Inactive Virus Scan Profile Alert
Inactive Virus Scan Profile Alert
Security Guide
VIMZ230402-GSM-EN-02
OpenText™ Vendor Invoice Management for SAP® Solutions
Security Guide
VIMZ230402-GSM-EN-02
Rev.: 2025-Jan-08
This documentation has been created for OpenText™ Vendor Invoice Management for SAP® Solutions 23.4 SPS2.
It is also valid for subsequent software releases unless OpenText has made newer documentation available with the product,
on an OpenText website, or by any other means.
Tel: +1-519-888-7111
Toll Free Canada/USA: 1-800-499-6544 International: +800-4996-5440
Fax: +1-519-888-0677
Support: [Link]
For more information, visit [Link]
Disclaimer
Every effort has been made to ensure the accuracy of the features and techniques presented in this publication. However,
Open Text Corporation and its affiliates accept no responsibility and offer no warranty whether expressed or implied, for the
accuracy of this publication.
Table of Contents
1 About OpenText Vendor Invoice Management (VIM) for
SAP Solutions ............................................................................ 5
1.1 Architectural Overview ....................................................................... 7
1.2 About this document .......................................................................... 8
1.2.1 Target audience ................................................................................ 8
1.2.2 Further information sources ............................................................... 8
Part 1 Foundation 11
GLS Glossary 49
OpenText Vendor Invoice Management (VIM) for SAP Solutions is an ABAP add-on
solution to SAP S/4HANA. It automates the processing of incoming documents into
SAP.
If the business rules pass, the document is posted in SAP without human
intervention. Although a straight through, no-touch process is the ultimate objective,
OpenText VIM for SAP also supports the fast and efficient handling and resolution
of exceptions. Exceptions are routed via workflow to the relevant user or user group
based on the role assigned to the exception.
For managers, OpenText VIM for SAP offers a comprehensive suite of operational
and analytical reports. In addition, it offers the tools to identify common exceptions
that should be addressed to achieve even higher levels of automation.
• Invoice Solution
• Procure to Pay Solutions
– Order Confirmation
– Delivery Note
– Quotation
• Order to Cash Solutions
– Sales Order
– Remittance Advice
Since OpenText VIM for SAP resides inside SAP, enrichments and business rules
have direct access to SAP master and transactional data, which avoids complex
interfaces and the replication and duplication of data.
VIM Solutions use features offered by its powerful feature rich Foundation.
• Inbound
• Process
• Workplace
• Analytics
Beside the components of this graphic, OpenText VIM for SAP offers additional
components such as SAP NetWeaver Business Warehouse or BW/4Hana for specific
solutions which are not shown in this basis architectural overview.
“Foundation” on page 11
This part provides security-related information that you have to consider for all
Solutions.
“Invoice Solution” on page 29
This part provides security-related information for the Invoice Solution.
• OpenText Vendor Invoice Management for SAP Solutions - User Guide for Invoice
Solution (VIMZ-UGD)
• OpenText Vendor Invoice Management for SAP Solutions - Installation Guide (VIMZ-
IGD)
• OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for
Invoice Solution (VIMZ-CGD)
• OpenText Vendor Invoice Management for SAP Solutions - Administration Guide
(VIMZ-AGD)
• OpenText Vendor Invoice Management for SAP Solutions - Reference Guide for Invoice
Solution (VIMZ-RGD)
• OpenText Vendor Invoice Management for SAP Solutions - Scenario Guide for Invoice
Solution (VIMZ-CCS)
• OpenText Vendor Invoice Management for SAP Solutions - Security Guide (VIMZ-
GSM)
• OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for
Foundation (VIMZ-CGF)
• OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for
Solutions Beyond Invoice (BOCPZ-CCS)
• OpenText Vendor Invoice Management for SAP Solutions - User Guide for Solutions
Beyond Invoice (BOCPZ-UGD)
The Release Notes are updated continuously. The latest version of the Release Notes
is available on OpenText My Support.
On OpenText My Support, you find the Vendor Invoice Management Forum where
you can post questions and discuss issues: [Link]
support/categories/cs-Vendor-Invoice-Management
This part provides security-related information that you have to consider for the
Foundation.
