BTP Settings for Process Insights

Objective

After completing this lesson, you will be able to explain which steps are carried out on the Business Technology Platform (BTP) in the Global Account and Sub-Account and how an SAP Signavio Process Insights Tenant can be created with the help of the Booster. You will also have familiarised yourself with the authorisation and user concept.

Global Account

Banner to show Step 2 of Administrators Collaboration
The graphic shows three persons in the upper part. Three people represent the different administrators for the source systems, SAP Signavio Process Insights, and BTP. In the lower part, the systems or Platforms visualized and their relationships represented with arrows. In addition, the 5 steps of collaboration between these persons are shown on a timeline. These steps need to be performed twice for test and production.

In this section, step 2 is considered in the interaction of administrators.

The banner indicates that this section is aimed at the administrator of the BTP.

This section of the course is relevant for: SAP BTP Administrators

BTP Setting for SAP Signavio Process Insights

The banner lists the steps of this section.

SAP BTP Global Account

In the previous chapters, the SAP Source System Administrator has dealt with identifying possible SAP on-premise and SAP cloud source systems and checking that they fulfil all the necessary requirements.

In this section, we describe the activities on the SAP Business Technology Platform (SAP BTP) to create the SAP Signavio Process Insights tenant, first users, roles and authorisations.

Hint

We explain how to work with the „Standard Base Package".

If you have access to the SAP Signavio Process Insights solution as part of the "RISE with SAP package" or if you're using the "partner application plan" please check the small variances in the documentation .

As a new customer of SAP Signavio Process Insights, you may or may not have previously had a global account in SAP BTP. 

  • If a new global account is set up for your organization when you become an SAP Signavio Process Insights customer, you receive welcome emails from SAP BTP about the global account set up for your organization in SAP BTP. These emails are sent to the email address specified in your contract. One email contains confirmation of what was provisioned and the other email contains the global account URL and logon credentials. The person in your organization named as the main IT contact in your contract is the person who is automatically given access to the global account and is assigned the entitlements. So, this person is the only person who is initially the global account administrator. The S-user specified in the welcome email has an SAP BTP user with the Global Account Administrator role collection for your global account and this account has the entitlements for SAP Signavio Process Insights. SAP recommends assigning at least one additional colleague as a global account administrator. Assigning an additional global account administrator ensures your organization can still access the global account if the initial colleague is absent. If you're new to working with SAP BTP, see Log On to Your Global Account in the SAP BTP documentation for information.
  • If your organization already has one or more global accounts and is licensed for a new subscription for an existing global account, the initial access email with credentials from SAP BTP is not sent again. The global account administrator for the existing global account is the global account administrator for the global account.

Optional: SAP BTP Cockpit Getting Started Videos

When you are new to SAP BTP you can check out the following videos from SAP BTP for help with getting started:

Entitlements and Subscriptions

Entitlements are assigned for the set of services that your organization has purchased or is entitled to use. Your global account administrator can check the entitlements of your global account in the SAP BTP cockpit. To check the plan entitlements for SAP Signavio Process Insights, you (the global account administrator) can choose Entitlements > Service Assignments and select SAP Signavio Process Insights to see what plan entitlements are configured. Your global account should have entitlements for:

  • the SAP Signavio Process Insights application and
  • API services.

Now you're on

The banner indicates that tasks need to be completed.
  • Check your entitlements ("SAP Signavio Process Insights application" and „API services").
  • Work on the next section (running the booster) for details and watch the video about the BTP Booster for SAP Signavio Process Insights to get a good understanding of the input needed and decisions to be made.
next chapter

Booster (Sub-Account)

Users in Booster

The image is a table which is showing the roles assgined to Administrators and Developers on BTP and in the application via the booster.

There is a booster available to prepare your account for SAP Signavio Process Insights. During the execution you have the option to get users created and authorizations assigned for BTP and the application SAP Signavio Process Insights.

The booster distinguishes between two user categories:

  • Administrators and
  • Developers.

