chain optimization workflows</a> from proof-of-concept to operational requires enterprise-grade discipline: <a href="/it-solutions/data-orchestration-workflow-orchestration.html" target="_blank" rel="noopener">governed data ingestion</a>, controlled model execution, managed LLM invocation.</p>
<p>With a control plane, ingestion, transformation, inference, and downstream updates are all coordinated, observable, and governed the same way. At that point, moving to production stops feeling like starting over.</p>
<h3>3. When governance isn’t a periodic fire drill</h3>
<p>In most environments, workflow sprawl builds up quietly over time. Pipelines stick around long after they’re needed, dependencies overlap, and no one really has a clear view of what’s still in use. You don’t notice it until something breaks, performance slips, or there’s an audit coming up.</p>
<p>Without a control plane, governance is something you piece together after the fact. With one, the system itself starts to surface what’s changed, what’s no longer used, and where things are drifting. Governance becomes continuous instead of reactive.</p>
<h2>Why the Lack of a Control Plane Feels Worse With AI</h2>
<p>This isn’t a new problem. The gaps in how workflows are coordinated have always been there. <a href="/blogs/ai-is-ready-are-your-operations/">AI just makes them obvious</a>.</p>
<p>You now have more steps, more variability, more external dependencies (LLMs, APIs), and less predictable behavior. So the same coordination gaps that were manageable before start to show up everywhere.</p>
<p><strong>Without a Control Plane</strong></p>
<p><img decoding="async" class="alignnone size-full wp-image-55935" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/Without-a-Control-Plane.svg" alt="" /></p>
<p>No shared context</p>
<ul>
<li>Each part runs its piece</li>
<li>Dependencies are implicit</li>
<li>Failures are discovered late</li>
<li>People connect the dots manually</li>
</ul>
<p><strong>With a Control Plane (SOAP)</strong></p>
<p><img decoding="async" class="alignnone size-full wp-image-55936" src="https://s7280.pcdn.co/wp-content/uploads/2026/06/With-a-Control-Plane-SOAP.svg" alt="" /></p>
<ul>
<li>One layer coordinates execution across everything</li>
<li>Dependencies are explicit and visible</li>
<li>Failures are understood in context</li>
<li>Impact is clear before it spreads</li>
</ul>
<h2>Where SOAP Changes Day-to-Day Work</h2>
<p>This is where it gets real.</p>
<ul>
<li>Instead of debugging across tools, you can actually see the workflow end to end.</li>
<li>Instead of isolated failures, you get context about what those failures affect.</li>
<li>Instead of relying on “who knows this pipeline,” the system carries that understanding.</li>
</ul>
<p>With a SOAP, AI workloads stop being special cases and start behaving like everything else you run in production—the same way mature teams handle <a href="/it-solutions/automation-orchestration.html">automation and orchestration</a> across the rest of the stack.</p>
<h2>Where to Start (Without Turning This Into a Rewrite)</h2>
<p>You don’t need to replatform everything. You need to expose where you don’t have control.</p>
<h3>1. Start with one pipeline that matters</h3>
<p>Not a clean one. A real one. Map what actually happens: where data comes from, what it triggers, and what breaks if something is late. This is where hidden dependencies show up.</p>
<h3>2. Count how many “control planes” you actually have</h3>
<p>Most teams have multiple orchestration tools, scripts filling gaps, and people connecting the dots. Everything is orchestrated. Nothing is coordinated.</p>
<h3>3. Make the system visible before you automate it</h3>
<p>You should be able to answer, in one place: what does this workflow actually do, what depends on it, and what happens if it fails or drifts. If you can’t answer those, automation just makes troubleshooting harder.</p>
<h3>4. Treat AI workloads like real workloads</h3>
<p>This is where things quietly break. AI steps often have different retry behavior, weaker monitoring, and less consistent control. That works in testing. It doesn’t in production. Treat them like everything else: observable, governed, and part of the same system—which is increasingly what <a href="https://www.bmc.com/it-solutions/agentic-orchestration.html">agentic orchestration</a> is being built to handle.</p>
<h3>5. Don’t try to fix everything at once</h3>
<p>If one pipeline becomes visible, predictable and understandable, that’s already meaningful progress. From there, it scales.</p>
<h2>What You’re Actually Building Toward</h2>
<p>Not a new tool. Not a perfect architecture. Just this: a single layer that understands how your workflows behave and keeps them from drifting.</p>
<p>Once you have that, automation gets easier, failures are less surprising, and scaling doesn’t multiply chaos.</p>
