0% found this document useful (0 votes)
53 views60 pages

Inactive Virus Scan Profile Alert

The OpenText Vendor Invoice Management (VIM) for SAP Solutions Security Guide provides essential security-related information for the Foundation and Invoice Solution components, applicable to version 23.4 SPS2 and later. It covers secure setup, connections, import, storage, and general security aspects, targeting SAP administrators involved in customization and implementation. The document also includes references to additional resources and guidelines for ensuring a secure environment for processing vendor invoices within SAP systems.

Uploaded by

Hemant Kulkarni
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
53 views60 pages

Inactive Virus Scan Profile Alert

The OpenText Vendor Invoice Management (VIM) for SAP Solutions Security Guide provides essential security-related information for the Foundation and Invoice Solution components, applicable to version 23.4 SPS2 and later. It covers secure setup, connections, import, storage, and general security aspects, targeting SAP administrators involved in customization and implementation. The document also includes references to additional resources and guidelines for ensuring a secure environment for processing vendor invoices within SAP systems.

Uploaded by

Hemant Kulkarni
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

OpenText™ Vendor Invoice Management

for SAP® Solutions

Security Guide

Find security-related information for the Foundation and


Invoice Solution components.

VIMZ230402-GSM-EN-02
OpenText™ Vendor Invoice Management for SAP® Solutions
Security Guide
VIMZ230402-GSM-EN-02
Rev.: 2025-Jan-08
This documentation has been created for OpenText™ Vendor Invoice Management for SAP® Solutions 23.4 SPS2.
It is also valid for subsequent software releases unless OpenText has made newer documentation available with the product,
on an OpenText website, or by any other means.

Open Text Corporation

275 Frank Tompa Drive, Waterloo, Ontario, Canada, N2L 0A1

Tel: +1-519-888-7111
Toll Free Canada/USA: 1-800-499-6544 International: +800-4996-5440
Fax: +1-519-888-0677
Support: [Link]
For more information, visit [Link]

© 2025 Open Text


Patents may cover this product, see [Link]

Disclaimer

No Warranties and Limitation of Liability

Every effort has been made to ensure the accuracy of the features and techniques presented in this publication. However,
Open Text Corporation and its affiliates accept no responsibility and offer no warranty whether expressed or implied, for the
accuracy of this publication.
Table of Contents
1 About OpenText Vendor Invoice Management (VIM) for
SAP Solutions ............................................................................ 5
1.1 Architectural Overview ....................................................................... 7
1.2 About this document .......................................................................... 8
1.2.1 Target audience ................................................................................ 8
1.2.2 Further information sources ............................................................... 8

Part 1 Foundation 11

2 Secure setup ............................................................................ 13


2.1 Secure connections ......................................................................... 13
2.2 Secure import ................................................................................. 13
2.3 Secure storage ............................................................................... 14
2.4 Capture integration .......................................................................... 14
2.4.1 OpenText Core Capture for SAP Solutions ....................................... 15
2.4.2 OpenText Capture for SAP Solutions ............................................... 16
[Link] User management and authorization concept ................................... 16
[Link] Authorizations for validation user ...................................................... 16
[Link] Logging of security-relevant events .................................................. 16
[Link] Encryption of communication channels ............................................. 17
[Link] Secure configuration ....................................................................... 17
[Link] Responsibilities ............................................................................... 17
2.4.3 Configuring authorizations for validation user .................................... 17
[Link] Authorizations for OpenText Windows Validation Client for SAP
Solutions ........................................................................................ 17
[Link] Authorizations for Fiori Capture Validation ........................................ 19

3 General security aspects ........................................................ 21


3.1 Preparing configuration ................................................................... 21
3.2 General authorization checks ........................................................... 21
3.3 General Data Protection Regulation (GDPR) ..................................... 22

4 Configuring authorization settings ........................................ 23

5 Authorization objects of the Fiori Task Apps ....................... 25

6 Authorization objects of the Fiori Element Apps ................. 27

Part 2 Invoice Solution 29

7 Understanding the Invoice Solution ...................................... 31


7.1 Delivery model ................................................................................ 31
7.2 Workflow scheme ............................................................................ 33

VIMZ230402-GSM-EN-02 Security Guide iii


Table of Contents

8 General security aspects ........................................................ 35


8.1 Specific authorization checks ........................................................... 35
8.2 Chart of Authority (COA) .................................................................. 36

9 Security aspects of specific components ............................. 39


9.1 Inbound Configuration ..................................................................... 39
9.2 VIM Invoice Workplace .................................................................... 40
9.3 Substitutes in the workflow processes .............................................. 41
9.4 Roles for the SAP early watch service .............................................. 41
9.5 Transactions ................................................................................... 41
9.6 Invoice Approval ............................................................................. 41
9.7 Approval Portal ............................................................................... 42
9.8 Mobile Approval Portal .................................................................... 43
9.9 Reports .......................................................................................... 43
9.10 Fiori Task Apps ............................................................................... 43
9.11 Supplier Self Service ....................................................................... 44
9.12 Supplier Self Service Fiori apps ....................................................... 45
9.13 Z constants ..................................................................................... 46
9.14 Vendor data cleanup program .......................................................... 46
9.15 Standard posting of invoices ............................................................ 46
9.16 Posted invoice reversal with a new DP workflow start ........................ 47
9.17 Translation ..................................................................................... 47

GLS Glossary 49

iv OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Chapter 1
About OpenText Vendor Invoice Management (VIM)
for SAP Solutions

OpenText Vendor Invoice Management (VIM) for SAP Solutions is an ABAP add-on
solution to SAP S/4HANA. It automates the processing of incoming documents into
SAP.

Document-centric business processes like the processing of incoming invoices from


vendors or incoming sales orders from customers are typical use cases. After
capture, data is enriched and validated against predefined business rules.

If the business rules pass, the document is posted in SAP without human
intervention. Although a straight through, no-touch process is the ultimate objective,
OpenText VIM for SAP also supports the fast and efficient handling and resolution
of exceptions. Exceptions are routed via workflow to the relevant user or user group
based on the role assigned to the exception.

For managers, OpenText VIM for SAP offers a comprehensive suite of operational
and analytical reports. In addition, it offers the tools to identify common exceptions
that should be addressed to achieve even higher levels of automation.

OpenText VIM for SAP includes the following solutions:

• Invoice Solution
• Procure to Pay Solutions

– Order Confirmation
– Delivery Note
– Quotation
• Order to Cash Solutions

– Sales Order
– Remittance Advice

Each solution consists of a best practice implementation for a specific document


scenario. It includes preconfigured mapping rules, enrichment rules, business rules,
user roles and user actions. Learning-based enrichments features embedded easy to
configure machine learning that automates input based on previous user input.

