0% found this document useful (0 votes)
38 views170 pages

Using Role-Based Permissions: Public Document Version: Q4 2019 - 2020-02-01

SuccessFactors Role Based Permissions
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
38 views170 pages

Using Role-Based Permissions: Public Document Version: Q4 2019 - 2020-02-01

SuccessFactors Role Based Permissions
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

PUBLIC

Document Version: Q4 2019 – 2020-02-01

Using Role-Based Permissions


© 2020 SAP SE or an SAP affiliate company. All rights reserved.

THE BEST RUN


Content

1 What's New in the Using Role-Based Permissions Guide. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .3

2 Introduction to Using RBP. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7

3 What Are Role-Based Permissions?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8


3.1 Permission Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Creating Static Permission Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Creating Dynamic Permission Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
View, Edit, Copy, and Delete Permission Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
3.2 Permission Roles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Creating Permission Roles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
Assigning Permissions to a Role. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
View, Edit, Copy, and Delete Permission Roles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Creating a New Role for External Users. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
3.3 Grant Permission Roles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Granting Roles to Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Assigning Target Populations to a Role. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Using Relationships to Grant Permission Roles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27

4 How to Use the Master List of Role-Based Permissions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31


4.1 List of Role-Based Permissions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31

5 Troubleshooting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159
5.1 How Do Permissions Update When User Information Changes?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159
5.2 How can you check the permissions assigned to a user?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 161
5.3 How can you run an ad hoc report?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 162
5.4 Cross Domain Ad Hoc Reporting Between the RBP and Employee Central Domains. . . . . . . . . . . . . . . .163
5.5 How do you run a user search. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .164

Using Role-Based Permissions


2 PUBLIC Content
1 What's New in the Using Role-Based
Permissions Guide

The most recent changes made to this guide are listed below.

Q4 2019

The following table summarizes changes to this guide for the Q4 2019 release.

What's New Description More Info

Updated the employee number limit for Large organizations with up to 1,500,000 What Are Role-Based Permissions?
large organizations using RBP employees can also use RBP now to de­ [page 8]
sign their security model. We've raised
the limit of employee number approved
for organizations using RBP from
300,000 to 1,500,000.

Added the following permissions: Recruiting Permissions ● When enabled for specific employ­
Recruiting ees or permission roles, disallows
viewing a proxied users career tab
● Hide Career Tab for Proxy User
and tile.
● Manage Multistage and Late Stage
● Enables being able to access the
Application Preview
Manage Multistage and Late Stage
Application Preview from Admin
Center.

Added the following permissions: The permissions enable users to receive ● Users without these permissions
alerts relating to the relevant workflows.
● Admin Alerts Object Permissions: can process the same workflows in
○ Invalid Approvers in Employee- the old Admin Alerts. When these
Related Workflows permissions are granted, the work­
○ Invalid Dynamic Role Users flows move over to Admin Alerts 2.0.
Admin Alert Field-level overrides are available,
○ Stalled Workflows - Employee meaning that users can be granted
Related
or denied permissions for individual
fields within the objects.

Added the following permissions: Some checks include a "quick fix" that
users can run to immediately correct the
● Check Tool issues found by the check. Users need
○ Allow Check Tool Quick Fix this permission before they can use the
quick fixes.

Using Role-Based Permissions


What's New in the Using Role-Based Permissions Guide PUBLIC 3
What's New Description More Info

Added the following permissions for These permissions enable users to man­
Manage Pending Hires: age the Manage Pending Hires tool.

● Manage Pending Hires


● Allow Manage Others Save Draft
● Configure Columns for the Manage
Pending Hires

Added the following permissions for: ● The permission prohibits roles from
● Succession Planners accessing the Talent Pool tab from
other Succession features and Peo­
○ Hide Talent Pool Page
ple Profile.
● Manage Succession
● The permission allows roles to ac­
○ Talent Pool Field Configuration cess the Manage Talent Pool Field
Settings in Admin Center.

Added a permission for Document Man­ The permission is called Manage Docu­ This permission allows you to separate
agement.
ment Categories document category permissions.

Added the following permissions for User ● This permission allows the Admin to
Management:
access the Manage Login Accounts
● Manage Login Accounts tool.
● Basic User Import ● When the "Enable Control on Basic
User Import in Role-Based Permis­
sions"option has been enabled, this
permission allows the Admin to per­
form basic user import in the Em­
ployee Central-enabled instances.

Added the following permissions to Re­ Reward and Recognition permissions ● To enable your users to redeem their
ward and Recognition: Spot Awards: supporting the points-based awards pro­
awarded points and see their current
gram.
● Spot Award Redemption point balance, set Spot Award
● Spot Award User Balance Redemption to Edit and Spot Award
User Balance to View.

 Caution
Make sure to restrict the target pop­
ulation to only allow users to see
their own data (Granted User (Self)).
If you set Target Population to
Everyone, then each user will be able
to see everyone's information.

Using Role-Based Permissions


4 PUBLIC What's New in the Using Role-Based Permissions Guide
Q3 2019

The following table summarizes changes to this guide for the Q3 2019 release.

What's New Description More Info

Added the following permissions:


 Note
● Admin Alerts 2.0
Admin Alerts 2.0 are currently only
○ Access Admin Alerts
supported for Employee Central
○ Configure Alert Types
Time Management.
○ Trigger Rerun

Added the Change Assignment ID per­ This permission allows the Admin to
mission change assignment ID using the conver­
tAssignmentIdExternal function import.

Q2 2019

The following table summarizes changes to this guide for the Q2 2019 release.

What's New Description More Info

Added Delegate Relationship. Topic


linked below.

Added the following permissions: We removed the Mentoring permission -


Admin access to MDF OData API
● Talent Search Export Permission
● Prevent Quick Approval for Workflow
● Allow Admin to Access OData API
through Basic Authentication

Q1 2019

The following table summarizes changes to this guide for the Q1 2019 release.

What's New Description More Info

No Updates

Using Role-Based Permissions


What's New in the Using Role-Based Permissions Guide PUBLIC 5
Q4 2018

The following table summarizes changes to this guide for the Q4 2018 release.

What's New Description More Info

November 30, 2018

We've added the master RBP list to this The list is located in the section called
How to Use the Master list of Role-
guide.
Based Permissions

November 16, 2018

No Change

November 02, 2018

No Change.

Q3 2018

The following table summarizes changes to this guide for the Q3 2018 release.

What's New Description More Info

We've updated the topics in this guide for Updated topics include: What are Role-
accuracy. Based Permissions? and all subsequent
topics.

Q2 2018

The following table summarizes changes to this guide for the Q2 2018 release.

What's New Description More Info

There were no updates to this guide for


Q2 2018

Related Information

Delegate Relationship Assignments [page 27]

Using Role-Based Permissions


6 PUBLIC What's New in the Using Role-Based Permissions Guide
2 Introduction to Using RBP

Filter and search for the role-based permissions specific to your system's implementation and learn how to test
your RBP configruation.

This content is intended for security administrators to enable them to manage Role-Based Permissions (RBP).

It is important to note that RBP is the only permission model that is available to new customers. New customers
cannot disable RBP to use legacy permissions. Existing customers, new companies of Professional Edition or free
trial are not affected.

The first section familiarizes you with the concept of role-based permissions.

The subsequent sections detail the individual tasks that make up the process. Finally, you will find troubleshooting
information in case problems occur with the permissions.

 Note

This implementation content covers all general aspects of setting up RBP. The implementation handbooks for
the individual modules may contain additional module-specific information.

Using Role-Based Permissions


Introduction to Using RBP PUBLIC 7
3 What Are Role-Based Permissions?

Role-Based Permissions (RBP) is a security model that allows you to restrict and grant access to your SAP
SuccessFactors HXM Suite. RBP controls access to the applications that employees can see and edit. This is a
suite-wide authorization model that applies to the majority of the SAP SuccessFactors products.

Open this video in a new window

The RBP security authorization model uses groups and roles to organize employees (groups) and permissions
(roles) to control access to your system; By organizing employees into groups and permissions into roles you can
assign a group of employees the same set of permissions by assigning them a role.

 Note

RBP is approved for organizations with up to 1,500,000 employees. We’ll continue to raise this bar in the future.
When in doubt, contact SAP Cloud Support.

Role-based permissions contain three main elements: permission groups, permission roles, and target populations.

● Permission groups are a set of employees who share certain attributes such as City or Job Code and require
access to a similar set of tasks within your system.
● Permission roles are defined as a set of permissions. You can assign the permission roles you define to a
permission group, and if the role requires that you define a target population, meaning a group to perform
tasks for, you assign the target population when you define the role.
● Target populations are groups that are assigned to permission roles when the permission granted is performed
on behalf of other employees.

 Tip

We recommend that you create groups before creating roles so that during role creation, you can select the
group for which to grant the role. In addition, you need defined groups for roles that require a target population.

Permission Groups [page 9]


Permission groups are used to define groups of employees who share specific attributes. You can use
various attributes to select the group members, for example a user's department, country/region, or job
code.

Permission Roles [page 16]


RBP uses permission roles to group a set of permissions. After grouping the permissions into a role, you
can assign the role to a group of users, granting them access to certain tasks and features in your system.

Grant Permission Roles [page 22]


You can assign a permission role to everyone or to a subset of employees, determined by permission
groups, target populations, or by relationships. When defining a role in RBP, you can assign the role to a
group that you've created or you can assign roles based on hierarchical relationships. Some roles will
require that you also assign target populations, they're only necessary for certain permissions in a role and
your system will notify you when a target population is required.

Using Role-Based Permissions


8 PUBLIC What Are Role-Based Permissions?
Related Information

Creating Dynamic Permission Groups [page 13]


Creating Permission Roles [page 17]
Granting Roles to Groups [page 24]

3.1 Permission Groups

Permission groups are used to define groups of employees who share specific attributes. You can use various
attributes to select the group members, for example a user's department, country/region, or job code.

 Example

There might be a permission group called "Human Resources in US", which lists all US-based employees who
work in the HR department. To define this group, you would specify that users must match the selection criteria
"Country/Region = United States" and "Department = HR".

 Note

The attributes or selection criteria that are available for defining groups are configurable.

In RBP, you can assign permission roles to permission groups. In addition, you use groups to define the target
population a granted user has access to.

 Example

The group "Human Resources in US" might have access to the group "US Employees".

Groups configured with criteria other than specific user names are called dynamic (as opposed to static),
which means that the assignment of employees into and out of a group is automated. For example, a group of
granted users can be “All employees in the Sales department”. As employees are transferred into and out of the
sales department, their permissions will automatically adjust. This automation will save you time and money.
This is especially beneficial for large organizations that need higher levels of administrative efficiency.

Creating Static Permission Groups [page 10]


Static permission groups are created and modified by adding individual user names to a group using an
excel spreadsheet. They store a static list of users instead of a list based on dynamically generated criteria.
Changing user information does not modify group members, you must redefine group members by
importing an updated spreadsheet.

Creating Dynamic Permission Groups [page 13]


Dynamic permission groups are generated automatically when the attributes of employees match the
group selection criteria. Administrators can create and manage dynamic permission groups for both
employees and external users.

View, Edit, Copy, and Delete Permission Groups [page 15]


You can edit, copy, and delete static or dynamic permission groups. For dynamic groups, you can also view
the group's change history.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 9
3.1.1 Creating Static Permission Groups
Static permission groups are created and modified by adding individual user names to a group using an excel
spreadsheet. They store a static list of users instead of a list based on dynamically generated criteria. Changing
user information does not modify group members, you must redefine group members by importing an updated
spreadsheet.

Procedure

1. In the Admin Center, search for Manage Permission Groups.


2. Click Import Static Groups to create or modify a group.
3. Select between Full Replace or Delta Replace.
A full replace, creates or entirely replaces a group, while a delta replace adds members to an already existing
group.

4. Download a blank CSV template after you've chosen an import type. The Full Replace template has two column
headers, GROUPNAME and USERID. The Delta Replace has an additional Action column.
5. For each user that you add to a group, add the group name to the GROUPNAME column and user's ID to the
USERID column.

 Note

For new users, you can create user IDs in the upload file.

 Note

Character encoding of your file should be Unicode(UTF-8). The maximum file size is 20MB. If your import
file exceeds 20MB, you can either split the file into several smaller files or request Professional Services to
modify the system configuration file.

Using Role-Based Permissions


10 PUBLIC What Are Role-Based Permissions?
6. Select the file with your data by clicking Choose File.
7. Click Validate File to validate file format, file size, etc.
8. If the validation is successful, click Upload to import the static permission groups.

If your file has errors, they display at the top of the Import Static Group window.

 Note

For one group type, a maximum of two jobs can run at the same time.

Results

After the upload completes, the system sends you a notification with success or error messages. Successfully
created groups display in the group list after refreshing your system.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 11
[Link] Adding Individual Members to Static Groups

You can add members to a static group in your system or by importing an excel file to your system.

Procedure

1. In the Admin Center, search for Manage Permission Groups.


2. Click the name of the static group you're updating.

The Permission Group screen displays.


3. To add a user to a static group, click Add User.
4. Search for the users you'd like to add to the group.

Entering keywords in the search field displays user names.


5. Select each user you want to add to the group.

Each user you select automatically displays in the right pane.


6. Click Done.

The users you selected are added to the group immediately.

Using Role-Based Permissions


12 PUBLIC What Are Role-Based Permissions?
[Link] Deleting Members from Static Groups

Although you add members to a static group using a spreadsheet, you can delete static group members using the
system.

Procedure

1. In the Admin Center, search for Manage Permission Groups.


2. Click the name of the static group you're updating.

The Permission Group screen displays.


3. Select the users that you want to delete from the group.
4. Click Delete.

The list of users updates immediately.


5. Click Close.

Results

Deleted members will no longer have access to the tasks or data of the group.

3.1.2 Creating Dynamic Permission Groups

Dynamic permission groups are generated automatically when the attributes of employees match the group
selection criteria. Administrators can create and manage dynamic permission groups for both employees and
external users.

Procedure

1. In the Admin Center, search for Manage Permission Groups.


2. Click Create New to create a new permission group.

The Permission Group page opens.


3. Enter a name for your permission group in the Group Name field.
4. Choose a User Type for your group.

The available user types vary depending on how your system is configured. Possible values may include:
○ Employee (default)
○ External Learning User

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 13
 Note

The External Learning User option is only available if you have Learning enabled in your system.

When defining a dynamic group for an external learning user, you can identify an External Source Channel to
complete the criteria for inclusion. This allows external learning users to be defined based on the source of
origin. The external source channel is only available to SAP SuccessFactors Learning customers. The External
Learning User must be enabled in Provisioning for external learner and external source channel to be available.

 Tip

When defining External Learning User groups in your system, it is recommended that you do not create
more than 50 groups.

5. Choose the group selection criteria from the People Pool, in the Choose Group Members section.

Depending on the complexity of your permission group selection criteria, you can choose multiple people
pools.

6. In the Search Results screen, enter a search term or click the  search, to display all available values.

For some categories, a smaller pop-up window appears where you can enter additional values or information,
such as Time Zone settings. If you select the Team View category, you can use hierarchical relationships to
specify the group. This allows you to apply rules such as: everybody in Carla Grant's team, all levels deep.
7. Make your selection and click Done.
8. If you want to add another condition for defining the people pool, click Add another category and choose a
category and item. If you use two or more categories, this functions as an AND operation, that is, only users are
selected who meet all selection criteria.

 Example

If you want to create a group of sales employees working in the US, you would need to choose the category
Department and select Sales. You add a second category Country/Region and select United States.

9. Complex group definitions may require you to use multiple people pools. If you use two or more people pools,
these people pools functions as an OR operation, that is, all users are selected who fulfill the selection criteria
of at least one pool.

Click Add another People Pool and then add categories and items.

 Example

You have two different offices: An office in Chicago and an office in Boston. Each office has a Sales team and
a Finance team. You only want to include Sales employees from the Chicago office and Finance employees
from the Boston office. You'll need to create two separate pools then.

 Note

The number of people pools in a group is limited to three.

10. If there are employees you'd like to exclude from the Permission Group definition, select them in the Exclude
these people from the group section.
11. If you want to prevent the group being updated automatically when new employees match the selection
criteria, click Lock group.

Using Role-Based Permissions


14 PUBLIC What Are Role-Based Permissions?
12. (Optional) Choose Update in the Active Group Membership box to see how many users match the criterial. Click
the number to see the detail list.

The active group membership number isn't updated automatically when you modify the dynamic group
definition.
13. Choose Done to complete the process.

3.1.3 View, Edit, Copy, and Delete Permission Groups

You can edit, copy, and delete static or dynamic permission groups. For dynamic groups, you can also view the
group's change history.

Context

 Note

You can only delete a permission group if it has no associated role.

Procedure

1. Go to the Admin Center Tools and search for Manage Permission Groups.
2. In the Manage Permission Groups screen, click the Take Action dropdown menu next to the permission group
you want to modify.
3. Choose the desired action.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 15
3.2 Permission Roles

RBP uses permission roles to group a set of permissions. After grouping the permissions into a role, you can assign
the role to a group of users, granting them access to certain tasks and features in your system.

Permission roles consist of a set of permissions that give employees access rights to an employee or a group of
employees. As such an employee or a group that has been granted with a permission role has access to certain
aspects of the SuccessFactors application or to aspects of employee data. With this access, they can perform
functions within the application for other groups of employees.

Role-based permissions allow you to grant a role to a specific employee, a manager, a group, or to all employees in
the company. The roles can provide very granular permissions, as this example illustrates:

 Example

There may be roles such as "HR Compensation and Benefits Manager", "HR Manager for Sales", and "HR
Learning and Development Manager". While all three are HR managers, their roles have been distinctly carved
out — one handling compensation and benefits, another handling the sales team, and the third handling
Learning and Development.

When your permissions roles consist of one or more permissions that require a target population, you'll need to
specify a target to complete creation of the role. Roles that require a target population will contain a permission
that gives a group access to perform actions or view information for other employees.

 Example

A Manager may have a role where one permission allows the manager to modify the salary for all of their direct
reports. In this example, the manager's direct reports represent the target population needed for the
permission role.

 Note

Customers can have as many permission roles as the company requires.

Creating Permission Roles [page 17]


Permission roles can be created for employees and for external users, such as External Learning Users.

Assigning Permissions to a Role [page 18]


After creating groups and roles, you'll need to assign permission roles to your employee groups.

View, Edit, Copy, and Delete Permission Roles [page 19]


You can edit, copy, or delete a permission role, view a summary of a permission role, and view its change
history.

Creating a New Role for External Users [page 20]


Role-based permissions support the role of External User and allows the External Learner User limited
access to complete specific tasks or training.

Using Role-Based Permissions


16 PUBLIC What Are Role-Based Permissions?
3.2.1 Creating Permission Roles

Permission roles can be created for employees and for external users, such as External Learning Users.

Context

Permission roles contain a group of permissions that can be granted to an employee or a group of employees
known as the Granted Users Circle. In general, it's best practice to define your user groups before defining your
permission roles.

Procedure

1. Go to the Admin Center.


2. In the Tools Search field, select Manage Permission Roles.
3. To add a Permission Role, click the Create New button. The Permission Role Detail page opens.
4. In the Role Name field, type a name describing of what the role allows you to do.
5. In the Description field, provide a statement describing what the role allows an employee to do. Add a note
about when the role was created and by whom.
6. In the Permission Settings section, click the Permission button to specify the permission you want to assign to
the role. The Permission Settings window opens.
7. On the left side of the page, you'll see the different permission categories. Click a permission category to reveal
the different permissions.

The list of permissions associated with this category is displayed.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 17
8. Select the checkboxes next to the permissions you'd like to grant to the role.
9. Click the Done button when you finish marking your selections.
10. In the Grant this role to section, click the Add button to select the employees to be granted this permission.
11. Grant the permissions and specify the target population according to what you have defined in the workbook.
For a detailed description, see the topic on granting permission roles in the Related Links section.
12. For some permissions, it might be necessary to exclude the granted users from applying the permissions on
themselves. For this, select Exclude Granted User from having the permission access to him/herself.

 Example

If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.

13. Click the Done button to assign this role to the defined users. You are taken back to the Permission Role Detail
page.
14. Click the Save Changes button to complete creating the role.

Next Steps

Once this role is successfully created, the new role will be listed on the Permission Role List page.

Related Information

Grant Permission Roles [page 22]

3.2.2 Assigning Permissions to a Role

After creating groups and roles, you'll need to assign permission roles to your employee groups.

Procedure

1. In the Permission Settings section, click the Permission button to specify the permission you want to assign to
the role. The Permission Settings window opens.
2. On the left side of the page, you'll see the different permission categories. Click a permission category to reveal
the different permissions.

The list of permissions associated with this category is displayed.

Using Role-Based Permissions


18 PUBLIC What Are Role-Based Permissions?
3. Select the checkboxes next to the permissions you'd like to grant to the role.
4. Click the Done button when you finish marking your selections.
5. Click Save Changes.

Next Steps

Assign a target population, if your role indicates that a target is needed.

3.2.3 View, Edit, Copy, and Delete Permission Roles

You can edit, copy, or delete a permission role, view a summary of a permission role, and view its change history.

Context

When you copy a role, only the permissions get copied over. You will need to manually grant employees access to
this new role.

Procedure

1. Go to the Admin Center Tools and search for Manage Permission Groups.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 19
2. In the Permission Role List screen, click the Take Action dropdown menu next to the permission role you want
to modify.
3. Choose the desired action.

3.2.4 Creating a New Role for External Users

Role-based permissions support the role of External User and allows the External Learner User limited access to
complete specific tasks or training.

The external user role can be granted to the user type External Onboarding user. Permissions for the external user
role can be set to grant access to the Onboarding home page.

