Using Basic Security Functions

Objectives
After completing this lesson, you will be able to:

After completing this lesson, you will be able to:

  • Apply data and object security

Object and Data Security

Like most SAP systems, SAP Analytics Cloud defines security for both functional and data access. At the core of any security, however, are the individual users of the system.

Users, Teams, Roles

Manage Users and Teams

There are three basic ways of creating users in SAP Analytics Cloud: creating users via SCIM API's and Dynamic User Creation using custom SAML IDP, manually, and by importing from a file.

Note
Importing users from an active directory server is not supported.

All SAP Analytics Cloud users must have the corresponding license and rights assigned to them within the system to access specific tasks. All users and their personal information are preconfigured by the system owner or the administrators of your Platform-as-a-Service (Paas). You can replace the default identity provider with your own custom identity provider.

A Team is a group of users. A user can belong to multiple teams. Each team has a team folder, which can only be accessed by the users in that team.

SAP Analytics Cloud Teams

Manage Roles

There are pre-delivered standard application roles as follows:

  • System Owner
    • Full privileges
    • Only one user can be assigned to this role
  • Admin
    • Full privileges
    • Can access all functional areas and has data read access
  • Modeler
    • Modeling privileges
    • Full access to all models and dimensions
  • Planner/Reporter
    • Planning and reporting privileges
    • Data access granted separately
  • Viewer
    • Planning read only
    • No privileges to change anything
  • BI Admin
    • Full privileges
    • Can access all functional areas and has data read access
  • BI Content Creator
    • Content creator
    • Can create BI content and models
  • BI Content Viewer
    • BI read only
    • No privileges to change anything
  • SAP BTP Content Creator
    • Access to SAP BTP as a datasource
  • SAP BTP Content Viewer
  • Boardroom Creator
    • Can create boardrooms
  • Boardroom Viewer
    • Allowed to view boardrooms

Watch this video to learn about the roles and the permissions associated with it.

Manage Data Security

Who is allowed what kind of access to data in SAP Analytics Cloud first starts with the dimensions and measures. If data must be secured, turn on Data Access Control in the Rights/Access property for the appropriate dimensions/measures. The specific access (read or read/write) to the data is then defined in any models that include those secured dimensions/measures in the Model Preferences. Write access is for planning.

Watch this video to learn about data security options.

Save progress to your learning plan by logging in or creating an account

Login or Register