Joule

0 2
Translate Translate English content into 9 languages using our machine translation tool.

Joule is SAP's enterprise-grade AI assistant, built into your SAP Concur subscription at no additional cost. This article covers what Joule does, how to activate it for your organization, and what you need to know about data security and privacy as an admin.

Joule with SAP Concur solutions enables true intent-driven work across travel and expense — transforming transactional tasks into intelligent, connected workflows that sharpen decisions and accelerate processes. Your organization benefits from less time spent booking travel and managing expenses, greater policy compliance, and a user experience that meets employees where they are.

How to Activate Joule

As an SAP Concur administrator, you'll play a key role in coordinating with your IT team to complete the activation process. Activation is self-service and SAP has created a step-by-step guide to walk you and your IT team through the process.

Activating Joule for SAP Concur solutions →

Rollout Communication Templates

Once Joule is activated, use these sample emails to communicate the launch to your organization:

Data Privacy and Security

When your organization starts using an AI tool, questions about data safety, compliance, and controls come quickly — often from leadership and legal. Here's what you need to know:

Your Data Stays Yours

SAP does not share your data with third-party LLM providers for the purpose of training their models. Your data stays within the SAP ecosystem, protected by cloud agreements and data processing agreements. For Concur specifically, your conversations with Joule never leave your instance and are never used to improve AI models.

Joule maintains strict, logical tenant separation — your conversations are yours and yours alone. SAP enforces multi-tenancy isolation as a foundational element of its continuous threat monitoring practice. Only authorized members of the SAP Joule product team can access submitted data, on a need-to-know basis, and only in connection with continuous improvement of the service.

Sensitive Data and PII

Users are actively reminded not to submit sensitive personal data, particularly special categories defined under GDPR Article 9. Even in cases where PII is inadvertently included, it is anonymized before being used in any continuous improvement process. The Joule interface reinforces this with the on-screen reminder: "Joule uses AI. Verify the results."

Admin Controls

You have meaningful control over how Joule data is handled in your organization:

  • Retention: By default, interaction data is retained for one year (365 days) for customers who have opted in to conversation log storage. Admins can request a change to this window via a support ticket. On the user side, conversations expire after 24 hours (or 8 hours of inactivity), with history reviewable for up to 7 days. All stored data is anonymized before analysis and automatically purged after the retention period.
  • Deletion: As the data controller, your organization can retrieve or request deletion of data at any time through SAP for Me. When your organization offboards, all interaction data is deleted. When an individual user is deactivated, all conversation logs go with them.
  • Access: You cannot fully block Joule visibility in Concur, but disabling Identity Authentication Services (IAS) for a user can change their login experience and limit Joule access. Joule inherits existing Concur permissions and cannot perform actions the user is not already authorized to take.
  • Conversation log storage: Global account admins have full control over opt-in/opt-out settings for conversation log storage as part of the Joule integration setup.

Security Certifications

Joule is certified against a comprehensive set of security and responsible AI standards:

  • ISO/IEC 42001 — International standard for responsible AI management
  • ISO/IEC 27001 — Information security management
  • SOC 2 — Service organization security controls
  • CSA STAR — Cloud security assurance
  • GDPR — EU data protection compliance
  • EU AI Act — Regulatory compliance for AI in Europe
  • NIST AI RMF — AI risk management framework

Joule undergoes annual internal audits and regular security and AI ethics reviews as part of every release cycle. Joule also uses secure, pooled connections to LLM providers — your organization's identity is concealed from the model provider entirely. All LLMs used by Joule are available within the Generative AI Hub in SAP Business Technology Platform (BTP); no unvetted third-party model access is allowed.

Responsible AI

SAP's content filtering mechanism operates on both inputs and outputs, actively identifying and blocking harmful content. Joule is purpose-scoped to respond only to business-relevant questions — it will not produce copyrighted, offensive, or inappropriate content, and steers clear of controversial topics.

Joule aligns with SAP's Global AI Ethics Policy, based on UNESCO guidelines and 10 core ethics principles. Each AI use case undergoes an AI Ethics Impact Assessment overseen by internal and external ethics bodies. SAP applies the "human in the loop" principle: as much autonomy as necessary, as little as possible. Complex decisions always engage human reasoning.

Read the full Joule for SAP Concur: AI Security Questions Answered FAQ →

More Resources

Bookmark the Joule Resource Center on the SAP Concur Community for activation guides, FAQs, videos, and updates as new capabilities are added:

About This Author
MitchellW
I am our Community Strategy Retention & Demand Senior Manager here at SAP Concur, and have been with SAP Concur since 2017. Some of you may recognize me from the "original Community", the LinkedIn Client User Group, which I managed and moderated. I am thrilled that we now have this evolution of Community available and hope you are taking full advantage of our resources, groups, and forums. Please reach out to me if you have any questions or concerns about our Community, or just to say hello!