[Link] Resetting External User Password

If you have external users, consider creating a management system for them so that you can maintain their access.

Prerequisites

Either Onboarding 2.0 (including Internal Hire Process) or Learning or both must be enabled in Provisioning to reset
the external user password.

 Remember

As a customer, you don't have access to Provisioning. To complete tasks in Provisioning, contact your
implementation partner. If you're no longer working with an implementation partner, contact SAP Cloud
Support.

Using Role-Based Permissions


20 PUBLIC What Are Role-Based Permissions?
Context

When you have external users in your extended enterprise, your plan for maintaining them must include: resetting
user passwords, granting access, and so on. In most cases, you manage external users as you do any other users.

One exception is target populations. External users can be a unique target population. For example, if you want to
manage external users in Onboarding, you must add All(External Onboarding User) to the target population of users
managed by the administrator.

Procedure

1. To reset an external user password, go to Admin Center Reset User Password .

The Resetting User Passwords page appears. From this page you can reset individual user password, or reset
the passwords for a group of users.
2. Select External Users from Onboarding and/or Learning (If enabled) from the Find dropdown.

Enter the First Name, Last Name, or the Username to search for the user whose password you’re trying to
reset. You can filter your search further using Starts With or Exact Match.
3. When the user details appear on the screen, select the user and enter the new password in the New Password:
field and confirm the same in the Confirm Password: field.
4. Click Reset User Password.

Results

You have successfully reset the external user password.

[Link] Creating Permission Roles for External Learners

Create a role mapping for external learners and grant them the permissions to log in to SAP SuccessFactors and
access Learning.

Prerequisites

Role Based Permissions (RBP) must be enabled.

Enable External Learning User is selected in Provisioning.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 21
Procedure

1. Log in and go to Admin Center.


2. In Tools, click See All.
3. In Search Tools, type Manage Permission Roles and then click Manage Permission Roles.
4. Click Create New Role For External User.
5. In User Type, select External Learner, and then click Done.
6. Type a name and description for the role and then click Permissions.

The Permission Settings page opens.

7. In User Permissions General User Settings , select User Login.

8. In User Permissions Learning , select Learning Access Permission.

You can select additional permissions. For example, you can grant the external learners access to SAP Jam or
Mobile.
9. Click Done.

You return to the Permission Role Detail page.


10. Click Add.

The Grant this role to... page opens.


11. In Grant role to, select Everyone (External Learner).
12. Click Done.

You return to the Permission Role Detail page.


13. Click Save Changes.

Next Steps

You grant admins permissions to manage external learners.

3.3 Grant Permission Roles

You can assign a permission role to everyone or to a subset of employees, determined by permission groups, target
populations, or by relationships. When defining a role in RBP, you can assign the role to a group that you've created
or you can assign roles based on hierarchical relationships. Some roles will require that you also assign target
populations, they're only necessary for certain permissions in a role and your system will notify you when a target
population is required.

● Permission groups: You assign a permission role to a defined group of users. However, relationships can also
play a role here as you can define that the granted user's managers have the same permissions. You can also
define how many levels up in the hierarchy you want this permission to be granted.

Using Role-Based Permissions


22 PUBLIC What Are Role-Based Permissions?
 Note

If you want to grant a role to a named user, you first have to create a group and add the user to this group.
Then you can grant the role to the just created group.

● Target Population: Depending on the permissions included in the role, you might also have to define the target
population. Not all permissions require you to define a target population. For example, if the permission
includes just the access to an application (such as the Learning Access Permission), there is no need to add a
target group. For certain permissions, in the Permission settings screen, a target population must be defined.
This is identified by the "t" icon next to the permission name with the following text displayed: t= Target needs
to be defined.

 Note

A target population for an external Learning user can be defined two ways:
○ Select Everyone (External Learner)
○ Select Target population of: and click Select, to select groups

● Relationships: Access groups can be defined using relationships (for example, manager-employee
relationship) that are derived from the job relationship object. These relationships can be hierarchical or non-
hierarchical. You can find more information in the following chapter Using Relationships to Grant Permissions
[page 27].

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 23
●  Note

If you allow the respective managers to have the same permissions, this may have a negative impact on the
performance. The hierarchy then has to be checked whenever such a manager tries to access an element
which was permissioned this way.

3.3.1 Granting Roles to Groups

After creating your roles, you must assign the role to a group of employees. This ensures that employees are given
access the permissions they need to perform their tasks.

Procedure

1. Go to the Admin Center.


2. In the Tools Search, search for Manage Permission Roles.
3. Select one of the permission roles you created.
4. In the Grant this role to section of the Permission Detail screen, click Add.
5. When the Grant this role to screen displays, select Permission Group.

Using Role-Based Permissions


24 PUBLIC What Are Role-Based Permissions?
6. Click Select to select the access groups you wish to assign to this permission role.

You can allow managers to have the same permissions and define how many levels up in the hierarchy you want
this permission to be granted. However, allowing respective managers to have the same permissions may have
a negative impact on the performance. The hierarchy then has to be checked whenever such a manager tries to
access an element which was permissioned this way.
7. Exclude Granted Users:

For some permissions, it might be necessary to exclude the granted users from applying the permissions on
themselves. For this, select Exclude Granted User from having the permission access to themselves.

 Example

If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.

8. Click Done to assign this role to the defined users. You are taken back to the Permission Role Detail page.
9. Click Save Changes to complete creating the role.

Next Steps

If required, assign a target population to your role.

3.3.2 Assigning Target Populations to a Role

Target populations are assigned to roles that require tasks to be performed on behalf of another employee.

Context

Target populations allow you to give employees such as managers and administrators access to data or tasks that
need to be maintained for other employees. Depending on the permissions included in the role, you may need to
define the target population. Not all permissions require you to define a target population. For example, if the
permission includes just the access to an application (such as the Learning Access Permission), there is no need to
add a target group. For certain permissions, in the Permission settings screen, a target population must be
defined. This is identified by the "t" icon next to the permission name with the following text displayed: t= Target
needs to be defined.

Procedure

1. Go to the Admin Center.


2. In the Tools Search, search for Manage Permission Roles.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 25
3. Select one of the permission roles you created.
4. In the Grant this role to section of the Permission Detail screen, click Add.
5. Select Everyone or choose Target population of to select a group .

6. Click Select to select the target groups that you want to assign to this permission role.
7. Exclude Granted Users:

For some permissions, it might be necessary to exclude the granted users from applying the permissions on
themselves. For this, select Exclude Granted User from having the permission access to themselves.

 Example

If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.

8. Click Done to assign this role to the defined users. You are taken back to the Permission Role Detail page.
9. Click Save Changes to complete creating the role.

Using Role-Based Permissions


26 PUBLIC What Are Role-Based Permissions?
3.3.3 Using Relationships to Grant Permission Roles

There are relationships that can be specified through employee fields, and managed through tools, like the
employee data.

General Relationship Types: Hierarchical relationships are characterized by a reporting line between the granted
user and the target user. These are relationships between employees and their managers, and employees and their
second managers or alternate managers. Non-hierarchical relationships on the other hand are single-level
relationships. These include the relationship of an employee to the HR manager, the matrix manager and custom
manager. While each employee can have only one Manager, one Second Manager and one HR Manager, they can
have multiple Matrix Managers and Custom Managers.

Employee Central Only: If employees have global assignments (that is, a job in another country/region), they have
both a home manager and a host manager. In addition, they have a home HR manager and a host HR manager. All
managers need to have access to both the home jobs of the employees as well as to the host jobs of the employees.
This is covered by the following additional relationship types for global assignments:

Employee Central Only: Relationship Types for Global As­


The Five General Relationship Types signments

Manager Home Managers

Second/Alternate Manager Home HR Managers

HR Manager Host Managers

Matrix Manager Host HR Managers

Custom Manager

[Link] Delegate Relationship Assignments

As a delegator you can assign delegates to perform actions on your behalf that affects other employees in your
organization.

As a manager, you can use the Delegate A and Delegate B relationship roles to assign permissions to up to two
individuals for each role, allowing them to act as your delegates. The delegate users, you assign, will have access to
your direct and indirect reports and can perform tasks that have been permitted to you, while acting as your
delegates. You can assign up to two delegates per delegate role and each delegate can be given separate tasks or
permissions to cover different functional or regional areas.

 Note

You must configure Delegate relationship type in the Employee Central Picklist. After you've configured your
delegates, you'll see the option to give permissions to this relationship type in your system. For more
information about how to configure picklists, see the topic Picklist Configuration for Employee Status and Job
Relationship Type.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 27
Why would I want to use delegates?

You might use a delegate when you want to assign delegates permissions in different functional areas.

You can also assign permissions to delegates that separate functionality according to locations.

 Note

For customers still using Oracle, you may have access to configure delegate relationships in Employee Central
but the delegate relationships won't be viewable in Role-Based Permissions.

Using Role-Based Permissions


28 PUBLIC What Are Role-Based Permissions?
[Link] Specifying the Hierarchy Depth

Understand how to use hiearchy depth when assigning permissions to your users.

When granting permissions using hierarchical relationships, you can specify how many levels down to go in the
hierarchy for the target population. For example, you can indicate that Managers can see performance ratings on
their direct reports (1 level deep), or allow it to go deeper into their team, that is 2 levels down or all levels.

When granting permissions to non-hierarchical relationships (HR, Matrix and Custom Managers), you can follow
this non-hierarchical relationship for only one level. Beyond the first level, you can cross over to the standard
manager hierarchy if desired to go deeper.

For example, using the Matrix Manager relationship, you can use hierarchical depth to accomplish the following:

● 1 Level Deep: Matrix Managers can view ratings information for their Matrix Reports.
● 2 Levels Deep: Matrix Managers can view ratings information for their Matrix Reports and the Direct Reports of
their Matrix Reports.
● All Levels Deep: Matrix Managers can view ratings information for their Matrix Reports (1 level deep) and the
Direct Reports, all levels deep of the manager hierarchy of their Matrix Reports.

Using Role-Based Permissions


What Are Role-Based Permissions? PUBLIC 29
The following graphic illustrates the different hierarchical depths you can specify when you use the Matrix Manager
relationship:

Using Role-Based Permissions


30 PUBLIC What Are Role-Based Permissions?
4 How to Use the Master List of Role-Based
Permissions

The master permissions list is a one-stop-shop for suite-wide permissions and general RBP information. Customize
your filter criteria to list permissions for your specific product permissions set.

The permissions list allows you to search for and filter permissions across products that use the RBP security
model. You can start by selecting your products from the Solution filter and narrow your selection by filtering the
components for your products and searching for specific keywords or phrases. To quickly understand the
permissions for your products, your filtered list displays all the available permissions for your combination of
products, where they are located in the system, and how they will function once enabled.

At first glance, the permissions table displays all available permissions in the SAP SuccessFactors suite. When
you've narrowed your search criteria and you're satisfied with the list of permissions for your products, you can
download the permissions into a CSV file for continued use. In your system, you can manage permissions by
creating roles in the following location: Admin Center Set User Permissions Manage Permission Roles

Related Information

List of Role-Based Permissions [page 31]

4.1 List of Role-Based Permissions

This is a master list of Role-Based Permissions used across the SAP SuccessFactors HXM Suite.

 Remember

All customers have access to the SAP SuccessFactors platform. General permissions that are common to
many or all SAP SuccessFactors solutions, such as User Login or User Search permissions, are listed below as
part of the "Platform" solution.

If you use filters to find permissions related to a specific solution, remember to include "Platform" in your filter.
It is very likely that some of these permissions are relevant to your system.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 31
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Admin Check Tool Allow Check Tool This permission al­
Quick Fix
lows users to fix
configuration and
data issues.

Platform Administration Admin Admin Alerts Access Admin This permission al­
Alerts
lows users to access
the admin alerts tile.

Platform Administration Admin Admin Alerts Configure Alert This permission al­
Types lows users to config-
ure the alert types.

Platform Administration Admin Admin Alerts Trigger Rerun This permission al­
lows users to trigger
the rerun after alerts
have been proc­
essed.

Platform Common Per­ Admin Admin Center Manage Upgrade This permission al­
missions Permissions Center lows users to access
Administration the Upgrade Center
where they can ena­
ble various features.

It is only visible if
Upgrade Center Per­
mission is enabled
in Provisioning. Oth­
erwise, Upgrade
Center is accessible
to all admin users.

Platform Variance Re­ Admin Manage System Variance Report This permission al­
port lows users to use
Properties
Variance Reporting.

Platform Variance Re­ Admin Manage Allow Admin to Ac­ This permission al­
port Integration Tools cess OData API lows users to access
through Basic Au­ OData APIs through
thentication basic authentica­
tion.

Platform Variance Re­ Admin Manage Manage OData API This permission al­
port Integration Tools Basic Authentica­ lows users to man­
tion age OData APIs
through basic au­
thentication.

Using Role-Based Permissions


32 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Variance Re­ Admin Manage Access to OData This permission al­
port Integration Tools API Data Dictionary lows users to man­
age OData API data
dictionary in Admin
Center.

Platform Variance Re­ Admin Manage OData API Todo Im­


port port
Integration Tools

Platform Variance Re­ Admin Manage OData API Attach­ This permission al­
port Integration Tools ment Import lows users to import
attachments
through OData APIs.

Platform Variance Re­ Admin Manage OData API Attach­ This permission al­
port Integration Tools ment Export lows users to export
attachments
through OData APIs.

Rewards and Spot Awards Admin Manage Spot Manage Spot This permission al­
Recognition Awards Awards Program lows a user to set up
Spot Awards Pro­
gram.

Rewards and Spot Awards Admin Manage Spot Manage Spot This permission al­
Recognition Awards Awards Reports lows a user to view
Spot Awards history
or budget informa­
tion reports.

Rewards and Spot Awards Admin Manage Manage Currency This permission al­
Recognition Compensation Compensation Conversion Rate lows you to create
Employee Cen­ Tables and manage the cur­
tral
rency exchange
rates you need.

 Note
The Import
Permission on
Metadata
Framework is
also required.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 33
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Rewards and Foundation Objects Admin Manage Pay component This permission al­
Recognition Foundation lows a user to ena­
Objects Types ble integration with
Employee Central.

Rewards and Spot Awards User Miscellaneous Spot Awards This permission al­
Recognition Permissions lows a user to view,
edit, import, or ex­
port Spot Awards
for all target popula­
tion for reporting
purpose.

Rewards and Spot Awards User Miscellaneous Spot Award Pro­ This permission al­
Recognition Permissions gram lows a user to view,
edit, import, or ex­
port Spot Awards
Program, and all its
related field.

Rewards and Spot Awards User Miscellaneous Spot Award Re­ Enable users to re­
Recognition Permissions
demption deem awarded
points

Rewards and Spot Awards User Miscellaneous Spot Award User Enable users to view
Recognition Permissions
Balance their balance of
awarded points

Rewards and Spot Awards User Miscellaneous Spot Award Budget This permission al­
Recognition Permissions lows user to create,
insert, update, de­
lete, import, or ex­
port Spot Awards
Budget for all target
populations.

Platform Workflow Admin Manage Workflow This permission al­


Rewards and MDF Foundation Object lows a user to create
Recognition Types a standard and a dy­
namic workflow, for
example, for Spot
Awards.

Using Role-Based Permissions


34 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Intelligent Services Admin Intelligent Service Event Center This permission al­
Rewards and Tools lows a user to ena­
Recognition Integration Center
ble Intelligent Serv­
ices.

Calibration Calibration Ses­ User Calibration Detailed Calibration This permission al­
sions Permissions lows a user to ac­
cess the Calibration
sessions involving
employees within
their target popula­
tion.

Calibration Calibration User Calibration View Calibration This permission en­


Tab ables a user to ac­
cess the Calibration
tab.

Calibration Calibration Ses­ Admin Manage Manage Calibration This permission en­
sions Calibration Sessions ables a user to cre­
ate and manage Cal­
ibration sessions.

Calibration Calibration Settings Admin Manage Manage Calibration This permission en­
Calibration Settings ables a user to con­
figure Calibration.

Calibration Calibration Tem­ Admin Manage Manage Calibration This permission en­
plates Calibration Templates ables a user to cre­
ate and manage Cal­
ibration templates.

Calibration Calibration Ses­ Admin Manage Mass Create Cali­ This permission en­
sions Calibration bration Sessions ables a user to mass
create Calibration
sessions.

Calibration Executive Review Admin Manage Manage Permission This permission en­
Calibration for Executive Re­ ables a user to ac­
view cess and manage
the Executive Re­
view tab in Calibra­
tion.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 35
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Calibration OData API Admin Manage OData API Calibra­ This permission en­
Data Protection Calibration tion Export ables a user to ex­
and Privacy (In­ port Calibration
formation Re­ data using OData
porting) APIs, for the pur­
pose of Information
Reporting for Data
Protection and Pri­
vacy.

Goals Goal Management User Goals Goal Management Enabling this per­
Access mission gives a user
or group the ability
to access the Goals
module.

Goals Group Goals User Goals New Group Goal Enabling this per­
Creation mission gives a user
or a group the ability
to create group
goals.

Goals Goal Management User Goals Target Population Select this permis­
sion to assign goal
permissions to the
user or the group
defined as the target
population

Goals Goal Execution User Goals Access Execution This permission al­
Map lows a user to ac­
cess the Execution
Map under Goal
Execution.

Goals Goal Execution User Goals Access Meeting This permission al­
Agenda lows a user to ac­
cess the Meeting
Agenda under Goal
Execution.

Goals Goal Execution User Goals Access Status Re­ This permission al­
port lows a user to ac­
cess the Status
Report under Goal
Execution.

Using Role-Based Permissions


36 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Goals Team Goals User Goals Manage Team Goal This permission al­
lows a user to cre­
ate, edit and delete
Team Goals.

Goals Goal Plans User Goals Access to Continu­ This permission pro­
ous Performance vides a user the ac­
Management Data cess to Continuous
Performance Man­
agement Achieve­
ments and feedback
received on the Ach­
ievements linked to
the performance
goals, directly on the
Goal Plan

Goals Goal Plans User Goals Goal Plan Permis­ Choose which goal
Development Development sions plans users can ac­
Goals cess.

Granting permis­
sions through roles
controls which tem­
plates users can
view; while tem­
plate-level permis­
sions control what
changes users can
make to a specific
template.

Goals Team Goals User Goals Assign Team Goals This permission al­
lows a user to assign
Team Goals to other
users.

Goals Team Goals User Goals Share Team Goals This permission al­
lows a user to share
Team Goals with
other users, thereby
making those users
the co-owners of the
Team Goals.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 37
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Goals Initiatives User Goals Manage Initiatives This permission al­


lows a user to cre­
ate, edit and delete
Initiatives.

Goals Initiatives User Goals Share Initiatives This permission al­


lows a user to share
Initiatives with other
users, making those
users the co-owners
of the Initiatives.

Goals Data Protection User Goals Admin Access for Note that this per­
and Privacy (Infor­ Goal ODATA API Ex­ mission has been
mation Reporting) port developed exclu­
sively for the Data
Protection Officer
role. The "Admin Ac­
cess for Goal ODATA
API Export" permis­
sion must not be
enabled for anyone
other than the Data
Protection Officer.
This permission
must not be used in
any other capacity
except to ensure the
Data Protection Offi-
cer has the ability to
carry out the duties
prescribed under
the regulation.

This permission al­


lows a user to re­
trieve all Goal details
of other users using
OData APIs, overrid­
ing the permissions
defined in the XML
template.

Using Role-Based Permissions


38 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Goals Goal Import Admin Goals Import Goals This permission al­
lows a user to cre­
ate, edit and delete
goals, using an im­
port file.

Goals Goal Import Admin Goals Import/Export This permission al­


Goals library lows a user to create
and edit Goal Libra­
ries, using an import
file.

Goals Goal Execution Admin Goals Manage Configura- This permission al­
tion of Goal Execu­ lows a user to ac­
tion cess the Goal Execu­
tion configurations
page.

Goals Goal Management Admin Goals Goal Management This permission al­
Feature Settings lows a user to ac­
cess the page that
controls the feature
settings in Goals
Management.

360 Degree Forms User General User Permission to Cre­ Select the form tem­
Multi-Rater Permission ate Forms plates along with
Performance this permission to
Management enable a user to cre­
ate forms of the se­
lected templates.

360 Degree Forms Manage Change 360 Proc­ This permission al­
Multi-Rater Documents ess Owner lows the user to
change the process
owner for a "Com­
pleted" or "In Prog­
ress" 360 review
form. The 360 proc­
ess owner is the one
who manages the
360 evaluation
process.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 39
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

360 Degree Forms Admin Manage Change Participant This permission al­
Multi-Rater Documents Category lows the user to
change the category
of a participant in a
"Completed" or "In
Progress" 360 re­
view form.

360 Degree Forms Admin Manage Complete/Decline This permission al­


Multi-Rater Documents 360 document lows a user to either
push a 360 review
form to completion
or decline it on be­
half of the process
owner.

360 Degree Forms Admin Manage Restore Completed This permission al­
Multi-Rater Documents 360 lows a user to re­
store the "Com­
pleted" 360 review
forms.

360 Degree Executive Re­ Admin Manage 360 Executive Re­ This permission and
Multi-Rater view Documents view all the permissions
under it, enable a
user to manage 360
Executive Reviews.

Continuous Per­ Continuous Per­ User Continuous Access to Continu­ This permission al­
formance Manage­ formance Manage­ Performance User ous Performance lows a user to ac­
ment ment Permission Management cess Continuous
Performance Man­
agement.

Continuous Per­ Continuous Feed­ User Continuous Access Continuous This permission al­
formance Manage­ back Performance User Feedback lows a user to view
ment Permission the feedback they
receive, and the
feedback received
by their direct re­
ports.

