Using Role-Based Permissions: Public Document Version: Q4 2019 - 2020-02-01
Using Role-Based Permissions: Public Document Version: Q4 2019 - 2020-02-01
5 Troubleshooting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159
5.1 How Do Permissions Update When User Information Changes?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159
5.2 How can you check the permissions assigned to a user?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 161
5.3 How can you run an ad hoc report?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 162
5.4 Cross Domain Ad Hoc Reporting Between the RBP and Employee Central Domains. . . . . . . . . . . . . . . .163
5.5 How do you run a user search. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .164
The most recent changes made to this guide are listed below.
Q4 2019
The following table summarizes changes to this guide for the Q4 2019 release.
Updated the employee number limit for Large organizations with up to 1,500,000 What Are Role-Based Permissions?
large organizations using RBP employees can also use RBP now to de [page 8]
sign their security model. We've raised
the limit of employee number approved
for organizations using RBP from
300,000 to 1,500,000.
Added the following permissions: Recruiting Permissions ● When enabled for specific employ
Recruiting ees or permission roles, disallows
viewing a proxied users career tab
● Hide Career Tab for Proxy User
and tile.
● Manage Multistage and Late Stage
● Enables being able to access the
Application Preview
Manage Multistage and Late Stage
Application Preview from Admin
Center.
Added the following permissions: The permissions enable users to receive ● Users without these permissions
alerts relating to the relevant workflows.
● Admin Alerts Object Permissions: can process the same workflows in
○ Invalid Approvers in Employee- the old Admin Alerts. When these
Related Workflows permissions are granted, the work
○ Invalid Dynamic Role Users flows move over to Admin Alerts 2.0.
Admin Alert Field-level overrides are available,
○ Stalled Workflows - Employee meaning that users can be granted
Related
or denied permissions for individual
fields within the objects.
Added the following permissions: Some checks include a "quick fix" that
users can run to immediately correct the
● Check Tool issues found by the check. Users need
○ Allow Check Tool Quick Fix this permission before they can use the
quick fixes.
Added the following permissions for These permissions enable users to man
Manage Pending Hires: age the Manage Pending Hires tool.
Added the following permissions for: ● The permission prohibits roles from
● Succession Planners accessing the Talent Pool tab from
other Succession features and Peo
○ Hide Talent Pool Page
ple Profile.
● Manage Succession
● The permission allows roles to ac
○ Talent Pool Field Configuration cess the Manage Talent Pool Field
Settings in Admin Center.
Added a permission for Document Man The permission is called Manage Docu This permission allows you to separate
agement.
ment Categories document category permissions.
Added the following permissions for User ● This permission allows the Admin to
Management:
access the Manage Login Accounts
● Manage Login Accounts tool.
● Basic User Import ● When the "Enable Control on Basic
User Import in Role-Based Permis
sions"option has been enabled, this
permission allows the Admin to per
form basic user import in the Em
ployee Central-enabled instances.
Added the following permissions to Re Reward and Recognition permissions ● To enable your users to redeem their
ward and Recognition: Spot Awards: supporting the points-based awards pro
awarded points and see their current
gram.
● Spot Award Redemption point balance, set Spot Award
● Spot Award User Balance Redemption to Edit and Spot Award
User Balance to View.
Caution
Make sure to restrict the target pop
ulation to only allow users to see
their own data (Granted User (Self)).
If you set Target Population to
Everyone, then each user will be able
to see everyone's information.
The following table summarizes changes to this guide for the Q3 2019 release.
Added the Change Assignment ID per This permission allows the Admin to
mission change assignment ID using the conver
tAssignmentIdExternal function import.
Q2 2019
The following table summarizes changes to this guide for the Q2 2019 release.
Q1 2019
The following table summarizes changes to this guide for the Q1 2019 release.
No Updates
The following table summarizes changes to this guide for the Q4 2018 release.
We've added the master RBP list to this The list is located in the section called
How to Use the Master list of Role-
guide.
Based Permissions
No Change
No Change.
Q3 2018
The following table summarizes changes to this guide for the Q3 2018 release.
We've updated the topics in this guide for Updated topics include: What are Role-
accuracy. Based Permissions? and all subsequent
topics.
Q2 2018
The following table summarizes changes to this guide for the Q2 2018 release.
Related Information
Filter and search for the role-based permissions specific to your system's implementation and learn how to test
your RBP configruation.
This content is intended for security administrators to enable them to manage Role-Based Permissions (RBP).
It is important to note that RBP is the only permission model that is available to new customers. New customers
cannot disable RBP to use legacy permissions. Existing customers, new companies of Professional Edition or free
trial are not affected.
The first section familiarizes you with the concept of role-based permissions.
The subsequent sections detail the individual tasks that make up the process. Finally, you will find troubleshooting
information in case problems occur with the permissions.
Note
This implementation content covers all general aspects of setting up RBP. The implementation handbooks for
the individual modules may contain additional module-specific information.
Role-Based Permissions (RBP) is a security model that allows you to restrict and grant access to your SAP
SuccessFactors HXM Suite. RBP controls access to the applications that employees can see and edit. This is a
suite-wide authorization model that applies to the majority of the SAP SuccessFactors products.
The RBP security authorization model uses groups and roles to organize employees (groups) and permissions
(roles) to control access to your system; By organizing employees into groups and permissions into roles you can
assign a group of employees the same set of permissions by assigning them a role.
Note
RBP is approved for organizations with up to 1,500,000 employees. We’ll continue to raise this bar in the future.
When in doubt, contact SAP Cloud Support.
Role-based permissions contain three main elements: permission groups, permission roles, and target populations.
● Permission groups are a set of employees who share certain attributes such as City or Job Code and require
access to a similar set of tasks within your system.
● Permission roles are defined as a set of permissions. You can assign the permission roles you define to a
permission group, and if the role requires that you define a target population, meaning a group to perform
tasks for, you assign the target population when you define the role.
● Target populations are groups that are assigned to permission roles when the permission granted is performed
on behalf of other employees.
Tip
We recommend that you create groups before creating roles so that during role creation, you can select the
group for which to grant the role. In addition, you need defined groups for roles that require a target population.
Permission groups are used to define groups of employees who share specific attributes. You can use various
attributes to select the group members, for example a user's department, country/region, or job code.
Example
There might be a permission group called "Human Resources in US", which lists all US-based employees who
work in the HR department. To define this group, you would specify that users must match the selection criteria
"Country/Region = United States" and "Department = HR".
Note
The attributes or selection criteria that are available for defining groups are configurable.
In RBP, you can assign permission roles to permission groups. In addition, you use groups to define the target
population a granted user has access to.
Example
The group "Human Resources in US" might have access to the group "US Employees".
Groups configured with criteria other than specific user names are called dynamic (as opposed to static),
which means that the assignment of employees into and out of a group is automated. For example, a group of
granted users can be “All employees in the Sales department”. As employees are transferred into and out of the
sales department, their permissions will automatically adjust. This automation will save you time and money.
This is especially beneficial for large organizations that need higher levels of administrative efficiency.
Procedure
4. Download a blank CSV template after you've chosen an import type. The Full Replace template has two column
headers, GROUPNAME and USERID. The Delta Replace has an additional Action column.
5. For each user that you add to a group, add the group name to the GROUPNAME column and user's ID to the
USERID column.
Note
For new users, you can create user IDs in the upload file.
Note
Character encoding of your file should be Unicode(UTF-8). The maximum file size is 20MB. If your import
file exceeds 20MB, you can either split the file into several smaller files or request Professional Services to
modify the system configuration file.
If your file has errors, they display at the top of the Import Static Group window.
Note
For one group type, a maximum of two jobs can run at the same time.
Results
After the upload completes, the system sends you a notification with success or error messages. Successfully
created groups display in the group list after refreshing your system.
You can add members to a static group in your system or by importing an excel file to your system.
Procedure
Although you add members to a static group using a spreadsheet, you can delete static group members using the
system.
Procedure
Results
Deleted members will no longer have access to the tasks or data of the group.
Dynamic permission groups are generated automatically when the attributes of employees match the group
selection criteria. Administrators can create and manage dynamic permission groups for both employees and
external users.
Procedure
The available user types vary depending on how your system is configured. Possible values may include:
○ Employee (default)
○ External Learning User
The External Learning User option is only available if you have Learning enabled in your system.
When defining a dynamic group for an external learning user, you can identify an External Source Channel to
complete the criteria for inclusion. This allows external learning users to be defined based on the source of
origin. The external source channel is only available to SAP SuccessFactors Learning customers. The External
Learning User must be enabled in Provisioning for external learner and external source channel to be available.
Tip
When defining External Learning User groups in your system, it is recommended that you do not create
more than 50 groups.
5. Choose the group selection criteria from the People Pool, in the Choose Group Members section.
Depending on the complexity of your permission group selection criteria, you can choose multiple people
pools.
6. In the Search Results screen, enter a search term or click the search, to display all available values.
For some categories, a smaller pop-up window appears where you can enter additional values or information,
such as Time Zone settings. If you select the Team View category, you can use hierarchical relationships to
specify the group. This allows you to apply rules such as: everybody in Carla Grant's team, all levels deep.
7. Make your selection and click Done.
8. If you want to add another condition for defining the people pool, click Add another category and choose a
category and item. If you use two or more categories, this functions as an AND operation, that is, only users are
selected who meet all selection criteria.
Example
If you want to create a group of sales employees working in the US, you would need to choose the category
Department and select Sales. You add a second category Country/Region and select United States.
9. Complex group definitions may require you to use multiple people pools. If you use two or more people pools,
these people pools functions as an OR operation, that is, all users are selected who fulfill the selection criteria
of at least one pool.
Click Add another People Pool and then add categories and items.
Example
You have two different offices: An office in Chicago and an office in Boston. Each office has a Sales team and
a Finance team. You only want to include Sales employees from the Chicago office and Finance employees
from the Boston office. You'll need to create two separate pools then.
Note
10. If there are employees you'd like to exclude from the Permission Group definition, select them in the Exclude
these people from the group section.
11. If you want to prevent the group being updated automatically when new employees match the selection
criteria, click Lock group.
The active group membership number isn't updated automatically when you modify the dynamic group
definition.
13. Choose Done to complete the process.
You can edit, copy, and delete static or dynamic permission groups. For dynamic groups, you can also view the
group's change history.
Context
Note
Procedure
1. Go to the Admin Center Tools and search for Manage Permission Groups.
2. In the Manage Permission Groups screen, click the Take Action dropdown menu next to the permission group
you want to modify.
3. Choose the desired action.
RBP uses permission roles to group a set of permissions. After grouping the permissions into a role, you can assign
the role to a group of users, granting them access to certain tasks and features in your system.
Permission roles consist of a set of permissions that give employees access rights to an employee or a group of
employees. As such an employee or a group that has been granted with a permission role has access to certain
aspects of the SuccessFactors application or to aspects of employee data. With this access, they can perform
functions within the application for other groups of employees.
Role-based permissions allow you to grant a role to a specific employee, a manager, a group, or to all employees in
the company. The roles can provide very granular permissions, as this example illustrates:
Example
There may be roles such as "HR Compensation and Benefits Manager", "HR Manager for Sales", and "HR
Learning and Development Manager". While all three are HR managers, their roles have been distinctly carved
out — one handling compensation and benefits, another handling the sales team, and the third handling
Learning and Development.
When your permissions roles consist of one or more permissions that require a target population, you'll need to
specify a target to complete creation of the role. Roles that require a target population will contain a permission
that gives a group access to perform actions or view information for other employees.
Example
A Manager may have a role where one permission allows the manager to modify the salary for all of their direct
reports. In this example, the manager's direct reports represent the target population needed for the
permission role.
Note
Permission roles can be created for employees and for external users, such as External Learning Users.
Context
Permission roles contain a group of permissions that can be granted to an employee or a group of employees
known as the Granted Users Circle. In general, it's best practice to define your user groups before defining your
permission roles.
Procedure
Example
If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.
13. Click the Done button to assign this role to the defined users. You are taken back to the Permission Role Detail
page.
14. Click the Save Changes button to complete creating the role.
Next Steps
Once this role is successfully created, the new role will be listed on the Permission Role List page.
Related Information
After creating groups and roles, you'll need to assign permission roles to your employee groups.
Procedure
1. In the Permission Settings section, click the Permission button to specify the permission you want to assign to
the role. The Permission Settings window opens.
2. On the left side of the page, you'll see the different permission categories. Click a permission category to reveal
the different permissions.
Next Steps
You can edit, copy, or delete a permission role, view a summary of a permission role, and view its change history.
Context
When you copy a role, only the permissions get copied over. You will need to manually grant employees access to
this new role.
Procedure
1. Go to the Admin Center Tools and search for Manage Permission Groups.
Role-based permissions support the role of External User and allows the External Learner User limited access to
complete specific tasks or training.
The external user role can be granted to the user type External Onboarding user. Permissions for the external user
role can be set to grant access to the Onboarding home page.
If you have external users, consider creating a management system for them so that you can maintain their access.
Prerequisites
Either Onboarding 2.0 (including Internal Hire Process) or Learning or both must be enabled in Provisioning to reset
the external user password.
Remember
As a customer, you don't have access to Provisioning. To complete tasks in Provisioning, contact your
implementation partner. If you're no longer working with an implementation partner, contact SAP Cloud
Support.
When you have external users in your extended enterprise, your plan for maintaining them must include: resetting
user passwords, granting access, and so on. In most cases, you manage external users as you do any other users.
One exception is target populations. External users can be a unique target population. For example, if you want to
manage external users in Onboarding, you must add All(External Onboarding User) to the target population of users
managed by the administrator.
Procedure
The Resetting User Passwords page appears. From this page you can reset individual user password, or reset
the passwords for a group of users.
2. Select External Users from Onboarding and/or Learning (If enabled) from the Find dropdown.
Enter the First Name, Last Name, or the Username to search for the user whose password you’re trying to
reset. You can filter your search further using Starts With or Exact Match.
3. When the user details appear on the screen, select the user and enter the new password in the New Password:
field and confirm the same in the Confirm Password: field.
4. Click Reset User Password.
Results
Create a role mapping for external learners and grant them the permissions to log in to SAP SuccessFactors and
access Learning.
Prerequisites
You can select additional permissions. For example, you can grant the external learners access to SAP Jam or
Mobile.
9. Click Done.
Next Steps
You can assign a permission role to everyone or to a subset of employees, determined by permission groups, target
populations, or by relationships. When defining a role in RBP, you can assign the role to a group that you've created
or you can assign roles based on hierarchical relationships. Some roles will require that you also assign target
populations, they're only necessary for certain permissions in a role and your system will notify you when a target
population is required.
● Permission groups: You assign a permission role to a defined group of users. However, relationships can also
play a role here as you can define that the granted user's managers have the same permissions. You can also
define how many levels up in the hierarchy you want this permission to be granted.
If you want to grant a role to a named user, you first have to create a group and add the user to this group.
Then you can grant the role to the just created group.
● Target Population: Depending on the permissions included in the role, you might also have to define the target
population. Not all permissions require you to define a target population. For example, if the permission
includes just the access to an application (such as the Learning Access Permission), there is no need to add a
target group. For certain permissions, in the Permission settings screen, a target population must be defined.
This is identified by the "t" icon next to the permission name with the following text displayed: t= Target needs
to be defined.
Note
A target population for an external Learning user can be defined two ways:
○ Select Everyone (External Learner)
○ Select Target population of: and click Select, to select groups
● Relationships: Access groups can be defined using relationships (for example, manager-employee
relationship) that are derived from the job relationship object. These relationships can be hierarchical or non-
hierarchical. You can find more information in the following chapter Using Relationships to Grant Permissions
[page 27].
If you allow the respective managers to have the same permissions, this may have a negative impact on the
performance. The hierarchy then has to be checked whenever such a manager tries to access an element
which was permissioned this way.
