PI/PO systems are usually located in a private environment so you need to use special SAP services to organize the connection.
- First of all, configure a cloud connector on the system which has access to PI/PO. See the guide.

- Create two services from the command line (or from UI):
cf create-service connectivity lite figaf-connectivity
cf create-service destination lite figaf-destination - Uncomment the two lines from the manifest.yml
- # - figaf-connectivity
- # - figaf-destination
- If your cloud connector has locationId, specify the corresponding value in vars.yml.
- Push the applications as usual:
cf push --vars-file vars.yml - Use virtual host and port in the Agent configuration. User should have appropriate user roles configuration. P4 port usage is not supported for now.
- Check the connectivity. If everything is fine, you will see the tests passed except PI libraries and EJB API access (it's expected for BTP deployment):

Specific services
Normally, it's enough just to expose root url path with all sub-paths:
If you want to specify specific services directly instead of just root url path, define the following services with `Path and All Subpaths` access policy:
- /dir/query/int
- /rep/query/int
- /dir/read/ext
- /rep/read/ext
- /dir/hmi_channel_xml/int
- /CommunicationPartyInService
- /BusinessComponentInService
- /BusinessSystemInService
- /ChangeListInService
- /CommunicationChannelInService
- /ConfigurationScenarioInService
- /IntegratedConfigurationInService
- /IntegratedConfiguration750InService
- /SenderAgreementInService
- /ReceiverAgreementInService
- /ReceiverDeterminationInService
- /InterfaceDeterminationInService
- /XISOAPAdapter
- /AdapterMessageMonitoring
- /webdynpro/dispatcher/sap.com/com.sap.xi.adminweb/AdminApp (used for user access test only)
- /webdynpro/dispatcher/sap.com/tc~lm~itsam~ui~mainframe~wd/FloorPlanApp
- /webdynpro/resources/sap.com/tc~lm~itsam~ui~mainframe~wd/FloorPlanApp
- /mdt
- /AdapterFramework/ChannelAdminServlet
- /BPMFacadeBeanImplService/BPMFacadeBeanImpl
SAP PRO system user roles configuration
Be sure that the user used in Agent configuration has roles depending on the Figaf Tool tools you are going to work with:
- Testing Tool: SAP_XI_API_DEVELOP_J2EE (to have read/write permissions in the integration directory), SAP_XI_MONITOR_J2EE (to use AdapterMessageMonitoring WS API for fetching payloads that required for SAP LOG Module integration), and custom role (to send messages through created XI channel) with the following action:

- Support Tool: SAP_XI_ALERT_CONSUMER.
- Migration overview and PI agent reports, and you would like to add BPM related interfaces: SAP_BPM_SolutionManager (used during report generation, otherwise the error occurs Requesting user does not own the permission 'bpm.solutionmanager' which is required for this call.).