Using Role-Based Permissions


40 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Continuous Per­ Continuous Feed­ User Continuous Give Continuous This permission al­
formance Manage­ back Performance User Feedback lows a user give
ment Permission feedback to employ­
ees included in the
target population.

Continuous Per­ Continuous Feed­ User Continuous Request feedback This permission al­
formance Manage­ back Performance User from others lows you to send
ment Permission feedback requests
to employees in­
cluded in the target
population. You also
need to select the
permission “Limit
about whom feed­
back can be re­
quested.

Continuous Per­ Continuous Feed­ User Continuous Limit about whom When ‘Request
formance Manage­ back Performance User feedback can be re­ feedback from oth­
ment Permission quested ers’ permission has
been enabled, by se­
lecting this permis­
sion, it allows user
to request feedback
about employees in­
cluded in the target
population. For ex­
ample, managers
can only request
feedback about
members of their
team.

Continuous Per­ Achievement User Continuous Achievement This permission al­


formance Manage­ Performance lows a user to cre­
ment Management ate, view and edit
Achievements.

Continuous Per­ Activity User Continuous Activity This permission al­


formance Manage­ Performance lows a user to cre­
ment Management ate, view and edit
Activity.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 41
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Continuous Per­ Continuous Per­ User Continuous Other Topic This permission al­
formance Manage­ formance Manage­ Performance lows a user to cre­
ment ment Management ate, view and edit
topics in Continuous
Performance Man­
agement.

Continuous Per­ Continuous Per­ Admin Manage Access to Adminis­ This permission al­
formance Manage­ formance Manage­ Continuous trative Configura- lows a user to ac­
ment ment Performance tion page cess the Continuous
Performance Man­
agement configura-
tion page.

Continuous Per­ Continuous Admin Manage Admin Access to all This permission al­
formance Manage­ Feedback Continuous Continuous Feed­ lows a user to ac­
ment Data Protection Performance back Data cess the Continuous
and Privacy
Feedback data of all
employees.

Note that this per­


mission has been
developed exclu­
sively for the Data
Protection Officer
role. The "Admin Ac­
cess to all Continu­
ous Feedback Data"
permission must not
be enabled for any­
one other than the
Data Protection Offi-
cer. This permission
must not be used in
any other capacity
except to ensure the
Data Protection Offi-
cer has the ability to
carry out the duties
prescribed under
the regulation.

Using Role-Based Permissions


42 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform OData API Admin Manage Allow Admin to Ac­ This permission en­
Continuous Apprentice Integration Tools cess OData API ables a user to cre­
Management through Basic Au­ ate, read, update, or
Performance
Employee Delta
Management thentication delete information
Export Add-In
Employee Cen­ using the available
for Microsoft
tral OData APIs.
Excel
Employee Cen­ ERP Integration
tral Payroll Integration
Mentoring Center

Platform OData API Admin Manage Access to OData This permission en­
Employee Cen­ Variance Re­ Integration Tools API Audit Log ables a user to mon­
tral Payroll port itor the API calls.

Platform OData API Admin Manage Access to OData This permission en­
Continuous Variance Re­ Integration Tools API Metadata Re­ ables a user to re­
port fresh and Export fresh the metadata
Performance
Management of the OData APIs

Employee Cen­ using the Admin

tral Center tools.

Platform MDF Positions Admin Metadata Manage Data This permission al­
Continuous Talent Pools Framework lows you to manage
Performance Business Con­ data on the meta­
figuration UI
Management data framework.
MDF
Employee Cen­
Data Protection
tral
and Privacy
Succession
Employee Cen­
tral Payroll

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 43
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform MDF Admin Metadata Access to non-se­ This permission al­


Continuous Alternative Framework cured objects (pre­ lows you to create,
Cost Distribu­ viously known as read, edit and delete
Performance
tion
Management 'Read/Write Per­ data from the meta­
MDF Positions
Employee Cen­ mission on Meta­ data framework.
Talent Pools
tral data Framework')
Spot Awards For Employee Cen­
Succession Business Con­ tral ERP Integration,
Development figuration UI this permission al­
Mentoring Apprentice lows a user to ac­
Management cess information
Rewards and
People Central provided by MDF
Recognition
Hub
objects (such as the
People Central ERP Integration
Target System)
Hub
when viewing data
replication records
in the Employee
Central Data Repli­
cation Monitor. The
Data Replication
Monitor is used in
employee master
data, organizational
assignment, and
time data replication
from Employee Cen­
tral.

This permission is
also required for
users to be able to
view the history
page for Alternative
Cost Distribution.

Using Role-Based Permissions


44 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Succession Succession User Succession Succession Man­ This permission


Succession Org Planners
agement and Ma­ makes the Succes­
Chart trix Report Permis­ sion Org Chart, Tal­
Matrix Grid Re­
sions ent Search (v1), and
ports
Matrix Grid Reports
Talent Search
visible to users. It's
also required before
you can assign the
permissions that
grant succession
planners access to
use those tools. This
permission also al­
lows users to see
nominations on the
Succession Org
Chart and Position
Tile view and user
ratings on Matrix
Grid reports.

The target popula­


tion associated with
this permission is
used for most other
succession planning
permissions.

Succession Succession Plan­ User Succession Succession Plan­ Allows users to


Planners
ning ning Permission nominate succes­
sors for the employ­
ees included in the
associated target
population.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 45
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Succession Approvals User Succession Succession Appro­ Allows users to ap­


Planners
val Permission prove successor
nominations for
their assigned target
population.

When you enable


approvals, all new
nominations and
any changes to ex­
isting nominations,
like removing a
nomination or
changing the readi­
ness, are pending
until approved. If
you don't enable ap­
provals, then all
nominations take ef­
fect immediately
and go straight to
the approved status.

Succession Succession Org User Succession Succession Org Allows users to ac­
Planners
Chart Chart Permission cess the Succession
Org Chart and the
Lineage Chart if it's
enabled in your sys­
tem. The target pop­
ulation of employees
a user is able to view
in the organization
chart is determined
by the Succession
Management and
Matrix Report Per­
missions.

Using Role-Based Permissions


46 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Succession Talent Search User Succession Talent Search Ac­ Once search fields
Planners
cess have been config-
ured for their role, a
user can perform a
talent search.

and each role has


been configured
with active search
fields, then they can
choose between
roles on the Talent
Search page.

The target popula­


tion associated with
the Succession
Management and
Matrix Report Per­
missions controls
the results a user
sees in Talent
Search. Only those
users who match
the search criteria
and who are part of
the assigned target
population of the
user performing the
search are displayed
in the search results.

Succession Talent Search User Succession Talent Search Ex­ This permission al­
Planners port Permission lows users to export
Talent Search re­
sults. The fields in
the results are con­
trolled by the Talent
Search Field permis­
sion.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 47
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Succession Position Tile View User Succession Position Tile Access Only available with
Planners
the MDF Position-
based nomination
method, this per­
mission allows users
to access the Posi­
tion Tile view.

Succession Position Tile User Miscellaneous Position Select the VisibilityIf


View Permissions
a user has multiple
MDF Positions roles with permis­
sion to access Talent
and Actions permis­
sions you want to
grant the role. As­
sign at least the
View Current per­
mission for users to
see the position
tiles.

This permission
grants access to the
Metadata Frame­
work (MDF) Position
object and uses the
associated target
population for posi­
tions. Only positions
that are in the target
population of the us­
er's role are dis­
played on the Posi­
tion Tile view.

Succession Talent Pools User Succession Plan­ Hide Talent Pool The permission pro­
ners Page hibits roles from ac­
cessing the Talent
Pool tab from other
Succession features
and People Profile.

Succession Talent Pools Admin Manage Succes­ Talent Pool Field The permission al­
sion Configuration lows roles to access
the Manage Talent
Pool Field Settings
in Admin Center.

Using Role-Based Permissions


48 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Talent Card User Employee Data Employee Profile Select the View and
Succession Spot Awards Edit permissions
Development Mentoring you want to assign
Mentoring Succession to the role.
Rewards and
Recognition

Platform Talent Card User Employee Data Background Select the View and
Succession Spot Awards Edit permissions
Development Mentoring you want to assign
Mentoring Succession to the role.
Rewards and
Recognition

Succession Talent Pools User Miscellaneous Talent Pool These object-level


Permissions
permissions only
control a user's abil­
ity to add, edit, and
delete talent pools
and their properties.
These settings have
no impact on a us­
er's ability to man­
age talent pool nom­
inations. To enable
users to add, edit or
delete nominations
to talent pools, as­
sign at least the ob­
ject permission to
This permission re­
quires that users
also have the object
level permission set­
ting to view talent
[Link] Current.

Select the View and


Edit permissions
you want to assign
to the role.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 49
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Succession Talent Pools User Succession View Talent Pool


Planners This permission re­
nominations
quires that users
also have the object
levelAllows users to
see nominations
within talent pools.
If you don't select
this option, users
can still see the pool
itself but not the
nominations within
the pool.

Using a setting in
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina­
tions permissions to
further control ac­
cess.

Succession Talent Pools User Succession Add/edit/delete This option only


Planners
Talent Pool nomina­ works if the View
tions Talent Pool nomina­
tions permission is
also active.

Allows users to add,


edit, and delete
nominations to tal­
ent pools.

Using a setting in
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina­
tions permissions to
further control ac­
cess.

Using Role-Based Permissions


50 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform MDF Positions Admin Metadata Configure Object


Succession Talent Pools Framework
Definitions
Employee Cen­ MDF
tral People Central
People Central Hub
Hub

Platform MDF Positions Admin Metadata Configure Business This enables a user
Succession Talent Pools Framework
Rules to create, edit, and
Rewards and Spot Awards execute business
Recognition MDF rules in their SAP
Employee Cen­ People Central SuccessFactors sys­
tral Hub
tem.
People Central Rules
Hub

Platform MDF Positions Admin Metadata Import Permission


Succession Talent Pools Framework
on Metadata
Employee Cen­ Business Con­ Framework
tral figuration UI
People Central MDF
Hub People Central
Hub

Platform MDF Positions Admin Metadata Admin access to This permission is


Succession Talent Pools Framework
MDF OData API required to set up
Development Business Con­ the Information Re­
Compensation figuration UI
port for Data Protec­
Employee Cen­ MDF
tion and Privacy.
tral People Central
People Central Hub
Hub Data Protection
and Privacy
Integration
Center

Platform MDF Positions Admin Metadata Manage Configura-


Succession Talent Pools Framework
tion UI
Employee Cen­ Business Con­
tral figuration UI
Employee Cen­ MDF
tral People Central
People Central Hub
Hub

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 51
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform MDF Positions Admin Metadata Manage Positions


Succession Talent Pools Framework

Employee Cen­ MDF


tral

Platform MDF Positions Admin Metadata Manage Sequence


Succession Talent Pools Framework

Employee Cen­ MDF


tral

Succession Talent Card Admin Manage Talent Manage Talent Grants users access
Calibration Presentations Card
Card Configuration to the Manage Tal­
Platform ent Card admin tool
where they can con­
figure the layout and
content of the talent
cards used in the
system.

Succession Talent Search Admin Manage System Talent Search Man­ Grants users access
Properties
agement to Talent Search
Settings where they
can manage how
Talent Search works
in your system.

Platform Email and Notifica- Admin Manage System Email Notification This permission al­
Compensation tions Properties Templates Settings lows a user to con­
figure email notifica-
tions for certain
workflow events.

Platform User Management Admin Manage User Change Assign­ This permission al­
lows the Admin to
ment ID
change assignment
ID using the conver­
tAssignmentIdExter­
nal function import.

Platform User Management Admin Manage User Manage Login Ac­ This permission al­
lows the Admin to
counts
access the Manage
Login Accounts tool.

Using Role-Based Permissions


52 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform User Management Admin Manage User Basic User Import When the "Enable
Control on Basic
User Import in Role-
Based Permis­
sions"option has
been enabled, this
permission allows
the Admin to per­
form basic user im­
port in the Employee
Central-enabled in­
stances.

Succession Talent Search User Talent Search Field Talent Search Field Select which fields
to make available to
the role when per­
forming a talent
search.

The system only al­


lows users to add
fields they have per­
mission to use in the
Talent Search form.
If you also define de­
fault search fields,
then the system
only displays the de­
fault fields that the
user actually has
permission to use.

Succession Succession Org User Learning Learning Access Allows users to ac­
Chart Permission cess Learning.

Succession MDF Positions Admin Manage Import Foundation Allows users to im­
Employee Cen­ Foundation
Data port foundation ob­
tral Objects
jects.

For example, job


classifications if
you're not using Em­
ployee Central or
haven't configured
Job Profile Builder
to use job classifica-
tions already.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 53
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform MDF Positions Admin Manage Import Translations Allows users to


Succession Foundation
manage translations
Objects
Employee Cen­ for foundation ob­
tral
jects.

Succession Succession User Career Recommended Enables the sug­


Planning Development
Successors gested successors
MDF Positions Planning
feature for the role.
When adding suc­
cessors to positions,
the user is pre­
sented with a list of
the top 10 sug­
gested successors
based on compe­
tency matching.

Mentoring Mentoring Admin Manage Career Manage Mentoring Allows users to cre­
Development
Programs ate and manage
mentoring pro­
grams.

Platform Mentoring Admin Manage User Manage Employee Allows users to cre­
Mentoring Dynamic Groups ate employee dy­
namic groups.

Mentoring Mentoring User Career Mentoring Pro­ Allows users to ac­


Development
grams Access Per­ cess the Mentoring
Planning
mission tab under
Development.

Platform Search User General User Company Info Ac­ This permission
Mentoring Permissions cess gives users access
to the Company Info
page, where they
can access the or­
ganization chart and
employee directory.

Using Role-Based Permissions


54 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Search User General User User Search This permission en­
Mentoring Permissions
ables users to find
other users with
People Search. You
can restrict user
searches to a target
population. It also
gives users access
to Action Search.

This permission
does NOT apply to
some search func­
tions necessary to
perform specific ac­
tions, such as sys­
tem administration
tasks.

 Note
Grant this per­
mission to a tar­
get population
of Everyone to
enable use of
the feedback
features.

Platform Search User General User Organization Chart Enables a user to


Permissions Navigation Permis­
access and navigate
sion
the basic organiza­
tion chart.

You can restrict or­


ganization chart
navigation by setting
a target population.
Users can only see
the organization
chart for people who
are in their target
population.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 55
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Employee Pro­ Admin Manage User Include Inactive Enables users to
file Employees in the search for inactive
Search search users on the People
Profile and Directory
Search.

 Note
This permission
cannot be re­
stricted to a tar­
get population
and is granted
to everyone in
the permission
role.

This permission
does not impact
behavior of the
People Search
in the global
page header,
which is control­
led by a com­
pany-level con­
figuration set­
ting and not by
role-based per­
missions.

Mentoring SAP Jam User General User Community Access For use when your
Permissions
system includes in­
tegration with SAP
Jam.

Allows users to ac­


cess SAP Jam.

Development Career Devel­ User Career Career Develop­ Allows users to navi­
opment Plan­ Development
ment Plan (CDP) gate to
ning Planning
Access Permission Development.
Career Work­
sheet
Development
Goals

Using Role-Based Permissions


56 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Development Career Work­ User Career Career Worksheet Allows users to ac­
sheet Development
Access Permission cess the career
Planning
worksheet.

Development Career Work­ User Career Career Worksheet If you're using Ca­
sheet Development
Suggested Roles reer Worksheet v12,
Planning
Access Permission this permission ena­
bles the suggested
target roles feature.

Development Development Admin Manage Career Development Ad­ Allows users to im­
Goals Development
min port development
goals and manage
templates.

Development Learning Activi­ Admin Manage Career Import Learning Allows users to im­
ties Development
Activity by web port learning activi­
service ties.

Development Career Path Admin Manage Career Manage Career Allows user to cre­
Development
Path ate and manage Ca­
reer Path.

Development Career Path User Miscellaneous Career Path Select the View and
Permissions
Edit options you
want to assign to the
role.

Performance Forms Admin Manage Approve Document Allows users to ac­


Management Documents
cess the Admin
tools to complete
the current step of a
form in the Modify
stage and move the
form to the next
step.

Performance Forms Admin Manage Change Document Allows users to ac­


Management Documents
Date cess the Admin
tools to change the
form start date, end
date, and due date
on an in-progress
form

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 57
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Performance Forms Admin Manage Admin Access to Allows users to ac­


Management Documents
Forms OData API cess Performance
Management using
the Web client. This
permission must be
enabled for both
employee and man­
ager roles.

Performance Forms Admin Manage Delete Documents Allows users to ac­


Management Documents
cess the Admin
tools to Delete
forms from the sys­
tem

Performance Forms Admin Manage Import Overall Allows users to ac­


Management Documents
Scores cess Admin tools to
update manual over­
all scores on the
forms through an
import.

Performance Forms Admin Manage Manage Document Allows users to re­


Management Documents
Visibility move or restore
document visibility.

Performance Forms Admin Manage Restore Deleted Allows users to re­


Management Documents
Documents store the docu­
ments that were
previously deleted.

Performance Forms Admin Manage Mass Route Docu­ Allows users to cre­
Management Documents
ment Forward ate and distribute
multiple instances
of the same form at
once, and to route
the form forward in
the workflow.

Performance Forms Admin Manage Mass Route Docu­ Allows users to cre­
Management Documents
ment Backward ate and distribute
Compensation multiple instances
of the same form at
once and to route
the form backward
in the workflow.

Using Role-Based Permissions


58 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Performance Forms Admin Manage Modify Form Route Allows users to add,
Management Documents
Map reorder, or remove
routing steps of the
workflow of a form.

Performance Forms Admin Manage Route Completed Allows users to


Management Documents
Documents route a completed
form back to an­
other stage.

Performance Forms Admin Manage Route Document Allows users to


Management Documents
move a form from
the Modify stage to
any other stage of
the Route map.

Allow Adding of a
Step allows users to
access the Admin
tools to add a step in
the route map.

Performance Forms Admin Manage Include Completed Allows users to ac­


Management Documents
Documents cess the Admin
tools to route com­
pleted forms.

Performance Forms Admin Manage Route Signature Allows users to


Management Documents
Stage Document route a form from
the Signature stage
back to the Modify
stage.

Performance Forms Admin Manage Sign Document Allows users to sign


Management Documents
a form in the Signa­
ture stage and move
the form to the next
person who will sign
the form.

Performance Route Maps Admin Manage Form Routing Maps Allows users to cre­
Management Templates
ate Route Maps and
360 Degree modify existing
Multi-Rater
Route Maps.
Compensation

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 59
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Performance Rating Scales Admin Manage Form Rating Scales Allows users to cre­
Management Templates
ate a Rating Scale
360 Degree and modify existing
Multi-Rater
Rating Scales.
Compensation

Performance Forms Admin Manage Form Export Perform­ Allows users to ex­
Management Templates
ance Management port Performance
Form Data Management form
data through API.

Performance Forms Admin Manage Form Schedule Mass Allows users to


Management Templates
Form Creation schedule mass crea­
360 Degree (Launch forms tion of forms at a
Multi-Rater
later) later time and date.

Performance Forms Admin Manage Form Mass Create Form Allows users to
Management Templates
Instances (Launch launch forms in bulk
360 Degree forms now) immediately.
Multi-Rater

Performance Forms Admin Manage Form Comprehensive Allows users to con­


Management Templates
template configura- figure and edit the
tion for PMv12 fields in the ad­
vanced options sec­
tion of the Perform­
ance Management
v12 Acceleration
form.

Performance Forms Admin Manage Form Form Templates Allows users to cre­
Management Templates
ate, edit, and ena­
360 Degree ble/disable Perform­
Multi-Rater ance Management
Compensation form templates.

Performance Notes User General User Permission to Cre­ Allows users to cre­
Management Employee Pro­ Permission
ate Notes ate notes on the em­
Platform file ployee profile.

Performance Notes User Employee Views Notes Allows users to view


Management Employee Pro­ notes.
Platform file

Using Role-Based Permissions


60 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Compensation Forms Admin Manage Manage Field Per­ This permission al­
Compensation mission Groups lows a user to con­
figure field-based
permission groups.

Compensation Forms Admin Manage Manage Merit Ma­


Compensation trices

Compensation Hierarchy Based Admin Manage Generate Compen­


Approval Compensation sation Hierarchy for
Rollup Report

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Forms lows a user to ac­
cess and manage
Compensation
forms.

Compensation Forms Admin Manage Manage Compen­


Compensation sation Planner Per­
mission

Compensation Forms Admin Manage Manage Job Code This permission en­
Compensation and Pay Grade Map ables View a user to
manage currency
conversion tables.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Number For­ lows a user to con­
mat Rules figure number for­
mat rules.

Compensation Forms Admin Manage View User Personal This permission al­
Variable Pay lows a user to view
Compensation Statements
User Personal
Statements tab on
the Import/Export
Data page

Platform Worksheets Admin Manage YouCalc Dash­ This permission al­


Compensation Dashboards / boards lows a user to ena­
Reports ble YouCalc widgets
in the compensation
worksheets.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 61
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Compensation Worksheets Admin Manage System Performance Man­ This permission al­
Variable Pay Properties agement Feature lows a user to ac­
Settings cess Performance
Management Fea­
ture Settings tool to
integrate 'CPM Ach­
ievements' to Com­
pensation work­
sheet.

Compensation Forms Admin Manage Budget Assignment This permission al­


lows a user to ac­
Compensation
cess Budget Assign­
ment settings under
Manage Worksheets.

Compensation Compensation Admin Manage Manage Compen­ This permission al­


Modeling Compensation sation Modeling lows a user to ena­
ble Compensation
Modeling in the sys­
tem.