Both user types receive role collections for both

  • the BTP subaccount as well as for
  • the SAP Signavio Process Insights application

assigned.

BTP Roles:

  • Administrators are assigned a role collection on the BTP as a „BTP subaccount administrator".
  • Developers are assigned a role collection on the BTP as a „BTP subaccount viewer".

SAP Signavio Process Insights Roles:

  • Administrators are assigned a role collection in the application as „administrators" and „users".
  • Developers are assigned a role collection in the application as a „user"

Hint

If you want to create SAP Signavio Process Insights application users only you do this later on BTP and not via the booster. We will present an overview of the delivered roles and role collections in a later section of this e-learning.

Booster Process Overview

The picture shows the concept of creating two tenants with the help of the booster. The sub-accounts as well as users will be generated via the booster

BTP Booster for SAP Signavio Process Insights

When you have access to your SAP BTP global account, you can use the booster available to prepare your account for SAP Signavio Process Insights. The booster is a wizard that guides you through some short steps to automate the tasks to set up your SAP Signavio Process Insighs in SAP Business Technology Platform (BTP).

Hint

You are executing the booster two times (2x):

  • once for the TEST tenant to get a quality assurance system connected and to learn and test the procedure and functions (using the Entitlement Service Plan "test")
  • secondly for the PRODUCTIVE tenant where the productive source system will be connected to for data load (using the Entitlement Service Plan "standard").

Watch this introduction video to understand how you can prepare your account for SAP Signavio Process Insights in SAP Business Technology Platform (SAP BTP).

You will execute the following steps on BTP:

  1. From your global account in the SAP BTP cockpit, choose Boosters
  2. Search for SAP Signavio Process Insights. Get more information about what the booster does by choosing the tile.
  3. Launch the booster by choosing Start.
  4. The booster wizard loads and the prerequisite checks run automatically. These checks ensure that your user account has the required authorizations to subscribe to services and that your SAP BTP global account has the entitlements for SAP Signavio Process Insights.
  5. When the check has completed successfully, choose Next
  6. In the Select Scenario step, specify whether you want to create a new subaccount or select an existing one.
  7. In the Configure Subaccount step, provide the details for your subaccount.Select the plan you want to subscribe to based on your entitlements. Only those plans that you're entitled to are available (select „test" for the test tenant and „standard" for the production tenant). And specify the relevant details for the subaccount if you're creating a new one.
  8. In the Add Users step, configure the authentication service for users, typically identified by email address, who will be working with the SAP Signavio Process Insights application. There are two types of users:

    - Platform users are usually developers, administrators or operators who deploy, administer, and troubleshoot applications and services on SAP BTP. These users are authorized using platform roles.

    - Application users use the applications that are deployed to SAP BTP, for example, administrators and business users of the SAP Signavio Process Insights application.

    These users are authorized using application-specific roles.

    A) Select two identity providers, one for the authetication of platform users and one for the authentication of application users.

    B) Enter the email addresses of the users you want to be authenticated and authorized to use the SAP Signavio Process Insights application.

Now you're on

The banner indicates that tasks need to be completed.
  • Check that you do have all needed details and access rights in BTP to run the booster.
  • Run the booster.
  • By entering Administrators and Developers in the booster you create initial users on SAP BTP and in the application SAP Signavio Process Insights

Hint

Execute the booster two times (2x):

  • once for the TEST tenant to get a quality assurance system connected and to learn and test the procedure and functions
  • secondly for the PRODUCTIVE tenant where the productive source system will be connected to for data load.
next chapter

Manage Application User & Authorization

Authorization Concept Overview

The picture contains out of 3 area to visualize the authorization concept. Data Visibility is one part of the authorization concept. The other two parts are Administration Tasks and Special User Tasks

Manage Application User & Authorization:

Before you create additional users for end users of the SAP Signavio Process Insights application, you should familiarize yourself with the delivered roles and role collections.