Since OpenText VIM for SAP resides inside SAP, enrichments and business rules
have direct access to SAP master and transactional data, which avoids complex
interfaces and the replication and duplication of data.

VIMZ230402-GSM-EN-02 Security Guide 5


Chapter 1 About OpenText Vendor Invoice Management (VIM) for SAP Solutions

Each solution offers a Workplace to manage and monitor outstanding and


completed work items. Each solution includes a preconfigured set of analytical
measures tailored for the specific document scenario. Solutions can be enhanced to
support company-specific business requirements.

VIM Solutions use features offered by its powerful feature rich Foundation.

VIM Foundation consists of the following components:

• Inbound
• Process
• Workplace
• Analytics

OpenText VIM for SAP offers you a wide range of functionality:

• It supports custom solutions where a preconfigured solution is not available for a


specific, less common business process.
• It offers a simple and intuitive user interface.
• You can choose between the classic SAP GUI or the modern SAP Fiori interface.
SAP Fiori offers a responsive web-based user interface that supports desktop and
mobile devices.
• It supports various input channels including scan, fax¸ email and web services.
• It supports various input formats, including paper, PDF, TIFF, IDoc and XML.
• It requires an ArchiveLink-compliant SAP-certified content repository for the
storage of incoming documents. OpenText recommends OpenText™ Archiving
and Document Access for SAP Solutions or OpenText™ Core Archive for SAP®
Solutions for the storage of documents.
• It integrates seamlessly via its Inbound component with OpenText™ Core
Capture for SAP Solutions and OpenText™ Capture for SAP® Solutions, which

6 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


1.1. Architectural Overview

use advanced machine learning algorithms to extract metadata from imaged-


based documents like PDF and TIFF.
• It offers integration with OpenText Content Management for SAP Solutions and
OpenText Document Presentment for SAP Solutions.

1.1 Architectural Overview


The following figure gives an overview of the basis architecture. It shows how the
core components are integrated into SAP and which additional OpenText
components like Document Pipeline, Document Storage, Capture, and WebViewer
complete the solution.

Note: Capture is used in this documentation as a common technical term for


both of the following OpenText products:

• OpenText™ Capture for SAP® Solutions


• OpenText™ Core Capture for SAP Solutions

Beside the components of this graphic, OpenText VIM for SAP offers additional
components such as SAP NetWeaver Business Warehouse or BW/4Hana for specific
solutions which are not shown in this basis architectural overview.

Figure 1-1: Technical system landscape

VIMZ230402-GSM-EN-02 Security Guide 7


Chapter 1 About OpenText Vendor Invoice Management (VIM) for SAP Solutions

1.2 About this document


The Security Guide provides an overview of security and authorization aspects of
OpenText VIM for SAP. Where appropriate, the document adds links to more
detailed descriptions in other guides.

The Security Guide comprises the following parts:

“Foundation” on page 11
This part provides security-related information that you have to consider for all
Solutions.
“Invoice Solution” on page 29
This part provides security-related information for the Invoice Solution.

1.2.1 Target audience


This document addresses those who participate in the customization and
implementation of OpenText VIM for SAP with a special focus on security aspects.
This includes:

• SAP Basis Administrators


• SAP Workflow Administrators
• SAP Configuration and Development Support

1.2.2 Further information sources


Product docu- The following documentation is available on OpenText My Support (https://
mentation [Link]/csm?id=kb_article_view&sysparm_article=KB0778393):

• OpenText Vendor Invoice Management for SAP Solutions - User Guide for Invoice
Solution (VIMZ-UGD)
• OpenText Vendor Invoice Management for SAP Solutions - Installation Guide (VIMZ-
IGD)
• OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for
Invoice Solution (VIMZ-CGD)
• OpenText Vendor Invoice Management for SAP Solutions - Administration Guide
(VIMZ-AGD)
• OpenText Vendor Invoice Management for SAP Solutions - Reference Guide for Invoice
Solution (VIMZ-RGD)
• OpenText Vendor Invoice Management for SAP Solutions - Scenario Guide for Invoice
Solution (VIMZ-CCS)
• OpenText Vendor Invoice Management for SAP Solutions - Security Guide (VIMZ-
GSM)

8 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


1.2. About this document

• OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for
Foundation (VIMZ-CGF)
• OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for
Solutions Beyond Invoice (BOCPZ-CCS)
• OpenText Vendor Invoice Management for SAP Solutions - User Guide for Solutions
Beyond Invoice (BOCPZ-UGD)

Release Notes Release Notes describe:

• The software supported by the product


• Requirements
• Restrictions
• Important dependencies
• New features
• Known issues
• Fixed issues
• Documentation extensions

The Release Notes are updated continuously. The latest version of the Release Notes
is available on OpenText My Support.

On OpenText My Support, you find the Vendor Invoice Management Forum where
you can post questions and discuss issues: [Link]
support/categories/cs-Vendor-Invoice-Management

Important note for SAP Reseller Customers

For information about all OpenText products resold by SAP (including


OpenText VIM for SAP), check SAP Marketplace Note 1791874: SAP Products
by OpenText - Software and Support Lifecycle. This note provides detailed
information about software life cycle, access to Support Packages, access to
latest documentation, language packages, and other patches, as well as
Support ticket handling.

VIMZ230402-GSM-EN-02 Security Guide 9


Part 1
Foundation
Part 1 Foundation

This part provides security-related information that you have to consider for the
Foundation.

12 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Chapter 2

Secure setup

Setting up OpenText VIM for SAP securely includes the following configurations:

• “Secure connections” on page 13


• “Secure import” on page 13
• “Secure storage” on page 14
• “Capture integration” on page 14

2.1 Secure connections


To connect to systems like SAP systems, or OpenText™ Archive Center, OpenText
recommends that you always use a secure connection, for example a trusted RFC
destination between SAP S/4HANA® systems.

For more information about the customization of logical systems that are needed for
trusted RFC connections, see the SAP documentation.

For Web Services connection settings, see Section 12.1.1 “System landscape” in
OpenText Vendor Invoice Management for SAP Solutions - Installation Guide (VIMZ-
IGD).

2.2 Secure import


Inject documents only from secure channels. It is your task to avoid getting wrong
data into the system.

The configuration described in this section allows you to set up a virus protection
that works directly at the import stage. This means, for example, that PDF files
containing viruses can be avoided in the OCR.

The delivered PIPELINE document handler (for more information, see Section [Link]
“Creating a document handler” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation (VIMZ-CGF)) processes a virus scan
with the /SCMS/KPRO_CREATE virus scan profile within the /OTX/PF01_CL_MODULE_
DOC_VSCAN module class. You can use this module class also within in a custom
document handler to process a virus scan for all available documents in inbound.
All other delivered inbound document handlers process already the same virus scan
profile within standard SAP ArchiveLink® processing.