Compensation Forms Admin Manage Budget Override This permission al­


Compensation lows a user to ac­
cess Budget Over­
ride settings under
Manage Worksheets

Compensation Compensation Admin Manage Enable Feature Up­ This permission al­
Compensation grades lows a user to ac­
cess feature up­
grades for SAP Suc­
cessFactors Com­
pensation.

Compensation Aggregate Export Admin Manage Compensation Ag­ This permission al­
gregate Export
Compensation lows a user to export
Compensation data
for a template.

Compensation Forms Admin Manage Compensation


Compensation Form Membership

Compensation Forms Admin Manage Compensation This permission al­


Compensation Management Per­ lows a user to edit
mission Compensation
Worksheets.

Using Role-Based Permissions


62 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Compensation Forms Admin Manage Roll up Report This permission al­


Compensation lows a user to ena­
ble roll up reports.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Summary lows a user to ac­
cess the read-only
summary of the
Compensation plan.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Settings lows a user to con­
trol the basic set­
tings of a Compen­
sation plan.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Display Set­ lows a user to ac­
tings cess worksheet dis­
play settings such
as rating format,
guideline pattern,
and so on, as a part
of plan set up.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Employee lows a user to ac­
Central Settings cess the Employee
Central menu op­
tions under Plan
Setup.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Design lows a user to ac­
Worksheet cess the worksheet
column designer.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Plan Instruc­ lows a user to ac­
tion cess the Plan
Instruction page

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 63
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Compensation Compensation Cal­ Admin Manage Manage Compen­ This permission al­
culations Compensation sation Budget lows a user to define
budget calculation
and budget setup
rules under Plan
Details.

Compensation Compensation Admin Manage Manage Compen­ This permission al­


Guidelines Compensation sation Eligibility lows a user to define
eligibility rules for a
Compensation plan
template.

Compensation Compensation Admin Manage Manage Compen­ This permission al­


Guidelines Compensation sation Guidelines lows a user to define
and export guide­
lines and rules for a
Compensation plan
template.

Compensation Forms Admin Manage Manage Compen­ This permission al­


lows a user to define
Compensation sation Rating Sour­
and edit rating sour­
ces
ces to be used in
Compensation plan
templates.

Compensation Compensation Pro­ Admin Manage Define Compensa­ This permission al­
file Compensation tion Period Data lows a user to create
history periods to
display on the Com­
pensation Profile,
and also associate
history periods with
a plan template.

Compensation Forms Admin Manage Add Edit Stock His­ This permission al­
Compensation tory lows a user to create
stock history peri­
ods.

Compensation Forms Admin Manage Manage Compen­ This permission al­


Compensation sation Stock Period lows a user to edit
Data and manage stock
history periods.

Using Role-Based Permissions


64 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Compensation Forms Admin Manage Update Compensa­


Compensation tion Forms for Tem­
plate

Compensation Executive Review User Compensation Executive Review This permission al­
lows a user to ac­
Read Permission
cess Compensation
Executive Review
with Read privileges.

Compensation Executive Review User Compensation Executive Review This permission al­
lows a user to ac­
Edit Permission
cess Compensation
Executive Review
with Edit privileges.

Compensation Statements User Employee Views Compensation This permission al­


Employee Pro­ Statements lows a user to view
file Personal Compen­
sation Statement
Block in People Pro­
file or view the
Compensation
Statement tab in a
V12-enabled Em­
ployee Profile.

Platform Ad-Hoc Reports User Reports Create Ad-Hoc Re­ This permission al­
Compensation Permission port lows a user to create
and edit reports for
all specific modules.

Platform Ad-Hoc Reports User Reports Run Ad-Hoc Report This permission al­
Compensation Permission lows a user to run
existing reports for
all or certain report
types.

Compensation Executive Review User Compensation Executive Review This permission al­
lows a user to ac­
Mass Action Per­
cess Compensation
mission
Executive Review
with Mass Action
privileges.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 65
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Compensation Statements User Employee Data Compensation This permission al­


Statements lows a user to view
generated Compen­
sation statements
on a RBP-enabled
instance.

Compensation Statements User Employee Views Combined State­ This permission al­
Employee Pro­ ments lows a user to view
file Personal Combined
Statement Block in
People Profile or
view the Combined
Statement tab in a
V12-enabled Em­
ployee Profile.

Compensation Statements User Employee Data Combined State­ This permission al­
ments lows a user to view
generated Com­
bined statements on
a RBP-enabled in­
stance.

Variable Pay Forms Admin Manage Variable Manage Variable This permission al­
Pay lows a user to ac­
Pay Programs
cess Employee
Central Employee
History Field
Mapping page.

Variable Pay Statements User Employee Views Bonus Assignment This permission al­
Employee Pro­ Statement lows a user to view
file Bonus Assignment
Statement Block in
People Profile or
view the Bonus
Assignment
Statement tab in a
V12-enabled Em­
ployee Profile.

Using Role-Based Permissions


66 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Variable Pay Statements User Employee Data Bonus Assignment This permission al­
Statements lows a user to view
generated bonus as­
signment state­
ments in a RBP ena­
bled instance.

Variable Pay Statements User Employee Views Variable Pay State­ This permission al­
Employee Pro­ ments lows a user to view
file the Variable Pay
Statements block in
People Profile or
view the Variable
Pay Statements tab
in a V12-enabled
Employee Profile.

Variable Pay Statements User Employee Data Variable Pay State­ This permission al­
ments lows a user to view
generated variable
pay statements in a
RBP enabled in­
stance.

Variable Pay Executive Review User Variable Pay Executive Review This permission al­
lows a user to ac­
Edit Permission
cess Executive Re­
view with Edit privi­
leges.

Variable Pay Executive Review User Variable Pay Executive Review This permission al­
lows a user to ac­
Read Permission
cess Executive Re­
view with Read privi­
leges.

Compensation Administration Admin Manage Decentralized Su­ This permission al­


Variable Pay Compensation and lows a user to de­
per Admin Permis­
VarPay centralize adminis­
sion
tration feature.

Compensation Administration Admin Manage Manage Adminis­ This permission al­


Variable Pay Compensation and trative Dynamic lows a user to man­
VarPay Groups age Admin groups
for decentralized ad­
ministration both in
Compensation and
Variable Pay.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 67
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Variable Pay Executive Review Admin Manage Access to Integra­ This permission al­
lows a user to ac­
Integration Tools tion Center
Integration Center cess the Integration
Center Builder tool
to turn on notifica-
tion configuration.

Compensation Forms Admin Manage Compensation and This permission al­


Variable Pay lows user to access
Compensation and Variable Pay Fea­
Company Settings
VarPay ture Settings
page from
Compensation
Home.

Compensation Forms Admin Manage Compensation Job This permission al­


Variable Pay Compensation and
Monitor lows a user to moni­
VarPay
tor the status of
background jobs
that run in the sys­
tem.

Variable Pay Forms Admin Manage Variable View All VarPay


Pay Manager Forms

Employee Cen­ Employee Data Im­ Admin Employee Central Workflows for se­ This permission al­
tral port
Import Settings lected areas lows a user to trig­
ger workflows using
business rules when
importing Job Infor­
mation and Termi­
nation Details using
the Incremental
mode.

Employee Cen­ Employee Data Im­ Admin Employee Central Enable Business This permission al­
tral port
Import Settings Rules for selected lows a user to trig­
areas ger business rules
onSave and on­
Change when im­
porting employees'
data such as com­
pensation, termina­
tion details and per­
sonal information.

Using Role-Based Permissions


68 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Employee Data Im­ Admin Manage User Allow users to view This permission al­
Employee Cen­ port lows a user to track
all the jobs. (By Dis­
tral all import jobs per­
abling this option,
formed by users.
users can view only
their job status.)

Platform Employee Data Im­ Admin Manage User Enable RBP Access This permission al­
Employee Cen­ port
Validation for EC El­ lows a user to ena­
tral ements during Im­ ble the RBP access
ports (Do not ena­ during imports.
ble during first time
import)

Employee Cen­ Employee Data Im­ User Employee Central Job History This permission al­
tral port
Import Entities lows a user to per­
form or restrict im­
ports for job infor­
mation.

Employee Cen­ Employee Data Im­ User Employee Central Compensation Info This permission al­
tral port
Import Entities lows a user to per­
form or restrict im­
ports for compensa­
tion information.

Employee Cen­ Employee Data Im­ User Employee Central Pay Component This permission al­
tral port
Import Entities Non Recurring lows a user to per­
form or restrict im­
ports for pass com­
ponent recurring in­
formation.

Employee Cen­ Employee Data Im­ User Employee Central Job Relationships This permission al­
tral port
Import Entities lows a user to per­
form or restrict im­
ports for job rela­
tionship informa­
tion.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 69
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Employee Data Im­ Admin Employee Central Enable Forward This permission al­
tral port
Import Settings Propagation of lows a user to for­
Compensation In­ ward propagate
formation Data for compensation and
Inserts in Incre­ pay component re­
mental Imports curring data when
inserting through In­
cremental mode.

Platform User Manage­ Admin Manage Data Create Legacy Data This permission al­
Employee Cen­ ment Purge Request
Purge lows users to create
tral Employee Data purge requests us­
Management
ing a legacy purge
Employee Data
request type.
Import

 Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.

Platform User Manage­ Admin Manage Data Manage and This permission en­
Employee Cen­ ment Approve Legacy
Purge ables users to ap­
tral Employee Data Data Purge Request
prove purge re­
Management
quests that use a
Employee Data
legacy purge re­
Import
quest type.

 Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.

Using Role-Based Permissions


70 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform User Manage­ Admin Manage Data Remove Preview This permission en­
Employee Cen­ ment and Complete
Purge ables users to delete
tral Employee Data Reports for Legacy
old purge reports for
Management Data Purge Request
legacy purge re­
Employee Data
quests.
Import

 Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.

Platform MDF Admin Metadata Manage Mass This permission al­


Employee Cen­ Employee Cen­ Framework Changes for Meta­ lows a user to man­
tral tral data Objects age mass changes
for objects.

Platform MDF Admin Metadata Access to Business This permission al­


Employee Cen­ Employee Cen­ Framework Rule Execution Log lows a user to ac­
tral tral cess business rule
execution logs.

Platform MDF Admin Metadata Hire Date Correc­ This permission al­
Employee Cen­ Employee Cen­ lows a user to
Framework tion
tral tral change the hire date
for an employee in
Employee Central in
one place for multi­
ple portlets.

Employee Cen­ Apprentice Admin Manage Supervisor This permission al­


tral Management Apprentice lows a supervisor to
manage apprentice
data.

Employee Cen­ Apprentice Admin Manage On-Site Supervisor This permission al­
tral Management Apprentice lows an on-site su­
pervisor to manage
apprentice data.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 71
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Apprentice User Apprentice Apprentice This permission al­


tral Management Management lows an apprentice
Permissions supervisor to view
and edit apprentice
information.

Employee Cen­ Apprentice User Apprentice Apprentice Group This permission al­
tral Management Management
lows an apprentice
Permissions
supervisor to view
and edit apprentice
group.

Employee Cen­ Apprentice User Apprentice Apprentice Internal This permission al­
tral Management Management
Training lows an apprentice
Permissions
supervisor to view
and edit apprentice
internal training.

Employee Cen­ Apprentice User Apprentice Apprentice On-the- This permission al­
tral Management Management
job Training lows an apprentice
Permissions
supervisor to view
and edit apprentice
on-the-job training.

Employee Cen­ Apprentice User Apprentice Apprentice School This permission al­
tral Management Management
lows an apprentice
Permissions
supervisor to view
and edit apprentice
school.

Employee Cen­ Apprentice User Apprentice Apprentice School This permission al­
tral Management Management
Event lows an apprentice
Permissions
supervisor to view
and edit apprentice
school event.

Employee Cen­ Apprentice User Employee Views Apprentice This permission al­
tral Management lows an apprentice
Employee Pro­ supervisor to view
file
apprentices in the
Employee Views
section.

Using Role-Based Permissions


72 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Apprentice User MDF Foundation Department This permission al­
tral Management Objects lows apprentice su­
pervisors to config-
ure the MDF founda­
tion object Depart­
ment used in Ap­
prentice Manage­
ment.

Employee Cen­ Employee Cen­ User MDF Foundation Business Unit Select the Visibility
tral tral Objects and Actions permis­
Cost Center
sions you want to
Division assign to the role.

Department

Location

Legal Entity

Employee Central Global Assign­ User Employee Data Global Assignment


 Note
ments Details
Make sure that
you have Edit
permission for
Global
Assignment
Details in the
HR Information
section.

You can assign field-


level permissions as
well as permissions
for portlet as well
add, edit, delete ac­
tions.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 73
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Concurrent User Employee Data Employment De­ New Assignment
Employment tails Company provides
ERP Integration field-level permis­
sion for the com­
pany field. This is re­
quired for Concur­
rent Employment.

Change primary
employment allows
users to change the
employment classi­
fication of an em­
ployee.

Add new
Employment allows
users to add multi­
ple employments.

Navigation Group
(View) allows users
to see the grouping
of URLs added in
the Take Action
menu for employees
whose system of re­
cord is the ERP sys­
tem and whose data
is replicated to Em­
ployee Central. The
permission is used
in UI integration of
ERP screens with
Employee Central.

Navigation Group
Entry in Take Action
Menu (Edit) allows
users to select the
URLs added in the
Take Action menu
for employees
whose system of re­
cord is the ERP sys­
tem and whose data

Using Role-Based Permissions


74 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

is replicated to Em­
ployee Central. The
permission is used
in UI integration of
ERP screens with
Employee Central.

Employee Central Deductions Admin Manage Create One Time This permission to
Deductions Deduction allow users to create
a non-recurring de­
duction.

Employee Central Deductions Admin Manage Edit One Time De­ This permission to
Deductions duction allow users to edit a
non-recurring de­
duction.

Employee Central Deductions Admin Manage View One Time De­ This permission to
Deductions duction allow users to view a
non-recurring de­
duction.

Employee Central Deductions User Miscellaneous Recurring Deduc­


 Note
Permissions tion
Make sure that
the Security
field for
Miscellaneous
Permissions is
set to Yes in the
object definition
for Recurring
Deduction.

Select the View and


Edit permissions
you want to assign
to the role.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 75
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Employee Central User Employee Data Report No-Shows Select the View and
Edit permissions
you want to assign
to the role.

This permission al­


lows the user to ter­
minate an employee
with 30 days by us­

ing Take Action

Report No-Shows
if they do not show
up on their starting
date with the com­
pany.

Employee Central Compensation User Employee Data Pay Components Select the View and
Edit permissions
you want to assign
to the role.

This permission al­


lows the user to edit
and delete a pay
component on the
Update Employee
Data page by click­

ing Take Action


Change Job and

Comp Info .

Employee Central Compensation User Employee Data Pay Component The View permission
Groups allows the user to
see the pay compo­
nent group in the
system, for exam­
ple, on the
Employment
Information page.

The Edit permission


does not work.

Using Role-Based Permissions


76 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Compensation Admin Manage Pay Scale Manage Pay Scale Allows access to the
Manage Pay Scale
Objects
Objects action in the
Admin Center.

However, the ob­


jects for pay scale
are visible/editable
in Manage Data un­
less you attach cus­
tomer permissions
to the objects them­
selves.

Employee Central Compensation Admin Manage Pay Scale Adjust Employees’ Controls access to
Compensation to the pay scale pay in­
Tariff Changes crease run.

Employee Central Compensation User Employee Central Pay Scale Area Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.

Employee Central Compensation User Employee Central Pay Scale Type Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.

Employee Central Compensation User Employee Central Pay Scale Group Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.

Employee Central Compensation User Employee Central Pay Scale Level Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.

Employee Central Compensation User Employee Central Range Penetration Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.

View permission is
required if you ena­
ble the compensa­
tion widgets.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 77
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Compensation User Employee Central Compa Ratio Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.

View permission is
required if you ena­
ble the compensa­
tion widgets.

Employee Central Compensation Admin Manage User Configure Charts


 Note
for Key Figures in
Compensation Embedded ana­
Portlet lytics must first
be enabled.

This permission en­


ables admins to use
widgets in the
Employment
Information page.

Employee Central Compensation User Employee Widgets Total Compensa­


 Note
tion History
Embedded ana­
lytics must first
be enabled.

This permission is
for the widget to
show the wage pro­
gression for an em­
ployee.

Employee Central Compensation User Employee Widgets Salary Positioning


 Note
Embedded ana­
lytics must first
be enabled.

This permission is
for the widget to
show the employ­
ee's salary in rela­
tion to the pay
range.

Using Role-Based Permissions


78 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Compensation User Employee Widgets Salary vs. Team


 Note
Embedded ana­
lytics must first
be enabled.

This permission is
for the widget to
show salaries for the
employee and
his/her peers.

Platform MDF User MDF Foundation Currency Exchange Select the Visibility
Objects Rate and Actions permis­
sions you want to
grant the role.

All permissions are


required for Em­
ployee Central ad­
mins who are re­
sponsible for com­
pensation areas.

Employee Central Employee Central Admin Manage System Employee Central This permission al­
Properties Feature Settings lows admins to turn
on Employee Cen­
tral features them­
selves without hav­
ing to request help
from SAP Cloud
Support.

Employee Central Dependents User Employee Central Dependents The administrator


Effective Dated can set the permis­
Entities sions needed for
each field. These
fields vary depend­
ing on the data
model.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 79
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Alternative Cost User Miscellaneous Alternative Cost


 Note
Distribution Permissions Distribution
Make sure that
the Security
field for
Miscellaneous
Permissions is
set to Yes in the
object definition
for Alternative
Cost Distribu­
tion.

Select the View and


Edit permissions
you want to assign
to the role.

Using Role-Based Permissions


80 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Employee Cen­ User Employee Data HR Information Select the View and
Employee Cen­ tral Edit permissions for
tral People Central the non-effective-
People Central Hub
dated portlets that
Hub Pension Pay­
you want to assign
outs
to the role.

Pension Payout
Details

Employment

Information Take

Action Add
Pension Payout

Details .

 Note
Global Assign­
ments and Pen­
sion Payouts
must be active
in your system
before you can
grant the per­
missions. allows
users to navi­
gate to

Employee Cen­ Employee Cen­ User Employee Views Employment Infor­ Allows users to ac­
tral tral mation cess related pages
People Central People Central from the allows
Hub Hub
users toEmployee
Employee Pro­
Files using the drop­
file
down menu.

Employee Cen­ Employee Cen­ User Employee Views Personal Informa­ Allows users to ac­
tral tral tion cess related pages
People Central People Central from the Employee
Hub Hub
Files using the drop­
Employee Pro­
down menu.
file

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 81
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Employee Cen­ User Employee Views Pending Requests Allows users to ac­
tral tral cess related pages
People Central People Central from the Employee
Hub Hub
Files using the drop­
Employee Pro­
down menu.
file

Employee Cen­ Employee Cen­ User Employee Central Personal Infor­ You can set field-
tral tral Effective Dated mation level permissions for
People Central People Central Entities Addresses effective-dated port­
Hub Hub Dependents
lets and fields. This
Employee Cen­ Employee Cen­ Job Information
also includes coun­
tral Payroll tral Payroll Compensation
try-specific fields
Information
that are prefixed by
Job Relation­
the 3-letter ISO
ships
code (for example,
FRA for France, DEU
for Germany, and so
on).

 Note
In Job Informa­
tion, set the
fields for Job
Title and
Location to visi­
ble if you use
the People
Search in Peo­
ple-Profile ena­
bled systems.

Platform Administration Admin Manage System Company System This permission en­
Employee Cen­ Employee Cen­ Properties and Logo Settings ables users to con­
tral tral figure system set­
People Central People Central
tings on the
Hub Hub
Company System
and Logo Settings
page and to use
other system config-
uration tools like
Theme Manager and
Configure Custom
Navigation.

Using Role-Based Permissions


82 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Admin Manage Business Manage Business These permissions


Employee Cen­ Employee Cen­ Configuration Configuration allow you to use the
tral tral Business Configura-
People Central People Central
tion UI to make
Hub Hub
changes to the Suc­
Business Con­
cession Data Model
figuration UI
without having to
contact SAP Cloud
Support to make
changes in Provi­
sioning.

Platform Administration Admin Manage User Manage User Use these permis­
Employee Cen­ Employee Cen­ sions to define who
tral tral can hire and rehire
People Central People Central
employees, manage
Hub Hub
workflows requests
and groups as well
import and export
employee data.

Employee Cen­ Employee Cen­ Admin Manage User Restrict fields of This allows admins
tral tral to further filter fields
type Worker
to only contingent
workers.

Employee Cen­ Employee Cen­ Admin Manage User Rehire Inactive Em­ This permission en­
tral tral ployee ables users to rehire
an employee while
keeping the previous
employment data
visible in the sys­
tem.

Employee Cen­ Employee Cen­ Admin Manage User Rehire Inactive Em­ This permission al­
tral tral ployee with New lows users to rehire
Employment an employee and
hide the previous
employment data in
the system.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 83
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Employee Cen­ Admin Manage User Rehire Inactive Em­ This permission al­
tral tral ployee with New lows users to rehire
Employment (by an employee using
'match' in New Re­ the Match pop-up
cruit) and hide the previ­
ous employment
data in the system.

Employee Cen­ Employee Cen­ Admin Manage User Rehire Inactive Em­ This permission en­
tral tral ployee (by 'match' ables users to rehire
in New Recruit) an employee using
the Match pop-up
while keeping the
previous employ­
ment data visible in
the system.

Employee Cen­ Employee Cen­ Admin Manage User Add New Employee This permission en­
tral tral for Fixed Term ables users to add
employees hired
with fixed-term con­
tracts, meaning that
the termination date
can be added during
the hire process.

Employee Cen­ Manage Pend­ Admin Manage User Manage Pending This permission en­
tral ing Hires ables users to use
Hires
the Manage Pending
Hires feature.

