Role-Based Permissions Guide 2024
Role-Based Permissions Guide 2024
5 Troubleshooting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
5.1 How Do Permissions Update When User Information Changes?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
5.2 Checking Permissions Assigned to a User. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
5.3 How can you run an ad hoc report?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
5.4 Cross Domain Ad Hoc Reporting Between the RBP and Employee Central Domains. . . . . . . . . . . . . . . .219
Filter and search for the role-based permissions specific to your system's implementation and learn how to test
your RBP configuration.
This content is for security administrators to enable them to manage Role-Based Permissions (RBP).
• RBP is the only permission model that is available to all customers across the SAP SuccessFactors HCM suite.
• The first two sections familiarize you with the concept of the legacy role-based permissions and the latest
role-based permissions.
• The subsequent sections detail the individual tasks that make up the process.
• Finally, you’ll find troubleshooting information in case problems occur with the permissions.
Note
This implementation content covers all general aspects of setting up RBP. The implementation handbooks for
the individual modules, including additional module-specific information.
Role-Based Permissions (RBP) is a security model that allows you to restrict and grant access to your SAP
SuccessFactors HCM suite. RBP controls access to the applications that employees can see and edit. Role-Based
Permissions (RBP) applies to the majority of SAP SuccessFactors products to restrict and grant user access to the
products.
The RBP security authorization model uses groups and roles to organize employees (groups) and permissions
(roles) to control access to your system; By organizing employees into groups and permissions into roles you can
assign a group of employees the same set of permissions by assigning them a role.
Note
RBP is approved for organizations with up to 1,500,000 employees. When in doubt, contact Product Support.
Role-based permissions contain three main elements: permission groups, permission roles, and target populations.
• Permission groups are a set of employees who share certain attributes such as City or Job Code and require
access to a similar set of tasks within your system.
• Permission roles are defined as a set of permissions. You can assign the permission roles you define to a
permission group, and if the role requires that you define a target population, meaning a group to perform
tasks for, you assign the target population when you define the role.
• Target populations are groups that are assigned to permission roles when the permission granted is performed
on behalf of other employees.
Tip
We recommend that you create groups before creating roles so that during role creation, you can select the
group for which to grant the role. In addition, you need defined groups for roles that require a target population.
Related Information
Permission groups are used to define groups of employees who share specific attributes. You can use various
attributes to select the group members, for example a user's department, country/region, or job code.
Example
There might be a permission group called "Human Resources in US", which lists all US-based employees who
work in the HR department. To define this group, you would specify that users must match the selection criteria
"Country/Region = United States" and "Department = HR".
Note
The attributes or selection criteria that are available for defining groups are configurable.
In RBP, you can assign permission roles to permission groups. In addition, you use groups to define the target
population a granted user has access to.
Example
The group "Human Resources in US" might have access to the group "US Employees".
Groups configured with criteria other than specific user names are called dynamic (as opposed to static),
which means that the assignment of employees into and out of a group is automated. For example, a group of
granted users can be “All employees in the Sales department”. As employees are transferred into and out of the
sales department, their permissions will automatically adjust. This automation will save you time and money.
This is especially beneficial for large organizations that need higher levels of administrative efficiency.
Static permission groups are created and modified by adding individual user names to a group using an excel
spreadsheet. They store a static list of users instead of a list based on dynamically generated criteria. Changing
user information does not modify group members, you must redefine group members by importing an updated
spreadsheet.
Procedure
4. Download a blank CSV template after you've chosen an import type. The Full Replace template has two column
headers, GROUPNAME and USERID. The Delta Replace has an additional Action column.
5. For each user that you add to a group, add the group name to the GROUPNAME column and user's ID to the
USERID column.
For new users, you can create user IDs in the upload file.
Note
Character encoding of your file should be Unicode (UTF-8). The maximum file size is 20MB. If your import
file exceeds 20MB, you can either split the file into several smaller files or request Professional Services to
modify the system configuration file.
If your file has errors, they display at the top of the Import Static Group window.
Note
For one group type, a maximum of two jobs can run at the same time.
Results
After the upload completes, the system sends you a notification with success or error messages. Successfully
created groups display in the group list after refreshing your system.
You can add members to a static group in your system or by importing an excel file to your system.
Procedure
Instead of opening static groups one by one to add members, you can add multiple members to several static
groups all at once with a CSV file.
Procedure
GROUPNAME Fill in the names of the static groups that you want to add
members to.
ACTION ADD
A message displays at the top of the Import Static Group popup to inform you whether there’s any format issue
in the CSV file.
9. If there are no issues found in the validation phase, choose the CSV file again and click Upload.
10. Click Cancel to dismiss the Import Static Group popup.
Results
You have successfully added members to the static groups with a CSV file. You receive an email about the details.
Next Steps
Refresh the Manage Permission Groups page to double check the active membership of the static groups that
you’ve updated.
Although you add members to a static group using a spreadsheet, you can remove static group members using the
system.
Procedure
Results
Removed members will no longer have access to the tasks or data of the group.
Instead of opening static groups one by one to remove members, you can remove multiple members from several
static groups all at once with a CSV file.
Procedure
GROUPNAME Fill in the names of the static groups that you want to re-
move members from.
ACTION REMOVE
A message displays at the top of the Import Static Group popup to inform you whether there’s any format issue
in the CSV file.
9. If there are no issues found in the validation phase, choose the CSV file again and click Upload.
10. Click Cancel to dismiss the Import Static Group popup.
You have successfully removed members from the static groups with a CSV file. You receive an email about the
details.
Next Steps
Refresh the Manage Permission Groups page to double check the active membership of the static groups that
you’ve updated.
Dynamic permission groups are generated automatically when the attributes of employees match the group
selection criteria. Administrators can create and manage dynamic permission groups for both employees and
external users.
Procedure
The available user types vary depending on how your system is configured. Possible values may include:
• Employee (default)
• External Learning User
Note
The External Learning User option is only available if you have Learning enabled in your system.
When defining a dynamic group for an external learning user, you can identify an External Source Channel
to complete the criteria for inclusion. This allows external learning users to be defined based on the source of
origin. The external source channel is only available to SAP SuccessFactors Learning customers. The External
Learning User must be enabled in Provisioning for external learner and external source channel to be available.
Remember
As a customer, you don't have access to Provisioning. To complete tasks in Provisioning, contact
your implementation partner or Account Executive. For any non-implementation tasks, contact Product
Support.
When defining External Learning User groups in your system, it is recommended that you do not create
more than 50 groups.
5. Choose the group selection criteria from the People Pool, in the Choose Group Members section.
Depending on the complexity of your permission group selection criteria, you can choose multiple people
pools.
6. In the Search Results screen, enter a search term or click the search, to display all available values.
For some categories, a smaller pop-up window appears where you can enter additional values or information,
such as Time Zone settings. If you select the Team View category, you can use hierarchical relationships to
specify the group. This allows you to apply rules such as: everybody in Carla Grant's team, all levels deep.
Note
When you search employees with the User category, the search results in the dropdown display only
employee names. When you search employees with the Team View category, the search results in the
dropdown display employee names, employee titles, and locations.
Example
If you want to create a group of sales employees working in the US, you would need to choose the category
Department and select Sales. You add a second category Country/Region and select United States.
9. Complex group definitions may require you to use multiple people pools. If you use two or more people pools,
these people pools functions as an OR operation, that is, all users are selected who fulfill the selection criteria
of at least one pool.
Click Add another People Pool and then add categories and items.
Example
You have two different offices: An office in Chicago and an office in Boston. Each office has a Sales team and
a Finance team. You only want to include Sales employees from the Chicago office and Finance employees
from the Boston office. You'll need to create two separate pools then.
Note
10. If there are employees you'd like to exclude from the Permission Group definition, select them in the Exclude
these people from the group section.
11. If you want to prevent the group being updated automatically when new employees match the selection
criteria, click Lock group.
12. (Optional) Choose Update in the Active Group Membership box to see how many users match the criteria. Click
the number to see the detail list.
You can manage static or dynamic permission groups. You can also mark a permission group as RBP-only, which
means the group can be only used in Role-Based Permissions. If a permission group isn't RBP-only, it can also be
used in other modules, for example, on home page. For dynamic groups, you can also view the group's change
history.
Context
Note
Procedure
1. Go to the Admin Center Tools and search for Manage Permission Groups.
2. In the Manage Permission Groups screen, click the Take Action dropdown menu next to the permission group
you want to modify.
• You can see delete and view summary of static groups.
• You can edit, copy, delete, view summary, and view change history of dynamic groups.
Note
You can only see the most recent 1000 changes in the View change history view. If you want to see
more than the last 1000 changes, use the Change Audit report.
RBP uses permission roles to group a set of permissions. After grouping the permissions into a role, you can assign
the role to a group of users, granting them access to certain tasks and features in your system.
Permission roles consist of a set of permissions that give employees access rights to an employee or a group of
employees. As such an employee or a group that has been granted with a permission role has access to certain
Role-based permissions allow you to grant a role to a specific employee, a manager, a group, or to all employees in
the company. The roles can provide very granular permissions, as this example illustrates:
Example
There may be roles such as "HR Compensation and Benefits Manager", "HR Manager for Sales", and "HR
Learning and Development Manager". While all three are HR managers, their roles have been distinctly carved
out — one handling compensation and benefits, another handling the sales team, and the third handling
Learning and Development.
When your permissions roles consist of one or more permissions that require a target population, you'll need to
specify a target to complete creation of the role. Roles that require a target population will contain a permission
that gives a group access to perform actions or view information for other employees.
Example
A Manager may have a role where one permission allows the manager to modify the salary for all of their
direct reports. In this example, the manager's direct reports represent the target population needed for the
permission role.
Note
Permission roles can be created for employees and for external users, such as External Learning Users.
Context
Permission roles contain a group of permissions that can be granted to an employee or a group of employees
known as the Granted Users Circle. In general, its leading practice to define your user groups before defining your
permission roles.
Procedure
Example
If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.
13. Click the Done button to assign this role to the defined users. You’re taken back to the Permission Role Detail
page.
14. Click the Save Changes button to complete creating the role.
If you grant permissions to every employee when creating or updating a permission role, a double confirmation
popup displays when you save the changes.
Next Steps
Once this role is successfully created, the new role is listed on the Permission Role List page.
Related Information
After creating groups and roles, you'll need to assign permission roles to your employee groups.
Procedure
1. In the Permission Settings section, click the Permission button to specify the permission you want to assign to
the role. The Permission Settings window opens.
2. On the left side of the page, you'll see the different permission categories. Click a permission category to reveal
the different permissions.
Next Steps
You can edit, copy, or delete a permission role, view a summary of a permission role, and view its change history.
You can also mark a permission role as RBP-only.
Context
When you copy a role, only the permissions get copied over. You need to manually grant employees access to this
new role.
Procedure
Role-based permissions support the role of External User and allows the External Learner User limited access to
complete specific tasks or training.
The external user role can be granted to the user type External Onboarding 1.0 user. Permissions for the external
user role can be set to grant access to the Onboarding 1.0 home page.
If you have external users, consider creating a management system for them so that you can maintain their access.
Prerequisites
Either Onboarding 1.0 (including Internal Hire Process) or Learning or both must be enabled in Provisioning to reset
the external user password.
Remember
As a customer, you don't have access to Provisioning. To complete tasks in Provisioning, contact your
implementation partner or Account Executive. For any non-implementation tasks, contact Product Support.
Context
When you have external users in your extended enterprise, your plan for maintaining them must include: resetting
user passwords, granting access, and so on. In most cases, you manage external users as you do any other users.
One exception is target populations. External users can be a unique target population. For example, if you want to
manage external users in Onboarding 1.0, you must add All(External Onboarding 1.0 User) to the target population
of users managed by the administrator.
Procedure
The Resetting User Passwords page appears. From this page you can reset individual user password, or reset
the passwords for a group of users.
2. Select External Users from Onboarding 1.0 and/or Learning (If enabled) from the Find dropdown.
Enter the First Name, Last Name, or the Username to search for the user whose password you’re trying to
reset. You can filter your search further using Starts With or Exact Match.
3. When the user details appear on the screen, select the user and enter the new password in the New Password:
field and confirm the same in the Confirm Password: field.
4. Click Reset User Password.
Results
Create a role mapping for external learners and grant them the permissions to log in to SAP SuccessFactors and
access Learning.
Prerequisites
Remember
As a customer, you don't have access to Provisioning. To complete tasks in Provisioning, contact your
implementation partner or Account Executive. For any non-implementation tasks, contact Product Support.
Procedure
You can select additional permissions. For example, you can grant the external learners access to SAP Jam.
9. Click Done.
You can assign a permission role to everyone or to a subset of employees, determined by permission groups, target
populations, or by relationships. When defining a role in RBP, you can assign the role to a group that you've created
or you can assign roles based on hierarchical relationships. Some roles will require that you also assign target
populations, they're only necessary for certain permissions in a role and your system will notify you when a target
population is required.
• Permission groups: You assign a permission role to a defined group of users. However, relationships can also
play a role here as you can define that the granted user's managers have the same permissions. You can also
define how many levels up in the hierarchy you want this permission to be granted.
Note
If you want to grant a role to a named user, you first have to create a group and add the user to this group.
Then you can grant the role to the just created group.
• Target Population: Depending on the permissions included in the role, you might also have to define the
target population. Not all permissions require you to define a target population. For example, if the permission
includes just the access to an application (such as the Learning Access Permission), there is no need to add a
target group. For certain permissions, in the Permission settings screen, a target population must be defined.
This is identified by the "t" icon next to the permission name with the following text displayed: t= Target needs
to be defined.
Note
You can define a target population for external users through Manage Permission Roles Add For
External Target Population . A target population for an external Learning user can be defined two ways:
• Select Everyone (External Learner)
• Select Target population of: and click Select, to select groups
Note
If you allow the respective managers to have the same permissions, this may have a negative impact on the
performance. The hierarchy then has to be checked whenever such a manager tries to access an element
which was permissioned this way.
After creating your roles, you must assign the role to a group of employees. This ensures that employees are given
access the permissions they need to perform their tasks.
Procedure
Note
If you have enabled Onboarding or Learning, you have an additional option Add For External Target
Population where you can restrict data access by defining external target populations.
5. When the Grant this role to screen displays, select Permission Group.
6. Click Select to select the access groups you wish to assign to this permission role.
You can allow managers to have the same permissions and define how many levels up in the hierarchy you want
this permission to be granted. However, allowing respective managers to have the same permissions may have
a negative impact on the performance. The hierarchy then has to be checked whenever such a manager tries to
access an element that was permissioned this way.
7. Exclude Granted Users:
For some permissions, it might be necessary to exclude the granted users from applying the permissions on
themselves. For this, select Exclude Granted User from having the permission access to themselves.
Example
If the role grants permission to edit the salary, you want to prevent the members of this permission group
to be able to edit their own salary as well.
8. Click Done to assign this role to the defined users. You’re taken back to the Permission Role Detail page.
9. Click Save Changes to complete creating the role.
Next Steps
You can restrict data access by defining target populations or criteria of roles that require tasks to be performed on
behalf of another employee.
Context
Target populations and criteria allow you to give employees such as managers and administrators access to data or
tasks that need to be maintained for other employees. Not all permissions require you to define a target population.
For example, if the permission includes just the access to an application (such as the Learning Access Permission),
there’s no need to add a target user group or target criteria.
For most of the permissions and secured MDF object definitions, you can restrict data access by either setting
target population or adding target criteria. For a few of the secured MDF object definitions, you can set its target
population and further restricting the target population with additional target criteria.
Remember
Only object definition Employee Time can be configured with concurrent target population and target criteria.
You can identify permissions and object definitions that are available for target population configuration, in the
Permission settings screen, by the "t" icon next to the permission name with the following text displayed: t= Target
needs to be defined.
Procedure
Note
As of the 2H 2022 release, you can configure target criteria for a permission role whose target population is
external users. If you have existing permission roles granted to groups whose target population is external
users, review the target criteria configurations of those roles. The target criteria configurations for said
permission roles will stay as null if you don't open and save the roles. When you open and save the roles, the
target criteria configurations are set to all.
Please note that this feature isn't available for instances using Onboarding 1.0.
4. Choose Edit Granting for a role you’ve assigned this permission to in the Grant this role to section of the
Permission Detail screen.
5. Define target population in the second section of the Grant this role to... popup window.
To exclude the granted users from applying the permissions on themselves, select Exclude Granted User from
having the permission access to themselves.
Note
Only secured MDF object definitions whose RBP Subject User Field is left empty are available for target
criteria configuration.
7. Click Done to assign this role to the defined users. You’re taken back to the Permission Role Detail page.
8. Click Save Changes to complete creating the role.
General Relationship Types: Hierarchical relationships are characterized by a reporting line between the granted
user and the target user. These are relationships between employees and their managers, and employees and
their second managers or alternate managers. Non-hierarchical relationships on the other hand are single-level
relationships. These include the relationship of an employee to the HR manager, the matrix manager and custom
manager. While each employee can have only one Manager, one Second Manager and one HR Manager, they can
have multiple Matrix Managers and Custom Managers.
Employee Central Only: If employees have global assignments (that is, a job in another country/region), they have
both a home manager and a host manager. In addition, they have a home HR manager and a host HR manager. All
managers need to have access to both the home jobs of the employees as well as to the host jobs of the employees.
This is covered by the following additional relationship types for global assignments:
Custom Manager
As a manager, you can use the Delegate A and Delegate B relationship roles to assign permissions to up to two
individuals for each role, allowing them to act as your delegates. The delegate users you assign, can access your
Note
You must configure Delegate relationship type in the Employee Central Picklist. After you've configured
your delegates, you'll see the option to give permissions to this relationship type in your system. For more
information about how to configure picklists, see the topic Picklist Configuration for Employee Status and Job
Relationship Type.
You might use a delegate when you want to assign delegates permissions in different functional areas.
You can also assign permissions to delegates that separate functionality according to locations.
If delegate relationship has been defined in Employee Central picklists, you can grant a permission role to
delegates. When a manager delegates his or her tasks to two delegates, delegate A and delegate B, the manager's
direct reports are the target population of delegate A and delegate B. If the manager, delegate A, and delegate
B are in the same permission roles, delegate A and delegate B will have the same permissions. The manager's
direct reports are the target populations of the delegate A and delegate B for the permissions that require a target.
However, this delegate relationship can’t be used in non-user-based permissions. For example, even if delegate A
and delegate B has the same Miscellaneous Permissions Position permission as the manager, delegate A
and delegate B can’t view the current state of the position or view its history because the Position permission isn’t
user-based.
Description Permission to the data of a user. MDF objects that are categorized in the
The target population of the permission Permission requiring MDF object target
can be grouped as a user list. section.
It can be RBP permissions or some of
the MDF permissions.
Understand how to use hiearchy depth when assigning permissions to your users.
When granting permissions using hierarchical relationships, you can specify how many levels down to go in the
hierarchy for the target population. For example, you can indicate that Managers can see performance ratings on
their direct reports (1 level deep), or allow it to go deeper into their team, that is 2 levels down or all levels.
When granting permissions to non-hierarchical relationships (HR, Matrix and Custom Managers), you can follow
this non-hierarchical relationship for only one level. Beyond the first level, you can cross over to the standard
manager hierarchy if desired to go deeper.
• 1 Level Deep: Matrix Managers can view ratings information for their Matrix Reports.
• 2 Levels Deep: Matrix Managers can view ratings information for their Matrix Reports and the Direct Reports of
their Matrix Reports.
• All Levels Deep: Matrix Managers can view ratings information for their Matrix Reports (1 level deep) and the
Direct Reports, all levels deep of the manager hierarchy of their Matrix Reports.
The following graphic illustrates the different hierarchical depths you can specify when you use the Matrix Manager
relationship:
Rules are defined by determining which permission roles you’ll assign to your groups or users. From the Permission
Role Detail screen in your system, each rule is represented by a row that contains your list of granted users or
From your permission role detail screen, where you manage your permission roles, each row represents a rule and
each rule can have multiple access and target group associations, as detailed in the display.
Role-Based Permissions (RBP) is a security model that allows you to restrict and grant access to your SAP
SuccessFactors HCM suite. RBP controls access to the applications that employees can see and edit. This is
a suite-wide authorization model that applies to the majority of the SAP SuccessFactors products. The latest
Role-Based Permissions is the newest version of the RBP experience. We encourage you to review information in
this guide about the latest Role-Based Permissions to get a feel of the new UI look and prepare for the retirement of
the legacy Role-Based Permissions in future releases.
Supported Features
• RBP-only permission roles and permission groups are also supported. RBP-only indicates that the permission
role or permission group is only accessible for RBP administrators for permission-related features. Other
features, such as home page, can't reuse this role or group.
• All four permission types are supported, including on-off permissions, parent-child permissions, all-other
permissions, and permissions with actions.
• Compensation and MDF permissions are supported.
• Tree security permissions aren't supported. You can view and configure tree security permissions using the
legacy Role-Based Permissions.
• If you update the data blocking settings of an existing permission using the latest Role-Based Permissions, the
last modified date of the permission role isn’t updated accordingly.
As an RBP administrator, you see a simplified administration page using the latest Role-Based Permissions.
Before we dive into the latest Role-Based Permissions, here’re four concepts you want to know.
To understand the concepts of RBP, consider an administrator named Carla Grant whose job requires this
administrator to edit the personal data of employees in Canada. The permission role for Carla includes a set of
permissions that give Carla write access to Canadian employees' personal data. Carla is one of the administrators
in the access population because Carla is granted permissions to edit Canadian Employees' data. Employees
working in Canada are the target population because Carla can access their data and manage them. The role
assignment is what Carla can do to access or manage Canadian Employees: as a simple example, add, edit, and
delete.