After creating your roles, you must assign the role to a group of employees. This ensures that employees are given
access the permissions they need to perform their tasks.
Procedure
You can allow managers to have the same permissions and define how many levels up in the hierarchy you want
this permission to be granted. However, allowing respective managers to have the same permissions may have
a negative impact on the performance. The hierarchy then has to be checked whenever such a manager tries to
access an element which was permissioned this way.
7. Exclude Granted Users:
For some permissions, it might be necessary to exclude the granted users from applying the permissions on
themselves. For this, select Exclude Granted User from having the permission access to themselves.
Example
If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.
8. Click Done to assign this role to the defined users. You are taken back to the Permission Role Detail page.
9. Click Save Changes to complete creating the role.
Next Steps
Target populations are assigned to roles that require tasks to be performed on behalf of another employee.
Context
Target populations allow you to give employees such as managers and administrators access to data or tasks that
need to be maintained for other employees. Depending on the permissions included in the role, you may need to
define the target population. Not all permissions require you to define a target population. For example, if the
permission includes just the access to an application (such as the Learning Access Permission), there is no need to
add a target group. For certain permissions, in the Permission settings screen, a target population must be
defined. This is identified by the "t" icon next to the permission name with the following text displayed: t= Target
needs to be defined.
Procedure
6. Click Select to select the target groups that you want to assign to this permission role.
7. Exclude Granted Users:
For some permissions, it might be necessary to exclude the granted users from applying the permissions on
themselves. For this, select Exclude Granted User from having the permission access to themselves.
Example
If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.
8. Click Done to assign this role to the defined users. You are taken back to the Permission Role Detail page.
9. Click Save Changes to complete creating the role.
There are relationships that can be specified through employee fields, and managed through tools, like the
employee data.
General Relationship Types: Hierarchical relationships are characterized by a reporting line between the granted
user and the target user. These are relationships between employees and their managers, and employees and their
second managers or alternate managers. Non-hierarchical relationships on the other hand are single-level
relationships. These include the relationship of an employee to the HR manager, the matrix manager and custom
manager. While each employee can have only one Manager, one Second Manager and one HR Manager, they can
have multiple Matrix Managers and Custom Managers.
Employee Central Only: If employees have global assignments (that is, a job in another country/region), they have
both a home manager and a host manager. In addition, they have a home HR manager and a host HR manager. All
managers need to have access to both the home jobs of the employees as well as to the host jobs of the employees.
This is covered by the following additional relationship types for global assignments:
Custom Manager
As a delegator you can assign delegates to perform actions on your behalf that affects other employees in your
organization.
As a manager, you can use the Delegate A and Delegate B relationship roles to assign permissions to up to two
individuals for each role, allowing them to act as your delegates. The delegate users, you assign, will have access to
your direct and indirect reports and can perform tasks that have been permitted to you, while acting as your
delegates. You can assign up to two delegates per delegate role and each delegate can be given separate tasks or
permissions to cover different functional or regional areas.
Note
You must configure Delegate relationship type in the Employee Central Picklist. After you've configured your
delegates, you'll see the option to give permissions to this relationship type in your system. For more
information about how to configure picklists, see the topic Picklist Configuration for Employee Status and Job
Relationship Type.
You might use a delegate when you want to assign delegates permissions in different functional areas.
You can also assign permissions to delegates that separate functionality according to locations.
Note
For customers still using Oracle, you may have access to configure delegate relationships in Employee Central
but the delegate relationships won't be viewable in Role-Based Permissions.
Understand how to use hiearchy depth when assigning permissions to your users.
When granting permissions using hierarchical relationships, you can specify how many levels down to go in the
hierarchy for the target population. For example, you can indicate that Managers can see performance ratings on
their direct reports (1 level deep), or allow it to go deeper into their team, that is 2 levels down or all levels.
When granting permissions to non-hierarchical relationships (HR, Matrix and Custom Managers), you can follow
this non-hierarchical relationship for only one level. Beyond the first level, you can cross over to the standard
manager hierarchy if desired to go deeper.
For example, using the Matrix Manager relationship, you can use hierarchical depth to accomplish the following:
● 1 Level Deep: Matrix Managers can view ratings information for their Matrix Reports.
● 2 Levels Deep: Matrix Managers can view ratings information for their Matrix Reports and the Direct Reports of
their Matrix Reports.
● All Levels Deep: Matrix Managers can view ratings information for their Matrix Reports (1 level deep) and the
Direct Reports, all levels deep of the manager hierarchy of their Matrix Reports.
The master permissions list is a one-stop-shop for suite-wide permissions and general RBP information. Customize
your filter criteria to list permissions for your specific product permissions set.
The permissions list allows you to search for and filter permissions across products that use the RBP security
model. You can start by selecting your products from the Solution filter and narrow your selection by filtering the
components for your products and searching for specific keywords or phrases. To quickly understand the
permissions for your products, your filtered list displays all the available permissions for your combination of
products, where they are located in the system, and how they will function once enabled.
At first glance, the permissions table displays all available permissions in the SAP SuccessFactors suite. When
you've narrowed your search criteria and you're satisfied with the list of permissions for your products, you can
download the permissions into a CSV file for continued use. In your system, you can manage permissions by
creating roles in the following location: Admin Center Set User Permissions Manage Permission Roles
Related Information
This is a master list of Role-Based Permissions used across the SAP SuccessFactors HXM Suite.
Remember
All customers have access to the SAP SuccessFactors platform. General permissions that are common to
many or all SAP SuccessFactors solutions, such as User Login or User Search permissions, are listed below as
part of the "Platform" solution.
If you use filters to find permissions related to a specific solution, remember to include "Platform" in your filter.
It is very likely that some of these permissions are relevant to your system.
Platform Administration Admin Check Tool Allow Check Tool This permission al
Quick Fix
lows users to fix
configuration and
data issues.
Platform Administration Admin Admin Alerts Access Admin This permission al
Alerts
lows users to access
the admin alerts tile.
Platform Administration Admin Admin Alerts Configure Alert This permission al
Types lows users to config-
ure the alert types.
Platform Administration Admin Admin Alerts Trigger Rerun This permission al
lows users to trigger
the rerun after alerts
have been proc
essed.
Platform Common Per Admin Admin Center Manage Upgrade This permission al
missions Permissions Center lows users to access
Administration the Upgrade Center
where they can ena
ble various features.
It is only visible if
Upgrade Center Per
mission is enabled
in Provisioning. Oth
erwise, Upgrade
Center is accessible
to all admin users.
Platform Variance Re Admin Manage System Variance Report This permission al
port lows users to use
Properties
Variance Reporting.
Platform Variance Re Admin Manage Allow Admin to Ac This permission al
port Integration Tools cess OData API lows users to access
through Basic Au OData APIs through
thentication basic authentica
tion.
Platform Variance Re Admin Manage Manage OData API This permission al
port Integration Tools Basic Authentica lows users to man
tion age OData APIs
through basic au
thentication.
Platform Variance Re Admin Manage Access to OData This permission al
port Integration Tools API Data Dictionary lows users to man
age OData API data
dictionary in Admin
Center.
Platform Variance Re Admin Manage OData API Attach This permission al
port Integration Tools ment Import lows users to import
attachments
through OData APIs.
Platform Variance Re Admin Manage OData API Attach This permission al
port Integration Tools ment Export lows users to export
attachments
through OData APIs.
Rewards and Spot Awards Admin Manage Spot Manage Spot This permission al
Recognition Awards Awards Program lows a user to set up
Spot Awards Pro
gram.
Rewards and Spot Awards Admin Manage Spot Manage Spot This permission al
Recognition Awards Awards Reports lows a user to view
Spot Awards history
or budget informa
tion reports.
Rewards and Spot Awards Admin Manage Manage Currency This permission al
Recognition Compensation Compensation Conversion Rate lows you to create
Employee Cen Tables and manage the cur
tral
rency exchange
rates you need.
Note
The Import
Permission on
Metadata
Framework is
also required.
Rewards and Foundation Objects Admin Manage Pay component This permission al
Recognition Foundation lows a user to ena
Objects Types ble integration with
Employee Central.
Rewards and Spot Awards User Miscellaneous Spot Awards This permission al
Recognition Permissions lows a user to view,
edit, import, or ex
port Spot Awards
for all target popula
tion for reporting
purpose.
Rewards and Spot Awards User Miscellaneous Spot Award Pro This permission al
Recognition Permissions gram lows a user to view,
edit, import, or ex
port Spot Awards
Program, and all its
related field.
Rewards and Spot Awards User Miscellaneous Spot Award Re Enable users to re
Recognition Permissions
demption deem awarded
points
Rewards and Spot Awards User Miscellaneous Spot Award User Enable users to view
Recognition Permissions
Balance their balance of
awarded points
Rewards and Spot Awards User Miscellaneous Spot Award Budget This permission al
Recognition Permissions lows user to create,
insert, update, de
lete, import, or ex
port Spot Awards
Budget for all target
populations.
Platform Intelligent Services Admin Intelligent Service Event Center This permission al
Rewards and Tools lows a user to ena
Recognition Integration Center
ble Intelligent Serv
ices.
Calibration Calibration Ses User Calibration Detailed Calibration This permission al
sions Permissions lows a user to ac
cess the Calibration
sessions involving
employees within
their target popula
tion.
Calibration Calibration Ses Admin Manage Manage Calibration This permission en
sions Calibration Sessions ables a user to cre
ate and manage Cal
ibration sessions.
Calibration Calibration Settings Admin Manage Manage Calibration This permission en
Calibration Settings ables a user to con
figure Calibration.
Calibration Calibration Tem Admin Manage Manage Calibration This permission en
plates Calibration Templates ables a user to cre
ate and manage Cal
ibration templates.
Calibration Calibration Ses Admin Manage Mass Create Cali This permission en
sions Calibration bration Sessions ables a user to mass
create Calibration
sessions.
Calibration Executive Review Admin Manage Manage Permission This permission en
Calibration for Executive Re ables a user to ac
view cess and manage
the Executive Re
view tab in Calibra
tion.
Calibration OData API Admin Manage OData API Calibra This permission en
Data Protection Calibration tion Export ables a user to ex
and Privacy (In port Calibration
formation Re data using OData
porting) APIs, for the pur
pose of Information
Reporting for Data
Protection and Pri
vacy.
Goals Goal Management User Goals Goal Management Enabling this per
Access mission gives a user
or group the ability
to access the Goals
module.
Goals Group Goals User Goals New Group Goal Enabling this per
Creation mission gives a user
or a group the ability
to create group
goals.
Goals Goal Management User Goals Target Population Select this permis
sion to assign goal
permissions to the
user or the group
defined as the target
population
Goals Goal Execution User Goals Access Execution This permission al
Map lows a user to ac
cess the Execution
Map under Goal
Execution.
Goals Goal Execution User Goals Access Meeting This permission al
Agenda lows a user to ac
cess the Meeting
Agenda under Goal
Execution.
Goals Goal Execution User Goals Access Status Re This permission al
port lows a user to ac
cess the Status
Report under Goal
Execution.
Goals Team Goals User Goals Manage Team Goal This permission al
lows a user to cre
ate, edit and delete
Team Goals.
Goals Goal Plans User Goals Access to Continu This permission pro
ous Performance vides a user the ac
Management Data cess to Continuous
Performance Man
agement Achieve
ments and feedback
received on the Ach
ievements linked to
the performance
goals, directly on the
Goal Plan
Goals Goal Plans User Goals Goal Plan Permis Choose which goal
Development Development sions plans users can ac
Goals cess.
Granting permis
sions through roles
controls which tem
plates users can
view; while tem
plate-level permis
sions control what
changes users can
make to a specific
template.
Goals Team Goals User Goals Assign Team Goals This permission al
lows a user to assign
Team Goals to other
users.
Goals Team Goals User Goals Share Team Goals This permission al
lows a user to share
Team Goals with
other users, thereby
making those users
the co-owners of the
Team Goals.
Goals Data Protection User Goals Admin Access for Note that this per
and Privacy (Infor Goal ODATA API Ex mission has been
mation Reporting) port developed exclu
sively for the Data
Protection Officer
role. The "Admin Ac
cess for Goal ODATA
API Export" permis
sion must not be
enabled for anyone
other than the Data
Protection Officer.
This permission
must not be used in
any other capacity
except to ensure the
Data Protection Offi-
cer has the ability to
carry out the duties
prescribed under
the regulation.
Goals Goal Import Admin Goals Import Goals This permission al
lows a user to cre
ate, edit and delete
goals, using an im
port file.
Goals Goal Execution Admin Goals Manage Configura- This permission al
tion of Goal Execu lows a user to ac
tion cess the Goal Execu
tion configurations
page.
Goals Goal Management Admin Goals Goal Management This permission al
Feature Settings lows a user to ac
cess the page that
controls the feature
settings in Goals
Management.
360 Degree Forms User General User Permission to Cre Select the form tem
Multi-Rater Permission ate Forms plates along with
Performance this permission to
Management enable a user to cre
ate forms of the se
lected templates.
360 Degree Forms Manage Change 360 Proc This permission al
Multi-Rater Documents ess Owner lows the user to
change the process
owner for a "Com
pleted" or "In Prog
ress" 360 review
form. The 360 proc
ess owner is the one
who manages the
360 evaluation
process.
360 Degree Forms Admin Manage Change Participant This permission al
Multi-Rater Documents Category lows the user to
change the category
of a participant in a
"Completed" or "In
Progress" 360 re
view form.
360 Degree Forms Admin Manage Restore Completed This permission al
Multi-Rater Documents 360 lows a user to re
store the "Com
pleted" 360 review
forms.
360 Degree Executive Re Admin Manage 360 Executive Re This permission and
Multi-Rater view Documents view all the permissions
under it, enable a
user to manage 360
Executive Reviews.
Continuous Per Continuous Per User Continuous Access to Continu This permission al
formance Manage formance Manage Performance User ous Performance lows a user to ac
ment ment Permission Management cess Continuous
Performance Man
agement.
Continuous Per Continuous Feed User Continuous Access Continuous This permission al
formance Manage back Performance User Feedback lows a user to view
ment Permission the feedback they
receive, and the
feedback received
by their direct re
ports.
Continuous Per Continuous Feed User Continuous Give Continuous This permission al
formance Manage back Performance User Feedback lows a user give
ment Permission feedback to employ
ees included in the
target population.
Continuous Per Continuous Feed User Continuous Request feedback This permission al
formance Manage back Performance User from others lows you to send
ment Permission feedback requests
to employees in
cluded in the target
population. You also
need to select the
permission “Limit
about whom feed
back can be re
quested.
Continuous Per Continuous Feed User Continuous Limit about whom When ‘Request
formance Manage back Performance User feedback can be re feedback from oth
ment Permission quested ers’ permission has
been enabled, by se
lecting this permis
sion, it allows user
to request feedback
about employees in
cluded in the target
population. For ex
ample, managers
can only request
feedback about
members of their
team.
Continuous Per Continuous Per User Continuous Other Topic This permission al
formance Manage formance Manage Performance lows a user to cre
ment ment Management ate, view and edit
topics in Continuous
Performance Man
agement.
Continuous Per Continuous Per Admin Manage Access to Adminis This permission al
formance Manage formance Manage Continuous trative Configura- lows a user to ac
ment ment Performance tion page cess the Continuous
Performance Man
agement configura-
tion page.
Continuous Per Continuous Admin Manage Admin Access to all This permission al
formance Manage Feedback Continuous Continuous Feed lows a user to ac
ment Data Protection Performance back Data cess the Continuous
and Privacy
Feedback data of all
employees.
Platform OData API Admin Manage Allow Admin to Ac This permission en
Continuous Apprentice Integration Tools cess OData API ables a user to cre
Management through Basic Au ate, read, update, or
Performance
Employee Delta
Management thentication delete information
Export Add-In
Employee Cen using the available
for Microsoft
tral OData APIs.