Employee Cen­ Manage Pend­ Admin Manage User Allow Manage Oth­ This permission al­
tral ing Hires lows Manage
ers Save Draft
Pending Hires users
to work with all
Drafts saved by any
user.

Employee Cen­ Manage Pend­ Admin Manage User Configure Columns This permission al­
tral ing Hires for the Manage lows users to config-
Pending Hires ure columns for En­
hanced Manage
Pending Hires

Employee Cen­ Employee Cen­ Admin Manage Import Foundation Allows user to im­
tral tral Foundation Data port foundation ob­
People Central People Central Objects jects.
Hub Hub

Using Role-Based Permissions


84 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Employee Cen­ Admin Manage Import Translations Allows users to im­
tral tral Foundation port translations for
People Central People Central Objects objects like the job
Hub Hub
code.

Employee Cen­ Employee Cen­ Admin Manage Manage Foundation Use these permis­
tral tral Foundation Object Object Types sions to set the ac­
Types tions allowed for
foundation objects
in the Manage
Organization, Pay
and Job Structures
page.

Employee Cen­ Employee Cen­ User Employee Data Event Reasons You can set permis­
tral tral sions for each event
People Central People Central reason type.
Hub Hub

Employee Cen­ Employee Cen­ User Employee Data Future Dated Trans­ You can set permis­
tral tral action Alert sions to view future
People Central People Central changes for effec-
Hub Hub
tive-dated entities.

Employee Cen­ Employee Cen­ User Employee Data Transactions Pend­ You can set permis­
tral tral ing Approval sions so that users
People Central People Central can see if a workflow
Hub Hub
has been initiated,
but not yet ap­
proved.

Employee Cen­ Employee Cen­ Admin Manage Mass Areas where user You can set permis­
tral tral Changes has permission to sions to allow users
People Central People Central make changes to make mass
Hub Hub
changes for certain
areas.

Platform Platform Admin Employee Data Job Title You can set the field
for Job Title to visi­
ble if you use the
People Search in
People-Profile ena­
bled systems.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 85
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Report Center User Reports Create Report You can create, edit,
Report - Table Permission Schema delete, share, copy
and add new label to
a Report - Table.

Platform Report Center User Reports Run Report You can run and
Report - Table Permission Schema schedule the Report
- Table.

Platform Report Center User Reports Create Report - Ta­ You can import a Re­
Report - Table port - Table.
Permission ble Schema

Platform Report Center User Analytics Report - Canvas You can create, run,
Report - Can­ Permissions Designer edit, delete, export,
vas add labels, share,
copy, schedule, and
import a Report -
Canvas.

Platform Report Center User Analytics Report - Canvas You can create, run,
Report - Can­ Permissions Designer Admin edit, delete, export,
vas add labels, share,
copy, schedule, and
import a Report -
Canvas.

Platform Report Center User Manage Analytics Tiles and You can create, edit,
Employee Cen­ Tiles Dashboards / Dashboards delete, export, add
tral Dashboards Reports labels, copy, and im­
Compensation port a tile.
Widgets
You can create, run,
edit, delete, export,
add labels, share,
copy, and import a
dashboard.

Employee Central Position Manage­ User Manage Position Access Position Or­ This permission al­
ment ganization Chart lows users to view
the position organi­
zation chart.

Using Role-Based Permissions


86 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Advances Admin Manage Advances Advances Eligibility This permission al­
lows user to view or
edit advances eligi­
bility of an em­
ployee.

Employee Central Advances Admin Manage Advances Create Advances This permission al­
lows users to create
advances.

Employee Central Advances Admin Manage Advances Advances Admin This permission al­
Overview lows user to manage
advances.

Employee Central Global Benefits Admin Manage Benefits Benefits Admin This permission al­
Overview lows users to create,
edit, delete or man­
age benefits.

Employee Central Global Benefits Admin Manage Benefits Enroll/Claim for This permission al­
Benefits/Benefit lows users to enroll
Programs or claim for benefits
or benefits pro­
grams.

Employee Central Global Benefits Admin Manage Benefits View on behalf of This permission al­
Employee lows users to view
benefits of employ­
ees.

Employee Central Global Benefits Admin Manage Benefits Manage on behalf This permission al­
of Employee lows users to man­
age benefits on be­
half of employees.

Employee Central Global Benefits User Miscellaneous Benefit Contact This permission al­
Permissions
Benefit Em­ lows users to edit,
ployee Claim enroll, claim bene­

Benefit Pro­ fits.

gram Enroll­
ment

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 87
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Position Manage­ User Manage Position Change Display This permission al­
ment Date of Position Or­ lows users to view
ganization Chart the position organi­
zation chart for a
specific date.

Employee Central Position Manage­ User Manage Position Mass Copy of Posi­ This permission al­
ment tion in Position Or­ lows users to create
ganization Chart up to 100 new posi­
tions by copying an
existing position in
the position organi­
zation chart.

Employee Central Position Manage­ User Manage Position View Job Requisi­ This permission al­
ment tion in Position Or­ lows users to view
ganization Chart job requisitions in
the position organi­
zation chart.

Employee Central Position Manage­ User Manage Position Create Job Requisi­ This permission al­
ment tion in Position Or­ lows users to create
ganization Chart job requisitions in
the position organi­
zation chart.

Employee Central Position Manage­ User Manage Position Select Job Requisi­ This permission al­
ment tion Template in Po­ lows users to select
sition Organization a job requisition
Chart template when cre­
ating a job requisi­
tion or job requisi­
tion in the position
organization chart.
Only active tem­
plates with the fol­
lowing fields can be
selected: id, title, re­
cruiterName, num­
berOpenings, posi­
tionNumber.

Using Role-Based Permissions


88 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Position Manage­ User Manage Position Option to move Po­ This permission al­
ment sition to New Su­ lows users to
pervisor on Job Info choose whether the
Change position of an em­
ployee is moved with
the employee below
the position of the
new supervisor.

Employee Central Position Manage­ User Manage Position Create Position This permission al­
ment from Position Or­ lows users to create
ganization Chart a position from the
position organiza­
tion chart. This does
not change the per­
mission for Add
Lower-Level Position
and Add Peer Posi­
tion.

Employee Central Position Manage­ User Manage Position Access Position This position allows
ment Management Set­ users to access the
tings in Admin settings for position
Tools management.

Employee Central Position Manage­ User Miscellaneous Position: Visibility These permissions
ment Permissions allow users to view
the current state of
the position and/or
to view its history.

Employee Central Position Manage­ User Miscellaneous Position: Actions These permissions
ment Permissions allow users to cre­
ate, insert, correct,
view, delete, and/or
import/export posi­
tions. There is also a
Field-Level Overrides
option, which ena­
bles you to vary
these permissions
for each individual
field in the Position
object.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 89
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Company Structure User Company Access Company This permission al­
Overview Structure Overview Structure Overview lows users to view
the company struc­
ture overview.

Employee Central Company Structure User Company Change Display This permission al­
Structure Overview Date of Company
Overview lows users to see
Structure Overview
how the company
structure overview
looks on various dif­
ferent dates.

Employee Central Company Structure User Company View Employment This permission al­
Structure Overview
Overview Count in Company lows users to see
Structure Overview how many employ­
ees are assigned to
a particular entity in
the company struc­
ture overview.

 Note
When displayed
on an entity in
the chart, this
count doesn't
take the user's
role-based per­
missions (RBP)
into account.
However, when
displayed in the
side panel it
does take RBP
into account.

Using Role-Based Permissions


90 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Company Structure User Company View Position This permission al­
Structure Overview
Overview Count in Company lows users to see
Structure Overview how many positions
are assigned to a
particular entity in
the company struc­
ture overview.

 Note
When displayed
on an entity in
the chart, this
count doesn't
take the user's
role-based per­
missions (RBP)
into account.
However, when
displayed in the
side panel it
does take RBP
into account.

Employee Central Company Structure User Company Access Company This permission al­
Structure Overview lows users to edit
Overview Structure Overview
the company struc­
Configuration
ture overview, both
directly in the com­
pany structure over­
view itself, and in the
Admin Center.

Employee Central Company Structure User Company Create Entity from This permission al­
Overview Structure Overview Company Structure lows users to create
Overview child entities di­
rectly in the com­
pany structure over­
view, using the
menu in the side
panel.

Employee Central Company Structure User Miscellaneous Company Structure This permission al­
Overview Permissions Definition lows users to create
company structure
overviews.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 91
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Company Structure User Miscellaneous Company Structure This permission al­
Overview Permissions UI Configuration lows users to edit
company structure
overviews.

Employee Central Localization User Miscellaneous Document Genera­ This permission al­
Permissions tion Business Ob­ lows users to config-
jects ure business rules
on the Document
Generation Tem­
plate Mapping
screen.

Employee Central Localization User Miscellaneous Payment Informa­ This permission al­
Permissions tion Business Ob­ lows users to config-
jects ure all business ob­
jects related to Pay­
ment Information.

Employee Central Localization Admin Miscellaneous Protection against This permission al­
Permissions Unfair Dismissal lows users to config-
Business Objects ure all business ob­
jects related to Pro­
tection against Un­
fair Dismissal.

Employee Central Localization Admin Miscellaneous Work Seniority This permission al­
Permissions Business Objects lows users to config-
ure all business ob­
jects related to Work
Seniority.

Employee Central Localization Admin Miscellaneous Location Based This permission al­
Permissions Payment Business lows users to config-
Objects ure all business ob­
jects related to Lo­
cation Based Pay­
ment.

Platform Check Tool User Check Tool Access Check Tool This permission al­
Employee Cen­ lows users to access
tral Payroll the Check Tool.

Using Role-Based Permissions


92 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Check Tool User Check Tool Allow Configuration This permission al­
Employee Cen­ Export lows users to attach
tral Payroll configuration infor­
mation to a ticket in
cases where they
need to create one.

Platform Compound Em­ User General User SFAPI User Login This permission
Employee Cen­ ployee API Permissions gives a user general
tral Employee Delta access to the SFAPI.
Export Add-In
for Microsoft
Excel
ERP Integration

Employee Cen­ Employee Delta Admin Employee Central Employee Central This permission
tral Export Add-In API Foundation SOAP gives a user general
for Microsoft
Employee Cen­ API access to the Foun­
Excel
tral Payroll dation SOAP API.
ERP Integration
Platform Employee Cen­
tral Payroll
Variance Re­
port

Employee Cen­ Compound Em­ Admin Employee Central Employee Central This permission
tral ployee API API HRIS SOAP API gives a user general
Employee Delta access to the HRIS
Employee Cen­
Export Add-In
tral Payroll SOAP API.
for Microsoft
Platform Excel
ERP Integration
Employee Cen­
tral Payroll
Variance Re­
port

Employee Cen­ Employee Cen­ Admin Employee Central Employee Central This permission
tral tral Payroll API Foundation OData gives a user read ac­
Employee Cen­ ERP Integration API (read-only) cess to the Founda­
tral Payroll Variance Re­
tion OData API.
Platform port

Employee Cen­ ERP Integration Admin Employee Central Employee Central This permission
tral API HRIS OData API gives a user read ac­
Employee Cen­
Employee Cen­ (read-only) cess to the HRIS
tral Payroll
tral Payroll
Variance Re­ OData API.
Platform
port

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 93
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Employee Delta Admin Employee Central Employee Central This permission
tral Export Add-In API Foundation OData gives a user write
Employee Cen­ for Microsoft
API (editable) access to the Foun­
tral Payroll Excel
dation OData API.
ERP Integration
Employee Cen­
tral Payroll

Employee Cen­ Employee Delta Admin Employee Central Employee Central This permission
tral Export Add-In API HRIS OData API gives a user write
Employee Cen­ for Microsoft
(editable) access to the HRIS
tral Payroll Excel
OData API.
Platform ERP Integration
Employee Cen­
tral Payroll
Variance Re­
port

Employee Cen­ Compound Em­ Admin Employee Central Employee Central Together with the
tral ployee API API Compound Em­ SFAPI User Login
Employee Cen­ ployee API (re­ permission, this per­
tral Payroll
stricted access) mission restricts the
data accessible us­
ing the Compound
Employee API ac­
cording to the defi-
nition of the target
population, for ex­
ample, for a country
or a department.

Platform Employee Delta Ex­ Admin Manage System Picklist Manage­ This permission al­
Employee Cen­ port Add-In for Mi­ Properties ment and Picklists lows a user to ex­
tral crosoft Excel Mappings Set Up tract picklist data
from the Employee
Central backend us­
ing the Compound
Employee API.

Using Role-Based Permissions


94 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Cen­ Employee Delta Ex­ Admin Manage Manage Employee This permission al­
tral port Add-In for Mi­ Dashboards / Delta Export Tem­ lows a user to ac­
crosoft Excel Reports plates cess the Employee
Delta Export UI.
You'll find this per­
mission either under
Manage User or un­
der Manage
Dashboards /
Reports.

Employee Central Employee Delta Ex­ Admin Manage User Manage Employee This permission al­
port Add-In for Mi­ Delta Export Tem­ lows a user to ac­
crosoft Excel plates cess the Employee
Delta Export UI.
You'll find this per­
mission either under
Manage User or un­
der Manage
Dashboards /
Reports.

Employee Central ERP Integration User Miscellaneous Data Replication These permissions
Permissions Proxy (View, Edit, allow a user to dis­
and Import/Export) play, change, im­
port, and export
Data Replication
Proxy objects used
in employee time
data replication
from Employee Cen­
tral.

Employee Central ERP Integration Admin Miscellaneous Data Replication These permissions
Permissions Configuration allow a user to dis­
(View, Edit, and Im­ play, change, im­
port/Export) port, and export
Data Replication
Configuration ob­
jects used in em­
ployee time data
replication from Em­
ployee Central.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 95
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central ERP Integration Admin Manage Access to Data This permission al­
Integration Tools Replication Monitor lows a user to ac­
cess all data replica­
tion records in the
Employee Central
Data Replication
Monitor, thus being
able to monitor em­
ployee master data,
organizational as­
signment, and time
data replication
from Employee Cen­
tral.

Employee Central ERP Integration Admin Manage Restrict Access to Together with the
Integration Tools Data Replication Access to Data
Monitor to Specific Replication Monitor
Target Population permission, this per­
mission allows a
user to access data
replication records
for specific groups
of employees in the
Employee Central
Data Replication
Monitor, thus being
able to monitor em­
ployee master data,
organizational as­
signment, and time
data replication
from Employee Cen­
tral for these em­
ployees.

Using Role-Based Permissions


96 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central ERP Integration Admin Manage Delete Records This permission al­
Integration Tools from Data Replica­ lows a user to delete
tion Monitor data replication re­
cords from the Em­
ployee Central Data
Replication Monitor
that are no longer
needed for monitor­
ing, for example, be­
cause they were cre­
ated during a test
phase. The Data
Replication Monitor
is used in employee
master data, organi­
zational assign­
ment, and time data
replication from Em­
ployee Central.

 Note
We recommend
that you grant
this permission
only in excep­
tional cases,
where mass de­
letion is actually
required. Once
the mass dele­
tion was carried
out, remove the
permission
from the per­
mission role.

Employee Central Payroll Administra­ Admin Payroll Payroll Administra­ This permissions al­
Payroll tion Permissions tion lows a user to ac­
cess payroll UI
mashups and con­
figure the settings
for links and admin
services required to
run payrolls for em­
ployees.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 97
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Payroll Self Service User Payroll Payroll Self Service This permission al­
Payroll Permissions lows a user to ac­
cess employee self-
services like the pay
statement.

Employee Central Payroll Infor­ User Employee Views Payroll Information


mation
 Note
Payroll
Employee Pro­ If People Profile
file has been ena­
bled for your
system, please
select the
Payroll
Information
checkbox. Fur­
ther, make sure
to select the
checkbox for
the section un­
der which you
want the Payroll
Information
block to be dis­
played. For ex­
ample, in the
standard deliv­
ery, the Payroll
Information
block is dis­
played under
the
Compensation
Information sec­
tion. Therefore,
please select
the
Compensation
Information
checkbox.

Using Role-Based Permissions


98 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Payment Informa­ Admin Miscellaneous Payment Informa­ This permission al­
lows you to maintain
tion Permissions tion
an employee's pay­
ment details in Em­
ployee Central.

Employee Central Employee Central Admin Payroll Integration Employee Run Re­ Select all available
Payroll Payroll Permission sults permissions. This
permission allows a
user to configure all
payroll run results
for employees.

Employee Central Employee Central User Payroll Integration Employee Run Re­ Select View Current
Payroll Payroll Permission sults and View History
permissions. This
permission allows a
user to view payroll
run results.

Employee Central Employee Central Admin Payroll Integration Payroll Data Main­ This permission al­
lows a user to con­
Payroll Payroll Permission tenance Task
figure all payroll
data maintenance
tasks.

Employee Central Employee Central Admin Payroll Integration Payroll Data Main­ This permission al­
Payroll Payroll Permission tenance Task Con­ lows a user to make
figuration settings for the Con­
figuration of all pay­
roll maintenance
tasks.

Employee Central Employee Central Admin Payroll Integration Payroll System As­ This permission al­
Payroll Payroll Permission signment lows a user to con­
figure all assign­
ments to payroll
systems.

Employee Central Time Data Replica­ Admin Payroll Integration Data Replication This permission al­
Payroll tion Permission Configuration lows a user to make
settings for all Data
Replication Configu-
rations.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 99
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Time Data Replica­ Admin Payroll Integration Data Replication This permission al­
Payroll tion Permission Proxy lows a user to view
and edit Data Repli­
cation Proxies.

Employee Central Time Data Replica­ Admin Payroll Integration Trigger Data Repli­ This permission al­
Payroll tion Permission cation Proxy Crea­ lows an admin to
tion Job trigger Data Replica­
tion Proxy creation
job for selected
users. Note that this
permission is op­
tional.

Employee Central Payroll Control Admin Manage SAP Access to SAP Sys­ This permission en­
Payroll Center System tem Configuration ables a user to see
Configuration the SAP System
Configuration link in
Admin Center.

Employee Central Payroll Control Admin SAP System SAP System Con­ Select View and Edit
Payroll Center Configuration figuration permissions. This
permission enables
a user to configure
Employee Central
Payroll parameters.

Employee Central Payroll Control Admin Payroll Integration Payroll Control Select View and Edit
Payroll Center Permission Center Configura- permissions. This
tion permission enables
a user to configure
the classic or the
new Payroll Control
Center solution for
each payroll system.

Employee Central Payroll Control Admin Payroll Integration Payroll Control Select View and Edit
Payroll Center Permission Center Assignment permissions. This
permission enables
a user to assign pay­
roll systems to a tar­
get user (payroll ad­
ministrator or pay­
roll process man­
ager, for example).

Using Role-Based Permissions


100 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Payroll Control Admin Payroll Control My Alerts Access This permission en­
Payroll Center Center ables a user to use
the My Alerts tab.

Employee Central Payroll Control Admin Payroll Control My Processes Ac­ This permission en­
Payroll Center Center cess ables a user to use
the My Processes
tab.

Employee Central Payroll Control Admin Payroll Control Unassigned Alerts This permission en­
Payroll Center Center Access ables a user to use
the Unassigned
Alerts tab.

Employee Central Payroll Control Admin Payroll Control Manage Processes This enables a user
Payroll Center Center Access to use the Manage
Processes tab.

Employee Central Payroll Control Admin Payroll Control Manage Policies This permission en­
Payroll Center Center Access ables a user to use
the Manage Policies
tab.

Employee Central Payroll Control Admin Payroll Control My Off-cycles Ac­ This enables a user
Payroll Center Center cess to use the My Off-
Cycles tab.

Employee Central Payroll Control Admin Payroll Control Manage Teams Ac­ This permission en­
Center Center cess
Payroll ables a user to use
the Manage Teams
tab.

Employee Central Payroll Control Admin Payroll Control My Teams Access This permission en­
Center Center
Payroll ables a user to use
the My Teams tab.

Employee Central Time Off User Employee Views Manage Time Off This enables a user
Employee Pro­ to create and man­
file age requests for
time off (for exam­
ple, vacation or sick
leave).

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 101
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Time Off User Employee Views Time Management This enables a user
Employee Pro­ to create and man­
file age requests for
time off (for exam­
ple, vacation or sick
leave).

Employee Central Time Off User Employee Central Holiday Calendar This enables a user
Effective Dated to view the Holiday
Entities Calendar field in
their Job Informa­
tion.

Employee Central Time Off User Employee Central Work Schedule This enables a user
Effective Dated to view the Work
Entities Schedule field in
their Job Informa­
tion.

Employee Central Time Off User Employee Central Time Profile This enables a user
Effective Dated to view the Time
Entities Profile field in their
Job Information.

Employee Central Time Off User Employee Central Time Recording This enables a user
Effective Dated Variant to view the Time
Entities Recording Variant
field in their Job In­
formation.

Employee Central Time Off Admin Manage Time Off Manage Time Off This enables a Time
Structures Off admin to create,
edit, or delete Time
Off-related objects
such as time pro­
files, time accounts,
or time types.

Employee Central Time Off Admin Manage Time Off Manage Time Off This enables a Time
Calendars Off admin to carry
out mass changes to
time data by using
calendar runs.

Using Role-Based Permissions


102 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Time Off Admin Manage Time Off Manage Payout This enables a Time
Off admin to enter
financial payouts on
time accounts.

Employee Central Time Off Admin Manage Time Access Workbench This enables a Time
Off admin to open
the Time Work­
bench and manage
time tasks for em­
ployees.

Employee Central Time Off Admin Manage Time Maintain Individual This enables a Time
Work Schedule Off admin to create
an individual work
schedule for an em­
ployee.

