What Concur AI and Concur Joule agents do with money in 2026
Joule is SAP's AI assistant and agent platform, and in 2026 it reached SAP Concur in three waves. At SAP Concur Fusion on 17 March 2026, SAP announced the Expense Automation Agent, which acts as a virtual delegate that creates the expense report, adds card transactions and fills in custom fields from context and the user's history, and the Expense Pre-Submit Audit Agent, which checks receipts and flags discrepancies before the report is submitted. Both sit in SAP's Early Adopter Care program, are sold through Joule Premium for Travel and Expense, and are expected to reach general availability later in 2026. The employee still reviews and submits.
The second wave reaches the approver. At GBTA in August 2026, SAP announced an AI-assisted approval manager that ranks expense reports by risk, highlights unusual patterns and missing context, and gives approvers the evidence for a decision. SAP plans it for US English-speaking customers with both Joule Premium and Concur Expense starting in Q4 2026, and describes it as decision support. The approver still clicks approve.
The third wave is the audit layer that already runs. The Receipt Analysis Agent became generally available in Q4 2025 inside ExpenseIt, and an AI-generated receipt checker in Verify is expanding into Concur Intelligent Audit during 2026. And employees can now create and submit reports, upload receipts and book travel from inside Microsoft 365 Copilot through the Joule integration, without opening Concur.
Is there a Concur MCP server
Not from SAP. On 6 October 2026 we checked the obvious hosts. mcp.concur.com, mcp.concursolutions.com and mcp.sap.com all returned NXDOMAIN, meaning the names do not exist. On the US API gateway, us.api.concursolutions.com, every MCP and OAuth discovery path we tried (/mcp, /.well-known/oauth-protected-resource, /.well-known/oauth-authorization-server, /.well-known/openid-configuration, /.well-known/agent-card.json) returned the same 161-byte 404 as a randomly generated control path. Nothing is listening there.
The servers that rank for "Concur MCP" are third-party connectors. The best known is CData's, whose open-source version describes itself as read-only and points to CData Connect AI for full create, update and delete access. Hobby projects on MCP directories wrap the same Concur REST API. Whichever you pick, the permissions an agent ends up with are the Concur OAuth scopes and user role behind the connector, which is why the scope list is the thing to read.
SAP's own route for outside AI is agent-to-agent. Microsoft 365 Copilot talks to Joule, and Joule acts in Concur. SAP has said A2A support across Joule Studio is arriving through 2026.
How we read the Concur API scopes
SAP publishes the Concur developer documentation as a public GitHub repository, SAP-docs/preview.developer.concur.com. On 6 October 2026 we cloned it at commit bc7d693 (last changed 2 October 2026) and extracted every OAuth scope name the API reference mentions, then removed one false positive from a code sample. Anyone can repeat this in two commands.
The control came first. The same reference documents 946 distinct field names, and 62 of them are about amounts, currencies, limits or budgets: approvedAmount, claimedAmount, amountNotApproved, approverAdjustedAmount, totalApprovedAmount, dailyLimitAmount, cardTransactionAmount. Concur models money in detail, so a search for money in its permission model is not looking in a place that never talks about money.
Then the scopes. There are 108. Concur names them by object and action, so .read is read only, .write is read and write, .writeonly and .delete are what they say. 47 grant more than read access. 25 of those touch money: expense reports, receipts, card accounts and transactions, cash advances, budget items, exchange rates, mileage, invoice payment confirmations, purchase requests, travel requests and travel booking. Not one scope name contains an amount, a limit, a threshold or a currency.
The Concur approve call has no amount in it
The scope that matters most for agents is expense.report.workflowstatus.write. Concur's Workflows v4 reference says it lets an application approve or send back a report with a PATCH to /expensereports/v4/reports/{reportId}/approve.
The request body has five optional fields: comment, expenseRejectedComment, expectedStepCode, expectedStepSequence and statusId, which defaults to approved. None is an amount, a ceiling or an approver identity. The two step fields are a safety check that the report is still on the step you expect, which is a good design for race conditions and says nothing about money.
The access rule is the detail a controller should read twice. The reference says the short approve and send-back URLs, the ones without a user ID or context, support the company-level access token, and tells you to use the short form when the report sits in a system step. The long form takes a user token in the MANAGER context. So an integration holding a company token and this one scope can advance reports through the system steps it is placed on, and an integration acting as a manager can approve whatever that manager can approve. In both cases the ceiling is wherever your workflow puts the step, never a number the agent carries.
Where the dollar limit sits for a Concur agent
Concur is strong on controls for people and reports. Workflow rules can route a report to an extra approver above an amount, expense type limits flag or block entries over policy, cost-object approvers see the approved amount per cost center, and Intelligent Audit and Verify catch receipt problems before reimbursement. Configure all of that before any agent goes near Concur. These are real ceilings on reports.
What none of them gives you is a ceiling on the agent. A Joule agent acting as an employee's delegate builds reports with that employee's authority. An integration acting as a manager approves within that manager's workflow position. A company-level token with the workflow scope advances any report in the system step it is attached to. There is no per-agent monthly total, no lower per-transaction cap for software, and no count of how many reports one integration approved this week.
The larger gap is outside Concur entirely. Concur governs money after it becomes an expense: a card swipe, a receipt, a report. An agent that books travel, renews a subscription or pays for API calls spends first and creates the expense later. SAP's Amex virtual card integration, available to select US customers and planned for all Amex Corporate and Business customers in Q3 2026, gets the card data into Concur faster. It does not stop the purchase.
A rollout checklist for Concur AI agents that touch spend
- Grant scopes by object, not by convenience. Concur's scopes are granular, so use that. A reporting agent needs
expense.report.read, notexpense.report.readwrite, and almost no agent needsexpense.report.workflowstatus.write. - Never give a company-level token the workflow scope unless the step is designed for it. If an external validation step exists for an agent, put amount-based routing before it so large reports reach a person first.
- Connect user-context agents as low-authority users. An agent acting as a manager inherits that manager's approval position. Create a dedicated approver for the agent with the narrowest scope of reports.
- Keep Intelligent Audit and expense type limits strict. They are the controls that still fire when the submitter or approver is software.
- Count what each agent approves. Export approvals by actor weekly. Concur gives you the per-report amount, not a running per-agent total.
- Put agent purchases behind a payment layer before they become expenses. A wallet or virtual card per agent, a monthly budget, a merchant allowlist and an approval threshold on the amount.
How AgentsPay fits alongside SAP Concur
AgentsPay does not replace Concur. Keep Concur as your system for expense reports, travel policy, audit and reimbursement. AgentsPay governs the agent before money moves: each agent gets its own wallet and identity, a hard per-agent spend limit that totals across the month, a per-transaction ceiling, an approval threshold that pauses for a named person, and scoped virtual cards locked to the merchants you allow. Every decision lands in an audit trail you can match against Concur at close.
The limit is a stored number checked before authorization, and an agent cannot edit its own policy. That is the piece a delegate token and a workflow scope cannot supply.
If you are costing the Concur side, our SAP Concur pricing breakdown covers the per-report plans and what Joule Premium adds. The same measurement for the rest of the SAP estate is in SAP Joule agents, and the closest Concur rivals are covered in Navan AI and Expensify agents and Coupa AI and Coupa MCP.