Roles and Default Role Collections

Get an overview of the roles that provide access to the SAP Signavio Process Insights application and the default role collections in which they are included. SAP Signavio Process Insights uses the SAP BTP concept of role collections to provide role-based access control to application users. The table below lists all the roles available for SAP Signavio Process Insights and what each role allows users to do. Default role collections that include these roles are created when you set up your subaccount and subscribe to the application using the booster provided.

Hint

Please always check the lastest version of the documentation „Roles and Default Role Collections"

Roles

The default roles can be grouped by (A) roles for dedicated tasks / features in the application and (B) roles that allow you data visibility.

(A) Tasks

The standard features (Process Flows, Standard Performance Indicatior, Correction Recommendations, Innovation Recommendations and Value Analysis) are accessable for all users. Some task / features in the application are protected by dedicated authorization roles. Dedicated authorization is available for the "Application Administration" (ADMIN) and the "Data Privicy Administration" (DATA_PRIVACY_ADMIN). These roles do not authorize for any of the features for business users.

Additionally there are default role templates for the special user tasks „Transformation Planning" (TRANSFORMATION_PLANNING) and the „editing of the value analysis parameters" (EDIT_VALUE_ANALYSIS).

Here you find a list of Role-Templates for Special User Tasks

RoleDescription
ADMINAdministration screen of the application
DATA_PRIVACY_ADMINData Privacy Management screen of the application
EDIT_VALUE_ANALYSISEdit button on the Value Analysis screen
TRANSFORMATION_PLANNINGTransformation Planning screen of the application

(B) Data Visibility

To get data displayed the relevant roles for end-to-end processes (E2E) or lines of business (LoB) need to be assigned to the user / user group. Data Visibility can be restricted by End-to-End (E2E) Processes (Roles with technical name "E2E_Process_ …") or via Line of Business (LoB) (Roles with technical name "LOB_ …"). Personal Data and Monetary Values are managed via dedicated roles (MONETARY_VALUES and PERSONAL_DATA).

Here you find a list of Role-Templates for E2E-Processes

E2E_Process_DTRData for the Governance end-to-end process
E2E_Process_HTRData for the Recruit to Retire end-to-end process
E2E_Process_ITMData for the Idea to Market end-to-end process
E2E_Process_OTCData for the Lead to Cash end-to-end process
E2E_Process_PLANTPData for the Plan to Fulfill end-to-end process
E2E_Process_PTPData for the Source to Pay end-to-end process
E2E_Process_RTRData for the Finance end-to-end process
E2E_Process_RTSData for the Acquire to Decommission end-to-end process

Here you find a list of Role-Templates for LoBs

LOB_AMData for the Asset Management line of business
LOB_COMMERCEData for the Commerce line of business
LOB_FINANCEData for the Finance line of business
LOB_HRData for the Human Resources line of business
LOB_MANUFData for the Manufacturing line of business
LOB_MARKETINGData for the Marketing line of business
LOB_RDEData for the R&D/Engineering line of business
LOB_SALESData for the Sales line of business
LOB_SERVICEData for the Service line of business
LOB_SOUR_PROCData for the Sourcing & Procurement line of business
LOB_SUP_CHAINData for the Supply Chain line of business
LOB_SUSTAINData for the Sustainability, Compliance, and Enterprise Strategy line of business

Here you find a list of Role-Templates for special data visibility

MONETARY_VALUESData relating to monetary values
PERSONAL_DATAData considered personal data, such as customer, supplier, or user IDs

Role Collections

Role collections contain one or more single roles. The following role collections are delivered:

SAP Signavio Process Insights AdministratorADMIN
SAP Signavio Process Insights Data Privacy AdministratorDATA_PRIVACY_ADMIN
SAP Signavio Process Insights User
  • all roles E2E-PROCESS_...
  • all roles LOB_...
  • MONETARY_VALUES
  • PERSONAL_DATA
  • EDIT_VALUE_ANALYSIS
  • TRANSFORMATION_PLANNING

Hint

These role collections are used by the booster for the application authorizations of the users for SAP Signavio Process Insights.

