Authorization objects are defined within roles and assigned to end users. Through these roles, end users are permitted to execute specific transactions with clearly defined authorizations.

When you use transaction PFCG to create a new role or modify an existing one, the first step is to define the transactions that are assigned to the role. These transactions are then displayed in the user menu. If a user attempts to start a transaction from the SAP standard menu that is not assigned to their role, the system issues an error message.
Within authorization maintenance, you generate an authorization profile based on the selected transactions. When you assign Document Management transactions, the system automatically proposes the required authorization objects for DMS.