Note: For further details about Virus Scan Provider, see the SAP
documentation.

VIMZ230402-GSM-EN-02 Security Guide 13


Chapter 2 Secure setup

SAP supports the integration of Virus Scan. For more information, see the following
SAP notes:

• 786179 - Data security products: Application in the antivirus area (https://


[Link]/#/notes/786179)
• 817623 - Frequent questions about VSI in SAP applications (https://
[Link]/#/notes/817623)

This is not specific but applies to SAP S/4HANA in general.

If you use this configuration with the right scan profile, the SAP transaction OAWD
(upload) is protected as well as other ArchiveLink features, for example the call that
is used by the email input.

2.3 Secure storage


Configure document archiving and document access in a proper way. SAP standard
takes care about security topics but you must set up the system in the correct way.

In the OpenText plugins, archived documents are shown in SAP GUI and HTML
control. Therefore corresponding security settings in SAP must be set correctly.

Note: For further details about ArchiveLink, see Section 3 “Configuring


ArchiveLink” in OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Invoice Solution (VIMZ-CGD).

2.4 Capture integration


Capture solutions include OpenText Core Capture for SAP Solutions and OpenText
Capture for SAP Solutions. Validation aspects apply to both solutions.

Service user When setting up the Capture result processing service according to the Foundation
authorizations documentation, you need to grant general MM and FI authorizations to the service
user if Capture is used with OpenText VIM for SAP. Perform this action in addition
to the authorizations listed in the Foundation documentation for authorization
objects S_ICF and J_6NPF_RFC. For more information, see Section [Link].2 “On-
premises: Inbound communication” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation (VIMZ-CGF).

If recognition results are not complete, for example, supplier or company code data
is not populated in general, perform an authorization trace to identify missing
authorizations. For more information about the Capture integration into OpenText
VIM for SAP, see Section 7.2.2 “Configuring the Capture integration for OpenText
VIM for SAP classic mode” in OpenText Vendor Invoice Management for SAP Solutions
- Configuration Guide for Invoice Solution (VIMZ-CGD).

14 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


2.4. Capture integration

2.4.1 OpenText Core Capture for SAP Solutions


Authorizations for validation user

As soon as the validation user has started OpenText™ Windows Validation Client
for SAP® Solutions, the user has to log in to SAP S/4HANA using a prepared SAP
user. This user requires special authorizations. For more information, see
“Configuring authorizations for validation user” on page 17.

Host names for services

You must configure OpenText Core Capture for SAP Solutions connection settings
in OpenText VIM for SAP. These settings enable OpenText VIM for SAP to
communicate with OpenText Core Capture for SAP Solutions. For more information,
see Section [Link].2 “Public cloud: Connection parameters” in OpenText Vendor
Invoice Management for SAP Solutions - Configuration Guide for Foundation (VIMZ-
CGF).

Data center OpenText Core Capture for SAP Authentication


Solutions
Europe [Link] [Link]
US (legacy) [Link] [Link]
US GCP [Link] [Link]
CA GCP [Link] [Link]
AU GCP [Link] [Link]

Rest endpoints

The following rest endpoints are used by OpenText VIM for SAP:

• OpenText Core Capture for SAP Solutions:

– GET /cp-rest
– POST /cp-rest/session/services/designer
– POST /cp-rest/session/services/extractdocument
– POST /cp-rest/session/services/learning
– GET /cp-rest/session/files/{fileId}
– DELETE /cp-rest/session
• Authentication:

– POST /oauth2/token

Data encryption

The following data encryption is provided by OpenText Core Capture for SAP
Solutions:

VIMZ230402-GSM-EN-02 Security Guide 15


Chapter 2 Secure setup

• In flight: HTTPS/TLS 1.2


• At rest: AES-256

2.4.2 OpenText Capture for SAP Solutions


[Link] User management and authorization concept
OpenText Capture for SAP Solutions has no own user management. It uses
Microsoft Windows user management. It is not possible to define or change
Microsoft Windows users within OpenText Capture for SAP Solutions. Provide the
required user accounts using the respective Microsoft Windows if needed.

Per default the Load Manager service runs under Local System. There is no need to
change this setting to a domain user account as long as no remote communication
will be setup.

If you want to use a domain user account for running the service, you must prepare
it before the installation and enter during installation. In this case the Load Manager
Service user must have local administrator rights.

For more information about using the Microsoft Windows user management, see
Best Practice Guide for Securing Active Directory Installations (https://
[Link]/en-us/windows-server/identity/ad-ds/plan/security-best-
practices/best-practices-for-securing-active-directory).

[Link] Authorizations for validation user


As soon as the validation user has started OpenText Windows Validation Client for
SAP Solutions, the user has to log in to SAP S/4HANA using a prepared SAP user.
For the necessary authorizations, see “Configuring authorizations for validation
user” on page 17.

[Link] Logging of security-relevant events


Because the system uses the Microsoft Windows user management, you can use the
Microsoft Windows features to log security events in the Microsoft Windows event
folder. To define which security events should be logged by Microsoft Windows,
implement an audit policy. For more information, see the Microsoft Windows Server
2016 Security Guide ([Link]
D3D6-410A-8B51-81C7FC9A727C/
Windows_Server_2016_Security_Guide_EN_US.pdf).

Security-relevant events on the SAP S/4HANA side can be logged using SAP S/
4HANA means.

16 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


2.4. Capture integration

[Link] Encryption of communication channels


All participants communicate with the Inbound Configuration in SAP S/4HANA by
HTTP or HTTPS, depending on the configuration of the web service.

[Link] Secure configuration


The system provides a secure configuration by default:

• All application specific configuration is stored in SAP S/4HANA.


• The core of the system, known as Inbound Configuration/Inbound Handler, is a
component of SAP S/4HANA.
• The repository is part of the SAP S/4HANA system.
• HTTPS communication can be setup with or without the use of client certificates.

[Link] Responsibilities
In the OpenText Capture for SAP Solutions system, no real users are involved.

In the OpenText VIM for SAP system, there are additional user types and
responsibilities. For more information, see “Supplier Self Service Fiori apps”
on page 45.

2.4.3 Configuring authorizations for validation user


This section defines the authorizations required for users in OpenText Windows
Validation Client for SAP Solutions, and Capture Validation in Fiori.

For OpenText™ Business Center Capture for SAP® Solutions, see Section [Link]
“Configuration authorizations for validation user and extraction user” in OpenText
Business Center Capture for SAP Solutions - Administration Guide (CPBC-AGD).