Excel
Employee Cen ERP Integration
tral Payroll Integration
Mentoring Center
Platform OData API Admin Manage Access to OData This permission en
Employee Cen Variance Re Integration Tools API Audit Log ables a user to mon
tral Payroll port itor the API calls.
Platform OData API Admin Manage Access to OData This permission en
Continuous Variance Re Integration Tools API Metadata Re ables a user to re
port fresh and Export fresh the metadata
Performance
Management of the OData APIs
Platform MDF Positions Admin Metadata Manage Data This permission al
Continuous Talent Pools Framework lows you to manage
Performance Business Con data on the meta
figuration UI
Management data framework.
MDF
Employee Cen
Data Protection
tral
and Privacy
Succession
Employee Cen
tral Payroll
This permission is
also required for
users to be able to
view the history
page for Alternative
Cost Distribution.
Succession Succession Org User Succession Succession Org Allows users to ac
Planners
Chart Chart Permission cess the Succession
Org Chart and the
Lineage Chart if it's
enabled in your sys
tem. The target pop
ulation of employees
a user is able to view
in the organization
chart is determined
by the Succession
Management and
Matrix Report Per
missions.
Succession Talent Search User Succession Talent Search Ac Once search fields
Planners
cess have been config-
ured for their role, a
user can perform a
talent search.
Succession Talent Search User Succession Talent Search Ex This permission al
Planners port Permission lows users to export
Talent Search re
sults. The fields in
the results are con
trolled by the Talent
Search Field permis
sion.
Succession Position Tile View User Succession Position Tile Access Only available with
Planners
the MDF Position-
based nomination
method, this per
mission allows users
to access the Posi
tion Tile view.
This permission
grants access to the
Metadata Frame
work (MDF) Position
object and uses the
associated target
population for posi
tions. Only positions
that are in the target
population of the us
er's role are dis
played on the Posi
tion Tile view.
Succession Talent Pools User Succession Plan Hide Talent Pool The permission pro
ners Page hibits roles from ac
cessing the Talent
Pool tab from other
Succession features
and People Profile.
Succession Talent Pools Admin Manage Succes Talent Pool Field The permission al
sion Configuration lows roles to access
the Manage Talent
Pool Field Settings
in Admin Center.
Platform Talent Card User Employee Data Employee Profile Select the View and
Succession Spot Awards Edit permissions
Development Mentoring you want to assign
Mentoring Succession to the role.
Rewards and
Recognition
Platform Talent Card User Employee Data Background Select the View and
Succession Spot Awards Edit permissions
Development Mentoring you want to assign
Mentoring Succession to the role.
Rewards and
Recognition
Using a setting in
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina
tions permissions to
further control ac
cess.
Using a setting in
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina
tions permissions to
further control ac
cess.
Platform MDF Positions Admin Metadata Configure Business This enables a user
Succession Talent Pools Framework
Rules to create, edit, and
Rewards and Spot Awards execute business
Recognition MDF rules in their SAP
Employee Cen People Central SuccessFactors sys
tral Hub
tem.
People Central Rules
Hub
Succession Talent Card Admin Manage Talent Manage Talent Grants users access
Calibration Presentations Card
Card Configuration to the Manage Tal
Platform ent Card admin tool
where they can con
figure the layout and
content of the talent
cards used in the
system.
Succession Talent Search Admin Manage System Talent Search Man Grants users access
Properties
agement to Talent Search
Settings where they
can manage how
Talent Search works
in your system.
Platform Email and Notifica- Admin Manage System Email Notification This permission al
Compensation tions Properties Templates Settings lows a user to con
figure email notifica-
tions for certain
workflow events.
Platform User Management Admin Manage User Change Assign This permission al
lows the Admin to
ment ID
change assignment
ID using the conver
tAssignmentIdExter
nal function import.
Platform User Management Admin Manage User Manage Login Ac This permission al
lows the Admin to
counts
access the Manage
Login Accounts tool.
Platform User Management Admin Manage User Basic User Import When the "Enable
Control on Basic
User Import in Role-
Based Permis
sions"option has
been enabled, this
permission allows
the Admin to per
form basic user im
port in the Employee
Central-enabled in
stances.
Succession Talent Search User Talent Search Field Talent Search Field Select which fields
to make available to
the role when per
forming a talent
search.
Succession Succession Org User Learning Learning Access Allows users to ac
Chart Permission cess Learning.
Succession MDF Positions Admin Manage Import Foundation Allows users to im
Employee Cen Foundation
Data port foundation ob
tral Objects
jects.
Mentoring Mentoring Admin Manage Career Manage Mentoring Allows users to cre
Development
Programs ate and manage
mentoring pro
grams.
Platform Mentoring Admin Manage User Manage Employee Allows users to cre
Mentoring Dynamic Groups ate employee dy
namic groups.
Platform Search User General User Company Info Ac This permission
Mentoring Permissions cess gives users access
to the Company Info
page, where they
can access the or
ganization chart and
employee directory.
Platform Search User General User User Search This permission en
Mentoring Permissions
ables users to find
other users with
People Search. You
can restrict user
searches to a target
population. It also
gives users access
to Action Search.
This permission
does NOT apply to
some search func
tions necessary to
perform specific ac
tions, such as sys
tem administration
tasks.
Note
Grant this per
mission to a tar
get population
of Everyone to
enable use of
the feedback
features.
Platform Employee Pro Admin Manage User Include Inactive Enables users to
file Employees in the search for inactive
Search search users on the People
Profile and Directory
Search.
Note
This permission
cannot be re
stricted to a tar
get population
and is granted
to everyone in
the permission
role.
This permission
does not impact
behavior of the
People Search
in the global
page header,
which is control
led by a com
pany-level con
figuration set
ting and not by
role-based per
missions.
Mentoring SAP Jam User General User Community Access For use when your
Permissions
system includes in
tegration with SAP
Jam.
Development Career Devel User Career Career Develop Allows users to navi
opment Plan Development
ment Plan (CDP) gate to
ning Planning
Access Permission Development.
Career Work
sheet
Development
Goals
Development Career Work User Career Career Worksheet Allows users to ac
sheet Development
Access Permission cess the career
Planning
worksheet.
Development Career Work User Career Career Worksheet If you're using Ca
sheet Development
Suggested Roles reer Worksheet v12,
Planning
Access Permission this permission ena
bles the suggested
target roles feature.
Development Development Admin Manage Career Development Ad Allows users to im
Goals Development
min port development
goals and manage
templates.
Development Learning Activi Admin Manage Career Import Learning Allows users to im
ties Development
Activity by web port learning activi
service ties.
Development Career Path Admin Manage Career Manage Career Allows user to cre
Development
Path ate and manage Ca
reer Path.
Development Career Path User Miscellaneous Career Path Select the View and
Permissions
Edit options you
want to assign to the
role.
Performance Forms Admin Manage Mass Route Docu Allows users to cre
Management Documents
ment Forward ate and distribute
multiple instances
of the same form at
once, and to route
the form forward in
the workflow.
Performance Forms Admin Manage Mass Route Docu Allows users to cre
Management Documents
ment Backward ate and distribute
Compensation multiple instances
of the same form at
once and to route
the form backward
in the workflow.
Performance Forms Admin Manage Modify Form Route Allows users to add,
Management Documents
Map reorder, or remove
routing steps of the
workflow of a form.
Allow Adding of a
Step allows users to
access the Admin
tools to add a step in
the route map.
Performance Route Maps Admin Manage Form Routing Maps Allows users to cre
Management Templates
ate Route Maps and
360 Degree modify existing
Multi-Rater
Route Maps.
Compensation
Performance Rating Scales Admin Manage Form Rating Scales Allows users to cre
Management Templates
ate a Rating Scale
360 Degree and modify existing
Multi-Rater
Rating Scales.
Compensation
Performance Forms Admin Manage Form Export Perform Allows users to ex
Management Templates
ance Management port Performance
Form Data Management form
data through API.
Performance Forms Admin Manage Form Mass Create Form Allows users to
Management Templates
Instances (Launch launch forms in bulk
360 Degree forms now) immediately.
Multi-Rater
Performance Forms Admin Manage Form Form Templates Allows users to cre
Management Templates
ate, edit, and ena
360 Degree ble/disable Perform
Multi-Rater ance Management
Compensation form templates.
Performance Notes User General User Permission to Cre Allows users to cre
Management Employee Pro Permission
ate Notes ate notes on the em
Platform file ployee profile.
Compensation Forms Admin Manage Manage Field Per This permission al
Compensation mission Groups lows a user to con
figure field-based
permission groups.
Compensation Forms Admin Manage Manage Job Code This permission en
Compensation and Pay Grade Map ables View a user to
manage currency
conversion tables.
Compensation Forms Admin Manage View User Personal This permission al
Variable Pay lows a user to view
Compensation Statements
User Personal
Statements tab on
the Import/Export
Data page
Compensation Worksheets Admin Manage System Performance Man This permission al
Variable Pay Properties agement Feature lows a user to ac
Settings cess Performance
Management Fea
ture Settings tool to
integrate 'CPM Ach
ievements' to Com
pensation work
sheet.
Compensation Compensation Admin Manage Enable Feature Up This permission al
Compensation grades lows a user to ac
cess feature up
grades for SAP Suc
cessFactors Com
pensation.
Compensation Aggregate Export Admin Manage Compensation Ag This permission al
gregate Export
Compensation lows a user to export
Compensation data
for a template.
Compensation Compensation Cal Admin Manage Manage Compen This permission al
culations Compensation sation Budget lows a user to define
budget calculation
and budget setup
rules under Plan
Details.
Compensation Compensation Pro Admin Manage Define Compensa This permission al
file Compensation tion Period Data lows a user to create
history periods to
display on the Com
pensation Profile,
and also associate
history periods with
a plan template.
Compensation Forms Admin Manage Add Edit Stock His This permission al
Compensation tory lows a user to create
stock history peri
ods.
Compensation Executive Review User Compensation Executive Review This permission al
lows a user to ac
Read Permission
cess Compensation
Executive Review
with Read privileges.
Compensation Executive Review User Compensation Executive Review This permission al
lows a user to ac
Edit Permission
cess Compensation
Executive Review
with Edit privileges.
Platform Ad-Hoc Reports User Reports Create Ad-Hoc Re This permission al
Compensation Permission port lows a user to create
and edit reports for
all specific modules.
Platform Ad-Hoc Reports User Reports Run Ad-Hoc Report This permission al
Compensation Permission lows a user to run
existing reports for
all or certain report
types.
Compensation Executive Review User Compensation Executive Review This permission al
lows a user to ac
Mass Action Per
cess Compensation
mission
Executive Review
with Mass Action
privileges.
Compensation Statements User Employee Views Combined State This permission al
Employee Pro ments lows a user to view
file Personal Combined
Statement Block in
People Profile or
view the Combined
Statement tab in a
V12-enabled Em
ployee Profile.
Compensation Statements User Employee Data Combined State This permission al
ments lows a user to view
generated Com
bined statements on
a RBP-enabled in
stance.
Variable Pay Forms Admin Manage Variable Manage Variable This permission al
Pay lows a user to ac
Pay Programs
cess Employee
Central Employee
History Field
Mapping page.
Variable Pay Statements User Employee Views Bonus Assignment This permission al
Employee Pro Statement lows a user to view
file Bonus Assignment
Statement Block in
People Profile or
view the Bonus
Assignment
Statement tab in a
V12-enabled Em
ployee Profile.
Variable Pay Statements User Employee Data Bonus Assignment This permission al
Statements lows a user to view
generated bonus as
signment state
ments in a RBP ena
bled instance.
Variable Pay Statements User Employee Views Variable Pay State This permission al
Employee Pro ments lows a user to view
file the Variable Pay
Statements block in
People Profile or
view the Variable
Pay Statements tab
in a V12-enabled
Employee Profile.
Variable Pay Statements User Employee Data Variable Pay State This permission al
ments lows a user to view
generated variable
pay statements in a
RBP enabled in
stance.
Variable Pay Executive Review User Variable Pay Executive Review This permission al
lows a user to ac
Edit Permission
cess Executive Re
view with Edit privi
leges.
Variable Pay Executive Review User Variable Pay Executive Review This permission al
lows a user to ac
Read Permission
cess Executive Re
view with Read privi
leges.
Variable Pay Executive Review Admin Manage Access to Integra This permission al
lows a user to ac
Integration Tools tion Center
Integration Center cess the Integration
Center Builder tool
to turn on notifica-
tion configuration.
Employee Cen Employee Data Im Admin Employee Central Workflows for se This permission al
tral port
Import Settings lected areas lows a user to trig
ger workflows using
business rules when
importing Job Infor
mation and Termi
nation Details using
the Incremental
mode.
Employee Cen Employee Data Im Admin Employee Central Enable Business This permission al
tral port
Import Settings Rules for selected lows a user to trig
areas ger business rules
onSave and on
Change when im
porting employees'
data such as com
pensation, termina
tion details and per
sonal information.
Platform Employee Data Im Admin Manage User Allow users to view This permission al
Employee Cen port lows a user to track
all the jobs. (By Dis
tral all import jobs per
abling this option,
formed by users.
users can view only
their job status.)
Platform Employee Data Im Admin Manage User Enable RBP Access This permission al
Employee Cen port
Validation for EC El lows a user to ena
tral ements during Im ble the RBP access
ports (Do not ena during imports.
ble during first time
import)
Employee Cen Employee Data Im User Employee Central Job History This permission al
tral port
Import Entities lows a user to per
form or restrict im
ports for job infor
mation.
Employee Cen Employee Data Im User Employee Central Compensation Info This permission al
tral port
Import Entities lows a user to per
form or restrict im
ports for compensa
tion information.
Employee Cen Employee Data Im User Employee Central Pay Component This permission al
tral port
Import Entities Non Recurring lows a user to per
form or restrict im
ports for pass com
ponent recurring in
formation.
Employee Cen Employee Data Im User Employee Central Job Relationships This permission al
tral port
Import Entities lows a user to per
form or restrict im
ports for job rela
tionship informa
tion.
Employee Cen Employee Data Im Admin Employee Central Enable Forward This permission al
tral port
Import Settings Propagation of lows a user to for
Compensation In ward propagate
formation Data for compensation and
Inserts in Incre pay component re
mental Imports curring data when
inserting through In
cremental mode.
Platform User Manage Admin Manage Data Create Legacy Data This permission al
Employee Cen ment Purge Request
Purge lows users to create
tral Employee Data purge requests us
Management
ing a legacy purge
Employee Data
request type.
Import
Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.
Platform User Manage Admin Manage Data Manage and This permission en
Employee Cen ment Approve Legacy
Purge ables users to ap
tral Employee Data Data Purge Request
prove purge re
Management
quests that use a
Employee Data
legacy purge re
Import
quest type.
Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.
Platform User Manage Admin Manage Data Remove Preview This permission en
Employee Cen ment and Complete
Purge ables users to delete
tral Employee Data Reports for Legacy
old purge reports for
Management Data Purge Request
legacy purge re
Employee Data
quests.
Import
Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.
Platform MDF Admin Metadata Hire Date Correc This permission al
Employee Cen Employee Cen lows a user to
Framework tion
tral tral change the hire date
for an employee in
Employee Central in
one place for multi
ple portlets.
Employee Cen Apprentice Admin Manage On-Site Supervisor This permission al
tral Management Apprentice lows an on-site su
pervisor to manage
apprentice data.
Employee Cen Apprentice User Apprentice Apprentice Group This permission al
tral Management Management
lows an apprentice
Permissions
supervisor to view
and edit apprentice
group.
Employee Cen Apprentice User Apprentice Apprentice Internal This permission al
tral Management Management
Training lows an apprentice
Permissions
supervisor to view
and edit apprentice
internal training.