Secure setup
Setting up OpenText VIM for SAP securely includes the following configurations:
For more information about the customization of logical systems that are needed for
trusted RFC connections, see the SAP documentation.
For Web Services connection settings, see Section 12.1.1 “System landscape” in
OpenText Vendor Invoice Management for SAP Solutions - Installation Guide (VIMZ-
IGD).
The configuration described in this section allows you to set up a virus protection
that works directly at the import stage. This means, for example, that PDF files
containing viruses can be avoided in the OCR.
The delivered PIPELINE document handler (for more information, see Section [Link]
“Creating a document handler” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation (VIMZ-CGF)) processes a virus scan
with the /SCMS/KPRO_CREATE virus scan profile within the /OTX/PF01_CL_MODULE_
DOC_VSCAN module class. You can use this module class also within in a custom
document handler to process a virus scan for all available documents in inbound.
All other delivered inbound document handlers process already the same virus scan
profile within standard SAP ArchiveLink® processing.
Note: For further details about Virus Scan Provider, see the SAP
documentation.
SAP supports the integration of Virus Scan. For more information, see the following
SAP notes:
If you use this configuration with the right scan profile, the SAP transaction OAWD
(upload) is protected as well as other ArchiveLink features, for example the call that
is used by the email input.
In the OpenText plugins, archived documents are shown in SAP GUI and HTML
control. Therefore corresponding security settings in SAP must be set correctly.
Service user When setting up the Capture result processing service according to the Foundation
authorizations documentation, you need to grant general MM and FI authorizations to the service
user if Capture is used with OpenText VIM for SAP. Perform this action in addition
to the authorizations listed in the Foundation documentation for authorization
objects S_ICF and J_6NPF_RFC. For more information, see Section [Link].2 “On-
premises: Inbound communication” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation (VIMZ-CGF).
If recognition results are not complete, for example, supplier or company code data
is not populated in general, perform an authorization trace to identify missing
authorizations. For more information about the Capture integration into OpenText
VIM for SAP, see Section 7.2.2 “Configuring the Capture integration for OpenText
VIM for SAP classic mode” in OpenText Vendor Invoice Management for SAP Solutions
- Configuration Guide for Invoice Solution (VIMZ-CGD).
As soon as the validation user has started OpenText™ Windows Validation Client
for SAP® Solutions, the user has to log in to SAP S/4HANA using a prepared SAP
user. This user requires special authorizations. For more information, see
“Configuring authorizations for validation user” on page 17.
You must configure OpenText Core Capture for SAP Solutions connection settings
in OpenText VIM for SAP. These settings enable OpenText VIM for SAP to
communicate with OpenText Core Capture for SAP Solutions. For more information,
see Section [Link].2 “Public cloud: Connection parameters” in OpenText Vendor
Invoice Management for SAP Solutions - Configuration Guide for Foundation (VIMZ-
CGF).
Rest endpoints
The following rest endpoints are used by OpenText VIM for SAP:
– GET /cp-rest
– POST /cp-rest/session/services/designer
– POST /cp-rest/session/services/extractdocument
– POST /cp-rest/session/services/learning
– GET /cp-rest/session/files/{fileId}
– DELETE /cp-rest/session
• Authentication:
– POST /oauth2/token
Data encryption
The following data encryption is provided by OpenText Core Capture for SAP
Solutions:
Per default the Load Manager service runs under Local System. There is no need to
change this setting to a domain user account as long as no remote communication
will be setup.
If you want to use a domain user account for running the service, you must prepare
it before the installation and enter during installation. In this case the Load Manager
Service user must have local administrator rights.
For more information about using the Microsoft Windows user management, see
Best Practice Guide for Securing Active Directory Installations (https://
[Link]/en-us/windows-server/identity/ad-ds/plan/security-best-
practices/best-practices-for-securing-active-directory).
Security-relevant events on the SAP S/4HANA side can be logged using SAP S/
4HANA means.
[Link] Responsibilities
In the OpenText Capture for SAP Solutions system, no real users are involved.