[Link] Authorizations for OpenText Windows Validation Client for SAP


Solutions
As soon as the validation user has started OpenText Windows Validation Client for
SAP Solutions, the user has to log in to SAP S/4HANA using a prepared SAP user.
This user needs the following authorizations:

• Full authorization for the J_6NPF_RFC object is required for all users. For more
information, see Section 8.4 “Authorization objects” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Foundation (VIMZ-CGF).
• Authorization for the S_WFAR_OBJ (ACTVT=03) object is required for all users for
the related content repository (OAARCHIV) and document type (OADOKUMENT).
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=SYST
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC1
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC_METADATA

VIMZ230402-GSM-EN-02 Security Guide 17


Chapter 2 Secure setup

• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME= /OTX/PF11_VALIDATION
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME= /OTX/PF01_IF_OCR
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME= /OTX/PF11_ASYNC
• S_TABU_NAM:ACTVT=03,TABLE=V_CURC

As of SAP Basis Release 7.10 you can choose a finer granularity for authorizations.
For more information, see SAP Note 460089. You can execute the authorization
check on individual function modules, instead of entire function groups.

You can replace the following authorizations:

• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=SYST
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=RFCPING
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC1
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=RFC_FUNCTION_SEARCH
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=RFC_METADATA
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=RFC_METADATA_GET
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=/OTX/PF01_IF_OCR
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF01_IF_LOOKUP_VAL
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=/OTX/PF11_VALIDATION
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_DATA
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_PROFILES
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_SETTINGS
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_SET_DATA
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/PF11_VAL_LOOKUP
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_ADHOC
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_GET_PAGES
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_VAL_SET_TIMEOUT
• S_RFC:ACTVT=16,RFC_TYPE=FUGR,RFC_NAME=/OTX/PF11_ASYNC
replace with
S_RFC:ACTVT=16,RFC_TYPE=FUNC,RFC_NAME=/OTX/
PF11_ASYNC_SET_VAL_DATA

18 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


2.4. Capture integration

You can also replace the other function group authorizations by the function module
authorizations but it is not necessary because nearly each function module within
the groups is used.

[Link] Authorizations for Fiori Capture Validation


Validation users require the following authorizations when working with the
Capture Validation in Fiori:

• Authorization for the S_WFAR_OBJ (ACTVT=03) object is required for all users
for the related content repository (OAARCHIV) and document type
(OADOKUMENT).
• S_TABU_NAM:ACTVT=03,TABLE=V_CURC

For more information, see OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Foundation (VIMZ-CGF).

The Capture Validation in Fiori submits validated documents asynchronously by


default in order to speed up processing for validation users. For further details, see
Section 4.1 “Customizing basic settings for Inbound Configuration” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Foundation
(VIMZ-CGF).

Asynchronous submit processing requires the following authorizations:

• Authorization object S_RFC with RFC_TYPE = FUNC, RFC_NAME = /OTX/


PF32_CAPT_VAL_SUBMIT_ASYN, ACTVT = 16
• Authorization object J_6NPF_RFC with ACTVT = 02

VIMZ230402-GSM-EN-02 Security Guide 19


Chapter 3
General security aspects

This part deals with general security aspects that are concerned with OpenText VIM
for SAP as a whole or more than one component. Where applicable, this section adds
links to more detailed descriptions.

The following security aspects are covered in this part:

• “Preparing configuration” on page 21


• “General authorization checks” on page 21
• “General Data Protection Regulation (GDPR)” on page 22

3.1 Preparing configuration


During the preparation phase, you need to create User IDs with appropriate
developer and configuration authorizations.

3.2 General authorization checks


When implementing OpenText VIM for SAP, OpenText recommends that you
restrict the access to administrative (configuration) transactions and utilities reports
through SAP authority checks like S_TCODE and S_PROGRAM. Ideally, invoice
processors should be restricted, in addition to the authorizations for standard SAP
transactions, to performing workflow items either from the SAP inbox or VIM
Invoice Workplace. For more information, see “Specific authorization checks”
on page 35.

During invoice processing, running SAP transactions from within OpenText VIM for
SAP can be required. For example, posting of an invoice in dialog mode results into
the call of FB60 or MIRO transactions. The called standard transactions implement
their own authority checks. This is normally part of the project authorization
concept, but you can adjust it in the context of the implementation.

VIMZ230402-GSM-EN-02 Security Guide 21


Chapter 3 General security aspects

3.3 General Data Protection Regulation (GDPR)


The General Data Protection Regulation (GDPR) is a new European Union (EU) law
that gives residents greater protection and control of their personal data. It will
regulate the data that companies in and outside the EU can collect, store, and
transfer, and how they use it. All companies that process EU resident data must be
ready to comply when the GDPR enforcement starts on May 25, 2018.

Note: No legal advice is provided in this document or any other part of the
product documentation. Product documentation does only provide general
technical guidelines that may be relevant to consider if a customer implements
the product and is looking to define their strategy towards GDPR and similar
data protection requirements.

Software solutions like OpenText VIM for SAP cannot be considered to be or not to
be GDPR compliant. Every customer using SAP S/4HANA and OpenText VIM for
SAP is responsible to provide GDPR compliance in their organization.

SAP S/4HANA already provides a superior level of user security and data protection
features. OpenText VIM for SAP as an add-on package profits from the high
standard of SAP S/4HANA compared to outside-in solutions with their own
database, duplication of data, and lower level security concepts.

For more information about GDPR, see Section 2 “General Data Protection
Regulation (GDPR)” in OpenText Vendor Invoice Management for SAP Solutions -
Scenario Guide for Invoice Solution (VIMZ-CCS).

OpenText VIM for SAP offers tools to delete vendor specific entries from some core
customizing tables as well as from the run time tables.

The following documentation sections explain the tools available in OpenText VIM
for SAP to delete specific user data and specific vendor information in tables:

• Section [Link] “Usermap and COA cleanup” in OpenText Vendor Invoice


Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-
CGD)
• Section 8.3.1 “Vendor data cleanup program” in OpenText Vendor Invoice
Management for SAP Solutions - Administration Guide (VIMZ-AGD)
• Section 23.7 “Vendor cleanup program for Supplier Self Service” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice
Solution (VIMZ-CGD)

22 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Chapter 4

Configuring authorization settings

Foundation is delivered with new authorization objects. The SAP authorization


object SAP_ALL must be re-generated to apply the authorizations to this object.

Foundation delivers the following general authorization objects.