Employee Cen Apprentice User Apprentice Apprentice On-the- This permission al
tral Management Management
job Training lows an apprentice
Permissions
supervisor to view
and edit apprentice
on-the-job training.
Employee Cen Apprentice User Apprentice Apprentice School This permission al
tral Management Management
lows an apprentice
Permissions
supervisor to view
and edit apprentice
school.
Employee Cen Apprentice User Apprentice Apprentice School This permission al
tral Management Management
Event lows an apprentice
Permissions
supervisor to view
and edit apprentice
school event.
Employee Cen Apprentice User Employee Views Apprentice This permission al
tral Management lows an apprentice
Employee Pro supervisor to view
file
apprentices in the
Employee Views
section.
Employee Cen Apprentice User MDF Foundation Department This permission al
tral Management Objects lows apprentice su
pervisors to config-
ure the MDF founda
tion object Depart
ment used in Ap
prentice Manage
ment.
Employee Cen Employee Cen User MDF Foundation Business Unit Select the Visibility
tral tral Objects and Actions permis
Cost Center
sions you want to
Division assign to the role.
Department
Location
Legal Entity
Employee Central Concurrent User Employee Data Employment De New Assignment
Employment tails Company provides
ERP Integration field-level permis
sion for the com
pany field. This is re
quired for Concur
rent Employment.
Change primary
employment allows
users to change the
employment classi
fication of an em
ployee.
Add new
Employment allows
users to add multi
ple employments.
Navigation Group
(View) allows users
to see the grouping
of URLs added in
the Take Action
menu for employees
whose system of re
cord is the ERP sys
tem and whose data
is replicated to Em
ployee Central. The
permission is used
in UI integration of
ERP screens with
Employee Central.
Navigation Group
Entry in Take Action
Menu (Edit) allows
users to select the
URLs added in the
Take Action menu
for employees
whose system of re
cord is the ERP sys
tem and whose data
is replicated to Em
ployee Central. The
permission is used
in UI integration of
ERP screens with
Employee Central.
Employee Central Deductions Admin Manage Create One Time This permission to
Deductions Deduction allow users to create
a non-recurring de
duction.
Employee Central Deductions Admin Manage Edit One Time De This permission to
Deductions duction allow users to edit a
non-recurring de
duction.
Employee Central Deductions Admin Manage View One Time De This permission to
Deductions duction allow users to view a
non-recurring de
duction.
Employee Central Employee Central User Employee Data Report No-Shows Select the View and
Edit permissions
you want to assign
to the role.
Report No-Shows
if they do not show
up on their starting
date with the com
pany.
Employee Central Compensation User Employee Data Pay Components Select the View and
Edit permissions
you want to assign
to the role.
Comp Info .
Employee Central Compensation User Employee Data Pay Component The View permission
Groups allows the user to
see the pay compo
nent group in the
system, for exam
ple, on the
Employment
Information page.
Employee Central Compensation Admin Manage Pay Scale Manage Pay Scale Allows access to the
Manage Pay Scale
Objects
Objects action in the
Admin Center.
Employee Central Compensation Admin Manage Pay Scale Adjust Employees’ Controls access to
Compensation to the pay scale pay in
Tariff Changes crease run.
Employee Central Compensation User Employee Central Pay Scale Area Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Pay Scale Type Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Pay Scale Group Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Pay Scale Level Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Range Penetration Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
View permission is
required if you ena
ble the compensa
tion widgets.
Employee Central Compensation User Employee Central Compa Ratio Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
View permission is
required if you ena
ble the compensa
tion widgets.
This permission is
for the widget to
show the wage pro
gression for an em
ployee.
This permission is
for the widget to
show the employ
ee's salary in rela
tion to the pay
range.
This permission is
for the widget to
show salaries for the
employee and
his/her peers.
Platform MDF User MDF Foundation Currency Exchange Select the Visibility
Objects Rate and Actions permis
sions you want to
grant the role.
Employee Central Employee Central Admin Manage System Employee Central This permission al
Properties Feature Settings lows admins to turn
on Employee Cen
tral features them
selves without hav
ing to request help
from SAP Cloud
Support.
Platform Employee Cen User Employee Data HR Information Select the View and
Employee Cen tral Edit permissions for
tral People Central the non-effective-
People Central Hub
dated portlets that
Hub Pension Pay
you want to assign
outs
to the role.
Pension Payout
Details
Employment
Information Take
Action Add
Pension Payout
Details .
Note
Global Assign
ments and Pen
sion Payouts
must be active
in your system
before you can
grant the per
missions. allows
users to navi
gate to
Employee Cen Employee Cen User Employee Views Employment Infor Allows users to ac
tral tral mation cess related pages
People Central People Central from the allows
Hub Hub
users toEmployee
Employee Pro
Files using the drop
file
down menu.
Employee Cen Employee Cen User Employee Views Personal Informa Allows users to ac
tral tral tion cess related pages
People Central People Central from the Employee
Hub Hub
Files using the drop
Employee Pro
down menu.
file
Employee Cen Employee Cen User Employee Views Pending Requests Allows users to ac
tral tral cess related pages
People Central People Central from the Employee
Hub Hub
Files using the drop
Employee Pro
down menu.
file
Employee Cen Employee Cen User Employee Central Personal Infor You can set field-
tral tral Effective Dated mation level permissions for
People Central People Central Entities Addresses effective-dated port
Hub Hub Dependents
lets and fields. This
Employee Cen Employee Cen Job Information
also includes coun
tral Payroll tral Payroll Compensation
try-specific fields
Information
that are prefixed by
Job Relation
the 3-letter ISO
ships
code (for example,
FRA for France, DEU
for Germany, and so
on).
Note
In Job Informa
tion, set the
fields for Job
Title and
Location to visi
ble if you use
the People
Search in Peo
ple-Profile ena
bled systems.
Platform Administration Admin Manage System Company System This permission en
Employee Cen Employee Cen Properties and Logo Settings ables users to con
tral tral figure system set
People Central People Central
tings on the
Hub Hub
Company System
and Logo Settings
page and to use
other system config-
uration tools like
Theme Manager and
Configure Custom
Navigation.
Platform Administration Admin Manage User Manage User Use these permis
Employee Cen Employee Cen sions to define who
tral tral can hire and rehire
People Central People Central
employees, manage
Hub Hub
workflows requests
and groups as well
import and export
employee data.
Employee Cen Employee Cen Admin Manage User Restrict fields of This allows admins
tral tral to further filter fields
type Worker
to only contingent
workers.
Employee Cen Employee Cen Admin Manage User Rehire Inactive Em This permission en
tral tral ployee ables users to rehire
an employee while
keeping the previous
employment data
visible in the sys
tem.
Employee Cen Employee Cen Admin Manage User Rehire Inactive Em This permission al
tral tral ployee with New lows users to rehire
Employment an employee and
hide the previous
employment data in
the system.
Employee Cen Employee Cen Admin Manage User Rehire Inactive Em This permission al
tral tral ployee with New lows users to rehire
Employment (by an employee using
'match' in New Re the Match pop-up
cruit) and hide the previ
ous employment
data in the system.
Employee Cen Employee Cen Admin Manage User Rehire Inactive Em This permission en
tral tral ployee (by 'match' ables users to rehire
in New Recruit) an employee using
the Match pop-up
while keeping the
previous employ
ment data visible in
the system.
Employee Cen Employee Cen Admin Manage User Add New Employee This permission en
tral tral for Fixed Term ables users to add
employees hired
with fixed-term con
tracts, meaning that
the termination date
can be added during
the hire process.
Employee Cen Manage Pend Admin Manage User Manage Pending This permission en
tral ing Hires ables users to use
Hires
the Manage Pending
Hires feature.
Employee Cen Manage Pend Admin Manage User Allow Manage Oth This permission al
tral ing Hires lows Manage
ers Save Draft
Pending Hires users
to work with all
Drafts saved by any
user.
Employee Cen Manage Pend Admin Manage User Configure Columns This permission al
tral ing Hires for the Manage lows users to config-
Pending Hires ure columns for En
hanced Manage
Pending Hires
Employee Cen Employee Cen Admin Manage Import Foundation Allows user to im
tral tral Foundation Data port foundation ob
People Central People Central Objects jects.
Hub Hub
Employee Cen Employee Cen Admin Manage Import Translations Allows users to im
tral tral Foundation port translations for
People Central People Central Objects objects like the job
Hub Hub
code.
Employee Cen Employee Cen Admin Manage Manage Foundation Use these permis
tral tral Foundation Object Object Types sions to set the ac
Types tions allowed for
foundation objects
in the Manage
Organization, Pay
and Job Structures
page.
Employee Cen Employee Cen User Employee Data Event Reasons You can set permis
tral tral sions for each event
People Central People Central reason type.
Hub Hub
Employee Cen Employee Cen User Employee Data Future Dated Trans You can set permis
tral tral action Alert sions to view future
People Central People Central changes for effec-
Hub Hub
tive-dated entities.
Employee Cen Employee Cen User Employee Data Transactions Pend You can set permis
tral tral ing Approval sions so that users
People Central People Central can see if a workflow
Hub Hub
has been initiated,
but not yet ap
proved.
Employee Cen Employee Cen Admin Manage Mass Areas where user You can set permis
tral tral Changes has permission to sions to allow users
People Central People Central make changes to make mass
Hub Hub
changes for certain
areas.
Platform Platform Admin Employee Data Job Title You can set the field
for Job Title to visi
ble if you use the
People Search in
People-Profile ena
bled systems.
Platform Report Center User Reports Create Report You can create, edit,
Report - Table Permission Schema delete, share, copy
and add new label to
a Report - Table.
Platform Report Center User Reports Run Report You can run and
Report - Table Permission Schema schedule the Report
- Table.
Platform Report Center User Reports Create Report - Ta You can import a Re
Report - Table port - Table.
Permission ble Schema
Platform Report Center User Analytics Report - Canvas You can create, run,
Report - Can Permissions Designer edit, delete, export,
vas add labels, share,
copy, schedule, and
import a Report -
Canvas.
Platform Report Center User Analytics Report - Canvas You can create, run,
Report - Can Permissions Designer Admin edit, delete, export,
vas add labels, share,
copy, schedule, and
import a Report -
Canvas.
Platform Report Center User Manage Analytics Tiles and You can create, edit,
Employee Cen Tiles Dashboards / Dashboards delete, export, add
tral Dashboards Reports labels, copy, and im
Compensation port a tile.
Widgets
You can create, run,
edit, delete, export,
add labels, share,
copy, and import a
dashboard.
Employee Central Position Manage User Manage Position Access Position Or This permission al
ment ganization Chart lows users to view
the position organi
zation chart.
Employee Central Advances Admin Manage Advances Advances Eligibility This permission al
lows user to view or
edit advances eligi
bility of an em
ployee.
Employee Central Advances Admin Manage Advances Create Advances This permission al
lows users to create
advances.
Employee Central Advances Admin Manage Advances Advances Admin This permission al
Overview lows user to manage
advances.
Employee Central Global Benefits Admin Manage Benefits Benefits Admin This permission al
Overview lows users to create,
edit, delete or man
age benefits.
Employee Central Global Benefits Admin Manage Benefits Enroll/Claim for This permission al
Benefits/Benefit lows users to enroll
Programs or claim for benefits
or benefits pro
grams.
Employee Central Global Benefits Admin Manage Benefits View on behalf of This permission al
Employee lows users to view
benefits of employ
ees.
Employee Central Global Benefits Admin Manage Benefits Manage on behalf This permission al
of Employee lows users to man
age benefits on be
half of employees.
Employee Central Global Benefits User Miscellaneous Benefit Contact This permission al
Permissions
Benefit Em lows users to edit,
ployee Claim enroll, claim bene
gram Enroll
ment
Employee Central Position Manage User Manage Position Change Display This permission al
ment Date of Position Or lows users to view
ganization Chart the position organi
zation chart for a
specific date.
Employee Central Position Manage User Manage Position Mass Copy of Posi This permission al
ment tion in Position Or lows users to create
ganization Chart up to 100 new posi
tions by copying an
existing position in
the position organi
zation chart.
Employee Central Position Manage User Manage Position View Job Requisi This permission al
ment tion in Position Or lows users to view
ganization Chart job requisitions in
the position organi
zation chart.
Employee Central Position Manage User Manage Position Create Job Requisi This permission al
ment tion in Position Or lows users to create
ganization Chart job requisitions in
the position organi
zation chart.
Employee Central Position Manage User Manage Position Select Job Requisi This permission al
ment tion Template in Po lows users to select
sition Organization a job requisition
Chart template when cre
ating a job requisi
tion or job requisi
tion in the position
organization chart.
Only active tem
plates with the fol
lowing fields can be
selected: id, title, re
cruiterName, num
berOpenings, posi
tionNumber.
Employee Central Position Manage User Manage Position Option to move Po This permission al
ment sition to New Su lows users to
pervisor on Job Info choose whether the
Change position of an em
ployee is moved with
the employee below
the position of the
new supervisor.
Employee Central Position Manage User Manage Position Create Position This permission al
ment from Position Or lows users to create
ganization Chart a position from the
position organiza
tion chart. This does
not change the per
mission for Add
Lower-Level Position
and Add Peer Posi
tion.
Employee Central Position Manage User Manage Position Access Position This position allows
ment Management Set users to access the
tings in Admin settings for position
Tools management.
Employee Central Position Manage User Miscellaneous Position: Visibility These permissions
ment Permissions allow users to view
the current state of
the position and/or
to view its history.
Employee Central Position Manage User Miscellaneous Position: Actions These permissions
ment Permissions allow users to cre
ate, insert, correct,
view, delete, and/or
import/export posi
tions. There is also a
Field-Level Overrides
option, which ena
bles you to vary
these permissions
for each individual
field in the Position
object.
Employee Central Company Structure User Company Access Company This permission al
Overview Structure Overview Structure Overview lows users to view
the company struc
ture overview.
Employee Central Company Structure User Company Change Display This permission al
Structure Overview Date of Company
Overview lows users to see
Structure Overview
how the company
structure overview
looks on various dif
ferent dates.
Employee Central Company Structure User Company View Employment This permission al
Structure Overview
Overview Count in Company lows users to see
Structure Overview how many employ
ees are assigned to
a particular entity in
the company struc
ture overview.
Note
When displayed
on an entity in
the chart, this
count doesn't
take the user's
role-based per
missions (RBP)
into account.
However, when
displayed in the
side panel it
does take RBP
into account.
Employee Central Company Structure User Company View Position This permission al
Structure Overview
Overview Count in Company lows users to see
Structure Overview how many positions
are assigned to a
particular entity in
the company struc
ture overview.
Note
When displayed
on an entity in
the chart, this
count doesn't
take the user's
role-based per
missions (RBP)
into account.
However, when
displayed in the
side panel it
does take RBP
into account.
Employee Central Company Structure User Company Access Company This permission al
Structure Overview lows users to edit
Overview Structure Overview
the company struc
Configuration
ture overview, both
directly in the com
pany structure over
view itself, and in the
Admin Center.
Employee Central Company Structure User Company Create Entity from This permission al
Overview Structure Overview Company Structure lows users to create
Overview child entities di
rectly in the com
pany structure over
view, using the
menu in the side
panel.
Employee Central Company Structure User Miscellaneous Company Structure This permission al
Overview Permissions Definition lows users to create
company structure
overviews.
Employee Central Company Structure User Miscellaneous Company Structure This permission al
Overview Permissions UI Configuration lows users to edit
company structure
overviews.
Employee Central Localization User Miscellaneous Document Genera This permission al
Permissions tion Business Ob lows users to config-
jects ure business rules
on the Document
Generation Tem
plate Mapping
screen.
Employee Central Localization User Miscellaneous Payment Informa This permission al
Permissions tion Business Ob lows users to config-
jects ure all business ob
jects related to Pay
ment Information.