You can use the latest Role-Based Permissions to create permission roles, define access population, define target
population, and manage roles and role assignments.
The latest Role-Based Permissions use permission roles to group a set of permissions.
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
Basic Information Provide a role name. This is a required field. The maximum
length is 255 bytes.
Provide a description. The maximum length is 4000 bytes.
Select a user type from the drop-down. Three user types are
suppoted: Employee, External Onboarding User, and External
Learner.
If you want to prevent other modules from using this role,
select RBP-Only.
Add Permissions Choose a permission category from the left panel. A list of
permissions of the category displays on the right panel for
your selection.
Results
A role assignment is a relationship between a role and its access population and target population. You can use
the Add Role Assignment page to assign permissions to a group of users and define whose data those users can
access.
Prerequisites
You're in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
After creating a permission role, choose OK on the Success popup to continue to assign the role. You can also add
role assignments in the Manage Permission Roles page or the Role Assignments page.
Procedure
Basic Information Provide a role assignment name. This is a required field. The
maximum length is 255 bytes.
Provide a description. The maximum length is 4000 bytes.
Select a user type for the target population.
Choose a status for the role assignment.
Note
When you search for a group, input the beginning of the
group name in the group search field and click "Enter".
Define Data Blocking (Optional) For permission roles that require data blocking,
choose Restricted, and enter the number of months (0 to
999) for which the role will have access to the historical
data.
• The system always uses the current date to calculate
the authorization period, so if you enter “12” the role
has access for 12 months from today.
• If you enter "0", the role has no historical access at all.
That is, the role won't be able to see anything older than
today.
• The system always uses the time zone of the signed-in
user to calculate the period.
Results
You can update details of a permission role, except for its user type.
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
Procedure
Results
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
Procedure
Results
You can delete permission roles that you no longer need. If you delete a permission role, all its role assignments are
deleted as well. In 2H 2021, only Clock In Clock Out module is supported.
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
Procedure
Results
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
Results
You can activate and deactivate multiple role assignments of a permission role at the same time.
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin (Edit)
permission.
Procedure
Note
You can select up to 30 role assignments. This limit is to ensure optimal system performance, especially
in systems that have enabled double-confirmation messages for large-size permission role or permission
group changes. See Enabling Double-Confirmation Messages for Large-Size Permission Changes in Related
Information.
Results
You've successfully activated or deactivated multiple role assignments of the permission role.
Related Information
If a permission role has many role assignments, you can search, sort, and filter role assignments easily.
Prerequisites
You are in the Manage Role-Based Permission Access list and assigned the Role-Based Permission Admin
permission.
Procedure
Function Description
Search In the search box, you can enter a role assignment ID, name, or description. Note that if you search by assign-
ment ID, the search result is a strict match.
Sort You can sort role assignments by ID, Name, or Last Modified in ascending or descending order.
• Choose OK to apply your sorting criteria.
• Choose Reset on the upper right hand of the popup to reset your changes.
• Choose Close to close the popup without applying your sorting criteria to the role assignment table.
Filter You can filter role assignments by role assignment ID, name, description, status, last modified date, access
population, and target population.
Note
For Permission Group Name field in both the Access Population and Target Population sections, you can
either choose to enter a group name, or select the Everyone option. If you enter a group name and also
select Everyone, the system returns results matching Everyone and the group name you entered.
You can check the change history of a permission role. You can also compare two versions of a permission role to
check which permissions were added or removed.
Context
When you add or remove permissions or role assignments of a permission role, a change record of the permission
role is created. But only permission changes are highlighted when you compare two versions. So, after you add
a role assignment to a permission role, and compare the current version with the previous record, no change is
highlighted.
Procedure
1. Go to Admin Center Manage Permission Roles [select a permission role] View History . Or, you can go
into the role details page and choose the View History button.
The role history page displays. There are two tabs, Role and Role Assignment, in this page. Please note that
comparing role assignment history records is currently not supported.
Results
Changes between the two versions are highlighted. The strikethrough texts highlighted in red are removed
permission. The underlined texts highlighted in green are newly added permissions.
Note
Next Steps
• Choose Show All to see all the permission details, changed or not.
• Choose Show Difference to see only the changed permissions.
This permissions list is a one-stop-shop for suite-wide permissions and general RBP information. Customize your
filter criteria to list permissions for your specific product permissions set.
The permissions list allows you to search for and filter permissions across products that use the RBP security
model. You can start by selecting your products from the Solution filter and narrow your selection by filtering
the components for your products and searching for specific keywords or phrases. To quickly understand the
permissions for your products, your filtered list displays all the available permissions for your combination of
products, where they are located in the system, and how they will function once enabled.
At first glance, the permissions table displays all available permissions in the SAP SuccessFactors suite. When
you've narrowed your search criteria and you're satisfied with the list of permissions for your products, you can
download the permissions into a CSV file for continued use. In your system, you can manage permissions by
creating roles in the following location: Admin Center Set User Permissions Manage Permission Roles
Related Information
This is a main list of role-based permissions used across the SAP SuccessFactors HCM suite.
Remember
All customers have access to the SAP SuccessFactors platform. General permissions that are common to
many or all SAP SuccessFactors solutions, such as User Login or User Search permissions, are listed in the
following table as part of the "Platform" solution.
If you use filters to find permissions related to a specific solution, remember to include "Platform" in your filter.
It's likely that some of these permissions are relevant to your system.
Platform Data Inspector Admin Manage System Data Inspector Allows you to access
Properties the Data Inspector
admin page.
Platform Scheduled Jobs Admin Admin Center Monitor Scheduled Allows users to use
Permissions Jobs Scheduled Job Man-
ager to monitor
jobs.
Platform Scheduled Jobs Admin Admin Center Manage Scheduled Allows users to use
Permissions Jobs Scheduled Job Man-
ager to rerun, cre-
ate, edit, or termi-
nate jobs.
Platform Scheduled Jobs Admin Admin Center Restrict Access Prevents users from
Permissions to Other viewing job requests
Administrators’ created, owned, or
Jobs in Scheduled last modified by
Job Manager other administrators
in Scheduled Job
Manager.
SAP Business AI SAP Business AI Admin Manage AI AI Services Allows you to ac-
Platform Capabilities Administration cess the AI Services
Administration page.
SAP Business AI Generative AI User AI Access Assisted Person Allows users to gen-
Employee Central Compensation Insights erate insights based
on employee data
using Generative AI
features.
SAP Business AI Generative AI User AI Access Assisted Writing Allows users to ac-
Platform cess the AI-assisted
writing tool to en-
hance the quality
of the content they
write in the text
fields in SAP Suc-
cessFactors applica-
tions.
Onboarding Object Permissions User Compliance Object Compliance Form Allows users to ac-
Permissions cess the compliance
form.
Onboarding Object Permissions User Compliance Object Compliance Allows users to view
Permissions [Link] the fields in the
ormFields compliance form.
(FormFieldMetadat
a)
Onboarding Object Permissions Admin Compliance Object Compliance Allows users to ac-
Permissions [Link] cess the compliance
DFs form data in PDF
(FormPDFMetadata form (form signa-
) ture & locale PDF
mapping)
Onboarding Object Permissions User Compliance Object Compliance Allows users to ac-
Permissions [Link] cess the compliance
[Link] form data in PDF
(FormPDFSignature form (form signa-
Metadata) ture & locale PDF
mapping)
Onboarding Object Permissions User Compliance Object Compliance Allows users to ac-
Permissions [Link] cess the compliance
[Link] form data in PDF
rLocales form (form signa-
(FormPDFLocaleMe ture & locale PDF
tadata) mapping)
Onboarding Object Permissions User Compliance Object Compliance Allows users to ac-
Permissions [Link] cess the compliance
Ui form data in UI
(FormUIMetadata) form.
Onboarding Object Permissions User Compliance Object Compliance Allows users to ac-
Permissions [Link] cess the compliance
[Link] form data in UI
ales form with different
(FormUILocaleMeta locales.
data)
You can assign View
access to this per-
mission.
Onboarding Object Permissions User Compliance Object Form Group Allows users to view
Permissions Metadata compliance forms
associated to a spe-
cific country/region.
Onboarding Object Permissions User Compliance Object FormGlobalFilter Allows users to fil-
Permissions ter forms by coun-
try/region and state.
Onboarding Object Permissions User Compliance Object FormSelectionFilter Allows users to filter
Permissions forms by version.
Onboarding Onboarding or Off- User Object Custom Task Allows users to cre-
boarding Object Permissions ate custom tasks.
Permissions
You can assign View
and Edit access to
this permission.
Onboarding Onboarding or Off- User Object Custom Task Allows users to de-
boarding Object Permissions Definition fine custom tasks.
Permissions
You can assign View
and Edit access to
this permission.
Onboarding Onboarding or Off- User Object Delegatable Task Allows users to dele-
boarding Object Permissions gate custom tasks.
Permissions
You can assign View,
Edit, and Import/
Export access to this
permission.
Onboarding Compliance User Compliance Object Compliance Form Allows users access
Permissions Data to the compliance
form data.
Platform Security Center Admin Manage Security Access to PGP File Allows users to im-
Center Encryption Keys port PGP Keys for
file encryption.
Platform User Management Admin Manage Identity Edit Access to Allows you to edit
Account and Group SCIM Group API the membership of
for Membership static permission
Assignment groups using the
SCIM Group API.
Platform User Management Admin Manage Identity Filter Permission Allows you to ac-
Account and Group Groups to be cess the Filter
Returned by Permission Groups
Workforce SCIM to be Returned
APIs by Workforce SCIM
APIs admin page
Platform User Management Admin Manage Identity Manage Workforce Allows you to ac-
Account and Group SCIM API Attributes cess the Manage
Workforce SCIM API
Attributes admin
page.
Platform Security Center Admin Manage Security Access to OAuth Enables access to
Center Configurations
outbound OAuth
configurations.
Platform Security Center Admin Manage Security Access to OAuth Enables access to
Center X509 Keys
OAuth X509 Keys
that are used in ex-
ternal SAML authen-
tication.
Platform Security Center Admin Manage Security Access to HTTP Enables access
Center Trust Certificates
to upload a
trusted certificate
for HTTPS server
calls.
Platform Security Center Admin Manage Security Access to Other Enables access to
Center Keys
generate keys for file
decryption, file sign-
ing for outbound
integrations and
SFTP server authen-
tication.
To access the
LinkedIn Account
Setup artifact in
Security Center,
you also need
the Metadata
Framework
Access to non-
secured objects
permission.
Platform Work Tech Admin Manage System Work Tech Allow admins to
Properties Configuration configure Work Tech
settings.
Onboarding 1.0 Object Permissions User Compliance Object I-9 User Data Allows users to view
Permissions and edit Form I-9
user data.
Onboarding 1.0 Object Permissions User Compliance Object I-9 User [Link] Allows users to
Permissions Data Documents view and edit Form
I-9 User Data Docu-
ments.
Onboarding 1.0 Object Permissions User Compliance Object I-9 User Allows translators to
Permissions [Link] view, edit, create,
and adjust the Form
I-9.
Onboarding 1.0 Object Permissions User Compliance Object I9AuditTrail Allows users to view
Permissions I-9 audit trail.
Platform User Management Admin Manage User Data Access: User Allows users to ac-
cess User Manage-
ment data using
People Analytics.
Platform User Management Admin Manage Identity Read Access to Allows users to view
Account and Group SCIM User API SCIM user resource,
which contains user-
name, user ID, login
method, and more.
Platform User Management Admin Manage Identity Edit Access to SCIM Allows users to edit
Account and Group User API SCIM user resource,
which contains user-
name, user ID, login
method, and more.
Platform User Management Admin Manage Identity Read Access to Allow users to
Account and Group SCIM Group API view SCIM group re-
source, which con-
tains group ID,
group name, last
modified date, and
more.
Platform User Management Admin Manage Identity Manage Identity Allow users to ac-
Account and Group Authentication/ cess the Manage
Identity Identity Authentica-
Provisioning Real tion/Identity Provi-
Time Sync sioning Real Time
Sync admin page.
Note
The Manage
Identity
Authentication/
Identity
Provisioning
Real Time Sync
admin tool is
planned to be
released in 1H
2023.
Platform Employee Data Im- Admin Manage User Import Extended Allows admins to
port User Information import extended
User Management user information to
Employee Profile.
Platform Employee Data Ex- Admin Manage User Export Extended Allows admins to ex-
port User Information port extended user
User Management information from
Employee Profile.
Platform Employee Data Im- Admin Manage User Hide the Option Hides the op-
port to Import tion Import by
User Management by Overwriting overwriting existing
Existing Data data from admins
for Background with this permis-
Information sion when they im-
port background in-
formation.
Platform Employee Data Im- Admin Manage User Bulk Upload Profile Allows admins to
port Photos upload multiple pro-
file photos for
employees in the
Scheduled Job
Manager.
Platform Employee Data Ex- Admin Manage User Bulk Export Profile Allows admins to ex-
port Photos port multiple profile
photos for employ-
ees in the Scheduled
Job Manager.
Employee Central Defaulting and Per- Admin Employee Central Condition Field Allows admins to
missibility Configu- Core Configuration create custom (con-
ration dition) fields of type
HRIS elements, MDF
objects, and Pick-
lists. These fields
determine the val-
ues of default fields.
Employee Central Defaulting and Per- Admin Employee Central Default Field Allows admins to
missibility Configu- Core Configuration create default fields
ration of type HRIS ele-
ments, MDF objects,
and Picklists.
Employee Central Defaulting and Per- Admin Employee Central Default Group Allows admins
missibility Configu- Core Configuration to create default
ration groups with multiple
entries for default
field values.
Employee Central Defaulting and Per- Admin Employee Central Employee Group Allows admins to
missibility Configu- Core Configuration create groups for
ration employees with the
selection criteria
as employee class
and employee type
fields.
Employee Central Defaulting and Per- Admin Employee Central Employee Group Allows admins to
missibility Configu- Core Configuration Item create multiple en-
ration tries with selection
criteria as employee
class and employee
type in an employee
group.
Employee Central Defaulting and Per- Admin Employee Central Employer Group Allows admins to
missibility Configu- Core Configuration create groups for
ration employers with the
selection criteria as
location and legal
entity fields.
Employee Central Defaulting and Per- Admin Employee Central Employer Group Allows admins to
missibility Configu- Core Configuration Item create multiple en-
ration tries with selection
criteria as location
and legal entity in an
employer group.
Employee Central Time Off User Time Management Create Purchase Allows users to cre-
User Permissions Leave in Self- ate purchase leave
Service requests using Em-
ployee Self-Service.
Employee Central Time Off Admin Manage Time Off Manage Purchase Allows users to pur-
Leave chase leave on be-
half of an employee.
Employee Central Time Off User Time Management Work Schedule Allows users to cre-
Absence Manage- Object Day Model Variant ate the Day Model
ment Permissions Identifier Variant Identifier ob-
ject, which is the
link between Holiday
Planned Working
Time Specification
and Day Model
Variant.
Employee Central Time Off User Time Management Work Schedule Allows you to pro-
Absence Manage- Object Day [Link] vide variant assign-
ment Permissions Assignments ments for a work
schedule day model
that is used as a
Regular Day Model.
Employee Central Time Off User Time Management Holiday Work Allows you to cre-
Object Pattern ate the Holiday
Permissions Work Pattern object
that is assigned to
the Job Information
record of an em-
ployee.
Platform Consent Agree- Admin Manage System Data Privacy Allows users to edit
ments Properties Consent Statement the content and
Settings manage settings of
the Data Privacy
Consent Statement.
Platform Administration Admin Admin Center Show Qualtrics in Allows users to view
Permissions Main Navigation a link to the Qual-
Menu trics Web site from
the main navigation
menu.
Platform Metadata Frame- User Miscellaneous MDF Audit Data Displays the volume
work Permissions Volume of audit data availa-
ble for a given MDF
object.
Platform Metadata Frame- User Miscellaneous MDF Association Displays the volume
work Permissions Data Volume of association data
available for a given
MDF object.
Platform Metadata Frame- User Miscellaneous MDF Transactional Displays the volume
work Permissions Data Volume of transactional data
available for a given
MDF object. Trans-
actional data refers
to the day-to-day
business data that's
available in a sys-
tem.
Platform Administration Admin Check Tool Allow Check Tool Allows users to fix
Quick Fix configuration and
data issues.
Platform Administration Admin Admin Alerts Access Admin Allows users to ac-
Alerts cess the admin
alerts tile.
Platform Administration Admin Admin Alerts Trigger Rerun Allows users to trig-
ger the rerun after
alerts have been
processed.
Platform Common Permis- Admin Admin Center Manage Upgrade Allows users to ac-
sions Permissions Center
cess the Upgrade
Administration Center where they
can enable various
features.
Platform Variance Report Admin Manage System Variance Report Allows users to use
Properties Variance Reporting.
Caution
This permission
is intended for
OData API ac-
cess only. It
shouldn't be a
prerequisite for
anything other
than authenti-
cating OData
API users.
Rewards and Rec- Spot Awards Admin Manage Spot Manage Spot Allows users to set
ognition Milestone Awards Awards Awards Program
up Spot Award Pro-
grams.
Note
This permission
is also needed
to allow users to
set up Mile-
stone Award
Programs.
Rewards and Rec- Spot Awards Admin Manage Spot Manage Spot Allows users to view
ognition Awards Awards Reports Spot Awards history
or budget informa-
tion reports.
Rewards and Rec- Spot Awards Admin Manage Spot Mass Upload for Allows users to cre-
ognition Awards Spot Awards ate a file to upload
a list of recipients to
award at one time.
Rewards and Rec- Spot Awards Admin Manage Manage Currency Allows users to cre-
ognition Compensation Compensation and Conversion Rate
ate and manage the
Compensation Varpay Tables
Forms currency exchange
rates you need.
Note
Import
Permission on
Metadata
Framework is
also required.
Rewards and Rec- Foundation Objects Admin Manage Pay component Allows users to ena-
ognition Foundation ble integration with
Objects Types Employee Central.
Rewards and Rec- Spot Awards User Miscellaneous Spot Award Allows users to view,
ognition Permissions edit, import, or ex-
port Spot Awards
for all target popu-
lation for reporting
purpose.
Rewards and Rec- Spot Awards User Miscellaneous Spot Award Allows users to view,
ognition Milestone Awards Permissions Program
edit, import, or ex-
port Spot Awards
Program, and all its
related field.
Note
Milestone
Award users
also need this
permission with
Visibility: View
and the target
group as Self.
Rewards and Rec- Spot Awards User Miscellaneous Spot Award Allows users to
ognition Permissions Redemption redeem awarded
points.
Rewards and Rec- Spot Awards User Miscellaneous Spot Award User Allows users to view
ognition Permissions Balance their balance of
awarded points.
Rewards and Rec- Spot Awards Admin Miscellaneous Refund Balance Allows users to view
ognition User Permissions and edit refunds
by redemption part-
ners.
Rewards and Rec- Spot Awards User Miscellaneous Spot Award Budget Allows user to cre-
ognition Permissions ate, insert, update,
delete, import, or
export Spot Awards
Budget for all target
populations.
Rewards and Rec- Milestone Awards User Miscellaneous MilestoneAward Allows users to
ognition Permissions view, edit, import,
or export Milestone
Awards, and all its
related field.
Rewards and Rec- Spot Awards User Miscellaneous Point Type Allows users to
ognition Milestone Awards Permissions view, edit, or create
the points used for
points-based award
programs.
Rewards and Rec- Spot Awards User Miscellaneous Wallet Allows users to
ognition Milestone Awards Permissions view, edit, or cre-
ate the wallet ac-
counts used for
points-based award
programs.
Rewards and Rec- Spot Awards User Miscellaneous OffCycleReporting Allows users to view,
ognition Milestone Awards Permissions edit, or create re-
ports for award pro-
grams.
Rewards and Rec- Spot Awards User Miscellaneous Redemption Option Allows users to
ognition Milestone Awards Permissions view, edit, or cre-
ate the redemption
options used with
points-based award
programs.
Rewards and Rec- Milestone Awards User Miscellaneous Milestone Program Allows users to view,
ognition Permissions edit, or create Mile-
stone Awards pro-
grams.
Rewards and Rec- Spot Awards User Miscellaneous Spot Award to EC Allows user to view,
ognition Permissions Integration Status edit, import, or ex-
port integration sta-
tus with EC.
Platform Intelligent Services Admin Intelligent Service Event Center Allows users to en-
Rewards and Rec- Integration Center Tools able Intelligent Serv-
ognition ices.
Calibration Calibration Ses- User Calibration Detailed Calibration Allows users to ac-
sions Permissions cess the calibration
sessions involving
employees within
their target popula-
tion.
Calibration Calibration Ses- User Calibration Manager Template Allow users to spec-
sions Permission for ify which Calibration
Creating Sessions templates managers
can access when
they create calibra-
tion sessions.
Calibration Calibration Ses- Admin Manage Manage Calibration Allows users to cre-
sions Calibration Sessions ate and manage cali-
bration sessions.
Calibration Calibration Settings Admin Manage Manage Calibration Allows users to con-
Calibration Settings figure Calibration.
Calibration Calibration Tem- Admin Manage Manage Calibration Allows users to cre-
plates Calibration Templates ate and manage Cal-
ibration templates.
Calibration Executive Review Admin Manage Manage Permission Allows users to ac-
Calibration for Executive cess and manage
Review the Executive Re-
view tab in Calibra-
tion.