Authorization Description Usage


object
J_6NPF_NAV Checks navigation in workplace according to VIM Central
workplace ID. For more information, see Workplace
OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation
(VIMZ-CGF).
J_6NPF_WTY Checks work object type with related actions, VIM Central
functions, and nodes. For more information, see Workplace
OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation
(VIMZ-CGF).
J_6NPF_PRF Checks the process configuration profile with Processing Screen
profile ID, characteristic attribute, and process Business Process
step. For more information, see OpenText Vendor
Invoice Management for SAP Solutions -
Configuration Guide for Foundation (VIMZ-CGF).
J_6NPF_PRJ Checks the authorized project ID. For more Displaying Data in
information, see OpenText Vendor Invoice the Query or
Management for SAP Solutions - Configuration Analytics Reports
Guide for Foundation (VIMZ-CGF).
J_6NPF_ADM Is checked in all administrative reports, Administration
transactions, and programs. For more
information, see OpenText Vendor Invoice
Management for SAP Solutions - Configuration
Guide for Foundation (VIMZ-CGF).
J_6NPF_RFC Is checked in all RFC functions and executable Processing
programs. For more information, see OpenText
Vendor Invoice Management for SAP Solutions -
Configuration Guide for Foundation (VIMZ-CGF).

For further details, see Section [Link] “Maintaining version settings” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Foundation
(VIMZ-CGF) (AUTH_CHECK_DATA method) and Section [Link].1 “Authorization
Exit” in OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide
for Foundation (VIMZ-CGF).

VIMZ230402-GSM-EN-02 Security Guide 23


Chapter 5
Authorization objects of the Fiori Task Apps

In the context of Fiori Task Apps, the following authorization objects are required:

App and OData service specific authorizations


You can assign necessary authorizations with the assignment of the catalogs to
the user roles.
For more information, see the SAP Help: SAP Fiori: App Implementation / User
Management and Authorization / Recommendations for Organizing SAP Fiori
UI Entities and Authorizations.
S_RFCACL
Authorization for trusted systems. The user must have authorizations for the
RFC connection between front end and back end system. Values for this
authorization object depend on your system landscape.
S_RFC
Access to function groups in name space /OTX/P* is required. For the Invoice
Solution component, additional authorization for function groups in name
space /OPT/* and /ORS/* is required.
Depending on business case and scenario settings, access to further function
groups might be required. The used function modules and groups depend on
the tasks performed by the user. Therefore not all users require the authorization
for all these function modules and groups.
To setup a more detailed authorization concept, OpenText recommends that you
follow the guidelines in the SAP Help: RFC/ICF Security Guide / RFC
Scenarios / RFC Communication Between SAP Systems / Authorizations /
Creating an Authorization Concept for RFC.

For details about authorization of the Fiori Task Apps of the Invoice Solution
component, see “Fiori Task Apps” on page 43.

VIMZ230402-GSM-EN-02 Security Guide 25


Chapter 6
Authorization objects of the Fiori Element Apps

In the context of Fiori Element Apps, the following authorization objects are
required:

Manage Inbound Documents

• Authorization object S_WFAR_OBJ with following fields:

– OAOBJEKTE = /OTX/PF01R

– ACTVT = 03

– OAARCHIV = <related content repository>

– OADOKUMENT = <related document type>

• Authorization object /OTX/PFIAC with following fields:

– /OTX/PFIHD = <related inbound document handler>


– /OTX/PFICS = <related capture scenario>

– /OTX/PFICP = <related capture profile>


– OADOKUMENT = <related document type>

– /OTX/PFIAC = <manage inbound document action>


• Authorization object J_6NPF_RFC with following fields:

– ACTVT = 03
• Authorization object S_APPL_LOG with following fields:

– ALG_OBJECT = /OTX/PF00
– ALG_SUBOBJ = /OTX/PF01

– ACTVT = 03

Maintain Staging Company Code Addresses


Authorization for the /OTX/PSBKR (ACTVT=03) object is required for all users for
the related company code (BUKRS).
Maintain Staging Customer Addresses
Authorization for the /OTX/PSKUN (ACTVT=03) object is required for all users for
the related customer (KUNNR).
Maintain Staging Plant Addresses
Authorization for the /OTX/PSWRK (ACTVT=03) object is required for all users for
the related plant (WERKS).

VIMZ230402-GSM-EN-02 Security Guide 27


Chapter 6 Authorization objects of the Fiori Element Apps

Maintain Staging Vendor Addresses


Authorization for the /OTX/PSLFR (ACTVT=03) object is required for all users for
the related vendor (LIFNR).

28 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Part 2
Invoice Solution
Part 2 Invoice Solution

This part covers security-related information for the OpenText VIM for SAP Invoice
Solution.

30 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Chapter 7
Understanding the Invoice Solution

Process steps The OpenText VIM for SAP business process typically includes the following main
steps:

1. An OCR process (optional) sends metadata and invoice image to OpenText VIM
for SAP. On a system without OCR, the invoice images go through a standard
SAP ArchiveLink® early archiving scenario.
2. The Document Processing (DP) component validates the metadata and identifies
exceptions.
3. Invoice Exception workflows address the exception issues.
4. After validating the data and handling data exceptions, OpenText VIM for SAP
creates an SAP invoice.
5. If no business rules are violated, OpenText VIM for SAP posts the invoice.

7.1 Delivery model


As OpenText VIM for SAP is basically a scenario, its function may best be described
as a problem solution. It enables the flexible configuration of a company's payment
workflow. To this end, OpenText VIM for SAP is delivered with a so-called Baseline
Configuration, a set of predefined configurations that work out of the box. In
conjunction with other OpenText products such as OpenText™ Archive Center it is
possible to realize comprehensive solutions. Core Functions are the technical
foundation of OpenText VIM for SAP: SAP screens, functions, workflow templates,
web pages, and so on.

VIMZ230402-GSM-EN-02 Security Guide 31


Chapter 7 Understanding the Invoice Solution

Note: Only end user screens are translated in additional languages other than
English. Customizing screens are provided in English language only.

32 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


7.2. Workflow scheme

7.2 Workflow scheme

Figure 7-1: Workflow scheme

Each workflow process has the same basic steps:

Validate data
The index data is validated against the SAP database. If validation fails, an
exception is triggered.
Check duplicates
The validated data is used to check whether the new invoice has been entered
already. If the new invoice is suspected to be a duplicate of any existing invoice,
an exception is triggered.
Apply business rules
Invoice pre-processing: Business rules are applied to detect additional
exceptions before posting.
Post for payment
The invoice is posted and released for payment.

VIMZ230402-GSM-EN-02 Security Guide 33


Chapter 8
General security aspects

This part deals with general security aspects that are concerned with OpenText VIM
for SAP as a whole or more than one component. Where applicable, this section adds
links to more detailed descriptions.

The following security aspects are covered in this part:

• “Specific authorization checks” on page 35


• “Chart of Authority (COA)” on page 36

8.1 Specific authorization checks


OpenText VIM for SAP implements authorization checks in several reports, for the
COA maintenance transaction /OPT/AR_COA, for the indexing screen, and for VIM
Invoice Workplace.