Employee Central Localization Admin Miscellaneous Protection against This permission al
Permissions Unfair Dismissal lows users to config-
Business Objects ure all business ob
jects related to Pro
tection against Un
fair Dismissal.
Employee Central Localization Admin Miscellaneous Work Seniority This permission al
Permissions Business Objects lows users to config-
ure all business ob
jects related to Work
Seniority.
Employee Central Localization Admin Miscellaneous Location Based This permission al
Permissions Payment Business lows users to config-
Objects ure all business ob
jects related to Lo
cation Based Pay
ment.
Platform Check Tool User Check Tool Access Check Tool This permission al
Employee Cen lows users to access
tral Payroll the Check Tool.
Platform Check Tool User Check Tool Allow Configuration This permission al
Employee Cen Export lows users to attach
tral Payroll configuration infor
mation to a ticket in
cases where they
need to create one.
Platform Compound Em User General User SFAPI User Login This permission
Employee Cen ployee API Permissions gives a user general
tral Employee Delta access to the SFAPI.
Export Add-In
for Microsoft
Excel
ERP Integration
Employee Cen Employee Delta Admin Employee Central Employee Central This permission
tral Export Add-In API Foundation SOAP gives a user general
for Microsoft
Employee Cen API access to the Foun
Excel
tral Payroll dation SOAP API.
ERP Integration
Platform Employee Cen
tral Payroll
Variance Re
port
Employee Cen Compound Em Admin Employee Central Employee Central This permission
tral ployee API API HRIS SOAP API gives a user general
Employee Delta access to the HRIS
Employee Cen
Export Add-In
tral Payroll SOAP API.
for Microsoft
Platform Excel
ERP Integration
Employee Cen
tral Payroll
Variance Re
port
Employee Cen Employee Cen Admin Employee Central Employee Central This permission
tral tral Payroll API Foundation OData gives a user read ac
Employee Cen ERP Integration API (read-only) cess to the Founda
tral Payroll Variance Re
tion OData API.
Platform port
Employee Cen ERP Integration Admin Employee Central Employee Central This permission
tral API HRIS OData API gives a user read ac
Employee Cen
Employee Cen (read-only) cess to the HRIS
tral Payroll
tral Payroll
Variance Re OData API.
Platform
port
Employee Cen Employee Delta Admin Employee Central Employee Central This permission
tral Export Add-In API Foundation OData gives a user write
Employee Cen for Microsoft
API (editable) access to the Foun
tral Payroll Excel
dation OData API.
ERP Integration
Employee Cen
tral Payroll
Employee Cen Employee Delta Admin Employee Central Employee Central This permission
tral Export Add-In API HRIS OData API gives a user write
Employee Cen for Microsoft
(editable) access to the HRIS
tral Payroll Excel
OData API.
Platform ERP Integration
Employee Cen
tral Payroll
Variance Re
port
Employee Cen Compound Em Admin Employee Central Employee Central Together with the
tral ployee API API Compound Em SFAPI User Login
Employee Cen ployee API (re permission, this per
tral Payroll
stricted access) mission restricts the
data accessible us
ing the Compound
Employee API ac
cording to the defi-
nition of the target
population, for ex
ample, for a country
or a department.
Platform Employee Delta Ex Admin Manage System Picklist Manage This permission al
Employee Cen port Add-In for Mi Properties ment and Picklists lows a user to ex
tral crosoft Excel Mappings Set Up tract picklist data
from the Employee
Central backend us
ing the Compound
Employee API.
Employee Cen Employee Delta Ex Admin Manage Manage Employee This permission al
tral port Add-In for Mi Dashboards / Delta Export Tem lows a user to ac
crosoft Excel Reports plates cess the Employee
Delta Export UI.
You'll find this per
mission either under
Manage User or un
der Manage
Dashboards /
Reports.
Employee Central Employee Delta Ex Admin Manage User Manage Employee This permission al
port Add-In for Mi Delta Export Tem lows a user to ac
crosoft Excel plates cess the Employee
Delta Export UI.
You'll find this per
mission either under
Manage User or un
der Manage
Dashboards /
Reports.
Employee Central ERP Integration User Miscellaneous Data Replication These permissions
Permissions Proxy (View, Edit, allow a user to dis
and Import/Export) play, change, im
port, and export
Data Replication
Proxy objects used
in employee time
data replication
from Employee Cen
tral.
Employee Central ERP Integration Admin Miscellaneous Data Replication These permissions
Permissions Configuration allow a user to dis
(View, Edit, and Im play, change, im
port/Export) port, and export
Data Replication
Configuration ob
jects used in em
ployee time data
replication from Em
ployee Central.
Employee Central ERP Integration Admin Manage Access to Data This permission al
Integration Tools Replication Monitor lows a user to ac
cess all data replica
tion records in the
Employee Central
Data Replication
Monitor, thus being
able to monitor em
ployee master data,
organizational as
signment, and time
data replication
from Employee Cen
tral.
Employee Central ERP Integration Admin Manage Restrict Access to Together with the
Integration Tools Data Replication Access to Data
Monitor to Specific Replication Monitor
Target Population permission, this per
mission allows a
user to access data
replication records
for specific groups
of employees in the
Employee Central
Data Replication
Monitor, thus being
able to monitor em
ployee master data,
organizational as
signment, and time
data replication
from Employee Cen
tral for these em
ployees.
Employee Central ERP Integration Admin Manage Delete Records This permission al
Integration Tools from Data Replica lows a user to delete
tion Monitor data replication re
cords from the Em
ployee Central Data
Replication Monitor
that are no longer
needed for monitor
ing, for example, be
cause they were cre
ated during a test
phase. The Data
Replication Monitor
is used in employee
master data, organi
zational assign
ment, and time data
replication from Em
ployee Central.
Note
We recommend
that you grant
this permission
only in excep
tional cases,
where mass de
letion is actually
required. Once
the mass dele
tion was carried
out, remove the
permission
from the per
mission role.
Employee Central Payroll Administra Admin Payroll Payroll Administra This permissions al
Payroll tion Permissions tion lows a user to ac
cess payroll UI
mashups and con
figure the settings
for links and admin
services required to
run payrolls for em
ployees.
Employee Central Payroll Self Service User Payroll Payroll Self Service This permission al
Payroll Permissions lows a user to ac
cess employee self-
services like the pay
statement.
Employee Central Payment Informa Admin Miscellaneous Payment Informa This permission al
lows you to maintain
tion Permissions tion
an employee's pay
ment details in Em
ployee Central.
Employee Central Employee Central Admin Payroll Integration Employee Run Re Select all available
Payroll Payroll Permission sults permissions. This
permission allows a
user to configure all
payroll run results
for employees.
Employee Central Employee Central User Payroll Integration Employee Run Re Select View Current
Payroll Payroll Permission sults and View History
permissions. This
permission allows a
user to view payroll
run results.
Employee Central Employee Central Admin Payroll Integration Payroll Data Main This permission al
lows a user to con
Payroll Payroll Permission tenance Task
figure all payroll
data maintenance
tasks.
Employee Central Employee Central Admin Payroll Integration Payroll Data Main This permission al
Payroll Payroll Permission tenance Task Con lows a user to make
figuration settings for the Con
figuration of all pay
roll maintenance
tasks.
Employee Central Employee Central Admin Payroll Integration Payroll System As This permission al
Payroll Payroll Permission signment lows a user to con
figure all assign
ments to payroll
systems.
Employee Central Time Data Replica Admin Payroll Integration Data Replication This permission al
Payroll tion Permission Configuration lows a user to make
settings for all Data
Replication Configu-
rations.
Employee Central Time Data Replica Admin Payroll Integration Data Replication This permission al
Payroll tion Permission Proxy lows a user to view
and edit Data Repli
cation Proxies.
Employee Central Time Data Replica Admin Payroll Integration Trigger Data Repli This permission al
Payroll tion Permission cation Proxy Crea lows an admin to
tion Job trigger Data Replica
tion Proxy creation
job for selected
users. Note that this
permission is op
tional.
Employee Central Payroll Control Admin Manage SAP Access to SAP Sys This permission en
Payroll Center System tem Configuration ables a user to see
Configuration the SAP System
Configuration link in
Admin Center.
Employee Central Payroll Control Admin SAP System SAP System Con Select View and Edit
Payroll Center Configuration figuration permissions. This
permission enables
a user to configure
Employee Central
Payroll parameters.
Employee Central Payroll Control Admin Payroll Integration Payroll Control Select View and Edit
Payroll Center Permission Center Configura- permissions. This
tion permission enables
a user to configure
the classic or the
new Payroll Control
Center solution for
each payroll system.
Employee Central Payroll Control Admin Payroll Integration Payroll Control Select View and Edit
Payroll Center Permission Center Assignment permissions. This
permission enables
a user to assign pay
roll systems to a tar
get user (payroll ad
ministrator or pay
roll process man
ager, for example).
Employee Central Payroll Control Admin Payroll Control My Alerts Access This permission en
Payroll Center Center ables a user to use
the My Alerts tab.
Employee Central Payroll Control Admin Payroll Control My Processes Ac This permission en
Payroll Center Center cess ables a user to use
the My Processes
tab.
Employee Central Payroll Control Admin Payroll Control Unassigned Alerts This permission en
Payroll Center Center Access ables a user to use
the Unassigned
Alerts tab.
Employee Central Payroll Control Admin Payroll Control Manage Processes This enables a user
Payroll Center Center Access to use the Manage
Processes tab.
Employee Central Payroll Control Admin Payroll Control Manage Policies This permission en
Payroll Center Center Access ables a user to use
the Manage Policies
tab.
Employee Central Payroll Control Admin Payroll Control My Off-cycles Ac This enables a user
Payroll Center Center cess to use the My Off-
Cycles tab.
Employee Central Payroll Control Admin Payroll Control Manage Teams Ac This permission en
Center Center cess
Payroll ables a user to use
the Manage Teams
tab.
Employee Central Payroll Control Admin Payroll Control My Teams Access This permission en
Center Center
Payroll ables a user to use
the My Teams tab.
Employee Central Time Off User Employee Views Manage Time Off This enables a user
Employee Pro to create and man
file age requests for
time off (for exam
ple, vacation or sick
leave).
Employee Central Time Off User Employee Views Time Management This enables a user
Employee Pro to create and man
file age requests for
time off (for exam
ple, vacation or sick
leave).
Employee Central Time Off User Employee Central Holiday Calendar This enables a user
Effective Dated to view the Holiday
Entities Calendar field in
their Job Informa
tion.
Employee Central Time Off User Employee Central Work Schedule This enables a user
Effective Dated to view the Work
Entities Schedule field in
their Job Informa
tion.
Employee Central Time Off User Employee Central Time Profile This enables a user
Effective Dated to view the Time
Entities Profile field in their
Job Information.
Employee Central Time Off User Employee Central Time Recording This enables a user
Effective Dated Variant to view the Time
Entities Recording Variant
field in their Job In
formation.
Employee Central Time Off Admin Manage Time Off Manage Time Off This enables a Time
Structures Off admin to create,
edit, or delete Time
Off-related objects
such as time pro
files, time accounts,
or time types.
Employee Central Time Off Admin Manage Time Off Manage Time Off This enables a Time
Calendars Off admin to carry
out mass changes to
time data by using
calendar runs.
Employee Central Time Off Admin Manage Time Off Manage Payout This enables a Time
Off admin to enter
financial payouts on
time accounts.
Employee Central Time Off Admin Manage Time Access Workbench This enables a Time
Off admin to open
the Time Work
bench and manage
time tasks for em
ployees.
Employee Central Time Off Admin Manage Time Maintain Individual This enables a Time
Work Schedule Off admin to create
an individual work
schedule for an em
ployee.
Employee Central Time Off Admin Manage Time Maintain Tempo This enables a Time
rary Change Off admin to make a
temporary change
to an employee's
work schedule.
Employee Central Time Off Admin Manage Time Link Absences This enables a Time
Off admin to link an
employee's absen
ces in case, for ex
ample, the em
ployee has been ab
sent with the same
sickness more than
once in a given peri
ods.
Employee Central Time Off Admin Manage Time Access Time Alerts This enables a Time
Off admin to access
time alerts in the
Time Workbench.
Employee Central Time Off Admin Manage Time Access Time Ac This enables a Time
count Process Sim Off admin to simu
ulator late time account
accruals for a partic
ular employee, date,
and time account
types.
Employee Central Time Off Admin Manage Time Access Time Man This enables a Time
agement Configu- Off admin to use the
ration Search time management
configuration
search.
Employee Central Time Off Admin Manage Time Show Time Ac This enables a Time
count Balance in Off admin to see the
Termination Screen time balance on the
screen where termi
nation payouts are
processed.
Employee Central Time Off Admin Manage Time Access Account This enables a Time
Payouts Off admin to access
the Accounts Pay
outs tab in the Time
workbench.
Employee Central Workflows User Employee Views Pending Requests Role based permis
Employee Pro sions for managers
file that want to approve
workflows for their
employees.
Employee Central Workflows Admin Manage Workflows Allow Auto Delega This permission al
tion lows users to set up
automatic delega
tion for their work
flow requests.
Employee Central Workflows User Employee Data View Workflow Ap Select either the
proval History View or Editpermis
sions as required
under View
Workflow Approval
History for manag
ers that want to ap
prove requests for
their employees.
Employee Central Workflows Admin Manage Workflows Manage Workflow Permissions to ac
Requests cess workflows
Employee Central Workflows Admin Manage Workflows Manage Workflow Role based permis
Groups sions so that HR Ad
ministrators can de
fine dynamic groups
for workflows.
Employee Central Workflows Admin Manage Workflows Professional Edition You can use the ad
Manage Workflow ditional organization
Requests filters within work
flow requests when
this is enabled.
Employee Central Workflows Admin Manage Workflows View Completed You can control who
Workflows sees completed
workflows and is
only available when
the Platform
Feature Settings
Add Permission:
Completed
Workflows is
turned on.
Employee Central Workflows Admin Manage Dynamic Role Dynamic role per
Foundation mission allows the
Objects Types HR administrator to
maintain the dy
namic role settings.
Platform Administration User General User User Login Enables a user to log
Employee Cen Job Profile into the system.
Permission
tral Builder
Platform Job Profile Builder Admin Manage Job Profile Select all check You can restrict
Employee Cen Builder boxes managing job profile
tral content by selecting
Can View Content
versus Can Edit
Content under the
Manage Job Profile
Content section
Platform Job Profile Builder Admin Manage Job & Skill Job Profile You must enable se
Employee Cen Profile Visibility curity and visibility
tral settings from the
Job Profile object
using the Configure
Object Definitions
tool so that Manage
Job & Skill Profile
Visibility is enabled
in role-based per
mission.
Platform Job Profile Builder Admin Manage Job & Skill Skill Profile You must enable se
Employee Cen Profile Visibility curity and visibility
tral settings from the
Job Profile object
using the Configure
Object Definitions
tool so that Manage
Job & Skill Profile
Visibility is enabled
in role-based per
mission.
Platform Job Profile Builder Admin Manage Job & Skill Rated Skills
Employee Cen Profile Visibility
tral
Recruiting Recruiting Manage User Recruiting Report Permission This permission en
ables the user to ac
ment Permissions
cess the Reports link
on the Recruiting
Marketing tab
Recruiting Recruiting Manage User Recruiting Source Quality This permission en
Portlet Permission ables the user to ac
ment Permissions
cess the Source sub-
tab on the Recruit
ing Marketing tab
Recruiting Recruiting Manage User Recruiting Standalone Search This permission en
Permission ables the user to ac
ment Permissions
cess the Candidates
tab and candidate
search, whether or
not the user has an
open requisition
Recruiting Recruiting Manage User Recruiting Candidate Search This permission en
Within Job Req ables the user to ac
ment Permissions
cess the Candidates
tab and candidate
search, only if the
user has an open
requisition. This
does not allow the
user to search
through candidates
that have already
applied to the requi
sition.