Calibration Calibration Ses- Admin Manage Remove Subjects Allows users to ac-
sions Calibration from Calibration cess the Remove
Sessions Subjects from Cali-
bration Sessions ad-
min tool.
Goals Group Goals User Goals New Group Goal Allows users or
Creation groups the ability to
create group goals.
Goals Goal Management User Goals Target Population Select this permis-
sion to assign goal
permissions to the
user or the group
defined as the target
population.
Goals Team Goals User Goals Manage Team Goal Allows users to cre-
ate, edit, and delete
Team Goals.
Goals Goal Plans User Goals Goal Plan Choose which goal
Career Develop- Development Goals Permissions
plans users can ac-
ment cess.
Onboarding
Granting permis-
sions through roles
controls which tem-
plates users can
view, while tem-
plate-level permis-
sions control what
changes users can
make to a specific
template.
Goals Team Goals User Goals Assign Team Goals Allows users to as-
sign Team Goals to
other users.
Goals Team Goals User Goals Share Team Goals Allows users to
share Team Goals
with other users,
making those users
the coowners of the
Team Goals.
Goals Goal Import Admin Goals Import Goals Allows users to cre-
ate, edit, and delete
goals, using an im-
port file.
Goals Goal Management Admin Goals Goal Management Allows users to ac-
Feature Settings cess the page that
controls the feature
settings in Goals
Management.
360 Reviews Forms User General User Permission to Select the form tem-
Performance Man- Employee Profile Permission Create Forms plates along with
agement this permission to
allow users to cre-
Recruiting
ate forms of the se-
Onboarding
lected templates.
Recom-
mendation
For administra-
tors in Onboard-
ing, select All.
360 Reviews 360 Reviews Admin Manage Change 360 Allows users to
Documents Process Owner change the process
owner for a "Com-
pleted" or "In Prog-
ress" 360 review
form. The 360 proc-
ess owner is the
one who manages
the 360 evaluation
process.
360 Reviews 360 Reviews Admin Manage Change Participant Allows users to
Documents Category change the category
of a participant in
a "Completed" or
"In Progress" 360
review form.
360 Reviews 360 Reviews Admin Manage Complete/Decline Allows users to ei-
Documents 360 document ther push a 360 re-
view form to com-
pletion or decline
it on behalf of the
process owner.
360 Reviews 360 Reviews Admin Manage Restore Completed Allows users to
Documents 360 restore the "Com-
pleted" 360 review
forms.
360 Reviews Executive Review Admin Manage 360 Executive This permission and
Documents Review all the permissions
under it, enable a
user to manage 360
Executive Reviews.
Continuous Per- Continuous Feed- User Continuous Access Continuous Allows users to view
formance Manage- back Performance User Feedback the feedback they
ment Permission receive, and the
feedback received
by their direct re-
ports.
Continuous Per- Continuous Feed- User Continuous Give Continuous Allows users to give
formance Manage- back Performance User Feedback feedback to employ-
ment Permission ees included in the
target population.
Continuous Per- Continuous Feed- User Continuous Request feedback Allows users to
formance Manage- back Performance User from others send feedback re-
ment Permission quests to employ-
ees included in the
target population.
You also need to se-
lect the permission
"Limit about whom
feedback can be re-
quested.
Continuous Per- Continuous Feed- User Continuous Limit about whom Allows users to
formance Manage- back Performance User feedback can be request feedback
ment Permission requested about employees in-
cluded in the tar-
get population when
"Request feedback
from others" per-
mission is enabled.
For example, man-
agers can only
request feedback
about members of
their team.
Continuous Per- Continuous Per- User Continuous Other Topic Allows users to cre-
formance Manage- formance Manage- Performance ate, view, and edit
ment ment Management topics in Continu-
ous Performance
Management.
Continuous Per- Continuous Per- Admin Miscellaneous MDFEventsConfig Allows the admin-
formance Manage- formance Manage- Permissions istrator to enable
ment ment sharing of activi-
ties, achievements,
and feedback with
the Growth Portfolio
of the Talent Intelli-
gence Hub.
Continuous Per- Continuous Per- Admin Manage Access to Allows users to ac-
formance Manage- formance Manage- Continuous Administrative cess the Continuous
ment ment Performance Configuration page Performance Man-
agement configura-
tion page.
Continuous Per- Continuous Per- Admin Manage Admin Access Allows users to
formance Manage- formance Manage- User Continuous Permission to
access all Contin-
ment ment Performance all Continuous
uous Performance
Data Protection Performance
Management Data Management data in
and Privacy
Story reports for the
employees that are
included in their tar-
get population. This
permission is also
required for Data
Protection Officers
(DPO) for creating
and running a Data
Subject Information
report for given sub-
ject users.
Note
This is an Ad-
ministrator per-
mission, which
is bound by tar-
get population.
Continuous Per- Continuous Feed- Admin Manage Admin Access to Allows administra-
formance Manage- back Continuous Delete Continuous
tors to search
ment Data Protection Performance Feedback Page
for any user feed-
and Privacy
back, even feedback
to inactive users.
The administrator is
shown the feedback
date, giver name,
receiver name, feed-
back topic, but not
the content of the
feedback. The ad-
ministrator can de-
lete selected feed-
back from the em-
ployee's view.
Caution
Because dele-
tion of feedback
data is perma-
nent, this per-
mission has
been developed
for a role like
the Data Protec-
tion Officer. This
permission
must be limited
to ensure the
role has the
ability to carry
out feedback
deletion, since
deletion of feed-
back is perma-
nent.
Employee Central Admin Center Admin Manage Admin Access to Allows admins to
Integration Tools Data Replication use the 2.0 version
Monitor 2.0 of the Data Replica-
tion Monitor.
Employee Central Employee Central Admin Service Center Access Service Required for all
Service Center Center users. Enables Em-
ployee Central Serv-
ice Center (Ask HR)
application for ev-
eryone.
Employee Central Employee Central Admin Employee Central Select All Allows Ask HR ad-
Service Center API ministrators to ac-
cess Employee Cen-
tral entities.
Employee Central Employee Central Admin Manage Access to Business Allows administra-
Integration Tools Scenarios tors to replicate em-
ployee data from
Employee Central to
SAP Cloud for Cus-
tomer.
Employee Central Employee Central User General User User Login Allows users to log
Permission on to SAP Success-
Factors.
Employee Central Employee Central User Employee Central • Job Only View Current
Service Center Effective Dated level as this allows
Information
Entities employees to view
Actions
Ask HR tickets.
• Company
Employee Central Employee Central User Employee Data Employment Only View Current
Service Center Details MSS level as this allows
employees to view
Ask HR tickets.
Employee Central Employee Central User Miscellaneous Service Center View: Only for em-
Service Center Permissions Contact ployees
Information Edit and Import/
Export: Only for ad-
ministrators
Allows employees to
access Contact HR
information, in Ask
HR.
Employee Central Employee Central User Miscellaneous Service Center Required for all
Service Center Permissions Configuration users.
Allows administra-
tors to configure
the Ask HR land-
ing page and Create
Ticket page using
the Admin Center
Manage Data
Service Center
Configuration Ask
HR configuration
object.
Employee Central Employee Central Admin Admin Center Export Succession Allows users to
Permissions Data Model export Succession
Data Model.
Employee Central Employee Central Admin Admin Center Export Country/ Allows users
Permissions Region-Specific to export Country/
Succession Data Region-Specific
Model Succession Data
Model.
This permission is
also required for
users to be able
to view the history
page for Alternative
Cost Distribution.
Succession Succession Org User Succession Succession Org Allows users to ac-
Chart Planners Chart Permission cess the Succession
Org Chart and the
Lineage Chart if it's
enabled in your sys-
tem. The target pop-
ulation of employees
a user is able to view
in the organization
chart is determined
by the Succession
Management and
Matrix Report Per-
missions.
Succession Talent Search User Succession Talent Search Allows users to ex-
Planners Export Permission port Talent Search
results. The fields in
the results are con-
trolled by the Talent
Search Field permis-
sion.
Succession Matrix Grid Reports User Succession Matrix Report Allow users to
Planners Permission view the Perform-
ance-Potential and
How vs What tabs.
Succession Position Tile View User Succession Position Tile Access Only available with
Planners the MDF Position-
based nomination
method, this per-
mission allows users
to access the Posi-
tion Tile view.
Succession Position Tile View User Miscellaneous Position Allows users to view
Employee Central MDF Positions Permissions
the current state of
Position Manage- the position and/or
ment
to view its history.
Succession Talent Pools User Succession Hide Talent Pool Prohibits roles from
Planners Page accessing the Talent
Pool tab from other
Succession features
and People Profile.
Succession Talent Pools Admin Manage Talent Pool Field Allows roles to ac-
Succession Configuration cess the Manage
Talent Pool Field
Settings admin tool.
Succession Matrix Grid Reports Admin Manage How vs. What Allows roles to con-
Succession Configuration figure the rating
sources, labels, and
colors of How vs.
What matrix grid re-
ports.
Succession Matrix Grid Reports Admin Manage Matrix Grid Rating Allows roles to mod-
Succession Scales ify the rating scales
used for matrix grid
reports and overall
ratings in the Em-
ployee Profile.
Succession Matrix Grid Reports Admin Manage Performance- Allows roles to con-
Succession Potential figure the rating
Configuration sources, labels, and
colors of Perform-
ance-Potential ma-
trix grid reports.
Succession MDF Positions Admin Manage Sync Position Allows roles to syn-
Succession Model chronize the posi-
tion model with Em-
ployee data.
Succession Position Model Admin Manage Position import & Allows roles to im-
Succession export port and export po-
sition model data
if they use the leg-
acy position-based
nomination method
for succession plan-
ning.
Succession Position Model Admin Manage Position Set up Allows roles to set
Succession position model op-
tions if they use
the legacy position-
based nomination
method for succes-
sion planning.
Platform Talent Card User Employee Data Employee Profile Allow users to view
Succession Spot Awards or edit employee
Career Develop- Mentoring data in People Pro-
ment Succession file.
Rewards and Rec- Employee Profile
ognition Items under the
Employee Profile
permission corre-
spond to the fields
defined by Standard
Elements in the Suc-
cession Data Model.
Platform Talent Card User Employee Data Background Allows users to view
Succession Spot Awards or edit background
Career Develop- Mentoring and trend informa-
ment Succession tion blocks in People
Rewards and Rec- Employee Profile Profile.
ognition
Platform Talent Card User Employee Data User Information Allow users to view
Succession Spot Awards or edit employee
Career Develop- Mentoring data in People Pro-
ment Succession file.
Rewards and Rec- Employee Profile
ognition Items under the
User Information
permission corre-
spond to the fields
defined by User Info
Elements in the Suc-
cession Data Model.
To enable users to
add, edit, or de-
lete talent pool nom-
inations, assign at
least the object-level
permission to View
Current talent pools.
Succession Talent Pools User Succession View Talent Pool This permission re-
Planners Nominations
quires that users
also have the
object-level permis-
sion to view tal-
ent pools under
Miscellaneous
Permissions
Talent Pool
Visibility: View
Current .
Using a setting on
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina-
tions permissions to
further control ac-
cess.
Using a setting on
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina-
tions permissions to
further control ac-
cess.
Using a setting on
the Nominations Set
Up admin page, you
can apply target
population to the
talent pool nomina-
tions permissions to
further control ac-
cess.
Platform MDF Positions Admin Metadata Configure Business Allows users to cre-
Succession Talent Pools Framework Rules
ate, edit, and exe-
Rewards and Rec- Spot Awards cute business rules
ognition MDF in their SAP Suc-
Employee Central Rules cessFactors system.
Onboarding 1.0
Onboarding
Platform MDF Positions Admin Metadata Import Permission Allows users to im-
Succession Talent Pools Framework on Metadata port data related
Framework to the Metadata
Employee Central Business Configu-
Framework.
Onboarding ration UI
MDF
Rules
Platform MDF Positions Admin Metadata Manage Sequence Allows users to ac-
Succession Talent Pools Framework
cess required proc-
Employee Centrall MDF esses related to
Onboarding Rules MDF objects.
Succession Talent Card Admin Manage Talent Manage Talent Card Allows users to ac-
Calibration Presentations Card Configuration cess the Manage
Talent Card admin
Platform
tool where they can
configure the layout
and content of the
talent cards used in
the system.
Succession Talent Search Admin Manage System Talent Search Allows users to
Properties Management access the Talent
Search Settings ad-
min tool.
Platform Email and Notifica- Admin Manage System Email Notification Allows users to con-
Compensation tions Properties Templates Settings figure email notifi-
cations for certain
workflow events.
Platform User Management Admin Manage User Change Assignment Allows the Ad-
ID min to change
assignment ID us-
ing the convertAs-
signmentIdExternal
function import.
Platform User Management Admin Manage User Manage Login Allows the Admin to
Accounts access the Manage
Login Accounts tool.
Platform User Management Admin Manage User Basic User Import When the "Enable
Control on Basic
User Import in
Role-Based Permis-
sions"option has
been enabled, this
permission allows
the Admin to per-
form basic user im-
port in the Employee
Central-enabled in-
stances.
Succession Talent Search User Talent Search Field Talent Search Field Select which fields
to make available
to the role when
performing a talent
search.
Succession Succession Org User Learning Learning Access Allows users to ac-
Chart Permission cess Learning.
Succession MDF Positions Admin Manage Import Foundation Allows users to im-
Employee Centrall Employee Central Foundation Data
port foundation ob-
Objects
jects.
Platform Menring Admin Manage User Manage Employee Allows users create
Career Develop- Dynamic Groups employee dynamic
ment groups.
Platform Search User General User Company Info Allows users access
Employee Centrall Absence Manage- Permission Access to the Company Info
ment page, where they
Employee Central
can access the or-
Payroll
ganization chart and
employee directory.
This permission
does not apply to
some search func-
tions necessary to
perform specific ac-
tions, such as sys-
tem administration
tasks.
Note
Grant this per-
mission to a tar-
get population
of Everyone to
enable use of
the feedback
features.
Platform Search User General User Perform Batch Allows users to per-
Permission Operations on the
form batch opera-
Results of Directory
tions: sending email
Search: Export,
Print, and Send to, exporting, or
Email printing the selected
results.
Platform Employee Profile Admin Manage Hires Include Inactive Allows users to ac-
Onboarding Search Employees in the
cess the date of new
search
hires and search for
inactive users on the
People Profile and
Directory Search.
Note
This permission
can’t be re-
stricted to a tar-
get population
and is granted
to everyone in
the permission
role.
This permission
does not impact
behavior of the
People Search
in the global
page header,
which is control-
led by a com-
pany-level con-
figuration set-
ting and not by
role-based per-
missions.
Career Develop- Career Develop- Admin Manage Career Development Allows users to
ment ment Development Admin manage all features
in Career Develop-
ment.
Career Develop- Development Goals User Career Career Allows users to ac-
ment Career Worksheet Development Development Plan cess Development.
Planning (CDP) Access
Learning Activity
Permission Note
This permission
is a prerequisite
for Career
Worksheet and
Suggested
Roles permis-
sions.
This permission
is required for
adding, updat-
ing, and delet-
ing learning ac-
tivities.
Career Develop- Development Goals Admin Manage Career Manage User's Allows users to view
ment Development Development Goals and edit the devel-
opment goals of
a selected user in
their target popula-
tion.
Career Develop- Career Worksheet User Career Career Worksheet Allows users to ac-
ment Development Access Permission cess the Career
Planning Worksheet tab un-
der Development.
Career Develop- Career Worksheet Admin Manage Career Manage Suggested Allows users to de-
ment Development Roles fine the criteria
and corresponding
weight that the sys-
tem uses to gener-
ate a list of sug-
gested roles for em-
ployees.
Career Develop- Career Worksheet User Career Career Worksheet Allows users to ac-
ment Development Suggested Roles cess the Suggested
Planning Access Permission Roles tab in Career
Worksheet.
Career Develop- Career Path Admin Manage Career Manage Career (For Career Path V1)
ment Development Path
Allows users to cre-
ate a career path
for each job fam-
ily, either manually
by adding lead-from
and lead-to roles
or by importing a
csv file, in Manage
Career Path.
Career Develop- Career Path Admin Manage Career Configure Career (For Career Path V2
ment Development Path Node
only) Allows users to
specify the informa-
tion to be displayed
on a career path
node, for example,
the number of com-
petencies, skills, and
talent pools for that
role.
Career Develop- Career Path User Miscellaneous Career Path Select the View and
ment Permissions Edit options you
want to assign to the
role.
Career Develop- Learning Activity Admin Manage Career Manage Learning (For legacy learning
ment Development Activity Catalogs activities only) Al-
lows users to cre-
ate multiple learn-
ing activities by im-
porting learning ac-
tivity catalogs in
csv files through
Manage Learning
Activity Catalogs.
Career Develop- Learning Activity Admin Manage Career Manage Learning (For legacy learning
ment Development Activity to activities only) Al-
Competency lows users to de-
Mappings fine the mappings
between competen-
cies and learning
activities by im-
porting csv files
through Manage
Learning Activity
to Competency
mappings.
Career Develop- Learning Activity Admin Manage Career Mapping Learning (For legacy learn-
ment Development Activities to ing activities only)
Competencies Allows users to
manually map
the learning activi-
ties to the availa-
ble competencies
through Mapping
Learning Activities to
Competencies.
Career Develop- Learning Activity Admin Manage Career Import Learning (For Transcript with-
ment Development Activity by Web out SAP Success-
service Factors Learning
only) Allows users to
import learning ac-
tivities.
Career Develop- Learning Activity Admin Manage Career Import User (For Transcript with-
ment Development Relationship out SAP Success-
for Learning Factors Learning
Administrator only) Allows users
and Educational to access the import
Representative page for assigning
learning administra-
tors and educational
representatives to
employees.
Career Develop- Learning Activity User Career Career (For Transcript with-
ment Development Development Plan out SAP Success-
Planning (CDP) Learning Factors Learning
Activity Mass Add only) Allows users
to assign learning
activities to employ-
ees.
Career Develop- Mentoring Admin Manage Career Manage Mentoring Allows users to
ment Development Programs create and man-
age mentoring pro-
grams.
Note
If users without
this permission
are assigned as
the owner of a
mentoring pro-
gram, they can
view and man-
age this pro-
gram only.
Note
To be able to ac-
cess Mentoring,
users must have
been invited to
a mentoring
program. Other-
wise, the tab
isn’t available
still.
Career Develop- Mentoring User General User Community Access If you plan to in-
ment Permission tegrate mentoring
programs with SAP
Jam, this permis-
sion allows users to
access SAP Jam.
Analytics Story Reports Admin Manage Career View Mentoring Allows users to view
Career Develop- Mentoring Development Data in Story mentoring data in
ment Reports Story reports.
Career Develop- Career Explorer Admin People Connection Manage People Allows users to
ment Connection access Manage
Integration People Connection
Integration to con-
figure settings for
using Career Ex-
plorer.
Career Develop- Career Explorer User Career Career Explorer Allows users to ac-
ment Development cess the Career
Planning Explorer tab under
Development and
use the feature for
their own career op-
portunities.
Career Develop- Career Explorer User Career View User's Career Allows users to view
ment Development Opportunities in the recommended
Planning Career Explorer job roles and career
paths of a selected
user in their target
population in Career
Explorer.
Career Develop- Career Develop- Admin Manage Career Admin Career Allows users to run
ment ment Development Development Plan the Data Privacy and
Export Data Protection Informa-
tion Report on the
data of Career De-
velopment.
Performance Man- Forms Admin Manage Approve Document Allows users to ac-
agement Documents cess the admin tools
to complete the cur-
rent step of a form
in the Modify stage
and move the form
to the next step.
Performance Man- Forms Admin Manage Change Document Allows users to ac-
agement Documents Date cess the admin tools
to change the form
start date, end date,
and due date on an
in progress form.
Performance Man- Forms Admin Manage Admin Access to Allows users to ac-
agement Documents Forms OData API cess Performance
Management using
the web client. This
permission must be
enabled for both
employee and man-
ager roles.
Performance Man- Forms Admin Manage Delete Documents Allows users to ac-
agement Documents cess the admin tools
to delete forms from
the system.
Performance Man- Forms Admin Manage Import Overall Allows users to ac-
agement Documents Scores Only for cess admin tools
Target Population to update manual
overall scores on
the forms through
an import for target
population.
Performance Man- Forms Admin Manage Include All Allows users to ac-
agement Documents Employees cess admin tools
to update manual
overall scores on the
forms through an
import for all em-
ployees.
Performance Man- Forms Admin Manage Manage Document Allows users to re-
agement Documents Visibility move or restore
document visibility.
Performance Man- Forms Admin Manage Mass Route Allows users to cre-
agement Documents Document Forward ate and distribute
multiple instances
of the same form at
once, and to route
the form forward in
the workflow.
Performance Man- Forms Admin Manage Mass Route Allows users to cre-
agement Documents Document ate and distribute
Compensation Backward multiple instances
of the same form at
once and to route
the form backward
in the workflow.
Performance Man- Forms Admin Manage Modify Form Route Allows users to add,
agement Documents Map reorder, or remove
routing steps of the
workflow of a form.
Allow Adding of a
Step allows users to
access the admin
tools to add a step in
the route map.
Performance Man- Forms Admin Manage Include Completed Allows users to ac-
agement Documents Documents cess the admin tools
to route completed
forms.
Performance Man- Forms Admin Manage Sign Document Allows users to sign
agement Documents a form in the signa-
ture stage and move
the form to the next
person who will sign
the form.
Performance Man- Route Maps Admin Manage Form Routing Maps Allows users to cre-
agement Templates ate route maps
360 Reviews and modify existing
route maps.