In the OpenText VIM for SAP system, there are additional user types and
responsibilities. For more information, see “Supplier Self Service Fiori apps”
on page 45.
For OpenText™ Business Center Capture for SAP® Solutions, see Section [Link]
“Configuration authorizations for validation user and extraction user” in OpenText
Business Center Capture for SAP Solutions - Administration Guide (CPBC-AGD).
• Full authorization for the J_6NPF_RFC object is required for all users. For more
information, see Section 8.4 “Authorization objects” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Foundation (VIMZ-CGF).
• Authorization for the S_WFAR_OBJ (ACTVT=03) object is required for all users for
the related content repository (OAARCHIV) and document type (OADOKUMENT).
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=SYST
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC1
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC_METADATA
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME= /OTX/PF11_VALIDATION
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME= /OTX/PF01_IF_OCR
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME= /OTX/PF11_ASYNC
• S_TABU_NAM:ACTVT=03,TABLE=V_CURC
As of SAP Basis Release 7.10 you can choose a finer granularity for authorizations.
For more information, see SAP Note 460089. You can execute the authorization
check on individual function modules, instead of entire function groups.
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=SYST
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=RFCPING
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC1
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=RFC_FUNCTION_SEARCH
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC_METADATA
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=RFC_METADATA_GET
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=/OTX/PF01_IF_OCR
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF01_IF_LOOKUP_VAL
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=/OTX/PF11_VALIDATION
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_DATA
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_PROFILES
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_SETTINGS
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_SET_DATA
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/PF11_VAL_LOOKUP
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_ADHOC
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_PAGES
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_SET_TIMEOUT
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=/OTX/PF11_ASYNC
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_ASYNC_SET_VAL_DATA
You can also replace the other function group authorizations by the function module
authorizations but it is not necessary because nearly each function module within
the groups is used.
• Authorization for the S_WFAR_OBJ (ACTVT=03) object is required for all users
for the related content repository (OAARCHIV) and document type
(OADOKUMENT).
• S_TABU_NAM:ACTVT=03,TABLE=V_CURC
For more information, see OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Foundation (VIMZ-CGF).
This part deals with general security aspects that are concerned with OpenText VIM
for SAP as a whole or more than one component. Where applicable, this section adds
links to more detailed descriptions.
During invoice processing, running SAP transactions from within OpenText VIM for
SAP can be required. For example, posting of an invoice in dialog mode results into
the call of FB60 or MIRO transactions. The called standard transactions implement
their own authority checks. This is normally part of the project authorization
concept, but you can adjust it in the context of the implementation.
Note: No legal advice is provided in this document or any other part of the
product documentation. Product documentation does only provide general
technical guidelines that may be relevant to consider if a customer implements
the product and is looking to define their strategy towards GDPR and similar
data protection requirements.
Software solutions like OpenText VIM for SAP cannot be considered to be or not to
be GDPR compliant. Every customer using SAP S/4HANA and OpenText VIM for
SAP is responsible to provide GDPR compliance in their organization.
SAP S/4HANA already provides a superior level of user security and data protection
features. OpenText VIM for SAP as an add-on package profits from the high
standard of SAP S/4HANA compared to outside-in solutions with their own
database, duplication of data, and lower level security concepts.
For more information about GDPR, see Section 2 “General Data Protection
Regulation (GDPR)” in OpenText Vendor Invoice Management for SAP Solutions -
Scenario Guide for Invoice Solution (VIMZ-CCS).
OpenText VIM for SAP offers tools to delete vendor specific entries from some core
customizing tables as well as from the run time tables.
The following documentation sections explain the tools available in OpenText VIM
for SAP to delete specific user data and specific vendor information in tables:
For further details, see Section [Link] “Maintaining version settings” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Foundation
(VIMZ-CGF) (AUTH_CHECK_DATA method) and Section [Link].1 “Authorization
Exit” in OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide
for Foundation (VIMZ-CGF).
In the context of Fiori Task Apps, the following authorization objects are required:
For details about authorization of the Fiori Task Apps of the Invoice Solution
component, see “Fiori Task Apps” on page 43.
