Describing SAP SuccessFactors Permission Roles

Objectives

After completing this lesson, you will be able to:
  • Describe Role-Based Permissions.
  • Manage Permission Roles.
  • Identify the different role types.

Permissions Overview

In this section, you will learn about setting up internal access controls using Role-Based Permissions (RBP).

The SAP SuccessFactors Security and Access Management can be broken down into these areas:

  • Role-Based Permissions
    • Purpose: Controls access within the SAP SuccessFactors system
    • How it works: Assigns permissions based on user role (e.g., employees, managers, HR admins).
    • Example: An HR admin can view all employee records, while a manager can only see their direct reports.
  • Single Sign-On (SSO)
    • Purpose: Provides seamless user login without requiring multiple passwords.
    • How it works: Uses authentication protocols (e.g., SAML 2.0) to allow users to log in once and access multiple systems.
    • Example: A user logs into their corporate portal and gains access to SAP SuccessFactors without entering another password.
  • Identity Authentication Service (IAS)
    • Purpose: Serves as an authentication hub for SAP cloud solutions, enhancing security
    • How it works: Manages user authentication centrally and integrates with SSO. Can enforce multi-factor authentication (MFA).
    • Example: Before accessing SAP SuccessFactors, a user is verified through IAS, which checks credentials and applies security policies.

IAS and SSO are out of scope in this guide. We only cover Role-Based Permissions, which control who can access which features/data in SAP SuccessFactors Employee Central.

Role-Based Permissions Main Concepts

RBP is a dynamic method of assigning permissions. Role-Based Permissions are comprised of several elements.

  • Permission Roles: Contain a set of permissions and role assignments
  • Permissions: A set of transactions or tasks that employees perform in your organization (e.g., edit job title, create reports, reset passwords)
  • Role Assignment: A relationship containing the granted and target population assigned to a permission role
  • Granted Population Group: Users who are granted the permissions
  • Target Population Group: Users whose data can be accessed or managed by the granted group
The diagram shows the different elements of Role-Based Permissions.

You can group employees with similar tasks to perform and create a Granted Population Group. This group typically consists of employees who share certain attributes, such as Job Code, and require access to similar tasks in the system.

For some permissions, you need to define a Target Population. A Target Population is a group of users that need tasks to be performed on their behalf.

For example, you could group all US-based HR Talent Managers as the granted population who will manage the employment records of US-based employees – the target population.

Role-Based Permissions are designed so that users will match more than one role. As a best practice, we recommend configuring roles by starting with the most generic role, as in All Employees Role, and casting the net as wide as possible to include all of the permissions given to everyone.

Permission Roles

A Permission Role is a collection of specific permissions that determine what actions a person can perform. For example, the HR-Talent Manager Role consists of the following permissions:

  • Edit Compensation
  • Edit Job Title
  • Hire Employee
  • Reset Passwords
  • Terminate Employee

This set of permissions can be assigned to different groups using Role Assignment.

The diagram shows how permissions are assigned using Role Assignment.

Administrators can define the permission roles by navigating to Manage Permission Roles using the Action Search.

The screenshot shows how assignments and permissions are managed in Manage Permission Roles.

In Manage Permission Roles, you can review, copy, and edit existing roles or create new roles. You can review and edit the list of permissions and the assignment for each role.

Standard Role Types

SAP SuccessFactors delivers standard role types. These are default roles that are similar across all organizations.

  • Employee – all employees that work for an organization
  • Manager – an employee that has employees directly reporting to them
  • Matrix Manager – dotted-line manager; a larger manager group that spans similar groups, like managers within the same department.
  • HR Manager – a human resources representative with direct reports
  • Custom Manager – additional special manager relationship
  • Second Manager – alternate manager used for salary planning
Shows the standard role types available when defining role assignment.

These standard role types can be used when assigning permission roles. For example, when assigning the Manager Self-Service Role, you won't need to group all the managers to create a Manager Permission Group; the standard role type Manager is used instead.

Log in to track your progress & complete quizzes