Compensation
Performance Man- Rating Scales Admin Manage Form Rating Scales Allows users to cre-
agement Templates ate rating scales and
360 Reviews modify existing rat-
ing scales.
Compensation
Performance Man- Forms Admin Manage Form Export Performance Allows users to ex-
agement Templates Management Form port Performance
Data Management form
data through API.
Performance Man- Forms Admin Manage Form Schedule Mass Allows users to
agement Templates Form Creation schedule mass cre-
360 Reviews (Launch forms ation of forms at a
later) later time and date.
Performance Man- Forms Admin Manage Form Mass Create Form Allows users to
agement Templates Instances (Launch launch forms in bulk
360 Reviews forms now) immediately.
Performance Man- Forms Admin Manage Form Comprehensive Allows users to con-
agement Templates template figure and edit the
configuration for fields in the ad-
PMv12 vanced options sec-
tion of Performance
Management forms.
Performance Man- Forms Admin Manage Form Form Templates Allows users to
agement Templates create, edit, and
360 Reviews enable/disable Per-
formance Manage-
Compensation
ment form tem-
plates.
Performance Man- Notes User General User Permission to Allows users to cre-
agement Employee Profile Permission Create Notes ate notes in People
Platform Profile.
Performance Man- Forms User Performance Restrict Data Restricts users from
agement Access of Inactive accessing data of
Users' Forms inactive users' Per-
formance Manage-
ment forms.
Performance Man- Team Overview User Performance Team Overview Allows users to ac-
agement Access cess Team Overview.
Performance Man- Story Report User Performance Data Access: Story Controls what data
agement users can see when
Reporting they run a report
built using the Per-
formance schema.
Allows users to view
the Performance-re-
lated data only for
the employees in-
cluded in their tar-
get population.
Note
The Data
Access: Story
permission be-
comes available
after you've en-
abled the
Admin Center
Performance
Management
Settings
Enable
Performance
Management
Access
Permission
setting.
Compensation Forms Admin Manage Manage Salary Pay Allows users to add
Compensation Matrices and edit salary pay
matrix associated
with the plan tem-
plates.
Compensation Forms Admin Manage Manage Plan Level Allows users to ac-
Compensation and Executive Review cess the manage
Varpay Filters plan-level Executive
Review filters.
Compensation Report Center Admin Manage Migrate Data for Allows users to mi-
Table Report Compensation and Story grate data from
Varpay forms that can be
used in the creation
of Report - Stories.
Compensation Forms Admin Manage Add Edit Stock Allows users to cre-
Compensation History
ate stock history pe-
riods.
Compensation Executive Review User Compensation and Executive Review Allows users to ac-
Variable Pay Read - cess Compensation
Compensation Executive Review
with Read privileges.
Compensation Executive Review User Compensation and Executive Review Allows users to ac-
Variable Pay Edit - cess Compensation
Compensation Executive Review
with Edit privileges.
Compensation Executive Review User Compensation and Executive Review Allows users to ex-
Variable Pay Export - port Executive Re-
Compensation view and Hierarchy-
based approvals for
compensation plan
templates.
Compensation Executive Review User Miscellaneous CompFilterDefinitio Allows the user Vis-
Permissions n ibility: View and Ac-
tions: Edit for end-
user data saved
in the Metadata
Framework (MDF)
when using en-
hanced Executive
Review filters.
Compensation Executive Review User Miscellaneous CompFilterPopulati Allows the user Vis-
Permissions on ibility: View and Ac-
tions: Edit for end-
user data saved
in the Metadata
Framework (MDF)
when using en-
hanced Executive
Review filters.
Compensation Lookup Tables Admin Compensation and Lookup Table Allows access to
Variable Pay Access specific lookup ta-
bles. The global ad-
ministrator is able
to decentralized
permissions to des-
ignate local admin-
istrators permission
to update lookup ta-
bles only for the
scope of their du-
ties.
Platform Table Reports (for- User Reports Create Report Allows users to cre-
Compensation merly Ad Hoc Re- Permission
ate and edit reports
ports)
for all specific mod-
ules.
• Compensation
Eligibility
• Compensation
Planning
• Compensation
Hierarchy-
based Appro-
vals
Platform Table Reports (for- User Reports Run Report Allows users to run
Compensation merly Ad Hoc Re- Permission
existing reports for
ports)
all or certain report
types.
• Compensation
Eligibility
• Compensation
Planning
• Compensation
Hierarchy-
based Appro-
vals
Compensation Executive Review User Compensation Executive Review Allows users to ac-
Mass Action cess Compensation
Permission Executive Review
with Mass Action
privileges.
Variable Pay Forms Admin Manage Variable View All VarPay Allows Admins to
Pay Manager Forms view launched Varia-
ble Pay Forms for all
Planners in Manage
Worksheet.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to cre-
Pay Pay Programs ate and manage Var-
iable Pay programs
from Compensation
Home.
Variable Pay Forms Admin Manage Variable Manage Employee Allows users to ac-
Pay Data for Employees cess all employee
data that includes
target population.
For example, em-
ployee history, bo-
nus calculation.
Variable Pay Forms Admin Manage Variable Run Variable Pay Allows users to run
Pay Processor processor for Varia-
ble Pay jobs.
Variable Pay Forms Admin Manage Variable Store Varpay Data Allows users to pub-
Pay in Employee Central lish Variable Pay
data in Employee
Central.
Variable Pay Forms Admin Manage Variable Employee Central Allows users to ac-
Pay Settings cess the Employee
Central Settings
page of plans from
Plan Setup
Variable Pay Forms Admin Manage Variable Set Bonus Allows users to ac-
Pay Calculation cess and set bonus
calculations from
Plan Setup.
Variable Pay Forms Admin Manage Variable Set Number Format Allows users to de-
Pay Rules fine rules to control
the display of the
number formats.
Variable Pay Forms Admin Manage Variable Configure Label Allows users to cus-
Pay Names and tomize the look
Visibility and feel of the
worksheets by mod-
ifying the label
names from Design
Worksheet.
Variable Pay Forms Admin Manage Variable Column Designer Allows users to
Pay modify worksheet
columns, rollup re-
port filed labels,
navigation tab la-
bels, budget field la-
bels and set custom
view links.
Variable Pay Forms Admin Manage Variable Set Number Allows users to cus-
Pay Formats tomize the display of
the number formats.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to ac-
Pay Pay Guidelines cess team and indi-
vidual guidelines.
Variable Pay Forms Admin Manage Variable Summary Allows users to ac-
Pay cess the summary
information page in
plan templates. This
is a default page,
which is visible
when you choose a
plan.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to ac-
Pay Pay Settings cess the Settings
tab from Plan Setup
for plan templates.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to ac-
Pay Pay Display cess the Display
Settings Settings tab from
Plan Setup for plan
templates.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to ac-
Pay Pay Budget cess the settings
for the budget from
Plan Details.
Variable Pay Forms Admin Manage Variable Define Planners Allows users to
Pay choose planners for
the plan from a hier-
archy of employees
from Manage Users.
Variable Pay Forms Admin Manage Variable Override Allows users to ac-
Pay Permission cess the menu link
on worksheets to
choose which user
can override the
calculated bonus
amount.
Variable Pay Forms Admin Manage Variable Live Profile Visibility Allows users to ac-
Pay cess the Live Pro-
file Visibility menu
link, which lets users
hide or display live
profiles.
Variable Pay Forms Admin Manage Variable Validation Reports Allows users to
Pay access all the re-
port types from
Validation Reports.
Variable Pay Forms Admin Manage Variable Import Business Allows users to im-
Pay Goals port business goals.
Variable Pay Forms Admin Manage Variable Export Business Allows users to ex-
Pay Goals port business goals.
Variable Pay Forms Admin Manage Variable Import Bonus Plans Allows users to im-
Pay port bonus plans.
Variable Pay Forms Admin Manage Variable Export Bonus Plans Allows users to ex-
Pay port bonus plans.
Variable Pay Forms Admin Manage Variable Configure Bonus Allows users to cre-
Pay Plans ate and manage bo-
nus plans.
Variable Pay Forms Admin Manage Variable Import Business Allows users to im-
Pay Goal Weights port business goal
weights.
Variable Pay Forms Admin Manage Variable Export Business Allows users to ex-
Pay Goal Weights port business goal
weights.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to set
Pay Pay Eligibility eligibility rules.
Variable Pay Forms Admin Manage Variable Import Employee Allows users to
Pay History from transfer employees
Employee Central information from
Employee Central
to Variable Pay pro-
grams.
Variable Pay Forms Admin Manage Variable Import Employee Allows users to im-
Pay History port employee his-
tory data.
Variable Pay Forms Admin Manage Variable Export Employee Allows users to ex-
Pay History port employee his-
tory data.
Variable Pay Forms Admin Manage Variable Edit Employee Allows users to
Pay History change employee
information, includ-
ing import and ex-
port options from
Manage Users.
Variable Pay Forms Admin Manage Variable Bonus Payout Allows users to cal-
Pay culate bonus for all
or for some employ-
ees in the plan.
Variable Pay Forms Admin Manage Variable Manage Variable Allows users to
Pay Pay Forms launch, create, and
manage worksheets
form Compensation
Home.
Variable Pay Forms Admin Manage Variable Update Variable Pay Allows users to up-
Pay Forms for Template date all worksheets
together from
Manage Worksheets.
Variable Pay Forms Admin Manage Variable Update Variable Pay Allows users to up-
Pay Worksheets date specific work-
sheet data from
Manage Worksheets.
Variable Pay Forms Admin Manage Variable Variable Pay Form Allows users to add,
Pay Membership move, or delete em-
ployees from Varia-
ble Pay forms.
Variable Pay Forms Admin Manage Variable Plan Activity Audit Allows users to ac-
Pay cess Plan Activity
Audit option from
Manage Worksheets.
Variable Pay Statements Admin Manage Variable Generate Goal Allows users to
Pay Statements download goal
statements.
Variable Pay Statements Admin Manage Variable Generate Bonus Allows users to cre-
Pay Assignment ate bonus assign-
Statements ment statements.
Variable Pay Statements Admin Manage Variable Recall Bonus Allows users to re-
Pay Assignment call bonus assign-
Statements ment statements.
Variable Pay Statements Admin Manage Variable Download Bonus Allows users to
Pay Assignment download bonus
Statements assignment state-
ments.
Variable Pay Statements Admin Manage Variable Manage Bonus Allows users to link
Pay Assignment employee groups to
Statement bonus assignment
Templates statements.
Variable Pay Forms Admin Manage Variable Manage Bonus Allows users to cre-
Pay Forecasting ate and manage bo-
nus forecasting for
plan templates.
Variable Pay Statements User Employee Views Bonus Assignment Allows users to
Employee Profile Statement view Bonus Assign-
ment Statement
Block in People Pro-
file or view the
Bonus Assignment
Statement tab in
People Profile.
Variable Pay Statements User Employee Data Bonus Assignment Allows users to view
Statements generated bonus
assignment state-
ments in an RBP-en-
abled instance.
Variable Pay Statements User Employee Views Variable Pay Allows users to view
Employee Profile Statement the Variable Pay
Statements block in
People Profile or
view the Variable
Pay Statements tab
in People Profile.
Variable Pay Executive Review User Compensation and Executive Review Allows users to ac-
Variable Pay Edit - Variable Pay cess Executive Re-
view with Edit privi-
leges.
Variable Pay Executive Review User Compensation and Executive Review Allows users to ac-
Variable Pay Read - Variable Pay cess Executive Re-
view with Read priv-
ileges.
Variable Pay Executive Review User Compensation and Executive Review Allows users to ex-
Variable Pay Export - Variable port Executive Re-
Pay view and Hierarchy-
based approvals for
Variable Pay plan
templates.
Variable Pay Executive Review Admin Manage Access to Allows users to ac-
Integration Center Integration Tools Integration Center cess the Integration
Center Builder tool
to turn on notifica-
tion configuration.
Employee Central Employee Data Im- Admin Employee Central Enable Workflows You can configure
port Import Settings for selected entities the system to trig-
ger approval work-
flows with all the
entities associated
with the permission
by default. Choose
Others to manually
select applicable en-
tities from the op-
tion box.
Employee Central Employee Data Im- Admin Employee Central Enable Business Allows users to
port Import Settings Rules for selected trigger business
entities rules onSave and
onChange when im-
porting employees'
data such as com-
pensation, termina-
tion details, and per-
sonal information.
Platform Employee Data Im- Admin Manage User Allow users to Allows users to
Employee Central port view all the jobs. track all import jobs
(By Disabling this performed by users.
option, users can
view only their job
status.)
Platform Employee Data Im- Admin Manage User Enable RBP Access Allows users to ena-
Employee Central port Validation for EC ble the RBP access
Elements during during imports.
Imports (Do not
enable during first
time import)
Employee Central Employee Data Im- User Employee Central Job History Allows users to per-
port Import Entities form or restrict im-
ports for Job Infor-
mation.
Employee Central Employee Data Im- User Employee Central Compensation Info Allows users to per-
port Import Entities form or restrict im-
ports for compensa-
tion information.
Employee Central Employee Data Im- User Employee Central Pay Component Allows users to per-
port Import Entities Non Recurring form or restrict im-
ports for pay com-
ponent recurring in-
formation.
Employee Central Employee Data Im- User Employee Central Job Relationships Allows users to per-
port Import Entities form or restrict im-
ports for job re-
lationship informa-
tion.
Employee Central Employee Data Im- Admin Employee Central Enable execution
port Import Settings of rules against
NO_OVERWRITE
Employee Central Employee Data Im- Admin Employee Central Enable Forward You can configure
port Import Settings Propagation during the system to up-
Incremental Import date the future re-
cords with a pre-
ceding value when
you insert records in
incremental mode.
All the entities as-
sociated with the
permission will be
applicable by de-
fault. Choose Others
to manually select
applicable entities
from the option box.
Employee Central Employee Data Im- Admin Employee Central Support cumulative You can configure
port Import Settings update of country/ the system to retain
region-specific data existing country/re-
for global gion-specific data in
information import the Employee Pro-
in full purge mode files while importing
global information in
full purge mode.
Employee Central Employee Data Im- Admin Manage User Basic User Import Only when you've
port enabled the Enable
Control on Basic
User Import in Role-
Based Permissions
option in Manage
Employee Central
Settings, will the
Basic User Import
permission be re-
quired for admins
to perform basic im-
port.
Employee Central Employee Central User Miscellaneous Service Center Select country to
Permissions Configuration enable catalogs to
view information
specific to your ge-
ography.
Employee Central Time Off User Time Management Create Payouts in Allows users to re-
Absence Manage- User Permissions Self-Service quest a cash payout
ment charged against the
time balance on eli-
gible time accounts.
Platform User Management Admin Manage Data Create Legacy Data Allows users to cre-
Employee Central Employee Data Purge Purge Request
ate purge requests
Management using a legacy purge
Employee Data Im-
request type.
port
Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.
Platform User Management Admin Manage Data Manage and Allows users to
Employee Central Employee Data Purge Approve Legacy
approve purge re-
Management Data Purge Request
quests that use
Employee Data Im-
a legacy purge re-
port
quest type.
Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.
Platform User Management Admin Manage Data Remove Preview Allows users to de-
Employee Data Purge and Complete
lete old purge re-
Management Reports for Legacy
ports for legacy
Data Purge Request
Employee Data Im-
purge requests.
port
Note
Legacy purge
requests do not
consider the
configured data
retention times
used for Data
Protection and
Privacy.
Employee Central Apprentice Man- Admin Manage On-Site Supervisor Allows on-site su-
agement Apprentice pervisors to manage
apprentice data.
Employee Central Apprentice Man- User Apprentice Apprentice Group Allows apprentice
agement Management supervisors to view
Permissions and edit apprentice
group.
Employee Central Apprentice Man- User Apprentice Apprentice Internal Allows apprentice
agement Management Training supervisors to view
Permissions and edit apprentice
internal training.
Employee Central Apprentice Man- User Apprentice Apprentice On-the- Allows apprentice
agement Management job Training supervisors to view
Permissions and edit apprentice
on-the-job training.
Employee Central Apprentice Man- User Apprentice Apprentice School Allows apprentice
agement Management supervisors to view
Permissions and edit apprentice
school.
Employee Central Apprentice Man- User Apprentice Apprentice School Allows apprentice
agement Management Event supervisors to view
Permissions and edit apprentice
school event.
Employee Central Apprentice Man- User Employee Views Apprentice Allows apprentice
agement supervisors to view
Employee Profile apprentices in the
Employee Views sec-
tion.
Employee Central Apprentice Man- User MDF Foundation Department Allows apprentice
agement Objects supervisors to con-
figure the MDF foun-
dation object De-
partment used in
Apprentice Manage-
ment.
Employee Central Employee Central User MDF Foundation Business Unit Select the Visibility
Objects Cost Center and Actions permis-
Division sions you want to
Department assign to the role.
Location
Legal Entity
Employee Central Global Assign- User Employee Data Global Assignment You can assign field-
ments Details
level permissions as
well as permissions
for block as well
add, edit, delete ac-
tions.
Note
Make sure that
you have Edit
permission for
Global
Assignment
Details in the
HR Information
section.
Employee Central Concurrent Em- User Employee Data Employment New Assignment
Onboarding ployment Details
Company provides
Data Replication field-level permis-
Monitor
sion for the com-
pany field. This is
required for Concur-
rent Employment.
Change primary
employment allows
users to change the
employment classi-
fication of an em-
ployee.
Add new
Employment allows
users to add multi-
ple employments.
Navigation Group
(View) allows users
to see the group-
ing of URLs added
in the Take Action
menu for employees
whose system of re-
cord is the ERP sys-
tem and whose data
is replicated to Em-
ployee Central. The
permission is used
in UI integration of
ERP screens with
Employee Central.
Navigation Group
Entry in Take Action
Menu (Edit) allows
users to select
the URLs added
in the Take Action
menu for employees
whose system of re-
cord is the ERP sys-
tem and whose data
is replicated to Em-
ployee Central. The
permission is used
in UI integration of
ERP screens with
Employee Central.
Employee Central Deductions Admin Manage Create One Time Allows users to cre-
Deductions Deduction ate a non-recurring
deduction.
Employee Central Deductions Admin Manage Edit One Time Allows users to edit
Deductions Deduction a non-recurring de-
duction.
Employee Central Deductions Admin Manage View One Time Allows users to view
Deductions Deduction a non-recurring de-
duction.
Employee Central Deductions User Miscellaneous Recurring Select the View and
Permissions Deduction
Edit permissions
you want to assign
to the role.
Note
Make sure that
the Security
field for
Miscellaneous
Permissions is
set to Yes in the
object definition
for Recurring
Deduction.
Employee Central Employee Central User Employee Data Report No-Shows Select the View and
Onboarding Edit permissions
you want to assign
to the role.
Report No-Shows
if they do not show
up on their starting
date with the com-
pany.
Employee Central Compensation User Employee Data Pay Components Select the View and
Edit permissions
you want to assign
to the role.
Comp Info .
Employee Central Compensation User Employee Data Pay Component The View permis-
Groups
sion allows the user
to see the pay
component group
in the system,
for example, on
the Employment
Information page.
Employee Central Compensation Admin Manage Pay Scale Manage Pay Scale Allows users to ac-
Objects
cess to the Manage
Pay Scale Objects
action in the Admin
Center.
Employee Central Compensation Admin Manage Pay Scale Adjust Employees’ Controls access to
Compensation to the pay scale pay in-
Tariff Changes crease run.
Employee Central Compensation User Employee Central Pay Scale Area Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Pay Scale Type Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Pay Scale Group Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Pay Scale Level Select the View and
Effective Dated Edit permissions
Entities you want to assign
to the role.
Employee Central Compensation User Employee Central Range Penetration Select the View and
Effective Dated
Edit permissions
Entities
you want to assign
to the role.
View permission is
required if you en-
able the compensa-
tion widgets.
Employee Central Compensation User Employee Central Compa Ratio Select the View and
Effective Dated
Edit permissions
Entities
you want to assign
to the role.
View permission is
required if you en-
able the compensa-
tion widgets.
Employee Central Compensation Admin Manage User Configure Charts Enables admins to
for Key Figures
use widgets in
in Compensation
the Employment
Portlet
Information page.
This permission is
obsolete and should
not be selected.
Employee Central Compensation User Employee Widgets Total Compensation This permission is
History
for the widget to
show the wage pro-
gression for an em-
ployee.
Employee Central Compensation User Employee Widgets Salary Positioning Enables the widget
to show the employ-
ee's salary in re-
lation to the pay
range.
Employee Central Compensation User Employee Widgets Salary vs. Team Enables the widget
to show salaries
for employees and
their same-level col-
leagues.
Platform MDF User MDF Foundation Currency Exchange Select the Visibility
Objects Rate
and Actions permis-
sions you want to
grant the role.
Employee Central Employee Central Admin Manage System Employee Central Allows admins to
Properties Feature Settings turn on Employee
Central features
themselves without
having to request
help from Product
Support.
Employee Central Alternative Cost User Miscellaneous Alternative Cost Select the View and
Distribution Permissions Distribution
Edit permissions
you want to assign
to the role.
Note
Make sure that
the Security
field for
Miscellaneous
Permissions is
set to Yes in the
object definition
for Alternative
Cost Distribu-
tion.
Platform Employee Central User Employee Data HR Information Allows users to view
Employee Central Pension Payouts or edit some entities
Onboarding in Employee Central.
Pension Payout
Details
Employment
Information Take
Action Add
Pension Payout
Details .
Note
Global Assign-
ments and Pen-
sion Payouts
must be active
in your system
before you can
grant the per-
missions.