In the context of Fiori Element Apps, the following authorization objects are
required:
– OAOBJEKTE = /OTX/PF01R
– ACTVT = 03
– ACTVT = 03
• Authorization object S_APPL_LOG with following fields:
– ALG_OBJECT = /OTX/PF00
– ALG_SUBOBJ = /OTX/PF01
– ACTVT = 03
This part covers security-related information for the OpenText VIM for SAP Invoice
Solution.
Process steps The OpenText VIM for SAP business process typically includes the following main
steps:
1. An OCR process (optional) sends metadata and invoice image to OpenText VIM
for SAP. On a system without OCR, the invoice images go through a standard
SAP ArchiveLink® early archiving scenario.
2. The Document Processing (DP) component validates the metadata and identifies
exceptions.
3. Invoice Exception workflows address the exception issues.
4. After validating the data and handling data exceptions, OpenText VIM for SAP
creates an SAP invoice.
5. If no business rules are violated, OpenText VIM for SAP posts the invoice.
Note: Only end user screens are translated in additional languages other than
English. Customizing screens are provided in English language only.
Validate data
The index data is validated against the SAP database. If validation fails, an
exception is triggered.
Check duplicates
The validated data is used to check whether the new invoice has been entered
already. If the new invoice is suspected to be a duplicate of any existing invoice,
an exception is triggered.
Apply business rules
Invoice pre-processing: Business rules are applied to detect additional
exceptions before posting.
Post for payment
The invoice is posted and released for payment.
This part deals with general security aspects that are concerned with OpenText VIM
for SAP as a whole or more than one component. Where applicable, this section adds
links to more detailed descriptions.
In the reports, in the indexing screen, and in VIM Invoice Workplace, the
authorization checks ensure that SAP users working with OpenText VIM for SAP
are able to see and process only the information that they are authorized for. In the
COA maintenance, the authorization checks make sure that the user is allowed to
display or maintain the entries.
For backward compatibility reasons, the authorization checks are disabled in the
standard configuration. You can enable them on demand as described in Section
6.3.3 “Enabling OpenText VIM for SAP authorization checks globally” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution
(VIMZ-CGD).
Important
Invoice Solution performs invoice data processing in the background with
tasks run by the technical workflow user WF-BATCH or SAP_WFRT. If the technical
user does not have administrator permissions (the role SAP_ALL), all
authorizations for invoice processing must be assigned to SAP_ALL and such
configuration must be thoroughly tested.
Building such authorization profile can be complex and is specific to a project,
you can use authorization check trace to determine the required
authorizations.
Roles typically used for invoice processing are delivered in BC sets and are normally
created during OpenText VIM for SAP installation. This configuration must be
verified and restricted if needed, depending on your process.
Tip: The standard Refer to... dialog might allow invoice processors to modify
the agent list. This depends on the process option override settings. Similarly,
Invoice Approval has options that can allow to override the next approver
automatically. You must verify the use of these override options and switch
them off if they are unwanted.
OpenText VIM for SAP provides the following method for Invoice Approval:
Level-based This method is considered only for Non PO document types. For PO document
approval types, a one-step approval is provided by default.
For more information, see Section 10.4.4 “Configuring approval flow settings” in
OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice
Solution (VIMZ-CGD).
COA configura- In level-based approval, COA details are checked when the user opens the work
tion item. That means that changes in the COA details are automatically reflected in the
Invoice Approval screen. When a task is performed, the next approval steps are
automatically determined according to the actual setting. Therefore, changes to user-
specific COA details are not critical. Changing or renaming a User ID might be
critical.
Purpose COA is required in the Invoice Approval process to allow users to approve Non PO
invoices. The data combination maintained in the COA helps to determine the
correct approver for a certain invoice in the approval process.
For details on how to configure the COA for level-based Invoice Approval, see
Section 4.1.4 “Maintaining Chart of Authority” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
This description includes the following major aspects of the COA:
COA The COA maintenance transactions for Invoice Approval allow you to restrict the
maintenance data that is displayed and maintained by checking authorization for company code
authorization
checks
and user groups (from SAP user master records). In addition, using the
authorization checks by company code allows to maintain COA in parallel, as long
as different maintaining users are responsible for different company codes. For more
information, see Section 6.2.2 “COA maintenance” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
This chapter deals with security aspects that are concerned with specific
components. Where applicable, this section adds links to more detailed descriptions.