Recruiting Recruiting Manage User Recruiting Grant eQuest Job This permission
Postings Permis gives the user the
ment Permissions
sion ability to post to
third-party job
boards via eQuest.
eQuest must be en
abled and config-
ured, and external
user accounts must
be properly loaded
for the users receiv
ing the permission.
Recruiting Recruiting Manage User Recruiting Jobs Applied Port This permission en
let Permission ables the user to
ment Permissions
view the Jobs
Applied portlet on
the Candidate Profile
and application re
cords
Recruiting Recruiting Manage User Recruiting SFAPI Insert Candi This permission en
date Permission
ment Permissions ables the user to in
sert candidate per
missions on candi
date profiles. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Update Can This permission en
didate Permission
ment Permissions ables the user to up
date candidate per
missions on candi
date profiles. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve This permission en
Candidate Permis
ment Permissions ables the user to re
sion
trieve candidate per
missions on candi
date profiles. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Insert Job This permission en
Application Permis ables the user to in
ment Permissions
sion sert job application
permissions on ap
plications. Typically
this is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Update Can This permission en
didate Permission ables the user to up
ment Permissions
date candidate per
missions on applica
tions. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve This permission en
Candidate Permis ables the user to re
ment Permissions
sion trieve candidate per
missions on applica
tions. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Insert Job This permission en
Application Permis ables the user to in
ment Permissions
sion sert job application
permissions on ap
plications. Typically
this is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Update Job This permission en
Application Permis ables the user to up
ment Permissions
sion date job application
permissions on ap
plications. Typically
this is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Insert Job This permission en
Requisition Permis ables the user to in
ment Permissions
sion sert job requisition
permissions on
requisitions. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Update Job This permission en
Requisition Permis ables the user to up
ment Permissions
sion date job requisition
permissions on
requisitions. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Upsert Job This permission en
Requisition Permis ables the user to up
ment Permissions
sion sert job requisition
permissions on
requisitions. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve Job This permission en
Requisition Permis ables the user to re
ment Permissions
sion trieve job requisition
permissions on
requisitions. Typi
cally this is granted
to a dummy user,
set up specifically
for integration pur
poses.
Recruiting Recruiting Manage User Recruiting SFAPI Insert Job This permission en
Code Permission
ment Permissions ables the user to in
sert job code per
missions on requisi
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Update Job This permission en
Code Permission
ment Permissions ables the user to up
date job code per
missions on requisi
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Permis User Recruiting SFAPI Upsert Job This permission en
Code Permission
sion Permissions ables the user to up
sert job code per
missions on requisi
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve Job This permission en
Code Permission
ment Permissions ables the user to re
trieve job code per
missions on requisi
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve Job This permission en
Posting Permission ables the user to re
ment Permissions
trieve job posting
permissions on
requisition job post
ings. Typically this is
granted to a dummy
user, set up specifi-
cally for integration
purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve As This permission en
sessment Order ables the user to re
ment Permissions
Permission trieve assessment
order permissions
on application as
sessments. Typically
this is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Update As This permission en
sessment Report ables the user to up
ment Permissions
Permission date assessment re
port permissions on
application assess
ments. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting SFAPI Retrieve Job This permission en
Applicant Permis ables the user to re
ment Permissions
sion trieve job applicant
permissions on ap
plication assess
ments. Typically this
is granted to a
dummy user, set up
specifically for inte
gration purposes.
Recruiting Recruiting Manage User Recruiting Careers Tab Per This permission pro
mission vides the user ac
ment Permissions
cess to the Careers
tab. This permission
is granted automati
cally to all newly-
created users. It is
necessary to adjust
this permission only
if the user is re-acti
vated in a non-RBP
environment or if
the client wishes to
restrict access to
the careers tab to a
given population of
employees.
Recruiting Recruiting Permis User Recruiting Delete Job Requisi Delete a job requisi
sions Permissions tions tion.
Recruiting Recruiting Manage User MDF Recruiting MDF Object: View Yes: Pipeline
Candidate
ment Permissions Status Structure
Relationship
dropdown shows list
Management
Status Set of pipelines.
Recruiting Recruiting Manage User MDF Recruiting MDF Object: View Yes: Dropdown
Candidate
ment Permissions shows list of sta
Relationship
tuses that can be
Management
Status Map set as default.
Recruiting Recruiting Adminis Admin Manage Recruiting Detailed Requisi This permission en
tion Reporting
tration ables the user to
view Detailed
Requisition
Reporting.
Recruiting Recruiting Adminis Admin Manage Recruiting Employee Referral This permission en
Program Setup
tration ables the user to set
up an employee re
ferral program.
Recruiting Recruiting Adminis Admin Manage Recruiting Edit Applicant Sta This permission en
tus Configuration
tration ables the user to
edit the applicant
status configura-
tion.
Recruiting Recruiting Adminis Admin Manage Recruiting Export New Hire This permission en
Candidates
tration ables the user to ex
port the records of
candidates newly
hired.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Custom Help Text
tration ables the user to
manage custom
Help instructions for
Recruiting.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Duplicate This permission en
Candidates
tration ables the user to
manage and purge
duplicate candidate
records.
Recruiting Recruiting Ad Admin Manage Recruiting Manage external This permission en
ministration data privacy con
ables the user to
Data Protection sent statements
manage external
and Privacy
data privacy con
sent statements.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage External This permission en
Password Policy
tration ables the user to
manage the external
password policy.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage External This permission en
User Accounts
tration ables the user to
manage external
user accounts.
Recruiting Recruiting Ad Admin Manage Recruiting Manage internal This permission en
ministration data privacy con
ables the user to
Data Protection sent statements
manage internal
and Privacy
data privacy con
sent statements.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Job Post This permission en
ing Header and
tration ables the user to
Footer
manage the job
posting header and
footer.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Offer Let This permission en
ter Templates
tration ables the user to
manage offer letter
templates.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Onboard This permission en
Onboarding ing Templates
tration ables you to manage
onboarding tem
plates. You can add
or edit Recruiting e-
mail templates for
Onboarding.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Email Templates
tration ables the user to
manage recruiting
email templates.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Groups
tration ables the user to
manage.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Languages
tration ables the user to
manage recruiting
languages.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Settings
tration ables the user to
manage recruiting
settings.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Sites
tration ables the user to
manage recruiting
sites.
Recruiting Recruiting Adminis Admin Manage Recruiting Set Up Agency Ac This permission en
cess
tration ables the user to set
up agency access.
Recruiting Recruiting Adminis Admin Manage Recruiting Set up Company In This permission en
formation
tration ables the user to set
up .
Recruiting Recruiting Adminis Admin Manage Recruiting Set up Internal This permission en
Candidate Search
tration ables the user to set
up company infor
mation.
Recruiting Recruiting Adminis Admin Manage Recruiting Set up Job Board This permission en
Options
tration ables the user to set
up job board op
tions.
Recruiting Recruiting Adminis Admin Manage Recruiting Configure Legal This permission en
Minimum Obliga
tration ables the user to
tion Period
configure legal mini
mum obligation pe
riod.
Recruiting Recruiting Adminis Admin Manage Recruiting Delete Candidate This permission al
lows the user to de
tration
lete candidate re
cords. You can grant
this permission only
if the application
status Deleted On
Demand By Admin
has been enabled
for the related sta
tus set on the pipe
line.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Recruiting This permission en
Team Settings
tration ables the user to
manage recruiting
team settings.
Recruiting Recruiting Adminis Admin Manage Recruiting Configure Stand This permission en
ardization Mapping
tration ables the user to
configure standardi
zation mapping.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Assess This permission en
ment Vendors
tration ables the user to
manage assessment
vendors.
Recruiting Recruiting Adminis Admin Manage Recruiting Set Up Recruiting This permission en
Marketing Job Field
tration ables the user to set
Mapping
up Recruiting Mar
keting Job Field
Mapping.
Recruiting Recruiting Adminis Admin Manage MDF MDF Object: Select any combina
Recruiting Objects
tration Campaign Limits tion of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over
rides, as desired.
Recruiting Recruiting Manage Admin Manage MDF MDF Objects: Enables Candidate
Recruiting Objects Relationship Man
ment Candidate
agement features.
Relationship
Management
Status
Candidate
Relationship
Management
Status Map
Candidate
Relationship
Management
Status Set
Recruiting Recruiting Adminis Admin Manage MDF MDF Object: Select any combina
Recruiting Objects
tration EmailBrandTemplat tion of Visibility:
e View, Actions: Edit
and Import/Export,
and Field Level Over
rides, as desired.
Recruiting Recruiting Adminis Admin Manage MDF MDF Object: Select any combina
Recruiting Objects MarketingBrand
tration tion of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over
rides, as desired.
Recruiting Recruiting Adminis Admin Manage MDF MDF Object: Pool Select View, Ac
Recruiting Objects
tration Limits tions: Edit and Im
port/Export, and
Field Level Over
rides, as desired.
Recruiting Recruiting Adminis Admin Manage MDF MDF Object: Select View and Edit
Recruiting Objects
tration Recruiting Rules to enable user to
Assignment configure business
Configuration rules for Recruiting.
Other permissions
are optional.
Recruiting Recruiting Permis Admin Manage Recruiting Restore Deleted Restore a deleted
Job Requisitions
sions job requisition.
Recruiting Recruiting Permis User Recruiting Hide Careers Tab When enabled for
sions Permissions for Proxy User specific employees
or permission roles,
disallows viewing a
proxied users career
tab and tile.
Recruiting Recruiting Adminis Admin Manage Recruiting Manage Multistage Enables being able
tration And Late Stage Ap to access the
plication Preview Manage Multistage
and Late Stage
Application Preview
from Admin Center.
Platform Data Protection Admin Admin Center View Change Audit Allows users to view
and Privacy Configuration configuration set
Permissions
tings for Change Au
dit.
Platform Data Protection Admin Admin Center Edit Change Audit Enables users to
and Privacy Configuration change configura-
Permissions
tion settings for
Change Audit.
Platform Data Protection Admin Admin Center Generate Change Enables users to
and Privacy Audit Reports create Change Audit
Permissions
reports. You can cre
ate change audit re
ports on personal
data for Data Pro
tection and Privacy
or on other types of
data for general au
dit purposes.
Platform Data Protection Admin Manage Data Create DRTM Data Enables users to
and Privacy Purge Purge Request create and submit a
DRTM purge request
for Data Protection
and Privacy.
Platform Data Protection Admin Manage Data Manage and Enables users to ap
and Privacy Purge Approve DRTM prove a DRTM purge
Data Purge Request request for Data
Protection and Pri
vacy.
Platform Data Protection Admin Manage Data Remove Preview This permission en
and Privacy Purge and Complete ables users to delete
Reports for DRTM old purge reports for
Data Purge Request DRTM purge re
quests.
Platform Data Protection User Data Retention [Dynamic permis Enables users to
and Privacy Management
sions for each MDF manage configura-
object configured in tions related to the
the system that is DRTM data purge
related to DRTM function for Data
data purge.] Protection and Pri
vacy, using MDF
tools.
Platform Data Protection Admin Admin Center Enable Information Enables users to
and Privacy Permissions
on Data Subject configure and run
the Data Subject In
formation Report,
which compiles a list
of all the personal
data that has been
stored on a particu
lar employee.
Platform Instance Man Admin Manage Instance Copy Package Allows users to copy
agement Instance Sync pack
Synchronization
ages between
source and target.
Platform Instance Man Admin Manage Instance Sync Data Model Enables users to
agement sync data models
Synchronization
between instances
using Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync MDF Data Enables users to
agement sync MDF data be
Synchronization
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Workflow Enables users to
agement sync EC Workflows
Synchronization
between instances
using Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Objectives Enables users to
agement sync goals between
Synchronization
instances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync Rating Scales Enables users to
agement sync rating scales
Synchronization
between instances
using Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Form Label Enables users to
agement Translations sync form label
Synchronization
translations be
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Competen Enables users to
agement cies sync competencies
Synchronization
between instances
using Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Families and Enables users to
agement Roles sync families and
Synchronization
roles between in
stances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync Performance- Enables users to
agement Management Tem sync Performance
Synchronization
plates Management tem
plates between in
stances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync Objective Enables users to
agement Templates sync Goal Manage
Synchronization
ment templates be
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Career-Devel Enables users to
agement opment-Plan Tem sync Career Devel
Synchronization
plates opment Plan tem
plates between in
stances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync System Prop Enables users to
agement erties sync miscellaneous
Synchronization
system settings be
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync RBP Permis Enables users to
agement sion Roles sync RBP permis
Synchronization
sion roles between
instances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync RBP Permis Enables users to
agement sion Groups sync RBP permis
Synchronization
sion groups be
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Dashboard Enables users to
agement Settings sync Analytics dash
Synchronization
board settings be
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync MDF Picklists Enables users to
agement sync MDF picklists
Synchronization
between instances
using Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync MDF Object Enables users to
agement Definitions sync MDF object
Synchronization
definitions between
instances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync MDF Configu- Enables users to
agement ration UI sync MDF configura-
Synchronization
tion UI settings be
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync MDF Rules Enables users to
agement sync MDF rules be
Synchronization
tween instances us
ing Instance Sync
tools.
Platform Instance Man Admin Manage Instance Sync Foundation Enables users to
agement Objects sync Foundation Ob
Synchronization
jects between in
stances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Sync Homepage Enables users to
agement Tile Configurations sync Home Page
Synchronization
configuration set
tings between in
stances using In
stance Sync tools.
Platform Instance Man Admin Manage Instance Manage Refresh Enables admin
agement users to create a
Refresh
new refresh request,
view history and
track refresh re
quest.
Platform Instance Man Admin Manage Instance View Refresh Re Provides users re
agement quests stricted access of
Refresh
the Instance Refresh
tool. Users can view
history, track re
quest but they can
not create a new re
fresh request.
Platform Search Admin Manage Action Manage Action Gives users access
Search Search to the Manage Ac
tion Search and
Configure Custom
Navigation pages so
that they can config-
ure the action
search.
Platform System Admin Admin Admin Center View or access Ad Enables users to see
istration min Alerts tile the Admin Alerts tile
Permissions
on the next-gen Ad
min Center page.
Platform Administration Admin Admin Center View or access Re Enables users to see
ports tile the Reports tile on
Permissions
the next-gen Admin
Center page.
Platform Administration User Homepage v3 Tile Homepage v3 To- Allows users to see
Do tile group the To-Do section on
Group Permission
the new home page.
Platform Administration User Homepage v3 Tile Homepage v3 On Allows users to see
boarding tile group the Onboarding sec
Group Permission
tion on the new
home page.
Platform Administration Admin Manage Security Manage SAML SSO Gives users the abil
Settings ity to manage SAML
SSO settings, only in
instances using SAP
Cloud Platform
Identity Authentica
tion service.
Platform Administration Admin Manage System Manage Home Gives users to ac
Page cess to the Manage
Properties
Home Page configu-
ration tool so that
they can configure
the content and lay
out of the home
page.
Platform Administration Admin Manage System View Provisioning Gives users the abil
Access ity to view Provision
Properties
ing accounts and
"super admin" ac
counts with access
to the system.
Platform Administration Admin Manage System Control Provision Gives users the abil
ing Access ity to manage which
Properties
Provisioning ac
counts can be used
to access the sys
tem.
Platform Administration Admin Manage User Manage Support Enables users man
Access age users with sec
ondary login access
to the system, using
the Manage Support
Access page.
Platform Employee Pro User General User Live Profile Access This permission
Employee Cen file Permission gives users access
tral ERP Integration to the Employee
Job Profile
Profile page.
Builder
It also allows a user
to access the em
ployee file from data
replication records
in the Employee
Central Data Repli
cation Monitor. The
Data Replication
Monitor is used in
employee master
data, organizational
assignment, and
time data replication
from Employee Cen
tral.
