Describing SAP Fieldglass Configuration Manager Features and Updates

Objective

After completing this lesson, you will be able to describe new or updated features in SAP Fieldglass related to Configuration Manager

User Role Based Visibility Across All Connectors

Overview & Use Case

Many companies operate in complex environments where connectors drive automated processes, integrations, and data exchanges. As connector usage grows, so does the need to control visibility for different User Roles. In this enhancement, a new company configuration Enable user role based visibility for all connectors gives configuration managers a centralized switch to apply visibility rules across every connector in the tenant. When this option is enabled, all connectors automatically adhere to user role–based visibility.

In this video, you'll learn about User Role Based Visibility for Connectors introduced as part of the SAP Fieldglass 2026.05 release.

UI Impact & Workflow Changes

For this option to appear in connectors, it must be enabled in the company configuration.

Company Details Page displaying several active and inactive fields. Among them is Enable User Role Based Visibility For All Connectors. A green checkmark next to it indicates that it is active for the tenant.

Companies that prefer selective control can leave the company configuration disabled and manage visibility individually through the new connector-level setting Enable user role based visibility?.

A Set Up Connector configuration interface. The left sidebar contains a navigation menu with sections including Welcome, Enable, Setup, Connector Header, and Security. The main content area displays the Setup section, which allows users to customize delimiters, volume thresholds, and notifications for success/failure during execution. It includes a Delimiter field, an Asynchronous? field, and an Enable user role based visibility? option with Yes selected, accompanied by a yellow warning box explaining that when this feature is enabled, a company administrator must associate user roles with the connector via the User Role admin module. Below this are additional optional settings for Encoding, Upload Data Format, and Pre-Processors.

This approach provides flexibility for companies. It supports consistent visibility across various user roles through selective connector-level visibility control. The result is a predictable and manageable visibility framework that reduces security risks and administrative overhead.

Since the main change is within the Company Configuration settings for a tenant, the only impactful changes seen within the UI are associated with the User Roles and permissions managed within the Admin menu, along with the Configuration Manager options available when maintaining and enabling individual integration connectors via the Self-Service dashboard.

As mentioned, if the company configuration is not enabled to enforce visibility controls for all user roles, administrators can simply manage this particular permission for each user role as applicable for the buyer.

Edit User Role page displaying a permissions matrix organized in columns including All, Module, View, Financial, Submit, Manage, Approve, Pay, Close, and Others. The table lists various modules such as Financial Data, Home Page Announcement, Integration Connector, Invoice Billing Schedule, and others, with corresponding checkboxes across different permission levels. The Integration Connector row has several checkboxes marked, including in the All, View, and Manage columns.

Configuration Steps

When the company configuration Enable user role based visibility for all connectors is enabled, all connector-level visibility settings are ignored.

Administrators must associate User Roles with every connector through the User Role admin module when this configuration is enabled. Connectors without role assignments are not accessible through subscriptions, web services, or the user interface.

Permissions for the User Role should be restricted so that non-admin Users cannot manage User Roles or modify their associations with connectors.

The Hide on UI option can hide the company configuration from other admin screens, which may limit visibility of this configuration for certain administrative Users.

Company Configuration Changes in Configuration Manager Self-Service Dashboard

Overview & Use Case

The Configuration Manager Self-Service Dashboard initially exposed several areas for management via the associated Company Configuration tile; however, it did not provide access to all configurations for a buyer, leaving a large volume to remain inaccessible due to complexity, legacy dependencies, or required support intervention. These initial limitations created challenges for configuration managers who needed a unified, self‑service experience.

This enhancement closes that gap by making additional configurations available for editing in a controlled, risk‑aware manner. The system evaluates each configuration individually and introduces warnings based on risk, impact, or whether it can be disabled. Additional enhancements have been established to remove former company configurations that are no longer valid for selection in the Self-Service Dashboard. The interface now shows only supported, relevant configurations while retaining required validations and dependencies. This change simplifies the experience for configuration manager users by focusing attention on configurations that are required. It reduces clutter, reinforces product standards, and supports more confident configuration decisions. The result feels cleaner, more intuitive, and easier to manage, especially when onboarding new tenants or reviewing existing setups.