Monitoring au- Some authorizations are needed to monitor Inbound Configuration. For more
thorization information, see the example in Section 8.4 “Authorization objects” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Foundation
(VIMZ-CGF).
Validation Validation might be required for an ArchiveLink document type. If you do not use a
agent custom logic to determine the validator, you must assign the corresponding agent to
the ArchiveLink document type. This way, you can determine who is allowed to see
what. If this is not enough, implement a project specific user exit. For more
information, see Section 5.2.5 “Assigning an agent to an ArchiveLink document
type” in OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide
for Foundation (VIMZ-CGF).
Button actions
These actions are defined as single or bulk action buttons within the process
output list button toolbar.
Output Field actions
These actions are defined as executable icons or hotspots within the process
output list itself.
VIM Invoice VIM Invoice Workplace provides the concept of action authority groups. For more
Workplace au- information, see Section 16.4 “Defining action authority groups for the VIM Invoice
thorization
checks
Workplace” in OpenText Vendor Invoice Management for SAP Solutions - Configuration
Guide for Invoice Solution (VIMZ-CGD).
VIM Invoice Workplace supports several authorization checks that allow you to
restrict different functions. For example, you can restrict the use of other users’ view.
When VIM Invoice Workplace is started, an authorization check is performed.
Note: Running actions in other users’ view may require you to have additional
SAP authorizations. In particular, this refers to the authorization for the SWIA
transaction and potentially for other workflow administration functions. These
checks are imposed by SAP if you are managing work items of other users.
Teams in VIM In the VIM Invoice Workplace, special team-related functionalities are available
Invoice based on the following different types of possible team definitions:
Workplace
Personal Team
Maintained by each user directly in the VIM Invoice Workplace team
configuration dialog box.
General Team
Generally maintained by an administrator. Users cannot change the general
team in the VIM Invoice Workplace team configuration dialog box.
For more information, see Section 16.7 “Maintaining general teams for the VIM
Invoice Workplace” in OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Invoice Solution (VIMZ-CGD).
Authorization A Scan button is available in VIM Invoice Workplace. It allows you to scan new
for scanning invoices directly from the VIM Invoice Workplace interface. For necessary
prerequisites regarding authorization, see Section 16.5 “Configuring scanning in
VIM Invoice Workplace” in OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Invoice Solution (VIMZ-CGD).
However, you can create a role to view the configuration with “display only”
authorization. For more information, see Section 7.6.1 “Creating a role for OpenText
VIM for SAP configuration display” in OpenText Vendor Invoice Management for SAP
Solutions - Administration Guide (VIMZ-AGD).
9.5 Transactions
Regarding domains, transactions, and the roles that have access to transactions,
adjusting the authorizations for OpenText VIM for SAP users might be necessary.
Also be aware of the Authorization objects. For more information, see Section 23
“Transaction profiles for various roles” in OpenText Vendor Invoice Management for
SAP Solutions - Reference Guide for Invoice Solution (VIMZ-RGD).
AFS For information about authorizations in the context of approval flow settings (AFS),
see Section 10.4.4 “Configuring approval flow settings” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
Troubleshoot- Symptom: When referring an invoice with the Wait for feedback check box set, the
ing invoice is not moved into the resubmission folder. Reason: This can happen if
authorizations are missing.
Security config- On the Configuration tab of the Admin console, a dedicated area Security
uration Configuration is available.
To prevent Click Jacking and Cross Site Request Forgery (CSRF), there is a
corresponding check box available on the Configuration tab of the Admin console.
For Click Jacking, the X-FRAME options have been restricted to same origin. For
more information, see Section [Link] “Configuration” in OpenText Vendor Invoice
Management for SAP Solutions - Administration Guide (VIMZ-AGD).