Platform Employee Pro User General User Permission to View Enables users to see
file LinkedIn Block the LinkedIn block
Permission
on People Profile.
Platform Employee Pro Admin Manage System Manage Employee Gives users to ac
file Files cess to the profile
Properties
configuration tool so
that they can config-
ure the content and
layout of the em
ployee profile.
Platform Employee Pro Admin Manage System Manage Badges Enables users to
file create and manage
Properties
custom badges, for
peer-to-peer recog
nition on the em
ployee profile.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Login Count view the Usage Ana
Permissions
lytics report for
Login Count, show
ing the number of
logins per day in the
system.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Daily Active view the Usage Ana
Permissions
Users Count lytics report for
Daily Active Users
Count, showing the
unique number of
users per day in the
system.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Transactions view the Usage Ana
Permissions
lytics report for
Transactions, show
ing the transactions
that are run in the
application.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Page Perform view the Usage Ana
Permissions
ance lytics report for
Page Performance,
showing the end
user experience with
regards to perform
ance of the system.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Module Re view the Usage Ana
Permissions
sponse Times lytics report for
Module Response
Times, showing the
response times in
the system on a
module level.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Session Time view the Usage Ana
Permissions
lytics report for Ses
sion Time, showing
the level of usage by
the average user
each day.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Search Terms view the Usage Ana
Permissions
lytics report for
Search Terms,
showing the most
frequently searched
terms in the system.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Locations view the Usage Ana
Permissions
lytics report for Lo
cations, showing the
geographical break
down of the loca
tions the users are
logging in from.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Browsers view the Usage Ana
Permissions
lytics report for
Browsers, showing a
breakdown of the
types of browsers
being used to ac
cess the applica
tions.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Devices view the Usage Ana
Permissions
lytics report for De
vices, showing a
breakdown of the
types of devices be
ing used to access
the applications.
Platform Administration Admin Admin Center View Usage Analyt Enables users to
ics Search Count by view the Usage Ana
Permissions
Session lytics report for
Search Count by
Session, showing
the breakdown of
the number of
searches by session.
Platform Administration Admin Admin Center Read Execution Enables users to ac
Integration Manager Events cess the main dash
Permissions
Center board and view suc
cess/fail informa
tion.
Platform Integration Admin Admin Center Data Access for Don't use this per
One Inbox Integra mission or assign it
Permissions
tion to anyone. It's only
used internally for
integration with SAP
One Inbox.
Platform Administration Admin Manage System Platform Feature Enables users to en
Settings able major platform
Properties
features, such as
Employee Profile or
User Directory, and
to configure other
platform-related
settings. This per
mission is also re
quired to access the
PGP Key Manage
ment page where
you can specify the
encryption keys.
Platform Mobile User General User Mobile Access This permission al
Permission lows users to access
the SAP Success
Factors Mobile app
on their iOS or An
droid mobile devi
ces.
Onboarding 2.0 Employee Central Admin Manage Business Select the options This permission al
Configuration you need for your lows you to use the
scenario Business Configura-
tion UI, where you
can make changes
to the Succession
Data Model directly,
without accessing
Provisioning.
Onboarding 2.0 Document Genera Admin Configure Configure Docu Provides access
tion Document ment Management necessary for man
Management aging documents re
lated to Onboarding
2.0.
Onboarding 2.0 Document Genera Admin Manage Document Manage Document This permission al
tion Generation Template lows you to view and
edit the document
template.
Onboarding 2.0 Document Genera Admin Manage Document Manage Document This permission al
tion Generation Template Mapping lows you to map
document template
variables.
Onboarding 2.0 Document Genera Admin Manage Document Generate All Docu This permission al
tion Generation ments as Admin lows you to generate
all or selected docu
ments for users.
Onboarding 2.0 Onboarding 2.0/ Admin Manage Administrate On This permission al
Offboarding 2.0 Onboarding 2.0 or boarding 2.0 or Off- lows you to manage
Offboarding 2.0 boarding 2.0 con Onboarding content
tent including configura-
tion settings and
document tem
plates.
Onboarding 2.0 Onboarding 2.0/ Admin Manage Cancel Onboarding This permission en
Offboarding 2.0 Onboarding 2.0 or Permission ables participants to
Offboarding 2.0 cancel Onboarding
process flow.
● Hiring manager
● Hiring manag
er's manager
● Onboarding co
ordinator
● HR admin
● System admin
Onboarding 2.0 Onboarding 2.0/ Admin Manage Permission to Can Allows you to cancel
Onboarding 2.0 or
Offboarding 2.0 cel Offboarding Offboarding proc
Offboarding 2.0
esses.
Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2Activities This permission al
Offboarding 2.0 Config lows you to config-
Admin Object ure and manage the
Permissions onboarding tasks
used in onboarding
programs in your
system.
Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2ActivityRes This permission al
Offboarding 2.0 ponsible lows you to assign
Admin Object responsible roles for
Permissions the onboarding ac
tivities in your sys
tem.
Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2FormTem This permission al
Offboarding 2.0 plate lows you to manage
Admin Object form templates.
Permissions
Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2Responsibili This permission al
Offboarding 2.0 tyConfig lows you to config-
Admin Object ure responsible
Permissions roles for the on
boarding activities in
your system.
Onboarding 2.0 DocuSign eSigna Admin Configure Configure Docu This permission pro
ture DocuSign Sign eSignature vides access to the
eSignature admin tool for con
figuring the Docu
Sign eSignature.
Onboarding 2.0 DocuSign eSigna Admin Configure Manage DocuSign This permission pro
ture DocuSign envelopes vides access to the
eSignature admin tool for man
aging DocuSign en
velopes.
Onboarding 2.0 MDF Admin Metadata Configure Object This permission al
Framework Definitions lows you to manage
MDF object defini-
tions.
Onboarding 2.0 MDF Admin Metadata Access to non-se This permission al
Framework cured objects lows a user to ac
cess information
provided by MDF
objects.
Onboarding 2.0 MDF Admin Metadata Import Permission This permission al
Framework on Metadata lows a user to im
Framework port data related to
the Metadata
Framework.
Onboarding 2.0 MDF Admin Metadata Manage Data This permission al
Framework lows a user to man
age data related to
the Metadata
Framework.
Onboarding 2.0 MDF Admin Metadata Configure Business This permission al
Framework Rules lows you to config-
ure business rules
related to MDF ob
jects.
Onboarding 2.0 MDF Admin Metadata Manage Configura- This permission pro
Framework tion UI vides access to the
Manage Configura-
tion admin tool.
Onboarding 2.0 MDF Admin Metadata Manage Positions This permission al
Framework lows you to manage
the MDF Position
object.
Onboarding 2.0 MDF Admin Metadata Manage Sequence This permission pro
Framework vides access to re
quired processes re
lated to MDF ob
jects.
Onboarding 2.0 MDF Admin Metadata Access to Business This permission pro
Framework Rule Execution Log vides access to the
business rule execu
tion log, with the op
tion of including a
permission for
downloading the log.
Onboarding 2.0 MDF Admin Metadata Manage Mass This permission pro
Framework Changes for Meta vides access to re
data Objects quired processes re
lated to MDF objects
in Onboarding 2.0.
Onboarding 2.0 MDF Admin Metadata Admin access to This permission pro
Framework MDF OData API vides access read all
the MDF OData API
entities.
Onboarding 2.0 Document Manage Admin Configure Configure Docu This permission pro
ment Document ment Management vides access neces
Management sary for managing
documents related
to Onboarding 2.0.
Onboarding 2.0 Recruiting Manage User Recruiting Recruit-to-Hire This permission al
ment Permissions Data Mapping lows you to map
fields for the recruit-
to-hire process.
Onboarding 2.0 Object Permissions User Onboarding Object Select the options The permissions
Permissions that best fit your you select deter
scenario mine the level of ac
cess for each type of
onboarding task.
Onboarding 2.0 Employee Profile User General User User Login This permission al
Permission lows you to log on to
the application.
Onboarding 2.0 Employee Profile User General User Permission to Cre Select the forms you
Permission ate Forms want to provide per
mission to create.
For administrators
in Onboarding 2.0, it
is recommended to
select All.
Onboarding 2.0 Administration User HomePage v3 Tile Homepage v3 To- This permission pro
Group Permission Do tile group vides access to the
home page tiles for
to-do notifications.
To provide access to
the other home
page tiles, select the
corresponding per
missions.
Onboarding 2.0 Goal Plans User Goals New Group Goal This permission al
Creation lows you to create
Group Goals.
Onboarding 2.0 Goal Plans User Goals Goal Plan Permis This permission al
sions lows you to access
the goal plans.
Onboarding 2.0 Object Permissions User Onboarding 2.0 or Message" Task Enables participants
Offboarding 2.0
to view, set, and up
Object
date the Welcome
Permissions
Message for the new
hire.
● Hiring manager
● Hiring manag
er's team
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Buddy" Task Enables participants
Offboarding 2.0
to view or edit As
Object
sign a Buddy activ
Permissions
ity.
● Hiring manager
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Recommended Enables participants
Offboarding 2.0 People" Task to view, add, or re
Object move recommended
Permissions people for new hire.
● Hiring manager
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Recommended Enables participants
Offboarding 2.0
Link" Task to view or modify
Object
recommended links.
Permissions
Full permission rec
ommended for:
● Hiring manager
Onboarding Object Permissions User Onboarding 2.0 or "Equipment" Task Enables participants
Offboarding 2.0
to view/edit fur
Object
nished equipment
Permissions
orders.
● Hiring manager
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Meeting" Task Enables participants
Offboarding 2.0
to schedule meet
Object
ings.
Permissions
Full permission rec
ommended for:
● Hiring manager
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Goal" Task Enables participants
Offboarding 2.0
to set up goals.
Object
Permissions Full permission rec
ommended for:
● Hiring manager
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Checklist" Task Enables participants
Offboarding 2.0
to create a checklist.
Object
Permissions
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Prepare for Day Enables participants
Offboarding 2.0
One" Task to view or edit sup
Object
plemental items.
Permissions
Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Where To Go" Task Enables participants
Offboarding 2.0
to view or edit sup
Object
plemental item loca
Permissions
tions.
Onboarding 2.0 Object Permissions User Onboarding 2.0 or Document Flow Enables participants
Offboarding 2.0
to view or edit pa
Object
perwork status.
Permissions
View permission
recommended for:
● Hiring manager
● Hiring manag
er's manager
● Onboarding co
ordinator
● HR admin
Onboarding 2.0 Object Permissions User Onboarding 2.0 or ONB2Process Enables participants
Offboarding 2.0
to close Onboarding
Object
process flow.
Permissions
Full permission rec
ommended for:
● Hiring manager
● Hiring manag
er's manager
● Onboarding co
ordinator
● HR admin
● System admin
Onboarding 2.0 Object Permissions User Onboarding 2.0 or ONB2ProcessTrig Enables participants
Offboarding 2.0
ger to trigger Onboard
Object
ing and Offboarding
Permissions
process flow.
● Hiring manager
● Hiring manag
er's manager
● Onboarding co
ordinator
● Offboarding co
ordinator
● HR Admin
● System Admin
Onboarding 2.0 Object Permissions User Onboarding 2.0 or Asset Task Enables participants
Offboarding 2.0
to list and track the
Object
oragnization's as
Permissions
sets that the Off-
boardee must return
before his last work
ing day.
● Hiring manager
● Hiring manag
er's manager
● Onboarding co
ordinator
● Offboarding co
ordinator
● HR Admin
● System Admin
Onboarding 2.0 Email Framework Admin Configure Email Configure Email Email category rep
Framework
Permissions Categories resents a certain
Permissions
email template
group, such as the
Buddy Category:
category for buddy
assignment and re
moval. It also in
cludes rules for
building email mes
sage attributes,
such as recipient
and content.
Onboarding 2.0 Email Framework Admin Configure Email Configure Email Triggers can be ap
Framework
Permissions Triggers plied as rules for
Permissions
sending emails. For
example, Buddy As
signment Cancella
tion Trigger: Notify
the assigned buddy
that the task has
been reassigned to a
different colleague.
Onboarding 2.0 Email Framework Admin Configure Email Configure Email Email Template pro
Framework
Permissions Templates vides a specific
Permissions
email form gener
ated by certain con
ditions and rules.
Onboarding 2.0 Email Framework Admin Configure Email Configure Audit This allows you to
Framework
Permissions Trail display a list of
Permissions
emails sent by the
system. The Actions
you can take in
clude: View Email,
Resend, and Display
Details.
Onboarding 2.0 Email Framework Admin Configure Email Allow Resend This allows you to
Framework
Permissions Emails trigger new re
Permissions
minder emails and
complete or edit the
To and CC fields.
Onboarding 2.0 MDF Admin Metadata Configure Business Allows you to config-
Framework
Rules ure the business
rules associated
with your onboard
ing programs.
Onboarding 2.0 Object Permissions Admin Email Framework EmailMessage Provides access
Object
necessary for man
Permissions
aging email mes
sages sent by the
system.
Onboarding 2.0 Object Permissions Admin Email Framework EmailReminder Provides access
Object
State necessary for man
Permissions
aging email remind
ers to be sent to the
Onboardee/
Employee. These
objects track an
email’s reminder
status and its last
sent timestamp.
Onboarding 2.0 Object Permissions Admin Email Framework EmailTemplate Provides access
Object
necessary for man
Permissions
aging email forms
(or templates)
present in the sys
tem.
Onboarding 2.0 Object Permissions Admin Email Framework EmailTrigger Provides access
Object
necessary for man
Permissions
aging email rules
used for sending dif
ferent types of
emails to the On
boardee/Employee.
Onboarding 2.0 Object Permissions Admin Email Framework EmailTriggerCate Provides access
Object
gory necessary for man
Permissions
aging categories of
emails that are trig
gered by the sys
tem.
Onboarding 2.0 Employee Profile User General User User Login Provides access to
Permission
your system.
Onboarding 2.0 Employee Central User Employee Data HR Information Select the view and
edit field options
that best fit your re
quirements.
Onboarding 2.0 Employee Central User Employee Data Employment De Select the view and
tails edit field options
that best fit your re
quirements.
Onboarding 2.0 Employee Central User Employee Central Select the options Determines which
Effective Dated
that best fit your re effective-dated
Entities
quirements. fields can be viewed
or edited.
Onboarding 2.0 Object Permissions User Onboarding Object Select the options The permissions
Permissions
that best fit your you select, deter
scenario. mine the level of ac
cess for each type of
onboarding task.
Onboarding 2.0 Manage Onboard Admin Manage On/ Manage Onboard Allows you to view
Offboarding
ing/Offboarding ing Permission the Onboarding or
On/Offboarding tab
in the main Suc
cessFactors HCM
menu. Also allows
access to the On
boarding application
work queue.
Onboarding Manage Onboard Admin Manage On/ Manage field map Allows you to access
Offboarding
ing/Offboarding ping tool for Em the Admin Center
ployee Central Field Mapping tool
for Onboarding/
Offboarding EC Inte
gration tool to de
fine field mappings
for integrating On
boarding/Offboard
ing with Employee
Central.
Onboarding Manage Onboard Admin Manage On/ Manage Onboard Allows you to access
Offboarding
ing/Offboarding ing additional con the Configure new
tent hire activity planning
process, Maintain
Central Orientation
Meetings, and Main
tain Lists of Items to
Bring tools in Admin
Center.
Recruiting Recruiting Manage User Recruiting Onboarding Initiate Allows you to initiate
Onboarding Permissions
ment Permission onboarding for a
candidate in RCM.
After Onboarding is
successfully initi
ated, an Onboarding
activity is created
for the candidate in
Onboarding.
Recruiting Recruiting Manage User Recruiting Onboarding Update Allows you to up
Onboarding Permissions
ment Permission date the Onboarding
activity for custom
ers using Recruiting
Management - Veri
fications Inc. inte
gration.
