
Access to business applications is controlled by role-based authorization management. You assign Business Roles to Business Users, and the roles provide access to business tasks. Business Users are defined as employees, contractors, or other individuals that need access to the SAP S/4HANA Cloud system.
How to Find Business Roles for a Scope Item
- Navigate to SAP Best Practices for SAP S/4HANA Cloud .
- Select your country localization from the Version drop-down list
- In the Solution Scope section, expand the relevant scope item group
- Select a scope item
- Download the test script
- Navigate to the Roles section of the test script
A Business Role is assigned to a Business User to grant permission to access applications in SAP S/4HANA Cloud.
One or more Business Catalogs have been assigned to a Business Role. Business Catalogs include access to one or more applications, dashboards, or displays of data.
Administrators can control visibility to the data granted through the catalog by applying General Restrictions to Business Catalogs. By maintaining access restrictions, you can define the subset of all existing business objects a user can view (read) or edit (write) when working with a particular business role.
The Business Catalog defines which access categories are available (Value Help, Read, Write), and for which fields restriction values can be maintained. The fields vary per catalog, as they are based on the fields within the apps in the catalog. The Business Role aggregates restrictions for all Business Catalogs.
Administrators define a restriction based on a supported field (e.g. company code, country, controlling area, etc.). Supported restriction fields vary per Business Catalog, as they are based on the fields within the apps in the catalog. You can restrict data access for the Value Help, Read, and Write separately. Read access always includes Value Help access, and Write access always includes Read access.
How to identify the Business Catalog(s) mapped to a Business Role and the Fiori application(s) mapped to a Business Catalog :
- Log into the SAP S/4HANA Cloud system.
- Select the Manage Business Roles application from the Launchpad.
- Select a Business Role.
- Select the Assigned Business Catalogs tab to view the standard Business Catalogs assigned to the standard Business Role.
- Select a Business Catalog.
- Select the Catalog Description tab to view the Functional Description, Authorization Criteria, and Associated Catalogs information.
- Select the Applications tab to view the Fiori apps mapped to the Business Catalog.
NotePlease do not edit SAP Standard Business Roles directly. To customize Business Roles, always make a copy of the SAP Standard Business Role or use the option Create From Template in the Maintain Business Roles application.
To apply General Restrictions, an Administrator should first make a copy of the SAP Standard Business Role, or create a new role based on the SAP Standard Business Role Template. For example, if you need to restrict access in the Accounts Payable Accountant Business Role for some users to only Company Code 1710 (United States), and for some users to only Company Code 1010 (Germany), you will create two new Business Roles based on the SAP Standard Accounts Payable Accountant role. You should name the roles accordingly (e.g. Accounts Payable Accountant_1710). In the first business role, you will edit the role and maintain the restriction value(s) for the entire Business Role (i.e. define the Company Code field = 1710). Then, you may edit the individual business catalogs within the role and define the access category (i.e. Value Help, Read, Write) as Restricted. When you create a new Business Role, the Read access is set to Unrestricted and Write access is set to No Access by default. When an access category is Restricted, you must select a specific field value (e.g. Company Code = 1710) or grant unrestricted access. If you leave fields empty within a business catalog, a user will be assigned No Access to the field in the business catalog's granted apps.