Employee Central Time Off Admin Manage Time Maintain Tempo­ This enables a Time
rary Change Off admin to make a
temporary change
to an employee's
work schedule.

Employee Central Time Off Admin Manage Time Link Absences This enables a Time
Off admin to link an
employee's absen­
ces in case, for ex­
ample, the em­
ployee has been ab­
sent with the same
sickness more than
once in a given peri­
ods.

Employee Central Time Off Admin Manage Time Access Time Alerts This enables a Time
Off admin to access
time alerts in the
Time Workbench.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 103
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Time Off Admin Manage Time Access Time Ac­ This enables a Time
count Process Sim­ Off admin to simu­
ulator late time account
accruals for a partic­
ular employee, date,
and time account
types.

Employee Central Time Off Admin Manage Time Access Time Man­ This enables a Time
agement Configu- Off admin to use the
ration Search time management
configuration
search.

Employee Central Time Off Admin Manage Time Show Time Ac­ This enables a Time
count Balance in Off admin to see the
Termination Screen time balance on the
screen where termi­
nation payouts are
processed.

Employee Central Time Off Admin Manage Time Access Account This enables a Time
Payouts Off admin to access
the Accounts Pay­
outs tab in the Time
workbench.

Employee Central Workflows User Employee Views Pending Requests Role based permis­
Employee Pro­ sions for managers
file that want to approve
workflows for their
employees.

Employee Central Workflows Admin Manage Workflows Allow Auto Delega­ This permission al­
tion lows users to set up
automatic delega­
tion for their work­
flow requests.

Using Role-Based Permissions


104 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Workflows User Employee Data View Workflow Ap­ Select either the
proval History View or Editpermis­
sions as required
under View
Workflow Approval
History for manag­
ers that want to ap­
prove requests for
their employees.

Employee Central Workflows Admin Manage Workflows Manage Workflow Permissions to ac­
Requests cess workflows

Employee Central Workflows Admin Manage Workflows Manage Workflow Role based permis­
Groups sions so that HR Ad­
ministrators can de­
fine dynamic groups
for workflows.

Employee Central Workflows Admin Manage Workflows Professional Edition You can use the ad­
Manage Workflow ditional organization
Requests filters within work­
flow requests when
this is enabled.

Employee Central Workflows Admin Manage Workflows View Completed You can control who
Workflows sees completed
workflows and is
only available when

the Platform

Feature Settings
Add Permission:
Completed

Workflows is
turned on.

Employee Central Workflows Admin Manage Dynamic Role Dynamic role per­
Foundation mission allows the
Objects Types HR administrator to
maintain the dy­
namic role settings.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 105
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Employee Central Workflows Admin Manage Workflow Enables the HR ad­


Foundation ministrator to create
Objects Types and maintain work­
flow definitions.

Platform Administration User General User User Login Enables a user to log
Employee Cen­ Job Profile into the system.
Permission
tral Builder

Platform Job Profile Builder Admin Metadata Select All Permis­


Employee Cen­ Framework sions
tral

Platform Job Profile Builder Admin Manage Job Profile Select all check­ You can restrict
Employee Cen­ Builder boxes managing job profile
tral content by selecting
Can View Content
versus Can Edit
Content under the
Manage Job Profile
Content section

Platform Job Profile Builder Admin Manage Job & Skill Job Profile You must enable se­
Employee Cen­ Profile Visibility curity and visibility
tral settings from the
Job Profile object
using the Configure
Object Definitions
tool so that Manage
Job & Skill Profile
Visibility is enabled
in role-based per­
mission.

You can set addi­


tional permissions
by selecting differ-
ent actions.

Using Role-Based Permissions


106 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Job Profile Builder Admin Manage Job & Skill Skill Profile You must enable se­
Employee Cen­ Profile Visibility curity and visibility
tral settings from the
Job Profile object
using the Configure
Object Definitions
tool so that Manage
Job & Skill Profile
Visibility is enabled
in role-based per­
mission.

You can set addi­


tional permissions
by selecting differ-
ent actions.

Platform Job Profile Builder Admin Manage Job & Skill Rated Skills
Employee Cen­ Profile Visibility
tral

Recruiting Recruiting Manage­ User Recruiting Report Permission This permission en­
ables the user to ac­
ment Permissions
cess the Reports link
on the Recruiting
Marketing tab

Recruiting Recruiting Manage­ User Recruiting Source Quality This permission en­
Portlet Permission ables the user to ac­
ment Permissions
cess the Source sub-
tab on the Recruit­
ing Marketing tab

Recruiting Recruiting Manage­ User Recruiting Standalone Search This permission en­
Permission ables the user to ac­
ment Permissions
cess the Candidates
tab and candidate
search, whether or
not the user has an
open requisition

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 107
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User Recruiting Candidate Search This permission en­
Within Job Req ables the user to ac­
ment Permissions
cess the Candidates
tab and candidate
search, only if the
user has an open
requisition. This
does not allow the
user to search
through candidates
that have already
applied to the requi­
sition.

Recruiting Recruiting Manage­ User Recruiting Candidate Tagging This permission


Permission gives the user the
ment Permissions
ability to add tags to
a candidate or appli­
cant.

Recruiting Recruiting Manage­ User Recruiting Grant eQuest Job This permission
Postings Permis­ gives the user the
ment Permissions
sion ability to post to
third-party job
boards via eQuest.
eQuest must be en­
abled and config-
ured, and external
user accounts must
be properly loaded
for the users receiv­
ing the permission.

Recruiting Recruiting Manage­ User Recruiting Jobs Applied Port­ This permission en­
let Permission ables the user to
ment Permissions
view the Jobs
Applied portlet on
the Candidate Profile
and application re­
cords

Recruiting Recruiting Manage­ User Recruiting SFAPI Insert Candi­ This permission en­
date Permission
ment Permissions ables the user to in­
sert candidate per­
missions on candi­
date profiles. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Using Role-Based Permissions


108 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User Recruiting SFAPI Update Can­ This permission en­
didate Permission
ment Permissions ables the user to up­
date candidate per­
missions on candi­
date profiles. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve This permission en­
Candidate Permis­
ment Permissions ables the user to re­
sion
trieve candidate per­
missions on candi­
date profiles. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Recruiting Recruiting Manage­ User Recruiting SFAPI Insert Job This permission en­
Application Permis­ ables the user to in­
ment Permissions
sion sert job application
permissions on ap­
plications. Typically
this is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Update Can­ This permission en­
didate Permission ables the user to up­
ment Permissions
date candidate per­
missions on applica­
tions. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 109
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve This permission en­
Candidate Permis­ ables the user to re­
ment Permissions
sion trieve candidate per­
missions on applica­
tions. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Insert Job This permission en­
Application Permis­ ables the user to in­
ment Permissions
sion sert job application
permissions on ap­
plications. Typically
this is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Update Job This permission en­
Application Permis­ ables the user to up­
ment Permissions
sion date job application
permissions on ap­
plications. Typically
this is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Insert Job This permission en­
Requisition Permis­ ables the user to in­
ment Permissions
sion sert job requisition
permissions on
requisitions. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Recruiting Recruiting Manage­ User Recruiting SFAPI Update Job This permission en­
Requisition Permis­ ables the user to up­
ment Permissions
sion date job requisition
permissions on
requisitions. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Using Role-Based Permissions


110 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User Recruiting SFAPI Upsert Job This permission en­
Requisition Permis­ ables the user to up­
ment Permissions
sion sert job requisition
permissions on
requisitions. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve Job This permission en­
Requisition Permis­ ables the user to re­
ment Permissions
sion trieve job requisition
permissions on
requisitions. Typi­
cally this is granted
to a dummy user,
set up specifically
for integration pur­
poses.

Recruiting Recruiting Manage­ User Recruiting SFAPI Insert Job This permission en­
Code Permission
ment Permissions ables the user to in­
sert job code per­
missions on requisi­
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Update Job This permission en­
Code Permission
ment Permissions ables the user to up­
date job code per­
missions on requisi­
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 111
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Permis­ User Recruiting SFAPI Upsert Job This permission en­
Code Permission
sion Permissions ables the user to up­
sert job code per­
missions on requisi­
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve Job This permission en­
Code Permission
ment Permissions ables the user to re­
trieve job code per­
missions on requisi­
tion job code entity
fields. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve Job This permission en­
Posting Permission ables the user to re­
ment Permissions
trieve job posting
permissions on
requisition job post­
ings. Typically this is
granted to a dummy
user, set up specifi-
cally for integration
purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve As­ This permission en­
sessment Order ables the user to re­
ment Permissions
Permission trieve assessment
order permissions
on application as­
sessments. Typically
this is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Using Role-Based Permissions


112 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User Recruiting SFAPI Update As­ This permission en­
sessment Report ables the user to up­
ment Permissions
Permission date assessment re­
port permissions on
application assess­
ments. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting SFAPI Retrieve Job This permission en­
Applicant Permis­ ables the user to re­
ment Permissions
sion trieve job applicant
permissions on ap­
plication assess­
ments. Typically this
is granted to a
dummy user, set up
specifically for inte­
gration purposes.

Recruiting Recruiting Manage­ User Recruiting Careers Tab Per­ This permission pro­
mission vides the user ac­
ment Permissions
cess to the Careers
tab. This permission
is granted automati­
cally to all newly-
created users. It is
necessary to adjust
this permission only
if the user is re-acti­
vated in a non-RBP
environment or if
the client wishes to
restrict access to
the careers tab to a
given population of
employees.

Recruiting Recruiting Permis­ User Recruiting Delete Job Requisi­ Delete a job requisi­
sions Permissions tions tion.

Recruiting Recruiting Manage­ User MDF Recruiting MDF Object: View Yes: Pipeline
Candidate
ment Permissions Status Structure
Relationship
dropdown shows list
Management
Status Set of pipelines.

View No: Pipeline


Status Structure
dropdown is empty.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 113
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User MDF Recruiting MDF Object: View Yes: Dropdown
Candidate
ment Permissions shows list of sta­
Relationship
tuses that can be
Management
Status Map set as default.

View No: Dropdown


is empty.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Detailed Requisi­ This permission en­
tion Reporting
tration ables the user to
view Detailed
Requisition
Reporting.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Employee Referral This permission en­
Program Setup
tration ables the user to set
up an employee re­
ferral program.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Edit Applicant Sta­ This permission en­
tus Configuration
tration ables the user to
edit the applicant
status configura-
tion.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Export New Hire This permission en­
Candidates
tration ables the user to ex­
port the records of
candidates newly
hired.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Custom Help Text
tration ables the user to
manage custom
Help instructions for
Recruiting.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Duplicate This permission en­
Candidates
tration ables the user to
manage and purge
duplicate candidate
records.

Using Role-Based Permissions


114 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Ad­ Admin Manage Recruiting Manage external This permission en­
ministration data privacy con­
ables the user to
Data Protection sent statements
manage external
and Privacy
data privacy con­
sent statements.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage External This permission en­
Password Policy
tration ables the user to
manage the external
password policy.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage External This permission en­
User Accounts
tration ables the user to
manage external
user accounts.

Recruiting Recruiting Ad­ Admin Manage Recruiting Manage internal This permission en­
ministration data privacy con­
ables the user to
Data Protection sent statements
manage internal
and Privacy
data privacy con­
sent statements.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Job Post­ This permission en­
ing Header and
tration ables the user to
Footer
manage the job
posting header and
footer.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Offer Let­ This permission en­
ter Templates
tration ables the user to
manage offer letter
templates.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Onboard­ This permission en­
Onboarding ing Templates
tration ables you to manage
onboarding tem­
plates. You can add
or edit Recruiting e-
mail templates for
Onboarding.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Email Templates
tration ables the user to
manage recruiting
email templates.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 115
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Groups
tration ables the user to
manage.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Languages
tration ables the user to
manage recruiting
languages.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Settings
tration ables the user to
manage recruiting
settings.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Sites
tration ables the user to
manage recruiting
sites.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Set Up Agency Ac­ This permission en­
cess
tration ables the user to set
up agency access.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Set up Company In­ This permission en­
formation
tration ables the user to set
up .

Recruiting Recruiting Adminis­ Admin Manage Recruiting Set up Internal This permission en­
Candidate Search
tration ables the user to set
up company infor­
mation.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Set up Job Board This permission en­
Options
tration ables the user to set
up job board op­
tions.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Configure Legal This permission en­
Minimum Obliga­
tration ables the user to
tion Period
configure legal mini­
mum obligation pe­
riod.

Using Role-Based Permissions


116 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Adminis­ Admin Manage Recruiting Delete Candidate This permission al­
lows the user to de­
tration
lete candidate re­
cords. You can grant
this permission only
if the application
status Deleted On
Demand By Admin
has been enabled
for the related sta­
tus set on the pipe­
line.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Recruiting This permission en­
Team Settings
tration ables the user to
manage recruiting
team settings.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Configure Stand­ This permission en­
ardization Mapping
tration ables the user to
configure standardi­
zation mapping.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Assess­ This permission en­
ment Vendors
tration ables the user to
manage assessment
vendors.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Set Up Recruiting This permission en­
Marketing Job Field
tration ables the user to set
Mapping
up Recruiting Mar­
keting Job Field
Mapping.

Recruiting Recruiting Adminis­ Admin Manage MDF MDF Object: Select any combina­
Recruiting Objects
tration Campaign Limits tion of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over­
rides, as desired.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 117
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ Admin Manage MDF MDF Objects: Enables Candidate
Recruiting Objects Relationship Man­
ment Candidate
agement features.
Relationship
Management
Status
Candidate
Relationship
Management
Status Map
Candidate
Relationship
Management
Status Set

Recruiting Recruiting Adminis­ Admin Manage MDF MDF Object: Select any combina­
Recruiting Objects
tration EmailBrandTemplat tion of Visibility:
e View, Actions: Edit
and Import/Export,
and Field Level Over­
rides, as desired.

Recruiting Recruiting Adminis­ Admin Manage MDF MDF Object: Select any combina­
Recruiting Objects MarketingBrand
tration tion of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over­
rides, as desired.

Recruiting Recruiting Adminis­ Admin Manage MDF MDF Object: Pool Select View, Ac­
Recruiting Objects
tration Limits tions: Edit and Im­
port/Export, and
Field Level Over­
rides, as desired.

Recruiting Recruiting Adminis­ Admin Manage MDF MDF Object: Select View and Edit
Recruiting Objects
tration Recruiting Rules to enable user to
Assignment configure business
Configuration rules for Recruiting.

Other permissions
are optional.

Recruiting Recruiting Permis­ Admin Manage Recruiting Restore Deleted Restore a deleted
Job Requisitions
sions job requisition.

Using Role-Based Permissions


118 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Permis­ User Recruiting Hide Careers Tab When enabled for
sions Permissions for Proxy User specific employees
or permission roles,
disallows viewing a
proxied users career
tab and tile.

Recruiting Recruiting Adminis­ Admin Manage Recruiting Manage Multistage Enables being able
tration And Late Stage Ap­ to access the
plication Preview Manage Multistage
and Late Stage
Application Preview
from Admin Center.

Platform Data Protection Admin Admin Center View Change Audit Allows users to view
and Privacy Configuration configuration set­
Permissions
tings for Change Au­
dit.

Platform Data Protection Admin Admin Center Edit Change Audit Enables users to
and Privacy Configuration change configura-
Permissions
tion settings for
Change Audit.

Platform Data Protection Admin Admin Center Generate Change Enables users to
and Privacy Audit Reports create Change Audit
Permissions
reports. You can cre­
ate change audit re­
ports on personal
data for Data Pro­
tection and Privacy
or on other types of
data for general au­
dit purposes.

Platform Data Protection Admin Manage Data Create DRTM Data Enables users to
and Privacy Purge Purge Request create and submit a
DRTM purge request
for Data Protection
and Privacy.

Platform Data Protection Admin Manage Data Manage and Enables users to ap­
and Privacy Purge Approve DRTM prove a DRTM purge
Data Purge Request request for Data
Protection and Pri­
vacy.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 119
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Data Protection Admin Manage Data Remove Preview This permission en­
and Privacy Purge and Complete ables users to delete
Reports for DRTM old purge reports for
Data Purge Request DRTM purge re­
quests.

Platform Data Protection User Data Retention [Dynamic permis­ Enables users to
and Privacy Management
sions for each MDF manage configura-
object configured in tions related to the
the system that is DRTM data purge
related to DRTM function for Data
data purge.] Protection and Pri­
vacy, using MDF
tools.

For each MDF ob­


ject, you can control
permissions to:

View Current, View


History, Create,
Insert, Correct,
Import/Export

Most MDF objects


listed here are used
to store data reten­
tion times for differ-
ent types of data.
There is also an ob­
ject used to manage
the Purge Freeze list.

Platform Data Protection Admin Admin Center Enable Information Enables users to
and Privacy Permissions
on Data Subject configure and run
the Data Subject In­
formation Report,
which compiles a list
of all the personal
data that has been
stored on a particu­
lar employee.

Platform Instance Man­ Admin Manage Instance Copy Package Allows users to copy
agement Instance Sync pack­
Synchronization
ages between
source and target.

Using Role-Based Permissions


120 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Instance Man­ Admin Manage Instance Sync Data Model Enables users to
agement sync data models
Synchronization
between instances
using Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync MDF Data Enables users to
agement sync MDF data be­
Synchronization
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Workflow Enables users to
agement sync EC Workflows
Synchronization
between instances
using Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Objectives Enables users to
agement sync goals between
Synchronization
instances using In­
stance Sync tools.

Platform Instance Man­ Admin Manage Instance Sync Rating Scales Enables users to
agement sync rating scales
Synchronization
between instances
using Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Form Label Enables users to
agement Translations sync form label
Synchronization
translations be­
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Competen­ Enables users to
agement cies sync competencies
Synchronization
between instances
using Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Families and Enables users to
agement Roles sync families and
Synchronization
roles between in­
stances using In­
stance Sync tools.

Platform Instance Man­ Admin Manage Instance Sync Performance- Enables users to
agement Management Tem­ sync Performance
Synchronization
plates Management tem­
plates between in­
stances using In­
stance Sync tools.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 121
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Instance Man­ Admin Manage Instance Sync Objective Enables users to
agement Templates sync Goal Manage­
Synchronization
ment templates be­
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Career-Devel­ Enables users to
agement opment-Plan Tem­ sync Career Devel­
Synchronization
plates opment Plan tem­
plates between in­
stances using In­
stance Sync tools.

Platform Instance Man­ Admin Manage Instance Sync System Prop­ Enables users to
agement erties sync miscellaneous
Synchronization
system settings be­
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync RBP Permis­ Enables users to
agement sion Roles sync RBP permis­
Synchronization
sion roles between
instances using In­
stance Sync tools.

Platform Instance Man­ Admin Manage Instance Sync RBP Permis­ Enables users to
agement sion Groups sync RBP permis­
Synchronization
sion groups be­
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Dashboard Enables users to
agement Settings sync Analytics dash­
Synchronization
board settings be­
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync MDF Picklists Enables users to
agement sync MDF picklists
Synchronization
between instances
using Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync MDF Object Enables users to
agement Definitions sync MDF object
Synchronization
definitions between
instances using In­
stance Sync tools.

Using Role-Based Permissions


122 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Instance Man­ Admin Manage Instance Sync MDF Configu- Enables users to
agement ration UI sync MDF configura-
Synchronization
tion UI settings be­
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync MDF Rules Enables users to
agement sync MDF rules be­
Synchronization
tween instances us­
ing Instance Sync
tools.

Platform Instance Man­ Admin Manage Instance Sync Foundation Enables users to
agement Objects sync Foundation Ob­
Synchronization
jects between in­
stances using In­
stance Sync tools.

Platform Instance Man­ Admin Manage Instance Sync Homepage Enables users to
agement Tile Configurations sync Home Page
Synchronization
configuration set­
tings between in­
stances using In­
stance Sync tools.

Platform Instance Man­ Admin Manage Instance Manage Refresh Enables admin
agement users to create a
Refresh
new refresh request,
view history and
track refresh re­
quest.

Platform Instance Man­ Admin Manage Instance View Refresh Re­ Provides users re­
agement quests stricted access of
Refresh
the Instance Refresh
tool. Users can view
history, track re­
quest but they can
not create a new re­
fresh request.

Platform Presentations Admin Manage Manage Presenta­ Gives users access


Presentations tion to the Presentations
feature.

Platform Search Admin Manage Action Manage Action Gives users access
Search Search to the Manage Ac­
tion Search and
Configure Custom
Navigation pages so
that they can config-
ure the action
search.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 123
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform System Admin­ Admin Admin Center View or access Ad­ Enables users to see
istration min Alerts tile the Admin Alerts tile
Permissions
on the next-gen Ad­
min Center page.

Platform Administration Admin Admin Center View or access Re­ Enables users to see
ports tile the Reports tile on
Permissions
the next-gen Admin
Center page.

Platform Administration Admin Configure Configure Docu­ Enables users to set


Document ment Management up the preferred
Management document storage
service, with either
SAP SuccessFactors
or a third-party ven­
dor.

Platform Administration User Homepage v3 Tile Homepage v3 To- Allows users to see
Do tile group the To-Do section on
Group Permission
the new home page.

Platform Administration User Homepage v3 Tile Homepage v3 Allows users to see


News tile group the News section on
Group Permission
the new home page.

Platform Administration User Homepage v3 Tile Homepage v3 My Allows users to see


Specialty tile group the My Specialty
Group Permission
section on the new
home page.

Platform Administration User Homepage v3 Tile Homepage v3 My Allows users to see


Team tile group the My Team section
Group Permission
on the new home
page.

Platform Administration User Homepage v3 Tile Homepage v3 My Allows users to see


Info tile group the My Info section
Group Permission
on the new home
page.