Note
This permission
is not relevant
for SuccessFac
tors HCM On
boarding.
Recruiting Recruiting Manage Admin Manage Recruiting Set Up Onboarding Allows you to define
Onboarding ment Integration field mappings for
the RCM entity tem
plates: Job Requisi
tion, Job Offer, and
Job Application. If
you are using Intelli
gent Services, you
will get options for
propagating RCM
updates to On
boarding and reas
signing ongoing On
boarding activities.
This permission is
also required for
users to be able to
view the history
page for Alternative
Cost Distribution.
Onboarding OData API Admin Manage Allow Admin to Ac This permission en
Integration Tools
cess OData API ables a user to cre
through Basic Au ate, read, update, or
thentication delete information
using the available
OData APIs.
Onboarding OData API Admin Manage Access to OData This permission en
Integration Tools
API Audit Log ables a user to mon
itor the API calls.
Onboarding OData API Admin Manage Access to API Cen This permission en
Integration Tools
ter ables a user to ac
cess the API Center.
Onboarding OData API Admin Manage Access to OData This permission en
Integration Tools
API Metadata Re ables a user to re
fresh and Export fresh the metadata
of the OData APIs
using the Admin
Center tools.
Onboarding OData API Admin Manage Access to OData This permission al
Integration Tools
API Data Dictionary lows users to man
age OData API data
dictionary in Admin
Center.
Onboarding Employee Profile User General User User Login Enables a user to log
Permission
into the system.
Onboarding Employee Profile User General User Live Profile Access This permission
Permission
gives users access
to the Employee
Profile page.
Onboarding Employee Profile User General User SAP Jam Access This permission al
Permission
lows users to access
the SAP Success
Factors JAM page.
Onboarding Employee Profile User General User Mobile Access This permission al
Permission
lows users to access
the SAP Success
Factors Mobile app
on their iOS or An
droid mobile devi
ces.
Recruiting MDF Recruiting User MDF Recruiting MDF Objects For View: Quickcard
Candidate Relation
Permissions icon is displayed if
ship Management:
the information al
Campaign
ready exists. Other
CampaignCont
wise nothing is dis
ent
played.
CampaignCont
ent View and Edit:
CampaignRecip Quickcard icon is
ient displayed if the in
Candidate formation already
Follow
exists. Otherwise a
CandidateActivi
Create icon is dis
ty
played.
Import/Export: Ena
bles you to use
standard MDF
framework import
and export function
ality for that object.
Recruiting Recruiting Manage User MDF Recruiting MDF Objects to en Enables Candidate
Permission able Talent Pool: Relationship Man
ment
agement talent pool
CampaignPool
features.
Pool Member
Recruiting Recruiting Manage User MDF Recruiting MDF Object: Pool Edit Yes: Create
ment Permissions Talent Pool link is
visible and active
(clickable). The
Talent Pool popup is
opened in Edit
mode. Edit link is al
ways active, and dy
namically opens the
Talent Pool popup in
Edit mode (Owner
only) or Read-only
mode (other users).
Edit No:
Row-Level (Sharing)
Permission: Owner
only
Recruiting Recruiting Manage User MDF Recruiting MDF Object: Share View Yes: Link is visi
Pool with Group
ment Permissions ble and active (click
able). Share with
Groups popup can
be opened, showing
list of recruiting
groups with which
this pool is shared.
Row-Level (Sharing)
Permission: Owner
only
Recruiting Recruiting Manage User MDF Recruiting MDF Object: Share View Yes: Link is visi
Pool with User
ment Permissions ble and active (click
able). Share with
People popup can
be opened, showing
list of users with
whom this pool is
shared.
Recruiting Recruiting Manage User MDF Recruiting CRM Saved Search View Yes: Makes List
ment Permissions of Saved Searches
visible and editable
on the Talent Pool
user interface. List
of saved searches
link is visible and ac
tive. Backend Utility
(CRMSavedSearch
permission check) is
required. Saved
Searches popup can
be opened, showing
list of saved search
criteria associated
with this pool.
Recruiting Recruiting Manage Admin In Manage Recruiting Permis An Admin role is cre
Permission Roles, sion ated
ment
create a role
named Admin.
Recruiting Recruiting Manage Admin Add the Admin Recruiting Permis The Admin role is
user to the Admins sion added to the Admins
ment
group. For the per group.
mission changes
to take effect, log
out, close the
browser, and log
back in.
Recruiting Recruiting Manage User In Manage Recruiting Permis Grants a user the
Employee Import, sion ability to access the
ment
grant a user the link and upload a
ability to access CSV file of test
the link and upload users.
a CSV file of test
users.
Recruiting Recruiting Manage User In Language Packs, Recruiting Permis Designates the lan
select the lan sion guages for Recruit
ment
guages for Recruit ing
ing
Recruiting Recruiting Manage User Company Settings Recruiting Permis Enables Employee
Click Employee sion Central Foundation
ment
Central Founda Objects. Required
tion Objects. for manually migrat
ing job classification
objects to MDF Ge
neric Objects.
Recruiting Recruiting Manage User General User Mobile To-Do List Enables requisition
Permission Access routing.
ment
Recruiting Recruiting Manage Admin Recruiting Odata API Grants OData API
Permissions RCMApplication permissions to an
ment
Export Admin.
Recruiting Recruiting Market User Recruiting Check these boxes: Enables Advanced
Permissions Analytics and allows
ing ● Recruiting
user to access the
Marketing
drill to details option
Advanced
when Access
Analytics
Advanced Analytics
Permission
with Details permis
● Access
sion is enabled.
Advanced
Analytics with
Details
● Recruiter RMK
SSO
Permission
● Job Marketing
● Access
Advanced
Analytics with
Details
Recruiting Recruiting Manage Admin Recruiting Check this box: Enables Careers Tab
Permissions Careers Tab
ment
Permission
Recruiting Recruiting Manage Admin Manage Recruiting Set Up Job Boards Sets options for job
Permission boards.
ment
Recruiting Recruiting Manage Admin Manage Recruiting Manage Detailed Enables Detailed
Requisition Requisition
ment
Reporting Privileges Reporting Privileges.
permission
Recruiting Recruiting Manage Admin Manage Recruiting Set up Agency Enables Agency
Access. functionality.
ment
Recruiting Recruiting Manage User Recruiting Bulk Create Allows users to bulk
Permissions Candidates create candidate
ment
from .CSV File profiles from .CSV
files. Follow instruc
tions in the guide on
how to enable per
mission.
Platform Integration Center Admin Manage Allow users to This permission al
Integration Tools execute lows you to trigger
"Application/UI" or any application or
"Event-based" Intelligent Service
Integrations event-based integra
tion. For example, to
do a background
check of a candidate
before actually
scheduling an inter
view, you need to
have an Applica
tion/UI triggered in
tegration created
and mapped to a
corresponding back
ground check ven
dor. Enable Allow
users to execute
"Application/UI" or
"Event-based"
Integrations permis
sion to a Recruiter
role to run any Ap
plication/UI based
integration.
Note
To trigger any
application or
Intelligent Serv
ice event-based
integration, you
do not need the
following man
datory Integra
tion Center per
missions:
Admin access to
MDF OData API,
Access to
Integration
Center, and
Access to non-
Secured
Objects. How
ever, you must
enable these
permissions to
use Integration
Platform Integration Center Admin Manage Read Security This permission al
Integration Tools Center artifacts lows you to access
using API and read security ar
tifacts (like configur-
ing outbound
OAuth, generating
OAuth X509 key,
and so on) main
tained in Security
Center. This permis
sion is only for API
access and not for
Security Center UI
access. There is no
change in permis
sions for Security
Center UI access.
Note
To access Se
curity Center ar
tifacts, you
need not have
the following In
tegration Cen
ter permissions:
1. Admin ac
cess to
MDF OData
API
2. Allow Ad
min to Ac
cess OData
API
through
Basic Au
thentica
tion
3. Access to
Integration
Center
Platform Document Admin Manage Document Configure Docu Enables users deter
Management Categories ment Management mine which catego
ries of documents
your users have ac
cess to.
Employee Central Workflows User Manage Workflows Prevent Quick Ap This permission pre
proval for Workflow vents users from
mass approving
their workflow re
quests in the
Approve Requests
dialog box or on the
My Workflow
Requests page. They
must open each
workflow request,
review the details,
and approve it indi
vidually on the
Workflow Details
page.
Platform Administration Administrator Admin Alerts Ob Invalid Approvers in This permission al
ject Permissions Employee-Related lows administrators
Employee Central Workflows
Workflows to view and access
employee-related
workflows with inva
lid approvers from
the Admin Alerts 2.0
tile.
Platform Administration Administrator Admin Alerts Ob Invalid Dynamic This permission al
ject Permissions Role Users lows administrators
Employee Central Workflows
to view and access
invalid users in
cluded in dynamic
roles from the Ad
min Alerts 2.0 tile.
Platform Administration Administrator Admin Alerts Ob Stalled Workflows - This permission al
ject Permissions Employee Related lows administrators
Employee Central Workflows
to view and access
stalled employee-re
lated workflows
from the Admin
Alerts 2.0 tile.
Context
If you find that users have access to applications or data they should not have, we recommend the following steps:
Procedure
1. Run the View User Permission report to determine how - through which role - the permission was granted to
the employees. For details see How can you check the permissions assigned to a user? [page 161]
2. If that does not clarify how/why they have that permission or creates concern about where else this permission
is visible, then use the RBP Permission to User Report with the Single Permission Filter to validate what other
groups have access to this permission. For details see How can you run an ad hoc report? [page 162]
Role-based permissions refresh periodically to propagate any changes to your dynamic groups or to the permission
roles in your system. These changes occur when employees are hired, employees change departments, and during
integration scenarios.
When changes to your employees' information occur in your SAP SuccessFactors HXM Suite such as, job title
changes, hiring of new employees, or giving additional responsibilities to employees, your role-based permissions
security platform runs an automated process that propagates these changes in your system. The changes affect
the permission roles that employees have access to and the permission groups they belong to. The Refresh
Framework handles this automated process in your system. Depending on the size of your organization, you may
have a high number of user changes or you could have a relatively low number of user changes in your system. The
refresh framework uses two types of refresh jobs to handle these scenarios.
On-demand mode (Previously called Real-Time Refresh) When changes to user information occur infrequently, each up
date action triggers its own refresh job.
The Refresh Framework consists of two types of refresh jobs: the on-demand mode and buffer mode. The refresh
framework automatically adjusts between buffer mode and on-demand mode, based on the actual refresh work
load.
When the workload is light, the framework enables the on-demand job. This is the refresh mode you're most
familiar with as you may currently use it for each refresh request. For example, an API call to change one user
causes a refresh on all user groups.
When the workload is heavy, on-demand mode is disabled and buffer mode is enabled. That means requests within
the next 5 minutes will buffer and reschedule tasks based on the buffer refresh request.
Note
If your company has scheduled a background job to refresh RBP regularly, the scheduled job remains effective
and RBP refresh follows the defined interval. The Refresh Framework doesn't take effect even if you stop the
background job. If you wish to start using the Refresh Framework in your company, contact SAP Cloud Support.
The Refresh Framework automatically switches between two refresh types depending on the workload detected. If
infrequent user information changes occur, your RBP roles and groups are immediately refreshed. If frequent user
information changes are detected, the buffer mode helps to reduce duplicate requests by collecting delta changes
and processing them in one refresh request. As a result, you experience improved system stability and better RBP
refresh performance. With the buffer mode enabled, you notice little delay.
No. If your organization uses Scheduled Jobs, the Refresh Framework doesn’t impact your system.
Procedure
1. Go to Administration Tools.
2. In the Manage Employees portlet, select Set User Permissions.
3. In the Set User Permissions section, select View User Permissions.
4. In the Advanced Search, enter the user name.
5. Click View Permission next to the user name.
A list of permissions is displayed along with the roles that grant those permissions.
6. To learn more about the roles, click the pop-up window icon next to any role name.
Context
Procedure
3. On the Execute Permission to User… screen, open the Take Action menu and choose Edit.
4. Choose By My Selection and select the permission you are interested in.
The cross domain ad hoc report capability allows Administrators to run reports between the Role-Based
Permission (RBP) domain and Employee Central (EC) domain. RBP reports are included in the drop-down menu
when selecting the Cross Domain Report Definition types.
Administrators can create Cross Domain Reports to join RBP and Employee Central data. Person and Employment
is the EC domain information that is included and the tables are joined using the user_sys_id key.
User Role Search can search the roles granted to specific users for a specific permission and a target user. When
some users get some permissions on some target users that should not be granted, the administrator can use this
tool to find which role grants the permission so they can update the permission settings.
● This tool does not support MDF RBP permission as search criteria.
● This tool does not support Inactive Internal User or TBH user to be selected as Target User.
● This tool does not support External User.
1. Go to Administration Tools.
2. In the Manage Employees portlet, select Set User Permissions.
3. In the Set User Permissions section, select User Role Search.
6. Click Search Roles Button. The search result will display all roles that grant this permission and target user to
the access users. If the target user field is empty, the search result will not consider target user. If a result you
expect to see is not showing up, it may be because there are back-end update jobs still running.
7. On the Result session, you can click on the role name to see role detail. On the role detail page, the grant rules
that grant the selected access user and target user will be highlighted in the “Grant this role to …” session.
You can use User Role Search to quickly search for and compare permission roles assigned to specified users in
role-based permissions.
1. Go to Administration Tools.
2. In the Manage Employees portlet, select Set User Permissions.
3. In the Set User Permissions section, select User Role Search.
4. In the Selection session of the tool, enter the Access Users whose roles you are comparing.
5. Click Search Roles Button. The search result will display which roles, if any, grant the specified permission to
either user. In the following example, you can see that both of the selected access users have permission to
view address data.
6. If a user does not have the specified permission, it is indicated as "no result." In the following example, you can
see that the user "cgrant" has permission to view "Impact of Loss" data, due to her roles as a manager and
administrator. The user "jreed" is not assigned to any role that allows him to view this information.
7. You can also specify one target user, in order to see whether either of the two access users has the specified
permission for the specified target. In the following example, you can see that although both user "cgrant" and
user "dsharp" are managers, only user "cgrant" has permission to view "Impact of Loss" data for user
"vstokes". This is because, in this example, the manager role has a target permission group of "All Direct
Hyperlinks
Some links are classified by an icon and/or a mouseover text. These links provide additional information.
About the icons:
● Links with the icon : You are entering a Web site that is not hosted by SAP. By using such links, you agree (unless expressly stated otherwise in your agreements
with SAP) to this:
● The content of the linked-to site is not SAP documentation. You may not infer any product claims against SAP based on this information.
● SAP does not agree or disagree with the content on the linked-to site, nor does SAP warrant the availability and correctness. SAP shall not be liable for any
damages caused by the use of such content unless damages have been caused by SAP's gross negligence or willful misconduct.
● Links with the icon : You are leaving the documentation for that particular SAP product or service and are entering a SAP-hosted Web site. By using such links, you
agree that (unless expressly stated otherwise in your agreements with SAP) you may not infer any product claims against SAP based on this information.
Example Code
Any software coding and/or code snippets are examples. They are not for productive use. The example code is only intended to better explain and visualize the syntax and
phrasing rules. SAP does not warrant the correctness and completeness of the example code. SAP shall not be liable for errors or damages caused by the use of example
code unless damages have been caused by SAP's gross negligence or willful misconduct.
Gender-Related Language
We try not to use gender-specific word forms and formulations. As appropriate for context and readability, SAP may use masculine word forms to refer to all genders.
SAP and other SAP products and services mentioned herein as well as
their respective logos are trademarks or registered trademarks of SAP
SE (or an SAP affiliate company) in Germany and other countries. All
other product and service names mentioned are the trademarks of their
respective companies.