In the reports, in the indexing screen, and in VIM Invoice Workplace, the
authorization checks ensure that SAP users working with OpenText VIM for SAP
are able to see and process only the information that they are authorized for. In the
COA maintenance, the authorization checks make sure that the user is allowed to
display or maintain the entries.

For backward compatibility reasons, the authorization checks are disabled in the
standard configuration. You can enable them on demand as described in Section
6.3.3 “Enabling OpenText VIM for SAP authorization checks globally” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution
(VIMZ-CGD).

With authorization checks activated, the information in the corresponding reports


and in VIM Invoice Workplace is filtered according to the settings. The documents
or work items for which the user is not authorized will not be shown. The COA
maintenance transaction also filters out unauthorized records and displays a
warning in this case.

An additional authorization check with the object J_6NIM_BRO is done in VIM


Analytics to control the execution based on the fields ROUTE_ID1 and ROUTE_ID2. For
more information, see Section 8.1 “Routing documents with the route ID” in
OpenText Vendor Invoice Management for SAP Solutions - Scenario Guide for Invoice
Solution (VIMZ-CCS).

For a comprehensive description of authorization checks, see Section 6


“Authorization checks” in OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Invoice Solution (VIMZ-CGD). This description includes the
following major aspects of authorization checks:

VIMZ230402-GSM-EN-02 Security Guide 35


Chapter 8 General security aspects

• Available authorization checks


• Configuring the authorization checks
• Authorization group for tables
• Authorization checks when performing transaction calls
• Authorization checks for RFC calls
• Restricting ALV layout for process logs

Important
Invoice Solution performs invoice data processing in the background with
tasks run by the technical workflow user WF-BATCH or SAP_WFRT. If the technical
user does not have administrator permissions (the role SAP_ALL), all
authorizations for invoice processing must be assigned to SAP_ALL and such
configuration must be thoroughly tested.
Building such authorization profile can be complex and is specific to a project,
you can use authorization check trace to determine the required
authorizations.

8.2 Chart of Authority (COA)


Roles and COA OpenText VIM for SAP provides means to direct invoices to specific persons or
groups, depending on the invoice data. Roles are used in DP and invoice exceptions
workflows. The responsibility based (COA) setup is used in Invoice Approval. This
helps to ensure that the data gets processed by the right agents, and misuse chances
are minimized. For more information, see Section 4 “Roles” in OpenText Vendor
Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-
CGD).

Roles typically used for invoice processing are delivered in BC sets and are normally
created during OpenText VIM for SAP installation. This configuration must be
verified and restricted if needed, depending on your process.

Tip: The standard Refer to... dialog might allow invoice processors to modify
the agent list. This depends on the process option override settings. Similarly,
Invoice Approval has options that can allow to override the next approver
automatically. You must verify the use of these override options and switch
them off if they are unwanted.

OpenText VIM for SAP provides the following method for Invoice Approval:

Level-based This method is considered only for Non PO document types. For PO document
approval types, a one-step approval is provided by default.

For more information, see Section 10.4.4 “Configuring approval flow settings” in
OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice
Solution (VIMZ-CGD).

36 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


8.2. Chart of Authority (COA)

COA configura- In level-based approval, COA details are checked when the user opens the work
tion item. That means that changes in the COA details are automatically reflected in the
Invoice Approval screen. When a task is performed, the next approval steps are
automatically determined according to the actual setting. Therefore, changes to user-
specific COA details are not critical. Changing or renaming a User ID might be
critical.

Purpose COA is required in the Invoice Approval process to allow users to approve Non PO
invoices. The data combination maintained in the COA helps to determine the
correct approver for a certain invoice in the approval process.

For details on how to configure the COA for level-based Invoice Approval, see
Section 4.1.4 “Maintaining Chart of Authority” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).
This description includes the following major aspects of the COA:

• User Details View


• Approval Limit/Level View
• COA Details View
• Coder Settings view
• Setting up a substitute for the IAP process
• Logging with change documents
• COA upload report
• Usermap and COA cleanup
• Maintaining COA - alternative transaction

COA The COA maintenance transactions for Invoice Approval allow you to restrict the
maintenance data that is displayed and maintained by checking authorization for company code
authorization
checks
and user groups (from SAP user master records). In addition, using the
authorization checks by company code allows to maintain COA in parallel, as long
as different maintaining users are responsible for different company codes. For more
information, see Section 6.2.2 “COA maintenance” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

VIMZ230402-GSM-EN-02 Security Guide 37


Chapter 9
Security aspects of specific components

This chapter deals with security aspects that are concerned with specific
components. Where applicable, this section adds links to more detailed descriptions.

The following security aspects are covered in this part:

• “Inbound Configuration” on page 39


• “VIM Invoice Workplace” on page 40
• “Substitutes in the workflow processes” on page 41
• “Roles for the SAP early watch service” on page 41
• “Transactions” on page 41
• “Invoice Approval” on page 41
• “Approval Portal” on page 42
• “Mobile Approval Portal” on page 43
• “Reports” on page 43
• “Fiori Task Apps” on page 43
• “Supplier Self Service” on page 44
• “Supplier Self Service Fiori apps” on page 45
• “Z constants” on page 46
• “Vendor data cleanup program” on page 46
• “Standard posting of invoices” on page 46
• “Posted invoice reversal with a new DP workflow start” on page 47
• “Translation” on page 47

9.1 Inbound Configuration


Inbound Configuration has replaced the Incoming Document Handling (IDH)
framework. For a comprehensive description of the Inbound Configuration, see
Section 4 “Inbound Configuration” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Foundation (VIMZ-CGF).

Monitoring au- Some authorizations are needed to monitor Inbound Configuration. For more
thorization information, see the example in Section 8.4 “Authorization objects” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Foundation
(VIMZ-CGF).

VIMZ230402-GSM-EN-02 Security Guide 39


Chapter 9 Security aspects of specific components

Validation Validation might be required for an ArchiveLink document type. If you do not use a
agent custom logic to determine the validator, you must assign the corresponding agent to
the ArchiveLink document type. This way, you can determine who is allowed to see
what. If this is not enough, implement a project specific user exit. For more
information, see Section 5.2.5 “Assigning an agent to an ArchiveLink document
type” in OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide
for Foundation (VIMZ-CGF).

9.2 VIM Invoice Workplace


Protected The VIM Invoice Workplace allows the following types of actions, which can be
actions protected using special authority checks:

Button actions
These actions are defined as single or bulk action buttons within the process
output list button toolbar.
Output Field actions
These actions are defined as executable icons or hotspots within the process
output list itself.