If the Create
or Delete Pay
Components Using
Business Rules
Without Additional
Permission Check
setting is selected,
then there’s no ad-
ditional check for
pay components
created from busi-
ness rules.
Employee Central Employee Central User Employee Data HR Actions Select the View and
Edit permissions
you want to assign
to the role.
Employee Central Employee Central User Employee Views Employee Views Allows users to
Employee Profile Section view the sections
in People Profile.
Each item under
the Employee Views
Section permission
corresponds to a
section in People
Profile. An item is
automatically listed
under the permis-
sion category after
you create a section.
Employee Central Employee Central User Employee Central Personal You can set
Employee Central Employee Central Effective Dated Information field-level permis-
Payroll Payroll Entities Addresses sions for effective-
Dependents
dated blocks and
Job Information
fields. This also
Compensation
includes country/re-
Information
gion-specific fields
Job Relationships
that are prefixed
by the 3-letter ISO
code (for example,
FRA for France, DEU
for Germany, and so
on).
• View Current:
The entity is
visible but not
the History.
• View History:
Allows read-
only access to
the entity His-
tory.
• Edit/Insert: Al-
lows a user to
add a new re-
cord for the en-
tity in the His-
tory.
• Correct: Allows
a user to
change an ex-
isting record in
the History.
• Delete: Allows a
user to remove
an existing re-
cord in the His-
tory.
Platform Administration Admin Manage User Manage Users Defines who can hire
Employee Central Employee Central and rehire employ-
ees, manage work-
flows requests and
groups as well im-
port and export em-
ployee data.
Employee Central Employee Central Admin Manage User Restrict fields of Allows admins to
type Worker further filter fields
to only contingent
workers.
Employee Central Employee Central Admin Manage Business HRIS element Select the View and
Configuration Edit permissions.
Enables a user to
configure HRIS Sync
Mappings.
Employee Central Employee Central Admin Manage Business Employee Central Allows admins to
Configuration Quick Actions create Employee
Central Quick Action
templates.
Employee Central Employee Central Admin Manage Hires Add New User Allows admins to
add new users in the
system.
Employee Central Employee Central Admin Manage Hires Add Contingent Allows admins to
Worker add external work-
ers in the system.
Employee Central Employee Central Admin Manage Hires Rehire Inactive Allows users to re-
Employee Data Im- Employee hire an employee
port while keeping the
previous employ-
ment data visible in
the system.
Employee Central Employee Central Admin Manage Hires Rehire Inactive Allows users to re-
Onboarding Employee with New hire an employee
Employment and hide the pre-
vious employment
data in the system.
Employee Central Employee Central Admin Manage Hires Rehire Inactive Allows users to re-
Employee with New hire an employee us-
Employment (by ing the Match popup
'match' in New and hide the pre-
Recruit) vious employment
data in the system.
Employee Central Employee Central Admin Manage Hires Rehire Inactive Allows users to re-
Employee (by hire an employee
'match' in New using the Match
Recruit) popup while keep-
ing the previous em-
ployment data visi-
ble in the system.
Employee Central Employee Central Admin Manage Hires Add New Employee Allows users to add
for Fixed Term employees hired
with fixed-term con-
tracts, meaning that
the termination date
can be added during
the hire process.
Employee Central Manage Pending Admin Manage Hires Manage Pending Allows users to use
Hires Hires the Manage Pending
Hires feature.
Employee Central Manage Pending Admin Manage Hires Allow users to Allows Manage
Hires manage all drafts Pending Hires users
including those to work with all
saved by others Drafts saved by any
(By disabling this user.
option, users can
only work with
drafts saved by
them)
Employee Central Manage Pending Admin Manage Hires Configure Columns Allows users to
Hires for the Manage configure columns
Pending Hires for Manage Pending
Hires
Employee Central Employee Central Admin Manage Hires Manage Hire Allows users to per-
Configuration tem- mission all or se-
plates lected templates to
manage hires.
Employee Central Employee Central Admin Manage Hires Concurrent Em- Allows users to per-
ployment Configu- mission all or se-
ration Templates lected templates to
manage concurrent
employment hires.
Employee Central Employee Central Admin Manage Hires Contingent Worker Allows users to per-
Configuration mission all or se-
Templates lected templates to
manage contingent
workforce hires.
Employee Central Employee Central Admin Manage Manage Foundation Use these permis-
Foundation Object Object Types sions to set the
Types actions allowed for
foundation objects
in the Manage
Organization, Pay
and Job Structures
page.
Employee Central Employee Central Admin Manage Import/Export Allows the user
Foundation Corporate Data to import and ex-
Objects Model port Corporate Data
Model.
Employee Central Employee Central Admin Manage Import/Export Allows the user
Foundation Country/Region- to import and
Objects Specific XML for export Country/
Corporate Data Region-Specific XML
Model for Corporate Data
Model.
Employee Central Foundation Objects Admin Administrator Manage Allow users to ac-
Permissions Organization, Pay cess the Managing
and Job Structures Foundation Objects
Employee Central Employee Central User Employee Data Event Reasons You can set permis-
sions for each event
reason type.
Employee Central Employee Central User Employee Data Future Dated You can set permis-
Transaction Alert sions to view future
changes for effec-
tive-dated entities.
Employee Central Employee Central User Employee Data Transactions Allows users to see
Pending Approval if a workflow has
been initiated, but
not yet approved.
Employee Central Employee Central User Employee Central Employee Central Allow users to
Quick Actions Quick Action view and/or change
Templates the Employee Cen-
tral Quick Action
manager or em-
ployee self-service
use case.
Employee Central Employee Central Admin Manage Mass Areas where user Allows users to
Changes has permission to make mass changes
make changes for certain areas.
Platform Platform Admin Employee Data Job Title Allows users to set
the field for Job Title
to visible if you use
the People Search in
People enabled sys-
tems.
Platform Report Center User Reports Run Report Allows users to run
Reporting Table Report Permission and schedule the
Table reports for
all schemas or the
schemas you select
for this permission.
Platform Report Center User Reports Create Table Allows users to im-
Table Report Permission Schema port a Table report.
Platform Employee Profile User Reports View People Profile Allows users to see
Reporting Permission Notes in Story the Notes data lim-
Reports ited to their target
population in Story
reports.
Platform Employee Profile User Reports View People Profile Allows users to see
Reporting Permission Tags in Story the Tags data lim-
Reports ited to their target
population in Story
reports.
Platform Report Center User Reports Access Tiles from Allows users to view
Reporting Tiles Permission Home Page Tile reports from the
home page.
Platform Report Center User Manage Analytics Tiles and Allows users to cre-
Employee Central Tiles Dashboards / Dashboards
ate, edit, delete, ex-
Reports
Reporting Dashboards port, add labels,
Compensation copy, and import a
Widgets
tile.
Employee Central Position Manage- Admin Manage Position Access Position Allows users to view
ment Organization Chart the position organi-
zation chart.
Employee Central Advances Admin Manage Advances Advances Eligibility Allows user to view
or edit advances el-
igibility of an em-
ployee.
Employee Central Advances Admin Manage Advances Create Advances Allows users to cre-
ate advances.
Employee Central Advances Admin Manage Advances Advances Admin Allows users to
Overview manage advances.
Employee Central Global Benefits Admin Manage Benefits Benefits Admin Allows users to cre-
Overview ate, edit, delete, or
manage benefits.
Employee Central Global Benefits User User Permissions View Benefits/ Allows person in this
for Benefits Benefit Programs role to view all eli-
Management gible Benefits, Bene-
fit Programs, enroll-
ments, and claims.
Employee Central Global Benefits User User Permissions Enroll Benefits/ Allows person in this
for Benefits Benefit Programs role to enroll into el-
Management igible Benefits and
Benefit Programs.
Employee Central Global Benefits User User Permissions Edit Benefit Allows person in this
for Benefits Enrollments role to edit and opt
Management out of benefit enroll-
ments.
Employee Central Global Benefits User User Permissions Claim Benefits Allows person in this
for Benefits role to claim eligible
Management Benefits.
Employee Central Global Benefits Admin Manage Benefits View on behalf of Allows users to view
Employee benefits of employ-
ees.
Employee Central Global Benefits Admin Manage Benefits Manage on behalf Allows administra-
of Employee tors to manage em-
ployee overview of
benefits such as en-
roll, claim, edit and
opt out. Please ena-
ble View on behalf of
Employee to use this
feature.
Employee Central Global Benefits User Miscellaneous Benefit Contact Allows users to edit,
Permissions Benefit Enrollment enroll, claim bene-
fits.
Benefit Employee
Claim
Benefit Program
Enrollment
Employee Central Position Manage- Admin Manage Position Change Display Allows users to view
ment Date of Position the position organi-
Organization Chart zation chart for a
specific date.
Employee Central Position Manage- Admin Manage Position Mass Copy of Allows users to cre-
ment Position in Position ate up to 100 new
Organization Chart positions by copying
an existing position
in the position or-
ganization chart.
Employee Central Position Manage- Admin Manage Position View Job Allows users to view
ment Requisition job requisitions in
in Position the position organi-
Organization Chart zation chart.
Employee Central Position Manage- Admin Manage Position Create Job Allows users to cre-
ment Requisition ate job requisitions
in Position in the position or-
Organization Chart ganization chart.
Employee Central Position Manage- Admin Manage Position Select Job Allows users to se-
ment Requisition lect a job requisition
Template in Position template when cre-
Organization Chart ating a job requisi-
tion or job requisi-
tion in the position
organization chart.
Only active tem-
plates with the fol-
lowing fields can be
selected: id, title, re-
cruiterName, num-
berOpenings, posi-
tionNumber.
Employee Central Position Manage- Admin Manage Position Option to move Allows users to
ment Position to New choose whether the
Manager on Job position of an em-
Info Change ployee is moved with
the employee below
the position of the
new manager.
Employee Central Position Manage- Admin Manage Position Create Position Allows users to cre-
ment from Position ate a position from
Organization Chart the position organ-
ization chart. This
does not change the
permission for Add
Lower-Level Position
and Add Same-Level
Position.
Employee Central Position Manage- Admin Manage Position Access Position Allows users to ac-
ment Management cess the settings
Settings in Admin for position man-
Tools agement.
Employee Central Company Structure User Company Access Company Allows users to view
Overview Structure Overview Structure Overview the company struc-
ture overview.
Employee Central Company Structure User Company Change Display Allows users to see
Overview Structure Overview Date of Company how the company
Structure Overview structure overview
looks on various dif-
ferent dates.
Employee Central Company Structure User Company View Employment Allows users to see
Overview Structure Overview Count in Company
how many employ-
Structure Overview
ees are assigned to
a particular entity in
the company struc-
ture overview.
Note
When displayed
on an entity in
the chart, this
count doesn't
take the user's
role-based per-
missions (RBP)
into account.
However, when
displayed in the
side panel it
does take RBP
into account.
Employee Central Company Structure User Company View Position Allows users to see
Overview Structure Overview Count in Company
how many positions
Structure Overview
are assigned to a
particular entity in
the company struc-
ture overview.
Note
When displayed
on an entity in
the chart, this
count doesn't
take the user's
role-based per-
missions (RBP)
into account.
However, when
displayed in the
side panel it
does take RBP
into account.
Employee Central Company Structure User Company Access Company Allows users to edit
Overview Structure Overview Structure Overview the company struc-
Configuration ture overview, both
directly in the com-
pany structure over-
view itself, and in the
Admin Center.
Employee Central Company Structure User Company Create Entity from Allows users to cre-
Overview Structure Overview Company Structure ate child entities di-
Overview rectly in the com-
pany structure over-
view, using the
menu in the side
panel.
Employee Central Company Structure User Miscellaneous Company Structure Allows users to cre-
Overview Permissions Definition ate company struc-
ture overviews.
Employee Central Company Structure User Miscellaneous Company Structure Allows users to edit
Overview Permissions UI Configuration company structure
overviews.
Employee Central Localization User Miscellaneous Protection against Allows users to con-
Permissions Unfair Dismissal figure all business
Business Objects objects related to
Protection against
Unfair Dismissal.
Employee Central Localization User Miscellaneous Work Seniority Allows users to con-
Permissions Business Objects figure all business
objects related to
Work Seniority.
Employee Central Localization User Miscellaneous Location Based Allows users to con-
Permissions Payment Business figure all business
Objects objects related to
Location Based Pay-
ment.
Platform Check Tool Admin Check Tool Access Check Tool Allows users to ac-
Employee Central cess the Check Tool.
Payroll
Platform Check Tool Admin Check Tool Allow Configuration Allows users to at-
Employee Central Export tach configuration
Payroll information to a
ticket in cases
where they need to
create one.
Platform Compound Em- User General User SFAPI User Login Allows users general
Employee Central ployee API Permission access to the SFAPI.
Employee Delta Ex-
port Add-In for Mi-
crosoft Excel
ERP Integration
Employee Central ERP Integration Admin Employee Central Employee Central Allows users general
Employee Central Employee Central API Foundation SOAP access to the Foun-
Payroll Payroll API dation SOAP API.
Employee Central Compound Em- Admin Employee Central Employee Central Allows users general
Employee Central ployee API API HRIS SOAP API access to the HRIS
Payroll Employee Delta Ex- SOAP API.
Employee Central Employee Central Admin Employee Central Employee Central Allows users read
Employee Central Payroll API Foundation OData access to the Foun-
Payroll ERP Integration API (read-only) dation OData API.
Employee Central ERP Integration Admin Employee Central Employee Central Allows users to have
Employee Central API HRIS OData API read access to the
Employee Central
Payroll (read-only) HRIS OData API.
Payroll
Platform
Variance Report
Onboarding
Employee Profile
Employee Central Employee Delta Ex- Admin Employee Central Employee Central Allows users to have
Employee Central port Add-In for Mi- API Foundation OData write access to the
Payroll crosoft Excel API (editable) Foundation OData
ERP Integration API.
Employee Central
Payroll
Employee Central ERP Integration Admin Employee Central Employee Central Allows users to have
Employee Central Employee Central API HRIS OData API write access to the
Payroll Payroll (editable) HRIS OData API.
Employee Central Compound Em- Admin Employee Central Employee Central Together with the
Employee Central ployee API API Compound SFAPI User Login
Payroll ERP Integration Employee API permission, this per-
(restricted access) mission restricts the
data accessible us-
ing the Compound
Employee API ac-
cording to the defi-
nition of the target
population, for ex-
ample, for a coun-
try/region or a de-
partment.
Employee Central Compound Em- Admin Employee Central Employee Central Allows the user to
Employee Central ployee API API Compound access
Payroll ERP Integration Employee API CompoundEmplo
(restricted segment yee segments ac-
access) cording to the con-
figuration setup
only. With this per-
mission, you can
further restrict ei-
ther the Employee
Central HRIS SOAP
API permission or
the Employee
Central Compound
Employee API
(restricted access)
permission.
Employee Central Employee Delta Ex- Admin Manage Manage Employee Allows users to ac-
port Add-In for Mi- Dashboards / Delta Export cess the Employee
crosoft Excel Reports Templates Delta Export UI.
You find this per-
mission either un-
der Manage User
or under Manage
Dashboards /
Reports.
Employee Central Employee Delta Ex- Admin Manage User Manage Employee Allows users to ac-
port Add-In for Mi- Delta Export cess the Employee
crosoft Excel Templates Delta Export UI.
You find this per-
mission either un-
der Manage User
or under Manage
Dashboards /
Reports.
Employee Central Data Replication Admin Manage Access to Data Allows users to ac-
Monitor Integration Tools Replication Monitor cess all data rep-
lication records in
the Employee Cen-
tral Data Replica-
tion Monitor, thus
being able to mon-
itor employee mas-
ter data, organiza-
tional assignment,
and time data rep-
lication from Em-
ployee Central.
Employee Central Data Replication Admin Manage Restrict Access to Together with the
Monitor Integration Tools Data Replication Access to Data
Monitor to Specific Replication Monitor
Target Population permission, this per-
mission allows users
to access data
replication records
for specific groups
of employees in
the Employee Cen-
tral Data Replica-
tion Monitor, thus
being able to mon-
itor employee mas-
ter data, organiza-
tional assignment,
and time data rep-
lication from Em-
ployee Central for
these employees.
Employee Central Data Replication Admin Manage Delete Records Allows users to
Monitor Integration Tools from Data
delete data replica-
Replication Monitor
tion records from
the Employee Cen-
tral Data Replication
Monitor that are no
longer needed for
monitoring, for ex-
ample, because they
were created dur-
ing a test phase.
The Data Replica-
tion Monitor is used
in employee mas-
ter data, organiza-
tional assignment,
and time data rep-
lication from Em-
ployee Central.
Recom-
mendation
Grant this per-
mission only in
exceptional
cases, where
mass deletion is
required. Re-
move the per-
mission from
the permission
role after per-
forming the
mass deletion.
Employee Central Payroll Self-Service User Payroll Payroll Self-Service Allows users to ac-
Payroll Permissions cess employee self-
services like the pay
statement.
Employee Central Employee Central Admin Payroll Integration Employee Run Select all available
Payroll Payroll Permission Results permissions. Allows
users to configure
all payroll run re-
sults for employees.
Employee Central Employee Central User Payroll Integration Employee Run Select View Current
Payroll Payroll Permission Results and View History
permissions. Allows
users to view payroll
run results.
Employee Central Employee Central Admin Payroll Integration Payroll Data Allows users to con-
Payroll Payroll Permission Maintenance Task figure all payroll
data maintenance
tasks.
Employee Central Employee Central Admin Payroll Integration Payroll Data Allows users to
Payroll Payroll Permission Maintenance Task make settings for
Configuration the Configuration of
all payroll mainte-
nance tasks.
Employee Central ERP Integration Admin Payroll Integration Data Replication Allows users to
Employee Central Time Data Replica- Permission Configuration make settings for
Payroll tion all Data Replication
Configurations.
Employee Central ERP Integration Admin Payroll Integration Data Replication Allows users to view
Employee Central Time Data Replica- Permission Proxy and edit Data Repli-
Payroll tion cation Proxies.
Employee Central ERP Integration Admin Payroll Integration Trigger Data Allows users to trig-
Employee Central Time Data Replica- Permission Replication Proxy ger Data Replication
Payroll tion Creation Job Proxy creation job
for selected users.
Note that this per-
mission is optional.
Employee Central ERP Integration Admin Payroll Integration Trigger Data Allows users to trig-
Employee Central Time Data Replica- Permission Replication Proxy ger Data Replication
Payroll tion Deletion Job Proxy deletion job
for selected users.
Note that this per-
mission is optional.
Employee Central ERP Integration Admin Payroll Integration Planned Working Allows users to con-
Employee Central Time Data Replica- Permission Time Replication figure the replication
Payroll tion Period of planned working
time.
Employee Central ERP Integration Admin Payroll Integration Work Schedule Allows users to ex-
Employee Central Time Data Replica- Permission Replication clude work sched-
Payrolll tion Exclusion List ules from the stand-
ard replication.
Employee Central ERP Integration Admin Admin Alerts Planned Working Allows users to
Employee Central Time Data Replica- Object Time Replication view/edit admin
Payroll tion Permissions Admin Alert alerts raised dur-
ing the replication
of planned working
time.
Employee Central ERP Integration Admin Admin Alerts Time Account Allows users to
Employee Central Time Data Replica- Object Replication Admin view/edit admin
Payroll tion Permissions Alert alerts raised during
the replication of
time account.
Employee Central Payroll Control Admin Manage Access to Allows users to see
Payroll Center SAP System SAP System the SAP System
Configuration Configuration Configuration link in
Admin Center.
Employee Central Payroll Control Admin Payroll Integration SAP System Select View and
Payroll Center Permission Configuration Edit permissions.
Enables a user to
configure Employee
Central Payroll pa-
rameters.
Employee Central Payroll Control Admin Payroll Integration Payroll Control Select View and
Payroll Center Permission Center Edit permissions.
Configuration Enables a user to
configure the classic
or the new Payroll
Control Center solu-
tion for each payroll
system.
Employee Central Payroll Control Admin Payroll Integration Payroll System Allow users to as-
Payroll Center Permission Assignment sign payroll systems
Employee Central to target users such
Payroll as payroll adminis-
trators and payroll
process managers.
Employee Central Payroll Control User Payroll Control My Alerts Access Allows users to use
Payroll Center Center the My Alerts tab.
Employee Central Payroll Control User Payroll Control My Processes Allows users to use
Payroll Center Center Access the My Processes
tab.
Employee Central Payroll Control User Payroll Control Unassigned Alerts Allows users to
Payroll Center Center Access use the Unassigned
Alerts tab.
Employee Central Payroll Control User Payroll Control Manage Processes Allows users to
Payroll Center Center Access use the Manage
Processes tab.
Employee Central Payroll Control User Payroll Control Manage Policies Allows users to use
Payroll Center Center Access the Manage Policies
tab.
Employee Central Payroll Control User Payroll Control My Off-cycles Allows users to use
Payroll Center Center Access the My Off-Cycles
tab.
Employee Central Payroll Control User Payroll Control Manage Teams Allows users to use
Payroll Center Center Access the Manage Teams
tab.
Employee Central Payroll Control User Payroll Control Manage Allows users to
Payroll Center Center Configuration use the Manage
Access Configuration tab.
Employee Central Payroll Control User Payroll Control My Teams Access Allows users to use
Payroll Center Center the My Teams tab.
Employee Central Time Off User Employee Views Manage Time Off Allows users to cre-
Employee Profile ate and manage re-
quests for time off
(for example, vaca-
tion or sick leave).
Employee Central Time Off User Employee Views Time Management Allows users to cre-
Employee Profile ate and manage re-
quests for time off
(for example, vaca-
tion or sick leave).
