Embedded Analytics has three user types: Administrator, Author, and Viewer.
Administrators can create, edit, and share stories, as well as create and manage users.
Authors can create, edit and share stories
Viewers can only view stories and cannot edit or create them. However, since stories can be dynamic, viewers can apply filters, change the format of charts and tables, and save those changes to a static file such as a PDF.

Users are created and managed using Single Sign-On for sales performance management. This is done in the SAP Cloud Identity Service and SAP Identity Provisioning applications.
While creating users in SAP Identity Authentication, you must ensure that the Login Name is the same as the userid of the participant in Incentive Management. If these values do not match, no data will be displayed in Embedded Analytics stories.
Once you have created users, associate each user with the Application user group for Embedded Analytics, APP_SCAN. Then, add users to one of the following Authorization user groups, depending on which role the user will have.
• ADMINISTRATOR_COMM-SCAN - corresponds to Embedded Analytics administrator
• AUTHOR_COMM-SCAN - corresponds to Embedded Analytics author
• AUTHENTICATED_COMM-SCAN - corresponds to Embedded Analytics viewer
The image below shows a user named Paula Wolf who should have administrator rights. She is assigned to APP_SCAN to grant access to the application, and ADMINISTRATOR_COMM_SCAN to designate her account as an administrator.

Managing Data Level Permissions
To ensure data security, the default user access to data is set to "none". This means that even if a user has Administrator or Author permissions, unless they are granted the data level access they need, they will not be able to see any data in their stories.
Administrators with the correct permissions can grant data level access in the Embedded Analytics Configuration application.

To set data level permissions:
- From the application menu, select Embedded Analytics configuration.
- Select User Settings.
- Select a user from the list.
- Select Set Permissions.
- Select a permission type from the list.
- Select Save.
The data level permissions types include:
- Business Units: This user can see data only in the business units to which they are assigned
- Position Groups: This user can see data only in the position group(s) to which they are assigned
- Positions: This user can see only data for their position and any positions below them in the hierarchy
- All: This user can see all data
- None: This user can see no data