Platform Administration User Homepage v3 Tile Homepage v3 On­ Allows users to see
boarding tile group the Onboarding sec­
Group Permission
tion on the new
home page.

Platform Administration Admin Manage Security Manage SAML SSO Gives users the abil­
Settings ity to manage SAML
SSO settings, only in
instances using SAP
Cloud Platform
Identity Authentica­
tion service.

Using Role-Based Permissions


124 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Admin Manage System Company System Enables users to


and Logo System configure general
Properties
Admin system settings and
access system con­
figuration tools like
Theme Manager and
Configure Custom
Navigation.

Platform Administration Admin Manage System Manage Home Gives users to ac­
Page cess to the Manage
Properties
Home Page configu-
ration tool so that
they can configure
the content and lay­
out of the home
page.

Platform Administration Admin Manage System To-Do Admin Enables users to


manage to-do set­
Properties
tings

Platform Administration Admin Manage System Picklist Manage­ Enables users to


ment and Picklists manage picklists in
Properties
Mappings Set Up the system.

Platform Administration Admin Manage System IP Restriction Man­ Enables users to


agement control which IP ad­
Properties
dresses can be used
to access the sys­
tem, using the IP Re­
striction Manage­
ment page.

Platform Administration Admin Manage System View Provisioning Gives users the abil­
Access ity to view Provision­
Properties
ing accounts and
"super admin" ac­
counts with access
to the system.

Platform Administration Admin Manage System Control Provision­ Gives users the abil­
ing Access ity to manage which
Properties
Provisioning ac­
counts can be used
to access the sys­
tem.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 125
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Admin Manage System Text Replacement Enables users to


change certain UI la­
Properties
bels and messages,
using the Text Re­
placement and Man­
age Languages
tools.

Platform Administration Admin Manage User Manage Support Enables users man­
Access age users with sec­
ondary login access
to the system, using
the Manage Support
Access page.

Platform Employee Pro­ User General User Live Profile Access This permission
Employee Cen­ file Permission gives users access
tral ERP Integration to the Employee
Job Profile
Profile page.
Builder
It also allows a user
to access the em­
ployee file from data
replication records
in the Employee
Central Data Repli­
cation Monitor. The
Data Replication
Monitor is used in
employee master
data, organizational
assignment, and
time data replication
from Employee Cen­
tral.

Platform Employee Pro­ User General User Permission to View Enables users to see
file LinkedIn Block the LinkedIn block
Permission
on People Profile.

Platform Employee Pro­ Admin Manage System Manage Employee Gives users to ac­
file Files cess to the profile
Properties
configuration tool so
that they can config-
ure the content and
layout of the em­
ployee profile.

Using Role-Based Permissions


126 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Employee Pro­ Admin Manage System Manage Badges Enables users to
file create and manage
Properties
custom badges, for
peer-to-peer recog­
nition on the em­
ployee profile.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Login Count view the Usage Ana­
Permissions
lytics report for
Login Count, show­
ing the number of
logins per day in the
system.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Daily Active view the Usage Ana­
Permissions
Users Count lytics report for
Daily Active Users
Count, showing the
unique number of
users per day in the
system.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Transactions view the Usage Ana­
Permissions
lytics report for
Transactions, show­
ing the transactions
that are run in the
application.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Page Perform­ view the Usage Ana­
Permissions
ance lytics report for
Page Performance,
showing the end
user experience with
regards to perform­
ance of the system.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Module Re­ view the Usage Ana­
Permissions
sponse Times lytics report for
Module Response
Times, showing the
response times in
the system on a
module level.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 127
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Session Time view the Usage Ana­
Permissions
lytics report for Ses­
sion Time, showing
the level of usage by
the average user
each day.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Search Terms view the Usage Ana­
Permissions
lytics report for
Search Terms,
showing the most
frequently searched
terms in the system.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Locations view the Usage Ana­
Permissions
lytics report for Lo­
cations, showing the
geographical break­
down of the loca­
tions the users are
logging in from.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Browsers view the Usage Ana­
Permissions
lytics report for
Browsers, showing a
breakdown of the
types of browsers
being used to ac­
cess the applica­
tions.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Devices view the Usage Ana­
Permissions
lytics report for De­
vices, showing a
breakdown of the
types of devices be­
ing used to access
the applications.

Platform Administration Admin Admin Center View Usage Analyt­ Enables users to
ics Search Count by view the Usage Ana­
Permissions
Session lytics report for
Search Count by
Session, showing
the breakdown of
the number of
searches by session.

Using Role-Based Permissions


128 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Admin Admin Center Read Execution Enables users to ac­
Integration Manager Events cess the main dash­
Permissions
Center board and view suc­
cess/fail informa­
tion.

Platform Administration Admin Admin Center Read Execution Enables users to


Data Protection Manager Event Pay­ view the payload for
Permissions
and Privacy load or Event Re­ each event in a proc­
port ess, including user
Integration
data, to assist in
Center
troubleshooting er­
rors. This permis­
sion is required to
set up the Informa­
tion Report for Data
Protection and Pri­
vacy.

Platform Integration Admin Admin Center Data Access for Don't use this per­
One Inbox Integra­ mission or assign it
Permissions
tion to anyone. It's only
used internally for
integration with SAP
One Inbox.

Platform Administration Admin Manage System Platform Feature Enables users to en­
Settings able major platform
Properties
features, such as
Employee Profile or
User Directory, and
to configure other
platform-related
settings. This per­
mission is also re­
quired to access the
PGP Key Manage­
ment page where
you can specify the
encryption keys.

Platform Mobile User General User Mobile Access This permission al­
Permission lows users to access
the SAP Success­
Factors Mobile app
on their iOS or An­
droid mobile devi­
ces.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 129
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Employee Central Admin Manage Business Select the options This permission al­
Configuration you need for your lows you to use the
scenario Business Configura-
tion UI, where you
can make changes
to the Succession
Data Model directly,
without accessing
Provisioning.

Onboarding 2.0 Document Genera­ Admin Configure Configure Docu­ Provides access
tion Document ment Management necessary for man­
Management aging documents re­
lated to Onboarding
2.0.

Onboarding 2.0 Document Genera­ Admin Manage Document Manage Document This permission al­
tion Generation Template lows you to view and
edit the document
template.

Onboarding 2.0 Document Genera­ Admin Manage Document Manage Document This permission al­
tion Generation Template Mapping lows you to map
document template
variables.

Onboarding 2.0 Document Genera­ Admin Manage Document Generate All Docu­ This permission al­
tion Generation ments as Admin lows you to generate
all or selected docu­
ments for users.

Onboarding 2.0 Onboarding 2.0/ Admin Manage Administrate On­ This permission al­
Offboarding 2.0 Onboarding 2.0 or boarding 2.0 or Off- lows you to manage
Offboarding 2.0 boarding 2.0 con­ Onboarding content
tent including configura-
tion settings and
document tem­
plates.

Using Role-Based Permissions


130 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Onboarding 2.0/ Admin Manage Cancel Onboarding This permission en­
Offboarding 2.0 Onboarding 2.0 or Permission ables participants to
Offboarding 2.0 cancel Onboarding
process flow.

Full permission rec­


ommended for:

● Hiring manager
● Hiring manag­
er's manager
● Onboarding co­
ordinator
● HR admin
● System admin

Onboarding 2.0 Onboarding 2.0/ Admin Manage Permission to Can­ Allows you to cancel
Onboarding 2.0 or
Offboarding 2.0 cel Offboarding Offboarding proc­
Offboarding 2.0
esses.

Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2Activities­ This permission al­
Offboarding 2.0 Config lows you to config-
Admin Object ure and manage the
Permissions onboarding tasks
used in onboarding
programs in your
system.

Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2ActivityRes­ This permission al­
Offboarding 2.0 ponsible lows you to assign
Admin Object responsible roles for
Permissions the onboarding ac­
tivities in your sys­
tem.

Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2FormTem­ This permission al­
Offboarding 2.0 plate lows you to manage
Admin Object form templates.
Permissions

Onboarding 2.0 Object Permissions Admin Onboarding 2.0 or ONB2Responsibili­ This permission al­
Offboarding 2.0 tyConfig lows you to config-
Admin Object ure responsible
Permissions roles for the on­
boarding activities in
your system.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 131
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 DocuSign eSigna­ Admin Configure Configure Docu­ This permission pro­
ture DocuSign Sign eSignature vides access to the
eSignature admin tool for con­
figuring the Docu­
Sign eSignature.

Onboarding 2.0 DocuSign eSigna­ Admin Configure Manage DocuSign This permission pro­
ture DocuSign envelopes vides access to the
eSignature admin tool for man­
aging DocuSign en­
velopes.

Onboarding 2.0 MDF Admin Metadata Configure Object This permission al­
Framework Definitions lows you to manage
MDF object defini-
tions.

Onboarding 2.0 MDF Admin Metadata Access to non-se­ This permission al­
Framework cured objects lows a user to ac­
cess information
provided by MDF
objects.

Onboarding 2.0 MDF Admin Metadata Import Permission This permission al­
Framework on Metadata lows a user to im­
Framework port data related to
the Metadata
Framework.

Onboarding 2.0 MDF Admin Metadata Manage Data This permission al­
Framework lows a user to man­
age data related to
the Metadata
Framework.

Onboarding 2.0 MDF Admin Metadata Configure Business This permission al­
Framework Rules lows you to config-
ure business rules
related to MDF ob­
jects.

Onboarding 2.0 MDF Admin Metadata Manage Configura- This permission pro­
Framework tion UI vides access to the
Manage Configura-
tion admin tool.

Using Role-Based Permissions


132 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 MDF Admin Metadata Manage Positions This permission al­
Framework lows you to manage
the MDF Position
object.

Onboarding 2.0 MDF Admin Metadata Manage Sequence This permission pro­
Framework vides access to re­
quired processes re­
lated to MDF ob­
jects.

Onboarding 2.0 MDF Admin Metadata Access to Business This permission pro­
Framework Rule Execution Log vides access to the
business rule execu­
tion log, with the op­
tion of including a
permission for
downloading the log.

Onboarding 2.0 MDF Admin Metadata Manage Mass This permission pro­
Framework Changes for Meta­ vides access to re­
data Objects quired processes re­
lated to MDF objects
in Onboarding 2.0.

Onboarding 2.0 MDF Admin Metadata Admin access to This permission pro­
Framework MDF OData API vides access read all
the MDF OData API
entities.

Onboarding 2.0 Document Manage­ Admin Configure Configure Docu­ This permission pro­
ment Document ment Management vides access neces­
Management sary for managing
documents related
to Onboarding 2.0.

Onboarding 2.0 Recruiting Manage­ User Recruiting Recruit-to-Hire This permission al­
ment Permissions Data Mapping lows you to map
fields for the recruit-
to-hire process.

Onboarding 2.0 Object Permissions User Onboarding Object Select the options The permissions
Permissions that best fit your you select deter­
scenario mine the level of ac­
cess for each type of
onboarding task.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 133
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Employee Profile User General User User Login This permission al­
Permission lows you to log on to
the application.

Onboarding 2.0 Employee Profile User General User Permission to Cre­ Select the forms you
Permission ate Forms want to provide per­
mission to create.
For administrators
in Onboarding 2.0, it
is recommended to
select All.

Onboarding 2.0 Administration User HomePage v3 Tile Homepage v3 To- This permission pro­
Group Permission Do tile group vides access to the
home page tiles for
to-do notifications.

To provide access to
the other home
page tiles, select the
corresponding per­
missions.

Onboarding 2.0 Goal Plans User Goals New Group Goal This permission al­
Creation lows you to create
Group Goals.

Onboarding 2.0 Goal Plans User Goals Goal Plan Permis­ This permission al­
sions lows you to access
the goal plans.

Onboarding 2.0 Object Permissions User Onboarding 2.0 or Message" Task Enables participants
Offboarding 2.0
to view, set, and up­
Object
date the Welcome
Permissions
Message for the new
hire.

Full permission rec­


ommended for:

● Hiring manager
● Hiring manag­
er's team

Using Role-Based Permissions


134 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Buddy" Task Enables participants
Offboarding 2.0
to view or edit As­
Object
sign a Buddy activ­
Permissions
ity.

Full permission rec­


ommended for:

● Hiring manager

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Recommended Enables participants
Offboarding 2.0 People" Task to view, add, or re­
Object move recommended
Permissions people for new hire.

Full permission rec­


ommended for:

● Hiring manager

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Recommended Enables participants
Offboarding 2.0
Link" Task to view or modify
Object
recommended links.
Permissions
Full permission rec­
ommended for:

● Hiring manager

Onboarding Object Permissions User Onboarding 2.0 or "Equipment" Task Enables participants
Offboarding 2.0
to view/edit fur­
Object
nished equipment
Permissions
orders.

Full permission rec­


ommended for:

● Hiring manager

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Meeting" Task Enables participants
Offboarding 2.0
to schedule meet­
Object
ings.
Permissions
Full permission rec­
ommended for:

● Hiring manager

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 135
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Goal" Task Enables participants
Offboarding 2.0
to set up goals.
Object
Permissions Full permission rec­
ommended for:

● Hiring manager

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Checklist" Task Enables participants
Offboarding 2.0
to create a checklist.
Object
Permissions

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Prepare for Day Enables participants
Offboarding 2.0
One" Task to view or edit sup­
Object
plemental items.
Permissions

Onboarding 2.0 Object Permissions User Onboarding 2.0 or "Where To Go" Task Enables participants
Offboarding 2.0
to view or edit sup­
Object
plemental item loca­
Permissions
tions.

Onboarding 2.0 Object Permissions User Onboarding 2.0 or Document Flow Enables participants
Offboarding 2.0
to view or edit pa­
Object
perwork status.
Permissions
View permission
recommended for:

● Hiring manager
● Hiring manag­
er's manager
● Onboarding co­
ordinator
● HR admin

Using Role-Based Permissions


136 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Object Permissions User Onboarding 2.0 or ONB2Process Enables participants
Offboarding 2.0
to close Onboarding
Object
process flow.
Permissions
Full permission rec­
ommended for:

● Hiring manager
● Hiring manag­
er's manager
● Onboarding co­
ordinator
● HR admin
● System admin

Onboarding 2.0 Object Permissions User Onboarding 2.0 or ONB2ProcessTrig­ Enables participants
Offboarding 2.0
ger to trigger Onboard­
Object
ing and Offboarding
Permissions
process flow.

Full permission rec­


ommended for:

● Hiring manager
● Hiring manag­
er's manager
● Onboarding co­
ordinator
● Offboarding co­
ordinator
● HR Admin
● System Admin

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 137
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Object Permissions User Onboarding 2.0 or Asset Task Enables participants
Offboarding 2.0
to list and track the
Object
oragnization's as­
Permissions
sets that the Off-
boardee must return
before his last work­
ing day.

Full permission rec­


ommended for:

● Hiring manager
● Hiring manag­
er's manager
● Onboarding co­
ordinator
● Offboarding co­
ordinator
● HR Admin
● System Admin

Onboarding 2.0 Email Framework Admin Configure Email Configure Email Email category rep­
Framework
Permissions Categories resents a certain
Permissions
email template
group, such as the
Buddy Category:
category for buddy
assignment and re­
moval. It also in­
cludes rules for
building email mes­
sage attributes,
such as recipient
and content.

Onboarding 2.0 Email Framework Admin Configure Email Configure Email Triggers can be ap­
Framework
Permissions Triggers plied as rules for
Permissions
sending emails. For
example, Buddy As­
signment Cancella­
tion Trigger: Notify
the assigned buddy
that the task has
been reassigned to a
different colleague.

Using Role-Based Permissions


138 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Email Framework Admin Configure Email Configure Email Email Template pro­
Framework
Permissions Templates vides a specific
Permissions
email form gener­
ated by certain con­
ditions and rules.

Onboarding 2.0 Email Framework Admin Configure Email Configure Audit This allows you to
Framework
Permissions Trail display a list of
Permissions
emails sent by the
system. The Actions
you can take in­
clude: View Email,
Resend, and Display
Details.

Onboarding 2.0 Email Framework Admin Configure Email Allow Resend This allows you to
Framework
Permissions Emails trigger new re­
Permissions
minder emails and
complete or edit the
To and CC fields.

Onboarding 2.0 MDF Admin Metadata Configure Business Allows you to config-
Framework
Rules ure the business
rules associated
with your onboard­
ing programs.

Onboarding 2.0 Object Permissions Admin Email Framework EmailMessage Provides access
Object
necessary for man­
Permissions
aging email mes­
sages sent by the
system.

Onboarding 2.0 Object Permissions Admin Email Framework EmailReminder­ Provides access
Object
State necessary for man­
Permissions
aging email remind­
ers to be sent to the
Onboardee/
Employee. These
objects track an
email’s reminder
status and its last
sent timestamp.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 139
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Object Permissions Admin Email Framework EmailTemplate Provides access
Object
necessary for man­
Permissions
aging email forms
(or templates)
present in the sys­
tem.

Onboarding 2.0 Object Permissions Admin Email Framework EmailTrigger Provides access
Object
necessary for man­
Permissions
aging email rules
used for sending dif­
ferent types of
emails to the On­
boardee/Employee.

Onboarding 2.0 Object Permissions Admin Email Framework EmailTriggerCate­ Provides access
Object
gory necessary for man­
Permissions
aging categories of
emails that are trig­
gered by the sys­
tem.

Onboarding 2.0 MDF Admin Metadata Access to non-se­ Access to non-se­


Framework
cured objects cured objects

Onboarding 2.0 Employee Profile User General User User Login Provides access to
Permission
your system.

Onboarding 2.0 Employee Central User Employee Data HR Information Select the view and
edit field options
that best fit your re­
quirements.

Onboarding 2.0 Employee Central User Employee Data Employment De­ Select the view and
tails edit field options
that best fit your re­
quirements.

Onboarding 2.0 Employee Central User Employee Central Select the options Determines which
Effective Dated
that best fit your re­ effective-dated
Entities
quirements. fields can be viewed
or edited.

Using Role-Based Permissions


140 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding 2.0 Object Permissions User Onboarding Object Select the options The permissions
Permissions
that best fit your you select, deter­
scenario. mine the level of ac­
cess for each type of
onboarding task.

Onboarding 2.0 Manage Onboard­ Admin Manage On/ Manage Onboard­ Allows you to view
Offboarding
ing/Offboarding ing Permission the Onboarding or
On/Offboarding tab
in the main Suc­
cessFactors HCM
menu. Also allows
access to the On­
boarding application
work queue.

Onboarding Manage Onboard­ Admin Manage On/ Manage field map­ Allows you to access
Offboarding
ing/Offboarding ping tool for Em­ the Admin Center
ployee Central Field Mapping tool
for Onboarding/
Offboarding EC Inte­
gration tool to de­
fine field mappings
for integrating On­
boarding/Offboard­
ing with Employee
Central.

Onboarding Manage Onboard­ Admin Manage On/ Manage Onboard­ Allows you to access
Offboarding
ing/Offboarding ing additional con­ the Configure new
tent hire activity planning
process, Maintain
Central Orientation
Meetings, and Main­
tain Lists of Items to
Bring tools in Admin
Center.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 141
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User Recruiting Onboarding Initiate Allows you to initiate
Onboarding Permissions
ment Permission onboarding for a
candidate in RCM.
After Onboarding is
successfully initi­
ated, an Onboarding
activity is created
for the candidate in
Onboarding.

Recruiting Recruiting Manage­ User Recruiting Onboarding Update Allows you to up­
Onboarding Permissions
ment Permission date the Onboarding
activity for custom­
ers using Recruiting
Management - Veri­
fications Inc. inte­
gration.

 Note
This permission
is not relevant
for SuccessFac­
tors HCM On­
boarding.

Recruiting Recruiting Manage­ Admin Manage Recruiting Set Up Onboarding Allows you to define
Onboarding ment Integration field mappings for
the RCM entity tem­
plates: Job Requisi­
tion, Job Offer, and
Job Application. If
you are using Intelli­
gent Services, you
will get options for
propagating RCM
updates to On­
boarding and reas­
signing ongoing On­
boarding activities.

Onboarding MDF Admin Metadata Configure Business Configure Business


Framework
Rules Rules

Using Role-Based Permissions


142 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding MDF Admin Metadata Manage Data This permission al­


Framework
lows you to manage
data on the meta­
data framework.

Onboarding MDF Admin Metadata Access to non-se­ This permission al­


Framework
cured objects lows you to create,
read, edit and delete
data from the meta­
data framework.

For Employee Cen­


tral ERP Integration,
this permission al­
lows a user to ac­
cess information
provided by MDF
objects (such as the
Target System)
when viewing data
replication records
in the Employee
Central Data Repli­
cation Monitor. The
Data Replication
Monitor is used in
employee master
data, organizational
assignment, and
time data replication
from Employee Cen­
tral.

This permission is
also required for
users to be able to
view the history
page for Alternative
Cost Distribution.

Onboarding MDF Admin Metadata Admin access to This permission is


Framework
MDF OData API required to set up
the Information Re­
port for Data Protec­
tion and Privacy.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 143
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding OData API Admin Manage Allow Admin to Ac­ This permission en­
Integration Tools
cess OData API ables a user to cre­
through Basic Au­ ate, read, update, or
thentication delete information
using the available
OData APIs.

Onboarding OData API Admin Manage Access to OData This permission en­
Integration Tools
API Audit Log ables a user to mon­
itor the API calls.

Onboarding OData API Admin Manage Access to API Cen­ This permission en­
Integration Tools
ter ables a user to ac­
cess the API Center.

Onboarding OData API Admin Manage Access to OData This permission en­
Integration Tools
API Metadata Re­ ables a user to re­
fresh and Export fresh the metadata
of the OData APIs
using the Admin
Center tools.