UI Impact & Workflow Changes

Within the Self-Service dashboard, nothing has structurally changed with this enhancement. Configuration Managers will still navigate to the Company Configuration implementation tile, but will now be greeted with more editable configuration options, with sunset items removed or deleted that no longer apply.

Here is a list of newly available company configuration categories and items that Configuration Manager users can now access.

Company

  • Login Authorization Type
  • TLS security check on login
  • Minimum TLS version required for login
  • Blocked TLS ciphers
  • 2-factor authentication for all users
  • 2-factor authentication for SSO or both (SSO and username / password)
  • 2-factor authentication for username / password
  • User account linking
  • Contingent Cost Centers
  • Services Cost Centers
  • Supplier company is automatically linked at onboard action
  • Ariba Supplier Network ID is required on supplier registration

Use Multiple Locations

  • Multiple Locations for contingent
  • Ad-hoc work Location and report-to Location for contingent
  • Multiple Locations for services
  • Ad-hoc work Location for services

Job Posting

  • Populate flexible skills via integration only
  • Job Posting is distributed to Suppliers before it's approved
  • Supplier can submit Job Seekers before approval
  • Rate negotiation

Statement of Work

  • Supplier can view the Lifecycle tab
  • Single line item per statement of work invoice

Machine Learning Features

  • Recommend Qualifications/Skills

Work Order

  • Worker tenure visibility

Worker

  • 2-factor authentication for workers

Consolidated Worker

  • Unique ID is masked (value is always stored encrypted)
  • Do not allow more than 24 hours for a day
  • Combine attributes to create a strong match

Time Sheet

  • Time in / Time out is not validated against total time entered
  • Workers can submit Time Sheet revisions
  • Approved Time Sheets can be revoked
  • Time Sheets can capture more than 24 hours in a day
  • Suppliers can submit revised Time Sheets
  • Workers can enter hours in hundredths
  • Time entry comments
  • Start day of time reporting defaults to the work order start date
  • Date bi-weekly Time Sheets should begin
  • Time sheet frequency
  • Time Sheet Start Day of Week
  • 8 Day Time Sheet Start Day of Week
  • Task Code customer fields are available on Time Sheets
  • Task Code custom fields are copied from previous Time Sheet
  • Supplier review on Time Sheets
  • Buyer can edit time sheet during approval
  • Buyers can submit simplified Time Sheets
  • Generate separate Invoices for reversed and revised contingent Worker Time Sheets
  • Generate separate Invoices for reversed and revised SOW Worker Time Sheets
  • Max number of weeks for Download Draft/Rejected Time Sheets search

Expense Sheet

  • Supplier review on Expense Sheets
  • Buyer can edit expense sheets
  • Workers can submit Expense Sheet revisions
  • Suppliers can submit revised Expense Sheets on behalf of Workers

Invoice

  • Auto Invoice Type
  • MSP Suppliers can create Invoices
  • Invoice code max number of characters

Ariba

  • Ariba integration for multi-line SOW
  • Tax Invoice with PDF attachment
  • Tax Invoice with cXML attachment
  • Ariba Service Confirmation integration
  • Include SES Attachments

Configuration Steps

  • User account linking
  • Login Authorization Type
  • TLS security check on login
  • Minimum TLS version required for login
  • Blocked TLS ciphers
  • 2-factor authentication for all users
  • 2-factor authentication for SSO or both (SSO and username / password)
  • 2-factor authentication for username / password
  • 2 factor authentication for workers

It should be noted that many of these configuration options may only be editable if certain parent configurations are active, while others may still require additional manual steps to ensure the related updates are fully and correctly implemented, requiring additional assistance from the SAP Fieldglass Product Support team. If these steps are not carried out, the system may experience broader impacts affecting users and related configurations.

The system classifies each configuration and determines whether to expose it, restrict it, or add warnings.

License‑controlled configurations must have a corresponding entry in the license table before they appear in Configuration Manager.