<h2>To Sum Up: The Shift That Actually Matters</h2>
<p>AI isn’t a modeling problem anymore. It’s an operations problem: can you run complex, cross-system workflows reliably under real conditions? That’s the same shift driving teams to <a href="/blogs/unlock-data-initiatives-with-dataops/">operationalize data and AI projects through orchestration</a>.</p>
<h3>If this feels familiar</h3>
<p>If your current setup works, but only with careful coordination, tribal knowledge, and a few “don’t touch that” pipelines, you’re not behind. You’re just missing the layer that turns all of it into a system you can actually control. That’s the role SOAP is starting to play.</p>
<p><em>If you’re trying to move from “we got it working” to “we can run this reliably, every day”—here’s a practical guide to turning complex workflows into AI-powered outcomes: </em><a href="/documents/e-book/orchestration-the-missing-layer-in-enterprise-ai.html"><strong><em>Orchestration: The Missing Layer in Enterprise AI</em></strong></a><em>.</em></p>
<p><em>This guide goes deeper into what’s missing when it comes to operationalizing AI—what it actually looks like in production, why it shows up so consistently, and how teams are starting to close the gap with a real control plane.</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Mainframe Digital Certificate Management: Solving the System Identity Crisis</title>
		<link>https://blogs.bmc.com/mainframe-digital-certificate-management/</link>
		
		<dc:creator><![CDATA[Matt Whitbourne]]></dc:creator>
		<pubDate>Mon, 18 May 2026 07:58:44 +0000</pubDate>
				<category><![CDATA[Mainframe Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55924</guid>

					<description><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400.png" class="attachment-large size-large wp-post-image" alt="bigdata_security" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400.png 700w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" />As digital certificate lifetimes drop to 47 days, automation becomes essential to maintain availability, security, and compliance. BMC AMI Digital Certificate Manager extends automated certificate lifecycle management to the mainframe, enabling standardization across the enterprise using your current CLM vendor. Digital certificates are the connective tissue of the enterprise environment, enabling systems, workloads, applications, and […]]]></description>
										<content:encoded><![CDATA[<img width="700" height="400" src="https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400.png" class="attachment-large size-large wp-post-image" alt="bigdata_security" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400.png 700w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-300x171.png 300w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-24x14.png 24w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-36x21.png 36w, https://s7280.pcdn.co/wp-content/uploads/2020/01/bigdata_security-700x400-48x27.png 48w" sizes="auto, (max-width: 700px) 100vw, 700px" /><p><em>As digital certificate lifetimes drop to 47 days, automation becomes essential to maintain availability, security, and compliance. BMC AMI Digital Certificate Manager extends automated certificate lifecycle management to the mainframe, enabling standardization across the enterprise using your current CLM vendor.</em></p>
<p>Digital certificates are the connective tissue of the enterprise environment, enabling systems, workloads, applications, and APIs to verify each other and communicate securely. When a certificate fails due to expiration or error, the impact on service availability and security can be immediate and severe. And with regulators driving certificate lifetimes down to as little as 47 days by 2029, organizations face a sharp increase in both <a href="/documents/infographics/certificate-lifetimes-are-shrinking.html">operational and compliance risk</a>. That makes digital certificate management a top priority for BMC customers.</p>
<p>By enabling organizations to discover, track, and renew certificates across the infrastructure, digital certificate management prevents the outages and security gaps that can result from expired, misconfigured, or otherwise compromised certificates. This task has grown more difficult in recent years, and even greater challenges are on the horizon. But BMC has a solution.</p>
<h2>Why digital certificate management is becoming an urgent challenge</h2>
<p>Traditionally, many organizations have managed mainframe certificates through manual processes centered on spreadsheets and tribal knowledge. In recent years, the growing number of system identities relying on these certificates has pushed these methods to the breaking point. Now, regulatory changes have made them completely unsustainable.</p>