Employee Central Time Off User Employee Central Holiday Calendar Allows users to
Effective Dated view the Holiday
Entities Calendar field in
their Job Informa-
tion.
Employee Central Time Off User Employee Central Work Schedule Allows users to view
Effective Dated the Work Schedule
Entities field in their Job In-
formation.
Employee Central Time Off User Employee Central Time Profile Allows users to view
Effective Dated the Time Profile field
Entities in their Job Informa-
tion.
Employee Central Time Off User Employee Central Time Recording Allows users to view
Effective Dated Variant the Time Recording
Entities Variant field in their
Job Information.
Employee Central Time Off Admin Manage Time Off Manage Time Off Allows a Time Off
Structures admin to create,
edit, or delete Time
Off-related objects
such as time pro-
files, time accounts,
or time types.
Employee Central Time Off Admin Manage Time Off Manage Time Off Allows a Time Off
Calendars admin to carry out
mass changes to
time data by using
calendar runs.
Employee Central Time Off Admin Manage Time Off Manage Payout Allows admins to
Absence Manage- enter financial pay-
ment outs on time ac-
counts.
Employee Central Time Off Admin Manage Time Access Workbench Allows admins to
Absence Manage- open the Time
ment Workbench and
manage time tasks
and create payouts
for employees.
Employee Central Time Off Admin Manage Time Maintain Individual Allows a Time Off
Work Schedule admin to create
an individual work
schedule for an em-
ployee.
Employee Central Time Off Admin Manage Time Maintain Temporary Allows a Time Off
Change admin to make a
temporary change
to an employee's
work schedule.
Employee Central Time Off Admin Manage Time Link Absences Allows a Time Off
admin to link an em-
ployee's absences in
case, for example,
the employee has
been absent with
the same sickness
more than once in a
given periods.
Employee Central Time Off Admin Manage Time Access Time Alerts Allows a Time Off
admin to access
time alerts in the
Time Workbench.
Employee Central Time Off Admin Manage Time Access Time Allows a Time Off
Account Process admin to simulate
Simulator time account ac-
cruals for a particu-
lar employee, date,
and time account
types.
Employee Central Time Off Admin Manage Time Access Time Allows a Time
Management Off admin to use
Configuration the time manage-
Search ment configuration
search.
Employee Central Time Off Admin Manage Time Show Time Allows a Time Off
Account Balance in admin to see the
Termination Screen time balance on the
screen where termi-
nation payouts are
processed.
Employee Central Time Off Admin Manage Time Access Account Allows a Time Off
Absence Manage- Payouts admin to access the
ment Accounts Payouts
tab in the Time
workbench.
Employee Central Time Off Admin Manage Time Access Review Time Allows a Time Off
Sheets admin to access the
Time Sheet Appro-
val Center page.
Employee Central Time Off User Miscellaneous Time Account You must enable
Absence Manage- Permissions Visibility: View and
ment Actions: Edit to allow
an administrator to
view and edit time
accounts.
Employee Central Time Off User Miscellaneous Time Account Enable only
Absence Manage- Permissions Visibility: View to al-
ment low a user to view
time accounts.
Employee Central Time Off User Miscellaneous Time Account Type You must enable
Absence Manage- Permissions Visibility: View and
ment Actions: Edit to al-
low an administra-
tor to view and edit
the types of time ac-
counts.
Employee Central Time Off User Miscellaneous Time Account Type Enable only
Absence Manage- Permissions Visibility: View to al-
ment low a user to view
the types of time ac-
counts.
Employee Central Time Off Admin Time Management Time Type You must enable
Absence Manage- Object
Visibility: View and
ment Permissions
Actions: Edit to allow
an administrator to
view and edit time
types.
Recom-
mendation
Use the Time
Management
Object
Permissions
category to se-
cure all time ob-
jects. Legacy
systems may
have this per-
mission in
Miscellaneous
Permissions.
Employee Central Time Off User Time Management Time Type Enable only
Absence Manage- Object
Visibility: View to al-
ment Permissions
low a user to view
time types.
Recom-
mendation
Use the Time
Management
Object
Permissions
category to se-
cure all time ob-
jects. Legacy
systems may
have this per-
mission in
Miscellaneous
Permissions.
Note
Employee Central Time Off Admin Time Management Time Account You must enable
Absence Manage- Object Payout
Visibility: View and
ment Permissions
Actions: Edit to allow
an administrator to
view and edit time
account payout.
Recom-
mendation
Use the Time
Management
Object
Permissions
category to se-
cure all time ob-
jects. Legacy
systems may
have this per-
mission in
Miscellaneous
Permissions.
Employee Central Time Off User Time Management Time Account You only enable
Absence Manage- Object Payout
Visibility: View to al-
ment Permissions
low a user to view
time account pay-
out.
Recom-
mendation
Use the Time
Management
Object
Permissions
category to se-
cure all time ob-
jects. Legacy
systems may
have this per-
mission in
Miscellaneous
Permissions.
Employee Central Time Off User Miscellaneous Time Account Allows admins to
Absence Manage- Permissions Payout Profile create and edit the
ment profile required for
enabling self-service
time account pay-
outs.
Employee Central Workflows Admin Manage Workflows Allow Auto Allows users to set
Delegation up automatic del-
egation for their
workflow requests.
Employee Central Workflows User Employee Data View Workflow Select either the
Approval History View or Edit
permissions as re-
quired under View
Workflow Approval
History for manag-
ers that want to ap-
prove requests for
their employees.
Employee Central Workflows Admin Manage Workflows Manage Workflow Allows users to ac-
Requests cess workflows.
Employee Central Workflows Admin Manage Workflows Manage Workflow Allows HR Adminis-
Groups trators to define dy-
namic groups for
workflows.
Employee Central Workflows Admin Manage Workflows Professional Edition You can use the ad-
Manage Workflow ditional organization
Requests filters within work-
flow requests when
this is enabled.
Employee Central Workflows Admin Manage Workflows View Completed You can control
Workflows who sees completed
workflows and is
only available when
the Platform
Feature Settings
Add Permission:
Completed
Workflows is
turned on.
Platform User Experience User General User User Login Allows users to log
Employee Central Permission into the system.
Onboarding 1.0
Onboarding
Platform Job Profile Builder Admin Manage Job Profile Select all You can restrict
Employee Central Builder checkboxes managing job profile
content by selecting
Can View Content
versus Can Edit
Content under the
Manage Job Profile
Content section.
Platform Job Profile Builder Admin Manage Job & Skill Job Profile You must enable se-
Employee Central Profile Visibility curity and visibility
settings from the
Job Profile object
using the Configure
Object Definitions
tool so that Manage
Job & Skill Profile
Visibility is enabled
in role-based per-
mission.
Platform Job Profile Builder Admin Manage Job & Skill Skill Profile You must enable se-
Employee Central Profile Visibility curity and visibility
settings from the
Job Profile object
using the Configure
Object Definitions
tool so that Manage
Job & Skill Profile
Visibility is enabled
in role-based per-
mission.
Platform Job Profile Builder Admin Manage Job & Skill Rated Skills
Employee Central Profile Visibility
Platform Job Profile Builder Admin Manage Job & Skill Family Allow users to view
Succession Talent Card Profile Visibility job families if they
want to find succes-
sors by browsing
through positions.
Platform Job Profile Builder Admin Manage Job & Skill Role Allow users to view
Succession Talent Card Profile Visibility job roles if they want
to find successors
by browsing through
positions.
Platform Center of Capabili- Admin Manage Center of Capability Library Allows users to
ties Capabilities Structure view, create, edit,
import, and export
libraries, categories,
and groups.
Platform Center of Capabili- Admin Manage Center of Competencies Allows users to view,
ties Capabilities create, edit, import,
and export compe-
tencies.
Platform Center of Capabili- Admin Manage Center of Portfolio Settings Allows users to
ties Capabilities and Proficiency configure the profi-
Rating Scale ciency rating scale
and enable Capabili-
ties Portfolio.
Recruiting Recruiting Manage- User Recruiting Report Permission Allows users to ac-
ment Permissions cess the Reports link
on the Career Site
Builder tab
Recruiting
Recruiting Recruiting Manage- Admin Recruiting Recruiting Job Allows users to fetch
ment Permissions Requisition Data job details and dis-
Access Permission play them on exter-
nal and internal ca-
reer sites.
Recruiting Recruiting Manage- User Recruiting Source Quality Allows users to ac-
ment Permissions Portlet Permission cess the Source sub-
tabtab on the Ca-
reer Site Builder
Recruiting Recruiting Manage- User Recruiting Standalone Search Allows users to ac-
ment Permissions Permission cess the Candidates
tab and candidate
search, whether or
not the user has an
open requisition
Recruiting Recruiting Manage- User Recruiting Candidate Search Allows users to ac-
ment Permissions Within Job Req cess the Candidates
tab and candidate
search, only if
the user has an
open requisition.
This does not allow
the user to search
through candidates
that have already
applied to the requi-
sition.
Recruiting Recruiting Manage- User Recruiting Candidate Tagging Gives the user the
ment Permissions Permission ability to add tags to
a candidate or appli-
cant.
Recruiting Recruiting Manage- User Recruiting Grant eQuest Gives the user
ment Permissions Job Postings the ability to post
Permission to third party job
boards via eQuest.
eQuest must be
enabled and config-
ured, and external
user accounts must
be properly loaded
for the users receiv-
ing the permission.
Recruiting Recruiting Manage- User Recruiting Jobs Applied Portlet Allows users to view
ment Permissions Permission theJobs Applied
block on the
Candidate Profile
and application re-
cords
Recruiting Recruiting Manage- User Recruiting SFAPI Insert Allows users to in-
ment Permissions Candidate
sert candidate per-
Permission
missions on candi-
date profiles. Typi-
cally this is granted
to a dummy user,
set up specifically
for integration pur-
poses.
Recruiting Recruiting Manage- User Recruiting SFAPI Update Allows users to up-
ment Permissions Candidate
date candidate data.
Permission
Typically this is
granted to a dummy
user, set up specifi-
cally for integration
purposes.
Recruiting Recruiting Manage- User Recruiting eSignature Sender Allows recruiting op-
ment Permissions Permission
erator user to send
out online offers to
candidates.
Recruiting Recruiting Manage- User Miscellaneous Candidate Data Allows users to view
ment Permissions Residency Log
and export candi-
Record
date data residency
logs that are gen-
erated when candi-
date data is created
or updated in the
Russian data center,
and then replicated
to the global data
center.
Recruiting Recruiting Manage- User Recruiting SFAPI Insert Allows users to in-
ment Permissions Job Application sert job application
Permission data. Typically this is
granted to a dummy
user, set up specifi-
cally for integration
purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Update Allows users to up-
ment Permissions Job Application date job application
Permission permissions on ap-
plications. Typically
this is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Insert Job Allows users to in-
ment Permissions Code Permission
sert job code per-
missions on requi-
sition job code en-
tity fields. Typically
this is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Update Job Allows users to up-
ment Permissions Code Permission
date job code per-
missions on requi-
sition job code en-
tity fields. Typically
this is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Permis- User Recruiting SFAPI Upsert Job Allows users to up-
sion Permissions Code Permission
sert job code per-
missions on requi-
sition job code en-
tity fields. Typically
this is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Retrieve Job Allows users to re-
ment Permissions Code Permission
trieve job code per-
missions on requi-
sition job code en-
tity fields. Typically
this is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Retrieve Job Allows users to
ment Permissions Posting Permission retrieve job post-
ing permissions on
requisition job post-
ings. Typically this is
granted to a dummy
user, set up specifi-
cally for integration
purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Retrieve Allows users to re-
ment Permissions Assessment Order trieve assessment
Permission order permissions
on application as-
sessments. Typically
this is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Manage- User Recruiting SFAPI Update Allows users to up-
ment Permissions Assessment Report date assessment re-
Permission port permissions on
application assess-
ments. Typically this
is granted to a
dummy user, set up
specifically for inte-
gration purposes.
Recruiting Recruiting Manage- User Recruiting Careers Tab Allows user to ac-
ment Permissions Permission cess the Careers
tab. This permission
is granted automat-
ically to all newly
created users. Ad-
just this permission
only if users are re-
activated in a non-
RBP environment or
if the organization
wants to restrict ac-
cess to the careers
tab to a given popu-
lation of employees.
Recruiting Recruiting Permis- User Recruiting Delete Job Allows users to de-
sions Permissions Requisitions lete a job requisi-
tion.
Recruiting Recruiting Manage- User MDF Recruiting MDF Object: View Yes: Pipeline
ment Permissions Candidate
Status Structure
Relationship
dropdown shows list
Management
Status Set of pipelines.
Recruiting Recruiting Manage- User MDF Recruiting MDF Object: View Yes: Dropdown
ment Permissions Candidate
shows list of sta-
Relationship
tuses that can be
Management
Status Map set as default.
Recruiting Recruiting Manage- User MDF Recruiting LinkedInIntegration Allows user to ac-
ment Permissions Configuration cess and update the
LinkedInIntegrationC
onfiguration entity.
Recruiting Recruiting Adminis- Admin Manage Recruiting Detailed Requisition Allows users to view
tration Reporting Detailed Requisition
Reporting.
Recruiting Recruiting Adminis- Admin Manage MDF Recruiting User Allows admins to
tration Recruiting Objects Personalization configure objects in
Object the Applicant Man-
Configuration agement tool.
Recruiting Recruiting Adminis- Admin Manage MDF Recruiting User Allows admins to
tration Recruiting Objects Personalization configure fields in
Field Configuration the Applicant Man-
agement tool.
Recruiting Recruiting Adminis- Admin Manage Recruiting Employee Referral Allows users to set
tration Program Setup up an employee re-
ferral program.
Recruiting Recruiting Adminis- Admin Manage Recruiting Edit Applicant Allows users to edit
tration Status the applicant status
Configuration configuration.
Recruiting Recruiting Adminis- Admin Manage Recruiting Export New Hire Allows users to ex-
tration Candidates port the records
of candidates newly
hired.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Custom Help Text manage custom
Help instructions for
Recruiting.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Duplicate Allows users to
tration Candidates manage and purge
duplicate candidate
records.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage external Allows users to
tration data privacy manage external
Data Protection consent statements data privacy con-
and Privacy sent statements.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage External Allows users to
tration Password Policy manage the external
password policy.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage External Allows users to
tration User Accounts manage external
user accounts.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage internal Allows users to
tration data privacy manage internal
Data Protection consent statements data privacy con-
and Privacy sent statements.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Job Posting Allows users to
tration Header and Footer manage the job
posting header and
footer.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Offer Letter Allows users to
tration Templates manage offer letter
templates.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Email Templates manage recruiting
email templates.
Recruiting Recruiting Adminis- User Recruiting Offer Enable Recruiting Allows users to view
tration Letter Templates Offer Letter and select offer let-
Templates ter templates. Se-
lect "All" to give
users access to
all offer letter tem-
plates. Select "Oth-
ers" to select spe-
cific offer letter tem-
plates.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Groups manage recruiting
groups.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Languages manage recruiting
languages.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Settings manage recruiting
settings.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Sites manage recruiting
sites.
Recruiting Recruiting Adminis- Admin Manage Recruiting Set up Company Allows users to set
tration Information up company infor-
mation.
Recruiting Recruiting Adminis- Admin Manage Recruiting Set up Internal Allows users to set
tration Candidate Search up an internal candi-
date search.
Recruiting Recruiting Adminis- Admin Manage Recruiting Set up Job Board Allows users to set
tration Options up job board op-
tions.
Recruiting Recruiting Adminis- Admin Manage Recruiting Delete Candidate Allows users to de-
tration lete candidate re-
cords. You can grant
this permission only
if the application
status Deleted On
Demand By Admin
has been enabled
for the related sta-
tus set on the pipe-
line.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Recruiting Allows users to
tration Team Settings manage recruiting
team settings.
Recruiting Recruiting Adminis- Admin Manage Recruiting Configure Allows users to con-
tration Standardization figure standardiza-
Mapping tion mapping.
Recruiting Recruiting Adminis- Admin Manage Recruiting Set Up Recruiting Allows users to set
tration Marketing Job Field up Recruiting Mar-
Mapping keting Job Field
Mapping.
Recruiting Recruiting Adminis- Admin Manage MDF Campaign Limits Select any combi-
tration Recruiting Objects nation of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over-
rides, as desired.
Recruiting Recruiting Manage- Admin Manage MDF MDF Objects: Enables Candidate
ment Recruiting Objects Relationship Man-
Candidate
agement features.
Relationship
Management
Status
Candidate
Relationship
Management
Status Map
Candidate
Relationship
Management
Status Set
Recruiting Recruiting Adminis- Admin Manage MDF EmailBrandTemplat Select any combi-
tration Recruiting Objects e nation of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over-
rides, as desired.
Recruiting Recruiting Adminis- Admin Manage MDF MarketingBrand Select any combi-
tration Recruiting Objects nation of Visibility:
View, Actions: Edit
and Import/Export,
and Field Level Over-
rides, as desired.
Recruiting Recruiting Adminis- Admin Manage MDF MDF Object: Pool Select View, Ac-
tration Recruiting Objects Limits tions: Edit and Im-
port/Export, and
Field Level Over-
rides, as desired.
Recruiting Recruiting Adminis- Admin Manage MDF Recruiting Rules Select View and Edit
tration Recruiting Objects Assignment
to enable users to
Configuration
configure business
rules for Recruiting.
Other permissions
are optional.
Recruiting Recruiting Permis- Admin Manage Recruiting Restore Deleted Job Allows users to re-
sions Requisitions store a deleted job
requisition.
Recruiting Recruiting Permis- User Recruiting Hide Careers Tab When enabled for
sions Permissions for Proxy User specific employees
or permission roles,
disallows viewing a
proxied users career
tab and tile.
Recruiting Recruiting Adminis- Admin Manage Recruiting Manage Multistage Allows users to ac-
tration And Late Stage cess the Manage
Application Preview Multistage and Late
Stage Application
Preview from Admin
Center.
Recruiting Recruiting Posting Admin Manage Recruiting Manage Recruiting Allows admins to
Posting manage all Recruit-
ing Posting settings,
Recruiting users as-
sociations, Posting
Profiles, Job Boards,
and field mappings.
Recruiting Career Site Builder Admin Manage Recruiting Manage Service Allows administra-
Provider tors to configure
Configuration Identity Provider
for Identity (IDP) to enable In-
Authentication ternal Career Site
Service (IAS) powered by Career
Site Builder
Platform Data Protection Admin Admin Center View Change Audit Allows users to
and Privacy Permissions Configuration view configuration
settings for Change
Audit.
Platform Data Protection Admin Admin Center Edit Change Audit Allows users to
and Privacy Permissions Configuration change configura-
tion settings for
Change Audit.
Platform Data Protection Admin Admin Center Generate Change Allows users to cre-
and Privacy Permissions Audit Reports ate Change Audit re-
ports. You can cre-
ate change audit re-
ports on personal
data for Data Pro-
tection and Privacy
or on other types of
data for general au-
dit purposes.
Platform Data Protection Admin Manage Data Create DRTM Data Allows users to cre-
and Privacy Purge Purge Request ate and submit a
DRTM purge request
for Data Protection
and Privacy.
Platform Data Protection Admin Manage Data Manage and Allows users to ap-
and Privacy Purge Approve DRTM prove a DRTM purge
Data Purge Request request for Data
Protection and Pri-
vacy.
Platform Data Protection Admin Manage Data Remove Preview Allows users to de-
and Privacy Purge and Complete lete old purge re-
Reports for DRTM ports for DRTM
Data Purge Request purge requests.
Platform Data Protection Admin Manage Data Additional access Allows users to
and Privacy Purge control based access purge re-
on DRTM-enabled ports or approve
countries or regions DRTM purge re-
quests when the tar-
get data of a DRTM
purge request is lim-
ited to countries or
regions with DRTM
enabled.
Platform Data Protection User Data Retention [Dynamic permis- Allows users to
and Privacy Management sions for each MDF
manage configura-
object configured
tions related to the
in the system that
is related to DRTM DRTM data purge
data purge.] function for Data
Protection and Pri-
vacy, using MDF
tools.
Platform Data Protection Admin Admin Center Enable Information Allows users to
and Privacy Permissions on Data Subject configure and run
the Data Subject
Information Report,
which compiles a list
of all the personal
data that has been
stored on a particu-
lar employee.
Platform Administration Admin Admin Center Access Manage Allow users to ac-
Permissions Data Storage cess Manage Data
Storage.
Platform Instance Manage- Admin Manage Instance Copy Package Allows users to
ment Synchronization copy Instance Sync
packages between
source and target.
Platform Instance Manage- Admin Manage Instance Sync Data Model Allows users to
ment Synchronization sync data models
between instances
using Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync MDF Data Allows users to sync
ment Synchronization MDF data between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync Workflow Allows users to sync
ment Synchronization EC Workflows be-
tween instances us-
ing Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync Objectives Allows users to
ment Synchronization sync goals between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync Rating Scales Allows users to
ment Synchronization sync rating scales
between instances
using Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync Form Label Allows users to sync
ment Synchronization Translations form label transla-
tions between in-
stances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync Competencies Allows users to
ment Synchronization sync competencies
between instances
using Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync Families and Allows users to sync
ment Synchronization Roles families and roles
between instances
using Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync Performance- Allows users to sync
ment Synchronization Management Performance Man-
Templates agement templates
between instances
using Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync Objective Allows users to sync
ment Synchronization Templates Goal Management
templates between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync Career- Allows users to sync
ment Synchronization Development-Plan Career Development
Templates Plan templates be-
tween instances us-
ing Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync System Allows users to
ment Synchronization Properties sync miscellaneous
system settings be-
tween instances us-
ing Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync RBP Allows users to
Onboarding ment Synchronization Permission Roles sync RBP permis-
sion roles between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync RBP Allows users to
Onboarding ment Synchronization Permission Groups sync RBP permis-
sion groups between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync Dashboard Allows users to sync
ment Synchronization Settings Analytics dashboard
settings between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync MDF Picklists Allows users to sync
ment Synchronization MDF picklists be-
tween instances us-
ing Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync MDF Object Allows users to
ment Synchronization Definitions sync MDF object
definitions between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync MDF Allows users to sync
ment Synchronization Configuration UI MDF configuration
UI settings between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync MDF Rules Allows users to sync
ment Synchronization MDF rules between
instances using In-
stance Sync tools.
