Navigating User Attributes in SAP Business Technology Platform (For Team Management)

Objective

After completing this lesson, you will be able to manage read and writer teams.

The Transition Process from the Previous Model

Effective user management is essential for maintaining a secure and efficient operational environment. In the updated SAP Universal Model (UM), user attributes such as team assignments are managed directly through SAP BTP, streamlining role management and meeting customer demands for centralized administration.

The image displays two screenshots from the SAP SuccessFactors interface. One shows the standard Model_ALL view, and the other shows the Model_READ, Model, and User Attribute views, along with a Team tile displaying user authorization details.

Transition from Previous Model

Previous Setup:​

Standard Models: In older standard models, there was an administration tab within the SAP UM where users could be assigned to specific teams.​

Allocation Process: Teams and user roles were managed within the SM itself, requiring separate administration.​

Current Setup in UM:​

Unified Management in BTP: In the updated UM, roles and team assignments are managed within SAP BTP, allowing for centralized user administration.​

Customer Request: This change was driven by customer feedback, aiming to simplify role management by consolidating it under the BTP interface.

Steps to Manage User Attributes and Teams in BTP

1. Creating Teams in UM:

Team Definition: Teams must be defined within the SAP UM to reflect the functional groups and their responsibilities.​

2. Mapping Teams to BTP:​

Centralized Role Management: Assign users to these teams through SAP BTP to streamline the process and improve role visibility.

Benefits of Centralized Role Management

1. Streamlined Administration:

Centralizing the role management in BTP ensures a more straightforward process for assigning roles and managing user permissions across various applications.​

2. Enhanced Security:​

Managing all roles under one application reduces the risk of misconfiguration and ensures that permissions are granted and monitored consistently.​

3. Improved Visibility and Control:​

Administrators can easily view and manage all user roles and team assignments from a single interface, enhancing operational transparency and control.

User Attributes

After this video you will be able to create teams and give read/write access to the desired group of people.

Step 1: Understanding Teams in Universal Model (UM)

ActionIntroduce the concept of Teams in UM.
Details
  • UM includes a tile called 'Teams' where you can specify reader and writer teams.
  • These teams control access to specific environments for display (reader) and editing (writer).
  • This functionality enhances security by restricting access to certain environments based on team roles.

Step 2: Viewing Environments

ActionAccess and view all environments.
Details
  • Initially, you can see all environments with your user account.
  • To manage specific environments, they must be set up as runtime environments.
  • Ensure environments are activated, even if they contain no artifacts (like fields).

Step 3: Activating an Environment

ActionActivate the environment.
Details
  • Navigate to the environment you want to set up.
  • Activate the environment to make it a runtime environment.
  • This activation can occur even if the environment has no initial artifacts.

Step 4: Creating Reader and Writer Teams

ActionAdd two teams in the Teams tile.
Details
  • Go to the Teams tile in UM.
  • Create a team for readers (e.g., "Demo Read").
  • Create a team for writers (e.g., "Demo Write").
  • These teams will be used to control access to the environment.

Step 5: Adding Teams in SAP BTP

ActionAdd users to teams in SAP BTP, not in UM.
Details
  • Users cannot be added to teams directly in UM.
  • User attributes must be mapped and managed in SAP BTP.
  • Go to the SAP BTP account to manage user attributes and roles.

Step 6: Restricting Access to an Environment

ActionAdd reader and writer teams to the environment.
Details
  • Go to the specific environment in UM.
  • Add the previously created reader and writer teams.
  • Activate the environment with these teams assigned.

Step 7: Creating User Attributes in SAP BTP

ActionCreate and configure user attributes in SAP BTP.
Details
  • In SAP BTP, navigate to the 'Roles' section.
  • Click on 'Create Role' under user attributes.
  • Configure the role with a name relevant to SAP BTP.
  • Add the configuration attribute 'Teams Static' and enter the exact ID created in UM.

Step 8: Mapping Teams in SAP BTP

ActionMap the created teams to roles in SAP BTP.
Details
  • Ensure the IDs match those created in UM under 'Managed Teams'.
  • This mapping connects the user attributes in SAP BTP to the teams in UM.

Step 9: Adding Roles to a Role Collection

ActionAdd the created roles to a role collection.
Details
  • Directly add the new roles (for reader and writer teams) to a role collection.
  • Complete the setup by clicking 'Finish'.
  • Repeat the process for both reader and writer roles.

Step 10: Hooking Teams into Role Collections

ActionIntegrate the teams into specific role collections.
Details
  • Ensure the roles for both reader and writer teams are part of their respective role collections.
  • This setup enables the appropriate access controls for users in UM.

Step 11: Verifying User Access in UM

ActionVerify the user's role in UM.
Details
  • Go back to UM and check the 'Manage Teams' section.
  • Ensure the user is listed under the appropriate teams (reader and writer).
  • Verify that the roles assigned allow for the correct access (view and edit permissions).

Step 12: Ensuring Proper Permissions

ActionEnsure users have both reader and writer roles if needed.
Details
  • To allow a user to view and edit environments, both reader and writer roles must be assigned.
  • Only assigning a writer role will not provide view permissions.
  • Double-check role assignments to ensure users have the necessary access.

Step 13: Summary and Q&A

  • We have covered how to create and manage teams in UM.
  • Discussed activating environments and assigning reader and writer teams.
  • Detailed the process of mapping user attributes in SAP BTP and integrating roles into role collections.
  • Verified user access and permissions in UM.