<p>To reduce the exposure that can result from a compromised certificate, the CA/Browser Forum has announced aggressive reductions in TLS certificate lifetimes. Until this month, companies were allowed a relatively manageable 398-day renewal cycle. Now that window has been nearly cut in half to 200 days. Next March, it will shrink once again to 100 days, and by March 2029, TLS certificates will be good for only 47 days. Each of these reductions effectively multiplies the certificate management workload for mainframe security teams, and with it, the chance of manual errors, expirations, and system outages.</p>
<p>This isn’t a future problem. The regulatory deadlines are fixed, the timelines are non-negotiable, and their impact is inevitable. That’s why I’m excited to announce <a href="/it-solutions/bmc-ami-digital-certificate-management.html">BMC AMI Digital Certificate Manager (DCM)</a>—a new solution that fundamentally changes certificate management on the mainframe.</p>
<h2>How to extend enterprise digital certificate management to the mainframe</h2>
<p>Most enterprises already invest in Certificate Lifecycle Management (CLM) platforms for their distributed and cloud environments. These platforms haven’t been able reach the mainframe, however, leaving z/OS as a manual island in an otherwise automated estate. Now BMC is filling that gap with the only solution enabling digital certificate management platforms to extend automation to the mainframe as part of a consistent enterprise strategy.</p>
<p>Proven in operational environments for over five years, DCM provides a unified integration layer to connect Venafi and Keyfactor digital certificate management tools to mainframe ESMs including RACF, ACF2, and Top Secret. With DCM, you can standardize on one BMC solution for your mainframe while supporting whichever certificate vendors your organization already uses, no rip-and-replace required.</p>
<h2>End-to-end automated certificate operations</h2>
<p>DCM extends your organization’s CLM to automate the entire mainframe certificate lifecycle, from issuance and renewal to replacement and rollback. The impact is immediate and measurable:</p>
<ul>
<li><strong>Dramatic effort reduction: </strong>Mainframe certificate implementations that previously took up to three hours of manual work are now fully automated.</li>
<li><strong>Eliminated outage risk: </strong>Expired or mismanaged certificates are a major cause of preventable mainframe outages. DCM’s scheduled renewals and built-in rollback ensure continuous availability without late-night firefighting.</li>
<li><strong>Reduced dependency on scarce skills: </strong>Mainframe security expertise is increasingly hard to find. DCM removes the need for skilled personnel to manually execute certificate commands across RACF, ACF2, or Top Secret, freeing them for higher-value work.</li>
<li><strong>Complete audit visibility: </strong>Every action is logged with full detail, including which commands were issued, which ESM responses were received, who authorized the change, and when.</li>
</ul>
<h2>Real-world impact at a major financial institution</h2>
<p>One of the world’s largest financial institutions evaluated DCM against its current, pre-automation state. With certificate volumes growing over 30 percent year over year, a small core team currently handles digital certificate management manually across many application owners and faces an increasing risk of outages, audit failures, and security gaps.</p>
<p>The firm projected the five-year value of deploying DCM as <strong>$8.6 million</strong>, driven by manual effort reduction and avoided headcount ($3.6M), eliminated application outages ($2.2M), compliance and audit risk reduction ($1.4M), operational efficiency gains ($0.8M), and future-proofing against accelerating certificate volumes ($0.6M). Beyond these measurable financial gains, the solution supports the institution’s broader strategic priorities around operational resilience and responsible growth.</p>
<h2>Strengthening Zero Trust across the enterprise</h2>
<p>Machine identity is foundational to Zero Trust: Every workload, process, and system must be authenticated. Working alongside <a href="/it-solutions/bmc-ami-mainframe-security.html">BMC AMI Security</a>, DCM becomes part of a comprehensive Zero Trust strategy for the mainframe, enabling continuous threat detection, automated response, and end-to-end protection across your most critical environment. Security teams gain the observability, policy enforcement, and confidence they need to report to the chief information security officer (CISO) and the board that the mainframe is truly protected.</p>
<h2>Looking ahead</h2>