Platform Instance Manage- Admin Manage Instance Sync Foundation Allows users to sync
ment Synchronization Objects Foundation Objects
between instances
using Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Sync Homepage Allows users to sync
ment Synchronization Tile Configurations Home Page config-
uration settings be-
tween instances us-
ing Instance Sync
tools.
Platform Instance Manage- Admin Manage Instance Manage Refresh Allows admin users
ment Refresh to create a new re-
fresh request, view
history and track re-
fresh request.
Platform Instance Manage- Admin Manage Instance View Refresh Allows users re-
ment Refresh Requests stricted access of
the Instance Refresh
tool. Users can
view history, track
request but they can
not create a new re-
fresh request.
Platform System Administra- Admin Admin Center View or access Allows users to see
tion Permissions Admin Alerts tile the Admin Alerts tile
on the next-gen Ad-
min Center page.
Platform Administration Admin Admin Center View or access Allows users to see
Permissions Reports tile the Reports tile on
the next-gen Admin
Center page.
Platform Administration Admin Manage Security Manage SAML SSO Allows users to
Settings manage SAML SSO
settings, only in
instances using
SAP Cloud Platform
Identity Authentica-
tion service.
Platform Administration Admin Manage System Manage Home Page Allows users to ac-
Properties cess the Manage
Home Page screen
and use it to config-
ure the home page.
Platform Employee Profile User General User Live Profile Access Allows users to ac-
Employee Central Data Replication Permission
cess the People Pro-
Employee Central Monitor file page.
Payroll Job Profile Builder
Onboarding 1.0 It also allows users
to access People
Profile from data
replication records
in the Employee
Central Data Repli-
cation Monitor. The
Data Replication
Monitor is used
in employee mas-
ter data, organiza-
tional assignment,
and time data rep-
lication from Em-
ployee Central.
Platform Employee Profile Admin Manage System Manage Employee Allows users to ac-
Employee Central Properties Files cess the profile con-
figuration tool so
Employee Central
that they can config-
Payroll
ure the content and
layout of the People
Profile.
Platform Employee Profile Admin Manage System Manage Badges Allows users to cre-
Properties ate and manage
custom badges, for
same-level to same-
level recognition on
the employee pro-
file.
Platform Administration Admin Admin Center Read Execution Allows users to ac-
Integration Center Permissions Manager Events cess the main dash-
board and view
success/fail infor-
mation.
Platform Administration Admin Admin Center Read Execution Allows users to view
Data Protection Permissions Manager Event the payload for each
and Privacy Payload or Event event in a process,
Report including user data,
Integration Center
to assist in trou-
bleshooting errors.
This permission is
required to set up
the Information Re-
port for Data Protec-
tion and Privacy.
Platform Integration Admin Admin Center Data Access Don't use this per-
Permissions for One Inbox mission or assign it
Integration to anyone. It's only
used internally for
integration with SAP
One Inbox.
Platform Mobile User General User Mobile Access Allows users to ac-
Recruiting Recruiting Manage- Permission cess the SAP Suc-
ment cessFactors Mobile
Onboarding 1.0
app on their iOS or
Employee Profile
Android mobile devi-
ces.
Onboarding Employee Central Admin Manage Business Select the options Allows users to
Configuration you need for your use the Business
scenario Configuration UI,
where you can
make changes to
the Succession Data
Model directly, with-
out accessing Provi-
sioning.
Onboarding Document Genera- Admin Manage Document Manage Document Allows users to view
tion Generation Template and edit the docu-
ment template.
Onboarding Document Genera- Admin Manage Document Manage Document Allows users to map
tion Generation Template Mapping document template
variables.
Onboarding Document Genera- Admin Manage Document Generate All Allows users to trig-
tion Generation Documents as ger document gen-
Admin eration for users
from the Document
Generation –
Generate Document
page.
Onboarding Employee Central User Employee Central Select applicable Provides access to
Effective Dated permissions from view or edit effec-
Entities the list. tive dated entities
inEmployee Central.
Full permission rec-
ommended for:
• Hiring manager
• Hiring manag-
er's manager
• Future manager
• Onboarding co-
ordinator
• HR admin
• System admin
Onboarding Onboarding/Off- User Onboarding or Show Form I-9 and Allows you to view
boarding Offboarding E-Verify Status on the status of Form
Permissions the Dashboard I-9 and E-Verify on
the dashboard.
Onboarding Instance Manage- Admin Manage Instance Sync MDF Picklist Allows you to sync
ment Synchronization MDF picklists be-
tween two instan-
ces. You need
this permission to
trigger email noti-
fications with dy-
namic group recipi-
ent builder.
Onboarding Object Permissions Admin Manage Enable Object Allows you to make
Onboarding or Visibility for objects visible to
Offboarding External Hires new hires during the
Personal Data Col-
lection step.
Onboarding Object Permissions Admin Onboarding or Onboarding Read Allows you to con-
Offboarding Access Logging figure fields as Sen-
Admin Object Configuration sitive Personal Data
Permissions (SPD) fields.
Onboarding Onboarding/Off- Admin Onboarding or Trigger I-9 Flow Allows you to trigger
boarding Offboarding the Form I-9 flow.
Admin Object
Permissions
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• HR admin
• System admin
Onboarding Object Permissions Admin Onboarding or Onboarding Admin Allows users to con-
Offboarding Configuration Item figure SAP Success-
Admin Object Factors eSignature
Permissions or DocuSign if re-
quired for an elec-
tronic signature.
Onboarding Onboarding/Off- Admin Manage Update New Hire Allows users to use
boarding Onboarding or Data for External the
Offboarding HRIS onb2UpdateFro
mExternalHris
API to upsert data.
Onboarding Onboarding/Off- Admin Manage Access New Hire Allows users to view
boarding Onboarding or Data Permission and edit the new
Offboarding hire data.
View permission is
recommended for:
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• HR admin
Onboarding DocuSign eSigna- Admin Configure Configure DocuSign Allows users to ac-
ture DocuSign eSignature cess the admin
eSignature tool for configur-
ing the DocuSign
eSignature.
Onboarding ERP Integration User Employee Data Employment Allows the new hires
Details MSS to view the compli-
ance forms.
Onboarding ERP Integration User Employee Data Employment Allows the new hires
Details Edit to edit the compli-
ance forms.
Onboarding DocuSign eSigna- Admin Configure Manage DocuSign Allows users to ac-
ture DocuSign envelopes cess the admin tool
eSignature for managing Docu-
Sign envelopes.
Onboarding Employee Data User Employee Data Event Reasons Allows the hiring
manager to view the
New Hire
new hire user record
(NEW_HIRE) in Employee Central.
Onboarding Recruiting Manage- User Recruiting Recruit-to-Hire Data Allows users to map
ment Permissions Mapping fields for the recruit-
to-hire process.
Onboarding Object Permissions User Onboarding Object Select the options The permissions
Permissions that best fit your you select deter-
scenario mine the level of ac-
cess for each type of
onboarding task.
Onboarding Administration User HomePage v3 Tile Homepage v3 To- Allows users to ac-
Platform Group Permission Do tile group
cess the home page
tiles for to-do notifi-
cations.
To provide access
to the other home
page tiles, select
the corresponding
permissions.
Onboarding Goal Plans User Goals New Group Goal Allows users to cre-
Creation ate Group Goals.
Onboarding Object Permissions User Onboarding or Select the options The permissions
Offboarding Object that best fit your you select, deter-
Permissions scenario mine the level of ac-
cess for each type of
onboarding task.
Onboarding Object Permissions User Onboarding or Message Task Allows users to view,
Offboarding Object
set, and update the
Permissions
Welcome Message
for the new hire.
Full permission is
recommended for:
• Hiring manager
• Hiring manag-
er's team
Onboarding Object Permissions User Onboarding or Buddy Task Allows users to view
Offboarding Object
or edit Assign a
Permissions
Buddy activity.
• Hiring manager
Onboarding Object Permissions User Onboarding or Configuration for Allows users to view
Offboarding Object Prepare for Day One
or modify the con-
Permissions Task
figuration for Pre-
pare for Day One
Task.
• Hiring manager
• Hiring manager
• Hiring manager
• Hiring manager
• Hiring manager
• Hiring manager
• Hiring manager
Onboarding Object Permissions User Onboarding or Recommended Link Allows users to view
Offboarding Object Task
or modify recom-
Permissions
mended links.
• Hiring manager
Full permission is
recommended for:
• Hiring manager
• Hiring manager
Onboarding Object Permissions User Onboarding or Goal Task Allows users to set
Offboarding Object
up goals.
Permissions
Full permission is
recommended for:
• Hiring manager
Onboarding Object Permissions User Onboarding or Checklist Task Allows users to cre-
Offboarding Object ate a checklist.
Permissions
Onboarding Object Permissions User Onboarding or Prepare for Day One Allows users to view
Offboarding Object Task or edit supplemental
Permissions items.
Onboarding Object Permissions User Onboarding or Where To Go Task Allows users to view
Offboarding Object or edit supplemental
Permissions item locations.
Onboarding Object Permissions User Onboarding or Document Flow Allows users to view
Offboarding Object
or edit paperwork
Permissions
status.
View permission
recommended for:
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• HR admin
Full permission is
recommended for:
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• HR admin
• System admin
Onboarding Object Permissions User Onboarding or Process Trigger Allows users to trig-
Offboarding Object
ger Onboarding and
Permissions
Offboarding process
flow.
Full permission is
recommended for:
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• Offboarding co-
ordinator
• HR Admin
• System Admin
Onboarding Object Permissions User Onboarding or Asset Task Allows users to list
Offboarding Object
and track the organ-
Permissions
ization's assets that
the employees leav-
ing the organization
must return before
their last working
day.
Full permission is
recommended for:
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• Offboarding co-
ordinator
• HR Admin
• System Admin
Recom-
mendation
Enable Off-
boarding for the
Asset task to
appear.
Onboarding Object Permissions User Onboarding or Document Data Allows users to view
Offboarding Object
or edit New Hire
Permissions
data, and also pro-
vides View permis-
sion to all the users
who would be using
the e-Signature sol-
ution.
View permission is
recommended for:
• Hiring manager
• Hiring manag-
er's manager
• Onboarding co-
ordinator
• HR admin
Onboarding Object Permissions User Onboarding or Knowledge Transfer Allows users to view
Offboarding Object Plan
or modify knowl-
Permissions
edge transfer plan.
Full permission is
recommended for:
• Hiring manager
Onboarding Object Permissions User Onboarding or Knowledge Transfer Allows users to view
Offboarding Object Task
or modify knowl-
Permissions
edge transfer task
activity.
Full permission is
recommended for:
• Hiring manager
Full permission is
recommended for:
• Hiring manager
Onboarding Object Permissions User Onboarding or Equipment Type Allows users to view
Offboarding Object
and edit equipment
Permissions
types.
Full permission is
recommended for:
• Hiring manager
Onboarding Object Permissions User Onboarding or Equipment Type Allows users to view
Offboarding Object Value
and edit equipment
Permissions
type value.
Full permission is
recommended for:
• Hiring manager
Onboarding Email Framework Admin Configure Email Configure Email Email category rep-
Permissions Framework Categories resents a certain
Permissions email template
group, such as
the Buddy Cate-
gory: category for
buddy assignment
and removal. It
also includes rules
for building email
message attributes,
such as recipient
and content.
Onboarding Email Framework Admin Configure Email Configure Email Triggers can be ap-
Permissions Framework Triggers plied as rules for
Permissions sending emails. For
example, Buddy As-
signment Cancella-
tion Trigger: Notify
the assigned buddy
that the task has
been reassigned to a
different colleague.
Onboarding Email Framework Admin Configure Email Configure Email Email Template pro-
Permissions Framework Templates vides a specific
Permissions email form gener-
ated by certain con-
ditions and rules.
Onboarding Email Framework Admin Configure Email Configure Audit Allows users to dis-
Permissions Framework Trail
play a list of emails
Permissions
sent by the system.
Available Actions in-
clude: View Email,
Resend, and Display
Details.
Onboarding Email Framework Admin Configure Email Allow Resend Allows users to trig-
Permissions Framework Emails ger new reminder
Permissions emails and com-
plete or edit the To
and CC fields.
Onboarding Object Permissions Admin Email Framework EmailMessage Allows users the
Object necessary access to
Permissions manage email mes-
sages sent by the
system.
Onboarding Object Permissions Admin Email Framework EmailReminderStat Allows users the
Object e necessary access
Permissions to manage email
reminders to be
sent to the On-
boardee/Employee.
These objects track
an email’s reminder
status and its last
sent timestamp.
Onboarding Object Permissions Admin Email Framework EmailTemplate Allows users the
Object necessary access
Permissions to manage email
forms (or tem-
plates) present in
the system.
Onboarding Object Permissions Admin Email Framework EmailTrigger Allows users the
Object necessary access to
Permissions manage email rules
used for sending
different types of
emails to the New
Hire/Employee.
Onboarding Object Permissions Admin Email Framework EmailTriggerCatego Allows users the
Object ry necessary access to
Permissions manage categories
of emails that are
triggered by the sys-
tem.
Onboarding Compliance User Compliance Object Compliance Form Allows users to add
Permissions Signature a signature to a
compliance form.
Onboarding Employee Central User Employee Data First Name Allows users to
Last Name view the new hire's
first name, last
Status
name, and status
on the Onboarding
dashboard.
Onboarding Object Permissions User Onboarding Object Select the options The permissions
Permissions that best fit your you select, deter-
scenario. mine the level of ac-
cess for each type of
onboarding task.
Onboarding Onboarding/Off- Admin Manage Hires Rehire Inactive Allows users to view
boarding Employee (by the details of former
‘match’ in New employees who are
Hire) identified as poten-
tial matches for re-
hire on old employ-
ment information.
With this permis-
sion, users can
also view the de-
tails of rehires on
old employment on
the Manage Pending
Hires page.
Onboarding Onboarding/Off- Admin Manage Hires Rehire Inactive Allows users to view
boarding Employee with New the details of former
Employment (by employees who are
‘match’ in New identified as poten-
Hire) tial matches for re-
hire with new em-
ployment. With this
permission, users
can also view the
details of rehires
with new employ-
ment information on
the Manage Pending
Hires page.
Onboarding 1.0 Manage Onboard- Admin Manage On/ Manage field Allows users to ac-
ing/Offboarding 1.0 Offboarding 1.0 mapping tool for cess the Admin Cen-
Employee Central ter Field Mapping
tool for Onboard-
ing/Offboarding EC
Integration tool to
define field map-
pings for integrat-
ing Onboarding/Off-
boarding 1.0 with
Employee Central.
Onboarding 1.0 Manage Onboard- Admin Manage On/ Manage Allows users to
ing/Offboarding 1.0 Offboarding 1.0 Onboarding access the Con-
additional content figure new hire
activity planning
process, Maintain
Central Orientation
Meetings, and Main-
tain Lists of Items to
Bring tools in Admin
Center.
Recruiting Recruiting Manage- User Recruiting Onboarding Initiate Allows users to ini-
Onboarding 1.0 ment Permissions Permission tiate onboarding for
a candidate in RCM.
After Onboarding
is successfully initi-
ated, an Onboarding
activity is created
for the candidate in
Onboarding.
Recruiting Recruiting Manage- User Recruiting Onboarding Update Allows users to up-
Onboarding 1.0 ment Permissions Permission
date the Onboarding
activity for custom-
ers using Recruiting
Management – Ver-
ifications Inc. inte-
gration.
Note
This permission
is not relevant
for SAP Suc-
cessFactors
HCM Onboard-
ing.
Recruiting Recruiting Manage- Admin Manage Recruiting Set Up Onboarding Allows users to de-
Onboarding 1.0 ment Integration fine field mappings
for the RCM en-
tity templates: Job
Requisition, Job Of-
fer, and Job Appli-
cation. If you're us-
ing Intelligent Serv-
ices, you get op-
tions for propagat-
ing RCM updates
to Onboarding and
reassigning ongoing
Onboarding activi-
ties.
Onboarding 1.0 Employee Profile User General User SAP Jam Access Allows users to ac-
Permission cess the SAP Suc-
cessFactors JAM
page.
Recruiting MDF Recruiting User MDF Recruiting MDF Objects For View: Quickcard
Permissions Candidate Relation-
icon is displayed if
ship Management:
the information al-
Campaign
ready exists. Other-
CampaignContent
wise, nothing is dis-
CampaignContent
played.
CampaignRecipient
Candidate Follow View and Edit:
CandidateActivity Quickcard icon is
displayed if the in-
formation already
exists. Otherwise a
Create icon is dis-
played.
Import/Export: En-
ables you to
use standard MDF
framework import
and export function-
ality for that object.
The Background
Check Update
Permission allows
users to update
background check
status
Recruiting Recruiting Manage- User MDF Recruiting MDF Objects to en- Enables Candidate
ment Permission able Talent Pool: Relationship Man-
agement talent pool
CampaignPool
features.
Pool Member
Recruiting Recruiting Manage- User MDF Recruiting MDF Object: Pool Edit Yes: Create
ment Permissions
Talent Pool link
is visible and ac-
tive (clickable). The
Talent Pool popup
is opened in Edit
mode. Edit link is al-
ways active, and dy-
namically opens the
Talent Pool popup in
Edit mode (Owner
only) or Read-only
mode (other users).
Edit No:
Row-Level (Sharing)
Permission: Owner
only
Recruiting Recruiting Manage- User MDF Recruiting MDF Object: Share View Yes: Link is visi-
ment Permissions Pool with Group
ble and active (click-
able). Share with
Groups popup can
be opened, show-
ing list of recruiting
groups with which
this pool is shared.
Row-Level (Sharing)
Permission: Owner
only
Recruiting Recruiting Manage- User MDF Recruiting MDF Object: Share View Yes: Link is visi-
ment Permissions Pool with User
ble and active (click-
able). Share with
People popup can
be opened, showing
list of users with
whom this pool is
shared.
Recruiting Recruiting Manage- User MDF Recruiting CRM Saved Search View Yes: Makes List
ment Permissions
of Saved Searches
visible and editable
on the Talent Pool
user interface. List
of saved searches
link is visible and ac-
tive. Backend Utility
(CRMSavedSearch
permission check)
is required. Saved
Searches popup can
be opened, showing
list of saved search
criteria associated
with this pool.
Recruiting Recruiting Manage- Admin Add the Admin Recruiting The Admin role is
ment user to the Admins Permission added to the Admins
group. For the per- group.
mission changes
to take effect,
log out, close the
browser, and log
back in.
Recruiting Recruiting Manage- User In Language Packs, Recruiting Designates the lan-
ment select the lan- Permission guages for Recruit-
guages for Recruit- ing
ing
Recruiting Recruiting Manage- Admin Recruiting Odata API Grants OData API
ment Permissions RCMApplication permissions to an
Export Admin.
Recruiting Recruiting Manage- Admin Recruiting OData API Job Offer Grants permissions
ment Permissions Export to query, create, and
OData API Job Offer update job offers us-
Create
ing OData APIs.
OData API Job Offer
Update Grants permissions
OData API Offer to query and create
Letter Export offer letters using
OData API Offer OData APIs.
Letter Create
Recruiting Recruiting Manage- User Recruiting OData API Validations for re-
ment Permissions Application Create quired fields are ig-
and Update nored so that users
Validation Bypass can skip them when
for Required Fields creating and updat-
ing job applications
using OData API.
Recruiting Recruiting Manage- Admin Manage Recruiting Set Up Job Boards Sets options for job
ment Permission boards.
Recruiting Recruiting Manage- Admin Manage Recruiting Manage Detailed Enables Detailed
ment Requisition Requisition
Reporting Privileges Reporting Privileges.
permission
Recruiting Recruiting Manage- Admin Manage Recruiting Set up Agency Enables the Set Up
ment Access Agency Access page
Recruiting Adminis- to appear in the Ad-
tration min Center. Admin-
istrator can then use
this page to set up
new agencies and
grant permission to
roles. Agency users
can then log in using
the Agency portal.
Recruiting Recruiting Manage- User Recruiting Bulk Create Allows users to bulk
ment Permissions Candidates create candidate
from .CSV File profiles from .CSV
files. Follow instruc-
tions in the guide on
how to enable this
permission.
Platform Intgration Center Admin Manage Allow users Allows users to trig-
Integration Tools to execute
ger any application
"Application/UI"
or Intelligent Serv-
or "Event-based"
Integrations ice event-based in-
tegration. For exam-
ple, to do a back-
ground check of a
candidate before ac-
tually scheduling an
interview, you need
to have an Appli-
cation/UI triggered
integration created
and mapped to a
corresponding back-
ground check ven-
dor. Enable Allow
users to execute
"Application/UI"
or "Event-based"
Integrations permis-
sion to a Recruiter
role to run any Ap-
plication/UI based
integration.