Onboarding OData API Admin Manage Access to OData This permission al­
Integration Tools
API Data Dictionary lows users to man­
age OData API data
dictionary in Admin
Center.

Onboarding Employee Profile User General User User Login Enables a user to log
Permission
into the system.

Using Role-Based Permissions


144 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Onboarding Employee Profile User General User Live Profile Access This permission
Permission
gives users access
to the Employee
Profile page.

It also allows a user


to access the em­
ployee file from data
replication records
in the Employee
Central Data Repli­
cation Monitor. The
Data Replication
Monitor is used in
employee master
data, organizational
assignment, and
time data replication
from Employee Cen­
tral.

Onboarding Employee Profile User General User SAP Jam Access This permission al­
Permission
lows users to access
the SAP Success­
Factors JAM page.

Onboarding Employee Profile User General User Mobile Access This permission al­
Permission
lows users to access
the SAP Success­
Factors Mobile app
on their iOS or An­
droid mobile devi­
ces.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 145
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting MDF Recruiting User MDF Recruiting MDF Objects For View: Quickcard
Candidate Relation­
Permissions icon is displayed if
ship Management:
the information al­
Campaign
ready exists. Other­
CampaignCont
wise nothing is dis­
ent
played.
CampaignCont
ent View and Edit:
CampaignRecip Quickcard icon is
ient displayed if the in­
Candidate formation already
Follow
exists. Otherwise a
CandidateActivi
Create icon is dis­
ty
played.

Import/Export: Ena­
bles you to use
standard MDF
framework import
and export function­
ality for that object.

Field Level Over­


rides: Enables you to
set View or Edit per­
missions for individ­
ual fields.

Recruiting Recruiting Manage­ User MDF Recruiting MDF Objects to en­ Enables Candidate
Permission able Talent Pool: Relationship Man­
ment
agement talent pool
CampaignPool
features.
Pool Member

Using Role-Based Permissions


146 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User MDF Recruiting MDF Object: Pool Edit Yes: Create
ment Permissions Talent Pool link is
visible and active
(clickable). The
Talent Pool popup is
opened in Edit
mode. Edit link is al­
ways active, and dy­
namically opens the
Talent Pool popup in
Edit mode (Owner
only) or Read-only
mode (other users).

Edit No:

Create Talent Pool


link is hidden. Talent
Pool popup is
opened in read-only
mode (see items un­
der View Talent
Pool).

Row-Level (Sharing)
Permission: Owner
only

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 147
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User MDF Recruiting MDF Object: Share View Yes: Link is visi­
Pool with Group
ment Permissions ble and active (click­
able). Share with
Groups popup can
be opened, showing
list of recruiting
groups with which
this pool is shared.

View No: Link is visi­


ble but inactive
(grayed-out). User
cannot open Share
with Groups popup.

Edit Yes: Add button


is active. Stop
Sharing icon is ac­
tive.

Edit No: Add button


is grayed out. Stop
Sharing icon is
grayed out. List of
recruiting groups
with which this pool
is shared is visible
and Search Group
Name is active.

Row-Level (Sharing)
Permission: Owner
only

Using Role-Based Permissions


148 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User MDF Recruiting MDF Object: Share View Yes: Link is visi­
Pool with User
ment Permissions ble and active (click­
able). Share with
People popup can
be opened, showing
list of users with
whom this pool is
shared.

View No: Link is visi­


ble but inactive
(grayed-out). User
cannot open Share
with People popup.

Edit Yes: Add button


is active. Stop
Sharing icon is ac­
tive.

Edit No: Add button


is grayed out. Stop
Sharing icon is
grayed out. List of
users this pool is
shared with is visible
and first name-last
name search is ac­
tive.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 149
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ User MDF Recruiting CRM Saved Search View Yes: Makes List
ment Permissions of Saved Searches
visible and editable
on the Talent Pool
user interface. List
of saved searches
link is visible and ac­
tive. Backend Utility
(CRMSavedSearch
permission check) is
required. Saved
Searches popup can
be opened, showing
list of saved search
criteria associated
with this pool.

View No: List of


saved searches link
is visible but inactive
(grayed-out). User
cannot open Saved
Searches popup.

Edit Yes: Add button


is active. Remove
icon is active.

Edit No: Add button


is grayed out.
Remove icon is
grayed out. List of
associated searches
for this pool is visi­
ble and search is ac­
tive.

CRM Saved Search


audit: No

Recruiting Recruiting Manage­ Admin In Manage Recruiting Permis­ An Admin role is cre­
Permission Roles, sion ated
ment
create a role
named Admin.

Using Role-Based Permissions


150 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Manage­ Admin Add the Admin Recruiting Permis­ The Admin role is
user to the Admins sion added to the Admins
ment
group. For the per­ group.
mission changes
to take effect, log
out, close the
browser, and log
back in.

Recruiting Recruiting Manage­ User In Manage Recruiting Permis­ Grants a user the
Employee Import, sion ability to access the
ment
grant a user the link and upload a
ability to access CSV file of test
the link and upload users.
a CSV file of test
users.

Recruiting Recruiting Manage­ User In Language Packs, Recruiting Permis­ Designates the lan­
select the lan­ sion guages for Recruit­
ment
guages for Recruit­ ing
ing

Recruiting Recruiting Manage­ Admin Metadata Recruiting Permis­ Grants administra­


Framework Select sion tors access to Re­
ment
all. cruiting Manage­
ment.

Recruiting Recruiting Manage­ User Company Settings Recruiting Permis­ Enables Employee
Click Employee sion Central Foundation
ment
Central Founda­ Objects. Required
tion Objects. for manually migrat­
ing job classification
objects to MDF Ge­
neric Objects.

Recruiting Recruiting Manage­ User General User Mobile To-Do List Enables requisition
Permission Access routing.
ment

Recruiting Recruiting Manage­ Admin Recruiting Odata API Grants OData API
Permissions RCMApplication permissions to an
ment
Export Admin.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 151
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Recruiting Recruiting Market­ User Recruiting Check these boxes: Enables Advanced
Permissions Analytics and allows
ing ● Recruiting
user to access the
Marketing
drill to details option
Advanced
when Access
Analytics
Advanced Analytics
Permission
with Details permis­
● Access
sion is enabled.
Advanced
Analytics with
Details
● Recruiter RMK
SSO
Permission
● Job Marketing
● Access
Advanced
Analytics with
Details

Recruiting Recruiting Manage­ Admin Recruiting Check this box: Enables Careers Tab
Permissions Careers Tab
ment
Permission

Recruiting Recruiting Manage­ Admin Manage Recruiting Set Up Job Boards Sets options for job
Permission boards.
ment

Recruiting Recruiting Manage­ Admin Manage Recruiting Manage Detailed Enables Detailed
Requisition Requisition
ment
Reporting Privileges Reporting Privileges.
permission

Recruiting Recruiting Manage­ Admin Manage Recruiting Set up Agency Enables Agency
Access. functionality.
ment

Recruiting Recruiting Manage­ User Recruiting Mass Upload Allows users to


Permissions Candidate Resumes mass upload candi­
ment
date resumes. Fol­
low instructions in
the guide on how to
enable permission.

Recruiting Recruiting Manage­ User Recruiting Bulk Create Allows users to bulk
Permissions Candidates create candidate
ment
from .CSV File profiles from .CSV
files. Follow instruc­
tions in the guide on
how to enable per­
mission.

Using Role-Based Permissions


152 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Integration Center Admin Manage Allow users to This permission al­
Integration Tools execute lows you to trigger
"Application/UI" or any application or
"Event-based" Intelligent Service
Integrations event-based integra­
tion. For example, to
do a background
check of a candidate
before actually
scheduling an inter­
view, you need to
have an Applica­
tion/UI triggered in­
tegration created
and mapped to a
corresponding back­
ground check ven­
dor. Enable Allow
users to execute
"Application/UI" or
"Event-based"
Integrations permis­
sion to a Recruiter
role to run any Ap­
plication/UI based
integration.

 Note
To trigger any
application or
Intelligent Serv­
ice event-based
integration, you
do not need the
following man­
datory Integra­
tion Center per­
missions:
Admin access to
MDF OData API,
Access to
Integration
Center, and
Access to non-
Secured
Objects. How­
ever, you must
enable these
permissions to
use Integration

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 153
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Center for mod­


eling and exe­
cuting the inte­
gration.

Using Role-Based Permissions


154 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Integration Center Admin Manage Read Security This permission al­
Integration Tools Center artifacts lows you to access
using API and read security ar­
tifacts (like configur-
ing outbound
OAuth, generating
OAuth X509 key,
and so on) main­
tained in Security
Center. This permis­
sion is only for API
access and not for
Security Center UI
access. There is no
change in permis­
sions for Security
Center UI access.

 Note
To access Se­
curity Center ar­
tifacts, you
need not have
the following In­
tegration Cen­
ter permissions:

1. Admin ac­
cess to
MDF OData
API
2. Allow Ad­
min to Ac­
cess OData
API
through
Basic Au­
thentica­
tion
3. Access to
Integration
Center

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 155
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Document Manage Manage Documents This permission al­


Management Documents lows administrators
to manage docu­
ment attachments
centrally for the
HXM Suite, using
the Manage
Documents page.

Platform Document Configure Configure This permission al­


Management Document Document lows administrators
Management Management to configure docu­
ment management
settings and set up
integration with
third-party storage
vendors like Open­
Text.

Platform Document Admin Manage Document Configure Docu­ Enables users deter­
Management Categories ment Management mine which catego­
ries of documents
your users have ac­
cess to.

Employee Central Workflows User Manage Workflows Prevent Quick Ap­ This permission pre­
proval for Workflow vents users from
mass approving
their workflow re­
quests in the
Approve Requests
dialog box or on the
My Workflow
Requests page. They
must open each
workflow request,
review the details,
and approve it indi­
vidually on the
Workflow Details
page.

Using Role-Based Permissions


156 PUBLIC How to Use the Master List of Role-Based Permissions
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Administrator Admin Alerts Ob­ Invalid Approvers in This permission al­
ject Permissions Employee-Related lows administrators
Employee Central Workflows
Workflows to view and access
employee-related
workflows with inva­
lid approvers from
the Admin Alerts 2.0
tile.

Users without the


permission can
process the same
workflows in the old
Admin Alerts. When
the permission is
granted, the work­
flows move over to
Admin Alerts 2.0.

Platform Administration Administrator Admin Alerts Ob­ Invalid Dynamic This permission al­
ject Permissions Role Users lows administrators
Employee Central Workflows
to view and access
invalid users in­
cluded in dynamic
roles from the Ad­
min Alerts 2.0 tile.

Users without the


permission can
process the same
invalid users in the
old Admin Alerts.
When the permis­
sion is granted, the
alert items move
over to Admin Alerts
2.0.

Using Role-Based Permissions


How to Use the Master List of Role-Based Permissions PUBLIC 157
Who's this Permis­
sion for? Admin or Permission Loca­
Solution Component User tion Permission Name Result

Platform Administration Administrator Admin Alerts Ob­ Stalled Workflows - This permission al­
ject Permissions Employee Related lows administrators
Employee Central Workflows
to view and access
stalled employee-re­
lated workflows
from the Admin
Alerts 2.0 tile.

Users without the


permission can
process the same
workflows in the old
Admin Alerts. When
the permission is
granted, the work­
flows move over to
Admin Alerts 2.0.

Using Role-Based Permissions


158 PUBLIC How to Use the Master List of Role-Based Permissions
5 Troubleshooting

Context

If you find that users have access to applications or data they should not have, we recommend the following steps:

Procedure

1. Run the View User Permission report to determine how - through which role - the permission was granted to
the employees. For details see How can you check the permissions assigned to a user? [page 161]
2. If that does not clarify how/why they have that permission or creates concern about where else this permission
is visible, then use the RBP Permission to User Report with the Single Permission Filter to validate what other
groups have access to this permission. For details see How can you run an ad hoc report? [page 162]

5.1 How Do Permissions Update When User Information


Changes?

Role-based permissions refresh periodically to propagate any changes to your dynamic groups or to the permission
roles in your system. These changes occur when employees are hired, employees change departments, and during
integration scenarios.

What's the Refresh Framework?

When changes to your employees' information occur in your SAP SuccessFactors HXM Suite such as, job title
changes, hiring of new employees, or giving additional responsibilities to employees, your role-based permissions
security platform runs an automated process that propagates these changes in your system. The changes affect
the permission roles that employees have access to and the permission groups they belong to. The Refresh
Framework handles this automated process in your system. Depending on the size of your organization, you may
have a high number of user changes or you could have a relatively low number of user changes in your system. The
refresh framework uses two types of refresh jobs to handle these scenarios.

Using Role-Based Permissions


Troubleshooting PUBLIC 159
Refresh Type Description

On-demand mode (Previously called Real-Time Refresh) When changes to user information occur infrequently, each up­
date action triggers its own refresh job.

Buffer mode When there's a high frequency of user information changes,


the framework buffers the refresh request for 5 minutes. Since
the refresh requests are always based on the same set of
groups and roles, buffering the request helps to avoid those
duplicated refresh actions that occur within that 5-minute
timeframe.

How Does the Refresh Framework Work?

The Refresh Framework consists of two types of refresh jobs: the on-demand mode and buffer mode. The refresh
framework automatically adjusts between buffer mode and on-demand mode, based on the actual refresh work
load.

When the workload is light, the framework enables the on-demand job. This is the refresh mode you're most
familiar with as you may currently use it for each refresh request. For example, an API call to change one user
causes a refresh on all user groups.

When the workload is heavy, on-demand mode is disabled and buffer mode is enabled. That means requests within
the next 5 minutes will buffer and reschedule tasks based on the buffer refresh request.

 Note

If your company has scheduled a background job to refresh RBP regularly, the scheduled job remains effective
and RBP refresh follows the defined interval. The Refresh Framework doesn't take effect even if you stop the
background job. If you wish to start using the Refresh Framework in your company, contact SAP Cloud Support.

Using Role-Based Permissions


160 PUBLIC Troubleshooting
What Are the Benefits to Using the Refresh Framework?

The Refresh Framework automatically switches between two refresh types depending on the workload detected. If
infrequent user information changes occur, your RBP roles and groups are immediately refreshed. If frequent user
information changes are detected, the buffer mode helps to reduce duplicate requests by collecting delta changes
and processing them in one refresh request. As a result, you experience improved system stability and better RBP
refresh performance. With the buffer mode enabled, you notice little delay.

My Organization Uses Scheduled Jobs, Are We Impacted by the Refresh


Framework?

No. If your organization uses Scheduled Jobs, the Refresh Framework doesn’t impact your system.

5.2 How can you check the permissions assigned to a user?

Procedure

1. Go to Administration Tools.
2. In the Manage Employees portlet, select Set User Permissions.
3. In the Set User Permissions section, select View User Permissions.
4. In the Advanced Search, enter the user name.
5. Click View Permission next to the user name.

A list of permissions is displayed along with the roles that grant those permissions.

6. To learn more about the roles, click the pop-up window icon next to any role name.

Using Role-Based Permissions


Troubleshooting PUBLIC 161
5.3 How can you run an ad hoc report?

Context

Procedure

1. Go to the Reporting page in Analytics and choose Ad Hoc Reports.


2. Open the menu next to the report name and choose Run Report.

3. On the Execute Permission to User… screen, open the Take Action menu and choose Edit.
4. Choose By My Selection and select the permission you are interested in.

Using Role-Based Permissions


162 PUBLIC Troubleshooting
5. Click OK and then Generate Report.
6. In the report, you can now see exactly to which role(s) the permission is granted.

5.4 Cross Domain Ad Hoc Reporting Between the RBP and


Employee Central Domains

The cross domain ad hoc report capability allows Administrators to run reports between the Role-Based
Permission (RBP) domain and Employee Central (EC) domain. RBP reports are included in the drop-down menu
when selecting the Cross Domain Report Definition types.

Administrators can create Cross Domain Reports to join RBP and Employee Central data. Person and Employment
is the EC domain information that is included and the tables are joined using the user_sys_id key.

Using Role-Based Permissions


Troubleshooting PUBLIC 163
5.5 How do you run a user search

User Role Search can search the roles granted to specific users for a specific permission and a target user. When
some users get some permissions on some target users that should not be granted, the administrator can use this
tool to find which role grants the permission so they can update the permission settings.

● This tool does not support MDF RBP permission as search criteria.
● This tool does not support Inactive Internal User or TBH user to be selected as Target User.
● This tool does not support External User.

1. Go to Administration Tools.
2. In the Manage Employees portlet, select Set User Permissions.
3. In the Set User Permissions section, select User Role Search.

Using Role-Based Permissions


164 PUBLIC Troubleshooting
4. In the Selection session of the tool, enter Access Users. You can select at most 2 access users.
5. Select Permission Category and one Permissions. If the permission needs target population, you can optionally
select one target user.

6. Click Search Roles Button. The search result will display all roles that grant this permission and target user to
the access users. If the target user field is empty, the search result will not consider target user. If a result you
expect to see is not showing up, it may be because there are back-end update jobs still running.

7. On the Result session, you can click on the role name to see role detail. On the role detail page, the grant rules
that grant the selected access user and target user will be highlighted in the “Grant this role to …” session.

Using Role-Based Permissions


Troubleshooting PUBLIC 165
How can you compare permission roles?

You can use User Role Search to quickly search for and compare permission roles assigned to specified users in
role-based permissions.

1. Go to Administration Tools.
2. In the Manage Employees portlet, select Set User Permissions.
3. In the Set User Permissions section, select User Role Search.
4. In the Selection session of the tool, enter the Access Users whose roles you are comparing.
5. Click Search Roles Button. The search result will display which roles, if any, grant the specified permission to
either user. In the following example, you can see that both of the selected access users have permission to
view address data.

6. If a user does not have the specified permission, it is indicated as "no result." In the following example, you can
see that the user "cgrant" has permission to view "Impact of Loss" data, due to her roles as a manager and
administrator. The user "jreed" is not assigned to any role that allows him to view this information.

7. You can also specify one target user, in order to see whether either of the two access users has the specified
permission for the specified target. In the following example, you can see that although both user "cgrant" and
user "dsharp" are managers, only user "cgrant" has permission to view "Impact of Loss" data for user
"vstokes". This is because, in this example, the manager role has a target permission group of "All Direct

Using Role-Based Permissions


166 PUBLIC Troubleshooting
Reports" and "vstokes" is a direct report of "cgrant".

Using Role-Based Permissions


Troubleshooting PUBLIC 167
Important Disclaimers and Legal Information

Hyperlinks
Some links are classified by an icon and/or a mouseover text. These links provide additional information.
About the icons:

● Links with the icon : You are entering a Web site that is not hosted by SAP. By using such links, you agree (unless expressly stated otherwise in your agreements
with SAP) to this:

● The content of the linked-to site is not SAP documentation. You may not infer any product claims against SAP based on this information.
● SAP does not agree or disagree with the content on the linked-to site, nor does SAP warrant the availability and correctness. SAP shall not be liable for any
damages caused by the use of such content unless damages have been caused by SAP's gross negligence or willful misconduct.

● Links with the icon : You are leaving the documentation for that particular SAP product or service and are entering a SAP-hosted Web site. By using such links, you
agree that (unless expressly stated otherwise in your agreements with SAP) you may not infer any product claims against SAP based on this information.

Beta and Other Experimental Features


Experimental features are not part of the officially delivered scope that SAP guarantees for future releases. This means that experimental features may be changed by SAP at
any time for any reason without notice. Experimental features are not for productive use. You may not demonstrate, test, examine, evaluate or otherwise use the
experimental features in a live operating environment or with data that has not been sufficiently backed up.
The purpose of experimental features is to get feedback early on, allowing customers and partners to influence the future product accordingly. By providing your feedback
(e.g. in the SAP Community), you accept that intellectual property rights of the contributions or derivative works shall remain the exclusive property of SAP.

Example Code
Any software coding and/or code snippets are examples. They are not for productive use. The example code is only intended to better explain and visualize the syntax and
phrasing rules. SAP does not warrant the correctness and completeness of the example code. SAP shall not be liable for errors or damages caused by the use of example
code unless damages have been caused by SAP's gross negligence or willful misconduct.

Gender-Related Language
We try not to use gender-specific word forms and formulations. As appropriate for context and readability, SAP may use masculine word forms to refer to all genders.

Videos Hosted on External Platforms


Some videos may point to third-party video hosting platforms. SAP cannot guarantee the future availability of videos stored on these platforms. Furthermore, any
advertisements or other content hosted on these platforms (for example, suggested videos or by navigating to other videos hosted on the same site), are not within the
control or responsibility of SAP.

Using Role-Based Permissions


168 PUBLIC Important Disclaimers and Legal Information
Using Role-Based Permissions
Important Disclaimers and Legal Information PUBLIC 169
[Link]/contactsap

© 2020 SAP SE or an SAP affiliate company. All rights reserved.

No part of this publication may be reproduced or transmitted in any form


or for any purpose without the express permission of SAP SE or an SAP
affiliate company. The information contained herein may be changed
without prior notice.

Some software products marketed by SAP SE and its distributors


contain proprietary software components of other software vendors.
National product specifications may vary.

These materials are provided by SAP SE or an SAP affiliate company for


informational purposes only, without representation or warranty of any
kind, and SAP or its affiliated companies shall not be liable for errors or
omissions with respect to the materials. The only warranties for SAP or
SAP affiliate company products and services are those that are set forth
in the express warranty statements accompanying such products and
services, if any. Nothing herein should be construed as constituting an
additional warranty.

SAP and other SAP products and services mentioned herein as well as
their respective logos are trademarks or registered trademarks of SAP
SE (or an SAP affiliate company) in Germany and other countries. All
other product and service names mentioned are the trademarks of their
respective companies.

Please see [Link] for


additional trademark information and notices.

THE BEST RUN

You might also like