NetWeaver If you deploy the Approval Portal inside of the SAP NetWeaver Portal, NetWeaver
user authenti- user authentication will take place. For more information, see the SAP
cation
documentation. In this scenario, two views are normally created, one for approvals
and one for administrative tasks like setting up server connections. Make sure the
roles are assigned to proper users.
CPIC SAP user Approval Portal, in both J2EE and NetWeaver portal deployment scenarios, runs
OpenText VIM for SAP application logic of all portal users using the same CPIC SAP
user. To prevent misuse of dialog transactions, OpenText recommends that you
create this user as a system user and not a dialog user. You must create a profile
with some authorization objects and add it to the CPIC user. For more information,
see Section 16.1.1 “Installation prerequisites” in OpenText Vendor Invoice Management
for SAP Solutions - Installation Guide (VIMZ-IGD).
Authorization When SAP GUI perfectly displays the invoice image and when only Approval Portal
issues with shows the error message when viewing the image, cross-check that the necessary
CPIC
authorizations are granted for the logged-in user in viewing the images. For more
information, see Section [Link].1 “Authorization issues with CPIC” in OpenText
Vendor Invoice Management for SAP Solutions - Administration Guide (VIMZ-AGD).
Application logs Approval Portal logs the information about Protocols, Security, and other actions
performed on the application. For more information, see Section [Link].1
Web Viewer For integration of OpenText™ Imaging Web Viewer (Web Viewer) in the Mobile
Approval Portal and related security aspects, see Section 17.3 “Installing Web
Viewer for the Mobile Approval Portal” in OpenText Vendor Invoice Management for
SAP Solutions - Installation Guide (VIMZ-IGD).
9.9 Reports
Reports, including VIM Analytics and central reporting, allow you to restrict the
displayed data by checking authorization for company code. For more information,
see Section 6.2.1 “Reporting” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
Confirm Quantity and Price app, Enter Cost Assignment Advanced app, Approve
Invoices app, Approve Invoices (bulk mode) app, My Approved Invoices app,
Vendor Invoices Report app
An SAP user account is required to use the app. The SAP user account must be
available on the SAP FIORI UI / Gateway system and also on the SAP S/4HANA
system having the following authorization objects minimum.
The authorization for the OData service /OTX/PF05_DATA is described in App
and OData service specific authorizations on page 25.
The SAP user account which is used on the SAP S/4HANA system requires the
following:
Notes
• The SAP user must have the identical user name on both systems.
• Within the COA, each user using the app must have assigned a
corresponding SAP user.
Gateway users Users of the SAP NetWeaver Gateway are grouped in roles, which are needed for
several other configurations. There is no restriction on the number and names of
roles created for SAP NetWeaver Gateway. You must enhance the roles of the users
in your SAP NetWeaver Gateway system with the authorizations contained in the
authorization template /IWFND/RT_GW_USER. For more information, see Section 23.1.3
“Configuring Gateway users” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
Gateway The Supplier Self Service On-Premise option allows the UI5 repository to be
service authori- uploaded on the Gateway server as a BSP application. The On-Premise URL is
zation
generated for the BSP application with default HTML, and the application is
accessed using this URL.
For information how to bypass authorization issues for the service path, see Section
23.1.7 “Configuring the Gateway service authorization” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
Vendor cleanup The vendor cleanup program for Supplier Self Service has been created to clean up
vendors data based on selection criteria.
The program provides built-in checks to ensure that only OpenText VIM for SAP
specific data is modified or deleted. The program also provides a specific
authorization check. The authorization object is J_6NIM_CA6. For more information,
see Section 23.7 “Vendor cleanup program for Supplier Self Service” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution
(VIMZ-CGD).
User Self To implement User Self Service, you must have users with proper authorizations to
Service create and to maintain the users in SAP NetWeaver AS ABAP. The following table
shows the different types of users:
For more information, see Section [Link] “Security aspects of User Self Service” in
OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice
Solution (VIMZ-CGD).
Template User You need to maintain a reference Template User, which must be present in both SAP
Gateway and SAP Business Suite systems. This Template User must have the roles
and authorizations required for the Supplier Invoices app. For more information, see
Section [Link] “User Self Service roles and authorizations” in OpenText Vendor
Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-
CGD).