<p>The certificate landscape continues to move toward shorter lifetimes, more frequent renewals, higher volumes, and tighter regulatory scrutiny. All of these trends will drive an exponential growth in manual digital certificate management workloads. By acting now, organizations can stay ahead of increasingly urgent certificate deadlines while preparing their infrastructure for continuous, automated certificate renewals.</p>
<p>BMC AMI Digital Certificate Manager is generally available. We invite you to <a href="/documents/solution-briefs/ami-digital-certificate-management.html">learn more about how DCM can modernize certificate management</a> across your mainframe environment—preserving your existing tools, eliminating manual effort, and building the operational resilience your business demands.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>BMC Statement: Industry Developments in AI-Driven Security Research</title>
		<link>https://blogs.bmc.com/bmc-statement-industry-developments-in-ai-driven-security-research/</link>
		
		<dc:creator><![CDATA[BMC Software]]></dc:creator>
		<pubDate>Mon, 04 May 2026 14:58:29 +0000</pubDate>
				<category><![CDATA[Security & Compliance Blog]]></category>
		<guid isPermaLink="false">https://blogs.bmc.com/?p=55917</guid>

					<description><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-1024x512.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="Shanghai cityscape network" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-1024x512.jpg.optimal.jpg 1024w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-300x150.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-768x384.jpg.optimal.jpg 768w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-810x405.jpg.optimal.jpg 810w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-1140x570.jpg.optimal.jpg 1140w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-24x12.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-36x18.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-48x24.jpg.optimal.jpg 48w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network.jpg.optimal.jpg 1401w" sizes="auto, (max-width: 810px) 100vw, 810px" />BMC is aware of recent industry discussion about the use of advanced AI techniques to identify software vulnerabilities, including initiatives such as Project Glasswing. As part of normal security operations, BMC continuously monitors emerging research, threat intelligence, and industry developments related to software and supply chain security. These developments reflect an acceleration in how vulnerabilities […]]]></description>
										<content:encoded><![CDATA[<img width="810" height="405" src="https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-1024x512.jpg.optimal.jpg" class="attachment-large size-large wp-post-image" alt="Shanghai cityscape network" decoding="async" loading="lazy" srcset="https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-1024x512.jpg.optimal.jpg 1024w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-300x150.jpg.optimal.jpg 300w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-768x384.jpg.optimal.jpg 768w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-810x405.jpg.optimal.jpg 810w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-1140x570.jpg.optimal.jpg 1140w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-24x12.jpg.optimal.jpg 24w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-36x18.jpg.optimal.jpg 36w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network-48x24.jpg.optimal.jpg 48w, https://s7280.pcdn.co/wp-content/uploads/2021/07/Shanghai-cityscape-network.jpg.optimal.jpg 1401w" sizes="auto, (max-width: 810px) 100vw, 810px" /><p>BMC is aware of recent industry discussion about the use of advanced AI techniques to identify software vulnerabilities, including initiatives such as Project Glasswing.</p>
<p>As part of normal security operations, BMC continuously monitors emerging research, threat intelligence, and industry developments related to software and supply chain security. These developments reflect an acceleration in how vulnerabilities may be identified across the industry.</p>
<p>BMC maintains a defense-in-depth security program and regularly evaluates opportunities to enhance controls and processes as technologies evolve. We engage with customers, partners, and the broader security community to remain aligned with industry best practices.</p>
<p>As new information becomes available, BMC will use its proactive notification process to help keep customers up to date.</p>
<p>To register for proactive notifications, please see the following BMC Support Central article:</p>
<p><a href="https://docs.bmc.com/xwiki/bin/view/Standalone/BMC-Support-Central-User-Guide/supportcentraluserguide/Manage-Your-Support-Account/Favorite-Products-and-Alerts/">https://docs.bmc.com/xwiki/bin/view/Standalone/BMC-Support-Central-User-Guide/supportcentraluserguide/Manage-Your-Support-Account/Favorite-Products-and-Alerts/</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