VIM Invoice VIM Invoice Workplace provides the concept of action authority groups. For more
Workplace au- information, see Section 16.4 “Defining action authority groups for the VIM Invoice
thorization
checks
Workplace” in OpenText Vendor Invoice Management for SAP Solutions - Configuration
Guide for Invoice Solution (VIMZ-CGD).

VIM Invoice Workplace supports several authorization checks that allow you to
restrict different functions. For example, you can restrict the use of other users’ view.
When VIM Invoice Workplace is started, an authorization check is performed.

Note: Running actions in other users’ view may require you to have additional
SAP authorizations. In particular, this refers to the authorization for the SWIA
transaction and potentially for other workflow administration functions. These
checks are imposed by SAP if you are managing work items of other users.

Teams in VIM In the VIM Invoice Workplace, special team-related functionalities are available
Invoice based on the following different types of possible team definitions:
Workplace

Personal Team
Maintained by each user directly in the VIM Invoice Workplace team
configuration dialog box.
General Team
Generally maintained by an administrator. Users cannot change the general
team in the VIM Invoice Workplace team configuration dialog box.

For more information, see Section 16.7 “Maintaining general teams for the VIM
Invoice Workplace” in OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Invoice Solution (VIMZ-CGD).

40 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


9.3. Substitutes in the workflow processes

Authorization A Scan button is available in VIM Invoice Workplace. It allows you to scan new
for scanning invoices directly from the VIM Invoice Workplace interface. For necessary
prerequisites regarding authorization, see Section 16.5 “Configuring scanning in
VIM Invoice Workplace” in OpenText Vendor Invoice Management for SAP Solutions -
Configuration Guide for Invoice Solution (VIMZ-CGD).

9.3 Substitutes in the workflow processes


Substitutes can be set up for the SAP inbox and for the Invoice Approval (IAP)
process. If a work item owner is on vacation or leaves the company, the substitute
can “adopt” the work items owned by the substituted user. For more information,
see Section 5.1 “Setting up substitutes for workflow processes” in OpenText Vendor
Invoice Management for SAP Solutions - Administration Guide (VIMZ-AGD).

9.4 Roles for the SAP early watch service


The SAP early watch service checks and analyzes in order to optimize the
performance of SAP solutions. Since OpenText VIM for SAP resides inside the SAP
S/4HANA system, it follows standard early watch practices. Client dependent
configuration data of OpenText VIM for SAP is not visible in the early watch client
and the early watch client is normally locked against any configuration changes.

However, you can create a role to view the configuration with “display only”
authorization. For more information, see Section 7.6.1 “Creating a role for OpenText
VIM for SAP configuration display” in OpenText Vendor Invoice Management for SAP
Solutions - Administration Guide (VIMZ-AGD).

9.5 Transactions
Regarding domains, transactions, and the roles that have access to transactions,
adjusting the authorizations for OpenText VIM for SAP users might be necessary.
Also be aware of the Authorization objects. For more information, see Section 23
“Transaction profiles for various roles” in OpenText Vendor Invoice Management for
SAP Solutions - Reference Guide for Invoice Solution (VIMZ-RGD).

9.6 Invoice Approval


Company code Processing invoice approval dialog tasks and background workflow steps involves
authorization authorization checks on the company code of the invoice with the authorization
object J_6NIM_BC1. Users that intend to process dialog steps need to have company
code specific authorization assigned to their profile. The background workflow user,
WF-BATCH or SAP_WFRT, must be allowed to process the steps for all company codes.
For more information, see Section 10.1 “Overview” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

AFS For information about authorizations in the context of approval flow settings (AFS),
see Section 10.4.4 “Configuring approval flow settings” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

VIMZ230402-GSM-EN-02 Security Guide 41


Chapter 9 Security aspects of specific components

Troubleshoot- Symptom: When referring an invoice with the Wait for feedback check box set, the
ing invoice is not moved into the resubmission folder. Reason: This can happen if
authorizations are missing.

For more information, see Section 9.10 “Troubleshooting Invoice Approval” in


OpenText Vendor Invoice Management for SAP Solutions - Administration Guide (VIMZ-
AGD).

9.7 Approval Portal


Single sign on Browser authentication is possible through a single sign on mechanism like SPNego
and SAML. For more information, see Section 16.1.3 “System architecture” in
OpenText Vendor Invoice Management for SAP Solutions - Installation Guide (VIMZ-
IGD).

Security config- On the Configuration tab of the Admin console, a dedicated area Security
uration Configuration is available.

To prevent Click Jacking and Cross Site Request Forgery (CSRF), there is a
corresponding check box available on the Configuration tab of the Admin console.
For Click Jacking, the X-FRAME options have been restricted to same origin. For
more information, see Section [Link] “Configuration” in OpenText Vendor Invoice
Management for SAP Solutions - Administration Guide (VIMZ-AGD).

NetWeaver If you deploy the Approval Portal inside of the SAP NetWeaver Portal, NetWeaver
user authenti- user authentication will take place. For more information, see the SAP
cation
documentation. In this scenario, two views are normally created, one for approvals
and one for administrative tasks like setting up server connections. Make sure the
roles are assigned to proper users.

HTTPs In all deployment scenarios, SSL-based HTTPs communication is supported if


additional security is required.

CPIC SAP user Approval Portal, in both J2EE and NetWeaver portal deployment scenarios, runs
OpenText VIM for SAP application logic of all portal users using the same CPIC SAP
user. To prevent misuse of dialog transactions, OpenText recommends that you
create this user as a system user and not a dialog user. You must create a profile
with some authorization objects and add it to the CPIC user. For more information,
see Section 16.1.1 “Installation prerequisites” in OpenText Vendor Invoice Management
for SAP Solutions - Installation Guide (VIMZ-IGD).

Authorization When SAP GUI perfectly displays the invoice image and when only Approval Portal
issues with shows the error message when viewing the image, cross-check that the necessary
CPIC
authorizations are granted for the logged-in user in viewing the images. For more
information, see Section [Link].1 “Authorization issues with CPIC” in OpenText
Vendor Invoice Management for SAP Solutions - Administration Guide (VIMZ-AGD).

Application logs Approval Portal logs the information about Protocols, Security, and other actions
performed on the application. For more information, see Section [Link].1

42 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


9.8. Mobile Approval Portal

“Application logs” in OpenText Vendor Invoice Management for SAP Solutions -


Administration Guide (VIMZ-AGD).

9.8 Mobile Approval Portal


Authentication For information about authentication of the Mobile Approval Portal, see Section 17.2
“Authentication for the Mobile Approval Portal” in OpenText Vendor Invoice
Management for SAP Solutions - Installation Guide (VIMZ-IGD).