9.13 Z constants
Various Z constants deal with authorization topics, see the following list:
• ALV_CHECK_ACTIVE
• AUTH_CHECK_ACTIVE
• SPROGRAM_CHECK_ACTIV
• SRFC_CHECK_ACTIV
For more information, see Section 38 “Z constants for product code 002 and 009”
in OpenText Vendor Invoice Management for SAP Solutions - Reference Guide for
Invoice Solution (VIMZ-RGD).
Product code 005
• PROPOSAL_ONE_VENDOR
For more information, see Section 39 “Z constants for product code 005” in
OpenText Vendor Invoice Management for SAP Solutions - Reference Guide for Invoice
Solution (VIMZ-RGD).
This utility includes an authorization check in reporting. For more information, see
Section 14 “Posted invoice reversal with a new DP workflow start” in OpenText
Vendor Invoice Management for SAP Solutions - Scenario Guide for Invoice Solution
(VIMZ-CCS)
9.17 Translation
Roles For information about authorization aspects of the SAP developer role and the
translator role, see Section 12.1 “Roles and responsibilities” in OpenText Vendor
Invoice Management for SAP Solutions - Scenario Guide for Invoice Solution (VIMZ-CCS).
Translator When creating translator profiles, each profile can include one or more
profiles authorizations. For more information, see Section 12.3.5 “Creating a translator
profile” in OpenText Vendor Invoice Management for SAP Solutions - Scenario Guide for
Invoice Solution (VIMZ-CCS).
After Image
Technical option to realize an delta upload from the source systems into the SAP
NetWeaver BW system. A data record loaded as After Image provides the status
of the record after it has been changed, or after data has been added.
Aging Report
Part of the Central Reporting infrastructure. The Aging Report reports about the
aging of documents and work items in the current system.
Approval Portal
Web interface for approving invoices.
Archive system
Computer system that enables storage, management and retrieval of archived
data and documents
ArchiveLink
Service integrated in the SAP NetWeaver Application Server ABAP for linking
archived documents and the application documents entered in the SAP ERP
system.
Authorization profiles
The SAP administrator assigns authorizations to the users that determine which
actions a user can perform in the SAP system. These authorizations are stored in
Authorization profiles.
Automation Report
Tool that provides data about automated and manual processing steps of
documents
BAdI
BAPI®
SAP programming interface: Business Application Programming Interface
Baseline
Set of functionality with predefined configuration and the starting point to
implement OpenText VIM for SAP.
BasisCube
See: InfoCube
BDC ID
Business Data Communication ID. The BDC ID is used by the system to process
an SAP transaction to create an SAP Document in user context.
Block
Situation where an invoice has a price or quantity variance that prevents invoice
from posting
BSP
BTE
Business rules
Rules that describe the operations, definitions and constraints that apply to an
organization
Capture
Common technical term for both of the following products: OpenText Core
Capture for SAP Solutions and OpenText Capture for SAP Solutions.
Central Reporting
Reporting infrastructure that provides several reports that enable you to measure
certain properties of documents and their work items, in order to optimize
working with OpenText VIM for SAP. Central Reporting comprises the following
individual reports: Aging Report, Central Audit Report, Exception Analysis Report,
Key Process Analytics Report, Productivity Report, and Summary Report.
Characteristic
Type of InfoObject in SAP NetWeaver BW that represents descriptions of fields,
such as Vendor ID, Invoice Number, Unit of Measure, and Posting Date.
COA
Coding
Coding allocates an invoice to G/L account and cost object if required.
Dashboard
User interface that organizes and presents information in a way that is easy to
read. Users can also perform actions from the dashboard.
DataSource
Set of fields in SAP NetWeaver BW that provide the data for a business unit for
data transfer to the SAP NetWeaver BW system; technically, it contains an extract
structure and an extraction function module.
DocuLink
OpenText™ DocuLink for SAP Solutions enables the archiving, management and
retrieval of SAP CRM or SAP S/4HANA documents from within the SAP
infrastructure.