Note
You don't need
these Integra-
tion Center per-
missions to trig-
ger any applica-
tion or Intelli-
gent Service
event-based in-
tegration:
• Admin ac-
cess to
MDF OData
API
• Access to
Integration
Center
• Access to
non-Se-
cured Ob-
jects
Note
You don't need
these Integra-
tion Center per-
missions to ac-
cess Security
Center artifacts:
• Admin ac-
cess to
MDF OData
API
• Allow Ad-
min to Ac-
cess OData
API
through
Basic Au-
thentica-
tion
• Access to
Integration
Center
Platform Document Manage- Admin Manage Document Configure Allows users to de-
ment Categories Document termine which cate-
Management gories of documents
your users have ac-
cess to.
Employee Central Workflows User Manage Workflows Prevent Quick Prevents users from
Approval for mass approving
Workflow their workflow re-
quests in the
Approve Requests
dialog box or on
the My Workflow
Requests page. They
must open each
workflow request,
review the details,
and approve it in-
dividually on the
Workflow Details
page.
Reporting Report Center User Reports Report Center Allows users to view
Permission the Report Center
page, and the con-
solidated list of all
Tiles, Dashboards,
Table reports, and
Canvas reports on
the Report Center
page.
Reporting Classic View User Reports List View Allows users to run
Permission a set of List View
reports. List View re-
ports are not part of
Report Center, and
you can disable this
permission if you no
longer use List View
reports.
Reporting Classic View User Reports Spotlight View Allows users to ac-
Permission cess and run a set
of Spotlight View re-
ports for the data
sets you select.
Reporting Report Center Admin Manage Manage Report Allows users to ac-
Dashboards / Center cess the Manage
Reports Report Center ad-
ministrative page to
control Report Cen-
ter settings.
Reporting Report Center Admin Manage View All Schedules Allows users to see
Dashboards / schedules owned by
Reports all users in the com-
pany.
Reporting Story Report Admin Manage Report Schema Allows users to ac-
Dashboards / Join Manager cess the Report
Reports Schema Join Man-
ager to manage how
different reporting
schemas can be
joined while building
Story type reports.
Platform Proxy Access Admin Manage User Proxy Management Gives users proxy
access to all user
accounts in the tar-
get population.
Allows users to
manage proxy as-
signments for every-
one in the target
population.
Platform Digital Assistant User General User Access to Joule Allows users to ac-
Permission cess Digital Assis-
tant.
Opportunity Mar- Opportunity Mar- User Opportunity Opportunity Allow users to ac-
ketplace ketplace Content Marketplace Marketplace Access cess the Opportu-
Opportunity Mar- nity Marketplace
ketplace Assign- solution.
ments
Opportunity Mar- Opportunity Mar- User Opportunity View Assignments Allow users to view
ketplace ketplace Assign- Marketplace
assignments.
ments
By default, the
View Assignments
permission is ap-
plicable to assign-
ments of all types.
Select Others for
specific types of as-
signments.
Opportunity Mar- Opportunity Mar- User Opportunity Create Allow users to cre-
ketplace ketplace Assign- Marketplace Assignments
ate assignments.
ments
By default, the
Create Assignments
permission is ap-
plicable to assign-
ments of all types.
Select Others for
specific types of as-
signments.
Opportunity Mar- Opportunity Mar- User Opportunity Data Access: Allows users to ac-
ketplace ketplace Assign- Marketplace Story (Opportunity cess data for appli-
ments Marketplace cants who are in
Assignments) their target popula-
tion when users run
an assignment re-
port.
Footnotes notes
Employee Central Employee Central Admin Manage User Allow Retroactive Is used to prevent
Payroll Employee Data
users from making
Compensation Changes
retroactive changes
to employee data,
for example, be-
cause such changes
will cause issues in
payroll.
Platform Digital Assistant Admin Manage System Manage Joule Allows administra-
Properties tors to manage cus-
tom terms.
Platform Dynamic Teams Admin Configure Dynamic Configure Dynamic Enables people to
Teams Teams
access the Dynamic
Teams Configuration
screen and config-
ure the Dynamic
Teams module.
Platform Dynamic Teams Admin Configure Dynamic Admin Access to Enables people in a
Teams Dynamic Teams
Data Protection Offi-
Data
cer role to view Dy-
namic Teams data in
data protection and
privacy reports, like
the Data Subject In-
formation report.
Platform Dynamic Teams Admin Configure Dynamic Access to Dynamic Enables people
Teams Teams Data in
to view Dynamic
People Analytics
Teams data and
OKR data in People
Analytics reports,
for a target popula-
tion.
Platform Dynamic Teams User Dynamic Teams Create, View, and Enables people to
Edit Dynamic
access, create, and
Teams
manage dynamic
teams.
Platform Dynamic Teams User Objectives and Key Create, View, and Enables people to
Results Edit Objectives and
create and man-
Key Results (OKR)
age objectives and
key results (OKRs)
for their dynamic
teams.
Platform Talent Intelligence Admin Manage Talent View Manage Talent Allows administra-
Hub Intelligence Hub Intelligence Hub
tors to view the Tal-
Settings Settings
ent Intelligence Hub
settings.
Platform Talent Intelligence Admin Manage Talent Edit Manage Talent Allows administra-
Hub Intelligence Hub Intelligence Hub
tors to edit the Tal-
Settings Settings
ent Intelligence Hub
settings.
Platform Talent Intelligence Admin Manage Talent Enable Growth Allows administra-
Hub Intelligence Hub Portfolio tors to enable the
Settings Growth Portfolio.
Platform Talent Intelligence Admin Manage Talent Create Tag Allows administra-
Hub Intelligence Hub tors to create tags in
Settings Attributes Library.
Platform Talent Intelligence Admin Manage Talent Edit Tag Allows administra-
Hub Intelligence Hub tors to edits tags in
Settings Attributes Library.
Platform Talent Intelligence Admin Manage Talent Create Attributes Allows administra-
Hub Intelligence hub tors to create attrib-
Settings utes in Attributes Li-
brary.
Platform Talent Intelligence Admin Manage Talent Edit Attributes Allows administra-
Hub Intelligence Hub tors to edit attrib-
Settings utes in Attributes Li-
brary.
Platform Talent Intelligence Admin Manage Talent Delete Attributes Allows administra-
Hub Intelligence Hub tors to delete attrib-
utes in Attributes Li-
brary.
Platform Talent Intelligence Admin Manage Talent Create Attribute Allow administrators
Hub Intelligence Hub Type to create attribute
types in Attributes
Library.
Platform Talent Intelligence Admin Manage Talent Edit Attribute Type Allow administrators
Hub Intelligence Hub to edit attribute
types in Attributes
Library.
Platform Talent Intelligence Admin Manage Talent Create Proficiency Allow administrators
Hub Intelligence Hub Level Scale to create proficiency
level scale in Attrib-
utes Library.
Platform Talent Intelligence Admin Manage Talent Edit Proficiency Allow administrators
Hub Intelligence Hub Level Scale to edit proficiency
level scale in Attrib-
utes Library.
Platform Talent Intelligence Admin Manage Talent Delete Proficiency Allow administrators
Hub Intelligence Hub Level Scale to delete proficiency
level scale in Attrib-
utes Library.
Platform Talent Intelligence User Manage Growth View Tag Allow users to view
Hub Portfolio and tags associated with
Attributes Library the attributes.
Settings
Platform Talent Intelligence User Manage Growth View Attributes Allow users to view
Hub Portfolio and attributes in the
Attributes Library Growth Portfolio.
Settings
Platform Talent Intelligence User Manage Growth View Attribute Type Allow users to view
Hub Portfolio and attribute type in
Attributes Library Growth Portfolio.
Settings
Platform Talent Intelligence User Manage Growth View Proficiency Allow users to view
Hub Portfolio and Level Scale proficiency level
Attributes Library scale.
Settings
Platform Talent Intelligence User Manage Growth View Portfolio Allow users to view
Hub Portfolio and the portfolio, the
Attributes Library capabilities present
Settings in the portfolio,
and the recommen-
dations.
Platform Talent Intelligence User Manage Growth Edit Portfolio Allow users to add
Hub Portfolio and recommended skills
Attributes Library to their portfolio,
Settings set a skill as highly-
interested, and re-
ject skill recommen-
dations.
Opportunity Mar- Opportunity Mar- User Opportunity View all assignment Allow users to all as-
ketplace ketplace Assign- Marketplace details in approval signment details in
ments workflows approval workflows.
If the Competency
object isn't set to se-
cured, this permis-
sion isn't necessary.
Platform Application Secur- Admin Manage Security Manage Interstitial Allow users to man-
ity Allowlist age a list of exter-
nal URLs that can
be accessed without
a warning page in
between using the
Manage Interstitial
Allowlist tool, if the
interstitial feature
is enabled in Provi-
sioning.
Platform Application Secur- Admin Manage Security Manage Application Allow users to en-
ity Security Feature able or disable
Settings settings in the
Application Security
Feature Settings
tool.
Employee Central Diagnostic Tool Admin Admin Center Access Diagnostic Allows users to use
Permissions Tool the Diagnostic Tool
to troubleshoot Em-
ployee Central con-
figuration issues on
their own.
Employee Central Diagnostic Tool Admin Diagnostic Tool Diagnostics Tracing Allows users to ac-
Configuration tivate the Diagnos-
tic Tracing Configu-
ration MDF object to
trace transactions in
Employee Central.
Employee Central Diagnostic Tool Admin Diagnostic Tool Workflows Allows users to ac-
Diagnostics Data
cess workflow trans-
action data to check
the processing stage
for any issues.
Employee Central Diagnostic Tool Admin Diagnostic Tool Centralized Allows users to ac-
Services
cess transactional
Diagnostics Data
data for HRIS enti-
ties, such as ESS or
MSS, to check the
processing stages
for any issues.
Related Information
Context
If you find that users have access to applications or data they should not have, we recommend the following steps:
Procedure
1. Run the View User Permission report to determine how - through which role - the permission was granted to
the employees. For details see Checking Permissions Assigned to a User [page 217]
2. If that does not clarify how/why they have that permission or creates concern about where else this permission
is visible, then use the RBP Permission to User Report with the Single Permission Filter to validate what other
groups have access to this permission. For details see How can you run an ad hoc report? [page 217]
Role-based permissions refresh periodically to propagate any changes to your dynamic groups or to the permission
roles in your system. These changes occur when employees are hired, employees change departments, and during
integration scenarios.
When changes to your employees' information occur in your SAP SuccessFactors HCM suite such as, job title
changes, hiring of new employees, or giving additional responsibilities to employees, your role-based permissions
security platform runs an automated process that propagates these changes in your system. The changes affect
the permission roles that employees have access to and the permission groups they belong to. The Refresh
Framework handles this automated process in your system. Depending on the size of your organization, you may
have a high number of user changes or you could have a relatively low number of user changes in your system. The
refresh framework uses two types of refresh jobs to handle these scenarios.
On-demand mode (Previously called Real-Time Refresh) When changes to user information occur infrequently, each
update action triggers its own refresh job.
The Refresh Framework consists of two types of refresh jobs: the on-demand mode and buffer mode. The refresh
framework automatically adjusts between buffer mode and on-demand mode, based on the actual refresh work
load.
When the workload is light, the framework enables the on-demand job. This is the refresh mode you're most
familiar with as you may currently use it for each refresh request. For example, an API call to change one user
causes a refresh on all user groups.
When the workload is heavy, on-demand mode is disabled and buffer mode is enabled. That means requests within
the next 5 minutes will buffer and reschedule tasks based on the buffer refresh request.
Note
If your company has scheduled a background job to refresh RBP regularly, the scheduled job remains effective
and RBP refresh follows the defined interval. The Refresh Framework doesn't take effect even if you stop the
background job. If you wish to start using the Refresh Framework in your company, contact Product Support.
The Refresh Framework automatically switches between two refresh types depending on the workload detected. If
infrequent user information changes occur, your RBP roles and groups are immediately refreshed. If frequent user
information changes are detected, the buffer mode helps to reduce duplicate requests by collecting delta changes
and processing them in one refresh request. As a result, you experience improved system stability and better RBP
refresh performance. With the buffer mode enabled, you notice little delay.
No. If your organization uses Scheduled Jobs, the Refresh Framework doesn’t impact your system.
Procedure
A list of permissions is displayed along with the roles that grant those permissions.
4. To learn more about the roles, click the pop-up window icon next to any role name.
Procedure
The cross domain ad hoc report capability allows Administrators to run reports between the Role-Based
Permission (RBP) domain and Employee Central (EC) domain. RBP reports are included in the drop-down menu
when selecting the Cross Domain Report Definition types.
Administrators can create Cross Domain Reports to join RBP and Employee Central data. Person and Employment
is the EC domain information that is included and the tables are joined using the user_sys_id key.
User Role Search can search the roles granted to specific users for a specific permission and a target user. When
some users get some permissions on some target users that should not be granted, the administrator can use this
tool to find which role grants the permission so they can update the permission settings.
• This tool does not support MDF RBP permission as search criteria.
• This tool does not support Inactive Internal User or TBH user to be selected as Target User.
• This tool does not support External User.
1. Go to Administration Tools.
2. In the Manage Employees block, select Set User Permissions.
3. In the Set User Permissions section, select User Role Search.
4. In the Selection session of the tool, enter Access Users. You can select at most 2 access users.
5. Select Permission Category and one Permissions. If the permission needs target population, you can optionally
select one target user.
6. Click Search Roles Button. The search result will display all roles that grant this permission and target user
to the access users. If the target user field is empty, the search result will not consider target user. If a
result you expect to see is not showing up, it may be because there are back-end update jobs still running.
session.
You can use User Role Search to quickly search for and compare permission roles assigned to specified users in
role-based permissions.
1. Go to Administration Tools.
2. In the Manage Employees block, select Set User Permissions.
3. In the Set User Permissions section, select User Role Search.
4. In the Selection session of the tool, enter the Access Users whose roles you are comparing.
5. Click Search Roles Button. The search result will display which roles, if any, grant the specified permission to
either user. In the following example, you can see that both of the selected access users have permission to
view address data.
6. If a user does not have the specified permission, it is indicated as "no result." In the following example, you can
see that the user "cgrant" has permission to view "Impact of Loss" data, due to her roles as a manager and
7. You can also specify one target user, in order to see whether either of the two access users
has the specified permission for the specified target. In the following example, you can see that
although both user "cgrant" and user "dsharp" are managers, only user "cgrant" has permission to
view "Impact of Loss" data for user "vstokes". This is because, in this example, the manager role
has a target permission group of "All Direct Reports" and "vstokes" is a direct report of "cgrant".
Learn about changes to the documentation for Using Role-Based Permissions in recent releases.
<1H 2024>
Added Added information about Show All and Comparing Two Change History Records
Show Difference modes in comparing two of a Permission Role [page 40]
history records of permission role.
Changed When RBP administrators create a per- Creating a Permission Role [page 32]
mission role, they can now choose from
the following three user types: Employee,
External Onboarding User, and External
Learner. Previously, only Employee user
type was supported.
Added Added a new permission and two existing List of Role-Based Permissions [page
permissions for scheduled jobs adminis- 42]
trators:
Added Added a new permission and an existing List of Role-Based Permissions [page
permission for administrators: 42]
Added We added a new permission titled Allow List of Role-Based Permissions [page
non-English language users to search in 42]
English for Action Search (Including the
Tools section of Admin Center) for ad-
ministrators to enable the cross-language
lookup functionality.
Added Added a new permission for Development List of Role-Based Permissions [page
Goals administrators and a new permis- 42]
sion for Career Explorer users:
<2H 2023>
Changed We’ve moved the Change History to the Introduction to Using RBP [page 4]
end of the guide.
Added Added new permissions for Onboarding List of Role-Based Permissions [page
custom tasks. 42]
Added Added new permissions for Onboarding List of Role-Based Permissions [page
Compliance metadata objects. 42]
Added Added new permissions for Onboarding List of Role-Based Permissions [page
Compliance APIs. 42]
Added Added the following new user permission: List of Role-Based Permissions [page
Recruiting Permissions OData API 42]
Application Create and Update Validation
Bypass for Required Fields
Added Added a new permission for admins: List of Role-Based Permissions [page
Manage Identity Account and Group 42]
Added Added a new permission for users: List of Role-Based Permissions [page
Manage Onboarding or Offboarding 42]
Added Added a new permission for ad- List of Role-Based Permissions [page
mins: Manage Compensation Structure 42]
Objects
Added Added a new permission for ad- List of Role-Based Permissions [page
42]
mins: Manage Business Configuration
Added Added a new permission for administra- List of Role-Based Permissions [page
42]
tors to manage Digital Assistant:
• Manage Joule
• Access to Joule
Competency
Added Added information that you can see the Managing Permission Groups [page 14]
most recent 1000 changes in the View
change history view. If you want to see
more than the last 1000 changes of a
permission group, use the Change Audit
report.
Hyperlinks
Some links are classified by an icon and/or a mouseover text. These links provide additional information.
About the icons:
• Links with the icon : You are entering a Web site that is not hosted by SAP. By using such links, you agree (unless expressly stated otherwise in your agreements
with SAP) to this:
• The content of the linked-to site is not SAP documentation. You may not infer any product claims against SAP based on this information.
• SAP does not agree or disagree with the content on the linked-to site, nor does SAP warrant the availability and correctness. SAP shall not be liable for any
damages caused by the use of such content unless damages have been caused by SAP's gross negligence or willful misconduct.
• Links with the icon : You are leaving the documentation for that particular SAP product or service and are entering an SAP-hosted Web site. By using such links,
you agree that (unless expressly stated otherwise in your agreements with SAP) you may not infer any product claims against SAP based on this information.
Example Code
Any software coding and/or code snippets are examples. They are not for productive use. The example code is only intended to better explain and visualize the syntax and
phrasing rules. SAP does not warrant the correctness and completeness of the example code. SAP shall not be liable for errors or damages caused by the use of example
code unless damages have been caused by SAP's gross negligence or willful misconduct.
Bias-Free Language
SAP supports a culture of diversity and inclusion. Whenever possible, we use unbiased language in our documentation to refer to people of all cultures, ethnicities, genders,
and abilities.
SAP and other SAP products and services mentioned herein as well as
their respective logos are trademarks or registered trademarks of SAP
SE (or an SAP affiliate company) in Germany and other countries. All
other product and service names mentioned are the trademarks of their
respective companies.
The primary advantage of assigning permission roles based on hierarchical relationships is that it mirrors organizational reporting structures, allowing managers to inherit permissions that fit their supervisory roles efficiently. However, disadvantages include the potential for system performance degradation due to hierarchy checks and increased complexity in managing permissions as hierarchical changes occur. Careful planning and minimal levels of hierarchical assignment can alleviate performance issues and ensure permissions remain relevant and accurate .
When hierarchical relationships are used in permission assignments, it can lead to performance issues as the system must check the hierarchy levels whenever an element access is attempted. This can slow down system performance. To mitigate these issues, it is important to carefully consider and limit the levels of hierarchy where permissions are granted, and avoid assigning broad permissions upwards unnecessarily. Streamlining hierarchy checks by effectively planning the permission structure can also help manage potential performance drawbacks .
Target populations are crucial for permission roles that perform tasks on behalf of other employees. They are defined when a permission role requires them, and the system will indicate this necessity with a 't' icon next to the permission name. Not all permissions require a target population; for instance, access to an application may not need it. Therefore, a role can be restricted to specific target populations or criteria to limit access only to necessary data or tasks .
Excluding granted users from applying permissions to themselves is necessary in sensitive scenarios, such as when a role grants the ability to edit personal data like salary information. This exclusion prevents potential conflicts of interest or data manipulation by removing self-modifying abilities from sensitive permissions. Implementing this ensures integrity and security in data management by maintaining separation between the user and personal action capabilities .
Dynamic permission groups enhance flexibility by allowing real-time adjustments and configurations of group memberships based on attributes such as department, region, or job title. This ability to dynamically assign and reassign users to groups without manually updating each user’s permission reduces administrative overhead and quickly adapts to organizational changes, ensuring the permission system remains aligned with current organizational structure .
Permission roles simplify management by establishing predefined sets of permissions that can be consistently applied to various groups or individuals within an organization. This use of standard roles reduces duplication, prevents errors across varying user groups, and maintains uniformity in access control. Organizations benefit from streamlined processes for updating permissions, consistent application of rules, and a clear overview of access rights, which eases administration of complex and ever-evolving organizational structures .
Creating permission groups before assigning permission roles is recommended because it allows for more streamlined role assignment. By defining groups first, administrators can easily select and assign roles to these pre-defined groups, ensuring that all group members receive the same permissions. This approach benefits organizations by enhancing consistency, reducing errors, and simplifying the management of roles and permissions as roles can be applied across multiple users without needing individual configurations .
To manage and mitigate performance impacts when managers are granted permissions similar to their subordinates, the system can limit hierarchical levels where permissions extend. Additionally, identifying key permissions rather than applying all subordinate permissions can refine performance. Implementing policies that regularly review hierarchical assignments and using performance metrics to adjust permissions dynamically are proactive strategies that help maintain system efficiency without overextending resource checks .
A target population does not need to be defined in a permission role when the permission involves access to non-sensitive applications or tasks that don’t require acting on behalf of another user, such as general application access. The implication of this is that permissions are streamlined for specific tasks, reducing the complexity and potential restrictions in permissions configuration, ensuring only necessary definitions are detailed, which simplifies administrative processes .
Permission groups allow for efficient management by grouping employees who share specific attributes such as department or job code. This way, permission roles can be systematically and consistently assigned across groups rather than individuals. This structured approach simplifies permissions management, reduces redundancy, and ensures that changes affect all necessary users consistently .