Now you're on

The banner indicates that tasks need to be completed.

The end user authorization concept is optional. You can make use of the predelivered roles and role collections to set up users.

  • Discuss the end user authorization requirements.
  • Define individual role collections for your organisation.

Creating Role Collections

One way to define a role collection is to create a new role collection. After you've entered a name and description, you find the new role collection in the list of role collections. You can then add the roles you need and assign users and user groups. If you have an existing role collection that you want to use as a template, it's a good idea to copy it. The copied role collection includes all of the roles of the origin. However, it doesn't include the users or user groups. You can give it a new name and description. You can find the copy in the list of role collections and assign users and user groups.

These are the steps to create new role collections in your SAP BTP subaccount:

  1. Open the SAP BTP cockpit.
  2. Go to your global account and subaccount
  3. Choose Security > Role Collections.
  4. To create a new role collection, choose + (Create New Role Collection). To copy an existing role collection, choose Copy at the end of the row.
  5. Enter a new name and description. If you copied an existing role collection, you can see the included roles.
  6. Save your changes.
  7. You can now add or remove roles and assign users or user groups.

For more information about creating role collections, see

Now you're on

The banner indicates that tasks need to be completed.

When you decided to have individual role collections for your organisation:

Create the new role collections for your organisation in your SAP BTP Subaccount.

Hint

The role collections are one part of the end user authorizations for the SAP Signavio Process Insights application (maintained on BTP). Role collections are NOT used to give access to source systems and their data. Access to specific source systems and their data (including attribute-based access control) must be configured in SAP Signavio Process Insights (in the application) after your source system has been connected. This release is the second necessary step to authorize end users for the data access and capabilities of SAP Signavio Process Insights. (See seperate Chapter in this e-learning)

next chapter

Create Users for SAP Signavio Process Insights on SAP BTP

Banner to introduce the lesson Create Users for SAP Signavio Process Insights on SAP BTP

As a subaccount administrator, you set up user access to the SAP Signavio Process Insights application in the SAP BTP cockpit. To do this, you must ensure that users can log on (user creation), as well as give them authorization to use the application's features they need by assigning role collections (role assginment).

All users in the subaccounts of SAP BTP are stored in identity providers, either in the default or in a custom identity provider. SAP BTP creates a copy of the user in the subaccount when a user-related action happens. The copy of the user in the subaccount is called shadow user. As an SAP BTP Sub account administrator, you can create shadow users in your subaccount and you must determine which identity provider stores the user. You can then give the user authorizations by assigning role collections to the user.

  1. Open the SAP BTP cockpit.
  2. Go to your global account and/or subaccount
  3. Choose Security - Users.
  4. Choose Create. The SAP BTP cockpit displays a new row where you can enter the user data.
  5. Enter the user ID and e-mail address.
  6. Choose the identity provider where the user is stored. The dropdown list displays the identity providers configured in the trust configuration of your subaccount.
  7. Save your changes.

You can now proceed to assign role collections to the new user.

Users stored in your identity provider can now log on the SAP Signavio Process Insights application with the permissions granted by the assigned role collections.

For more information about creating user on BTP check the BTP documentation „Create Users"

Now you're on

The banner indicates that tasks need to be completed.

The end user authorization concept and setting up application users is optional. You can set up application users (w/o BTP roles assigned) based on your individual role collections:

  • collect the needed user details you would like to set up in your BTP identity provider
  • create the user master data and assign the required role collections to the user.

Hint

Source System Authorization maintained in SAP Signavio Process Insights

Once your source system has been connected, an application administrator of SAP Signavio Process Insights must explicitly grant users access to that system or system/client combination. By default, no users are authorized to access the data for new source systems connected. Administrators can also restrict access to system data to specific users. In addition, they can use attribute-based access to restrict access to data based on organizational attributes, where supported (see seperate section in this e-learning).

Log in to track your progress & complete quizzes