Document type
Type of document such as PO, Non PO, OCR, Non OCR
DP
DSO
DTP
EDI
Exception
Action that is not part of normal operations or standards
FI
IAP
IDoc
IE
Inbound Configuration
Connection to various inbound channels, for example scanned paper documents,
fax, email, or IDoc, and the corresponding configuration.
Indexing
Process of entering or storing data into the system
InfoArea
Folder in SAP NetWeaver BW to organize InfoCubes, DataStore Objects, InfoObjects,
and InfoObject Catalogs
InfoCube
Self-contained dataset in SAP NetWeaver BW, for example, of a business-oriented
area; an InfoCube is a quantity of relational tables arranged according to the
enhanced star schema: A large fact table in the middle surrounded by several
dimension tables
InfoObject Catalog
Folder structure in SAP NetWeaver BW to organize InfoObjects
InfoObject
Smallest information unit in SAP NetWeaver BW. Key figures and Characteristics
are collectively called InfoObjects.
InfoPackages
Object in SAP NetWeaver BW that specifies when and how to load data from a
given source system to the SAP NetWeaver BW system
InfoProvider
Object in SAP NetWeaver BW for which queries can be created or executed.
InfoProviders are the objects or views that are relevant for reporting.
Invoice characteristic
A value specific to each invoice (for example country) that allows flexible
processing. An invoice characteristic is determined during runtime and depends
on the corresponding index data of the document.
Invoice coder
Person who enters the accounting info on invoices to allocate the cost
Invoice requester
Person who requested goods and services for Non PO invoices
Key Figure
Type of InfoObject in SAP NetWeaver BW that represents numeric values or
quantities, such as Number of Invoices and Gross Invoice Amount.
LIV
MM
MultiProvider
Object in SAP NetWeaver BW that is based on InfoCube(s), DataStore Object(s),
and/or InfoObject(s). A MultiProvider is used as a layer for the creation of end user
queries; the MultiProvider itself does not contain any data; rather, data resides in
the BasisCubes.
Namespace
Name range reserved by SAP for customer objects and SAP objects to make sure
that objects are not overwritten by SAP objects during the import of corrections or
an upgrade
Number range
Array of numbers that can be used for an object in the SAP S/4HANA system
OCR
Park
Situation where an invoice is not posted and is waiting for further processing
Perspective
Web Services element that defines which item related data is displayed in the
Fiori Task App and where. A perspective defines the content and visual
appearance of items for a specific area of the screen in the Fiori Task App. The
Fiori Task App displays only one perspective at the same time.
PO
Price variance
Situation where the price on the invoice is different from the price in the purchase
order
Process Chain
Sequence of processes in SAP NetWeaver BW that are scheduled to wait in the
background for an event; used to automate, visualize and monitor the processes.
Process Configuration
Easy and technically simplified configuration of complex business scenario
aspects. Process Configuration covers profile configuration, profile assignment,
and authorizations.
Process Foundation
Flexible framework to configure and run processes. It utilizes generic workflow
definitions, which are processed by the SAP Business Workflow engine.
Process options
Processing options for the user in the dashboard, such as Referral, Authorization,
and Actions
Process type
Process type for a document. The process type determines the initial actor and
various collaboration options available to the various actors during the process
flow.
Productivity Report
Part of the Central Reporting infrastructure. The Productivity Report reports
about the productivity of users/roles and the activities of users/roles.
PSA
Quantity variance
Situation where the quantity on the invoice is different from the quantity in the
purchase order
Roles
Set of predefined roles for the SAP user
Scan operator
Person who scans the invoices into images (may not have a SAP ID)
Summary Report
Part of the Central Reporting infrastructure. The Summary Report provides a
summary of all documents processed through OpenText VIM for SAP.
Technical catalog
SAP term: Repository for creating role-specific business catalogs
Transformation (TRF)
Object in SAP NetWeaver BW to connect source objects to data targets; it allows
to consolidate, cleanse and integrate data
TRF
VAN
Web Services
Underlying technical concept of the Fiori Task App interface. You configure the
complete content of the Fiori Task App either by customizing or by implementing
an interface for the Web Services.
Workflow
SAP Business Workflows can be used to define business processes that are not yet
mapped in the SAP S/4HANA system.