Web Viewer For integration of OpenText™ Imaging Web Viewer (Web Viewer) in the Mobile
Approval Portal and related security aspects, see Section 17.3 “Installing Web
Viewer for the Mobile Approval Portal” in OpenText Vendor Invoice Management for
SAP Solutions - Installation Guide (VIMZ-IGD).

9.9 Reports
Reports, including VIM Analytics and central reporting, allow you to restrict the
displayed data by checking authorization for company code. For more information,
see Section 6.2.1 “Reporting” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

9.10 Fiori Task Apps


The Fiori Task Apps of the Invoice Solution component use SAP user authentication.
The communication with SAP S/4HANA back ends is done with trusted RFC
connections, with the authenticated SAP user. For general information, see
“Authorization objects of the Fiori Task Apps“ on page 25.

For more information, see the following list:

Confirm Quantity and Price app, Enter Cost Assignment Advanced app, Approve
Invoices app, Approve Invoices (bulk mode) app, My Approved Invoices app,
Vendor Invoices Report app
An SAP user account is required to use the app. The SAP user account must be
available on the SAP FIORI UI / Gateway system and also on the SAP S/4HANA
system having the following authorization objects minimum.
The authorization for the OData service /OTX/PF05_DATA is described in App
and OData service specific authorizations on page 25.
The SAP user account which is used on the SAP S/4HANA system requires the
following:

• Authorization object J_6NPF_NAV (VIM Central Workplace)


• Authorization object J_6NPF_WTY (VIM Central Workplace)

Notes

• The SAP user must have the identical user name on both systems.

VIMZ230402-GSM-EN-02 Security Guide 43


Chapter 9 Security aspects of specific components

• Within the COA, each user using the app must have assigned a
corresponding SAP user.

Confirm Quantity and Price app


The user needs additional authorization for the /OTX/PS33_DATA_SRV service.
Therefore the user needs to be authorized for the object S_SERVICE:

• Type: HT (TADIR service)


• Name: choose service:

– Program ID: R3TR


– Object Type: IWSG
– Object Name: technical service name of service /OTX/PS33_DATA_SRV
(default ZPS33_DATA_SRV)

The system will calculate the correct ID from this input.

Addition for the Confirm Quantity and Price app


The app inbox shows only the items for which the current user is authorized.
The following authorizations are checked:

• Company code authorization object J_6NIM_BC1 (company code, activity =


02).
• Vendor authorization object F_LFA1_BEK (if authorization group is
maintained in the vendor master, with the vendor number, activity = 03).

Resolve Invoice Exceptions app


When accessing the work list, the following authority objects are checked.
Company Code Check
Check of Authority Object J_6NIM_BC1
Vendor Check
Check of Authority Object F_LFA1_BEK (Authorization Group in LFA1)

9.11 Supplier Self Service


Supplier Self Service needs authorization settings regarding the following
components:

Gateway users Users of the SAP NetWeaver Gateway are grouped in roles, which are needed for
several other configurations. There is no restriction on the number and names of
roles created for SAP NetWeaver Gateway. You must enhance the roles of the users
in your SAP NetWeaver Gateway system with the authorizations contained in the
authorization template /IWFND/RT_GW_USER. For more information, see Section 23.1.3
“Configuring Gateway users” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

44 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


9.12. Supplier Self Service Fiori apps

Gateway The Supplier Self Service On-Premise option allows the UI5 repository to be
service authori- uploaded on the Gateway server as a BSP application. The On-Premise URL is
zation
generated for the BSP application with default HTML, and the application is
accessed using this URL.

For information how to bypass authorization issues for the service path, see Section
23.1.7 “Configuring the Gateway service authorization” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

Vendor cleanup The vendor cleanup program for Supplier Self Service has been created to clean up
vendors data based on selection criteria.

The program provides built-in checks to ensure that only OpenText VIM for SAP
specific data is modified or deleted. The program also provides a specific
authorization check. The authorization object is J_6NIM_CA6. For more information,
see Section 23.7 “Vendor cleanup program for Supplier Self Service” in OpenText
Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution
(VIMZ-CGD).

9.12 Supplier Self Service Fiori apps


User account An SAP user account is required to use Supplier Self Service apps. The SAP user
account must be available on the SAP Fiori UI / Gateway system and also on the
SAP ERP system having specific authorization objects. For more information, see
Section 24.2 “User authorization” in OpenText Vendor Invoice Management for SAP
Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

User Self To implement User Self Service, you must have users with proper authorizations to
Service create and to maintain the users in SAP NetWeaver AS ABAP. The following table
shows the different types of users:

User User Type SAP Gateway SAP Business Suite


Hub (with IW_BEP)
Service User Service Yes Yes
Admin User Dialog No Yes
Reference User Reference Yes Yes

For more information, see Section [Link] “Security aspects of User Self Service” in
OpenText Vendor Invoice Management for SAP Solutions - Configuration Guide for Invoice
Solution (VIMZ-CGD).

Template User You need to maintain a reference Template User, which must be present in both SAP
Gateway and SAP Business Suite systems. This Template User must have the roles
and authorizations required for the Supplier Invoices app. For more information, see
Section [Link] “User Self Service roles and authorizations” in OpenText Vendor
Invoice Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-
CGD).

VIMZ230402-GSM-EN-02 Security Guide 45


Chapter 9 Security aspects of specific components

9.13 Z constants
Various Z constants deal with authorization topics, see the following list:

Product code 002 and 009

• ALV_CHECK_ACTIVE
• AUTH_CHECK_ACTIVE
• SPROGRAM_CHECK_ACTIV
• SRFC_CHECK_ACTIV

For more information, see Section 38 “Z constants for product code 002 and 009”
in OpenText Vendor Invoice Management for SAP Solutions - Reference Guide for
Invoice Solution (VIMZ-RGD).
Product code 005

• PROPOSAL_ONE_VENDOR

For more information, see Section 39 “Z constants for product code 005” in
OpenText Vendor Invoice Management for SAP Solutions - Reference Guide for Invoice
Solution (VIMZ-RGD).

9.14 Vendor data cleanup program


The vendor data cleanup program provides built-in checks to ensure that only
OpenText VIM for SAP specific data is modified or deleted. The program also
provides a specific authorization check. The authorization object is J_6NIM_CA6. For
more information, see Section 8.3.1 “Vendor data cleanup program” in OpenText
Vendor Invoice Management for SAP Solutions - Administration Guide (VIMZ-AGD).

9.15 Standard posting of invoices


The posting logic uses some SAP BAPIs. The accountant using dialog posting and
the background user needs the authorization to call these BAPIs. For more
information, see Section 34.1.3 “Authorization” in OpenText Vendor Invoice
Management for SAP Solutions - Configuration Guide for Invoice Solution (VIMZ-CGD).

46 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


9.16. Posted invoice reversal with a new DP workflow start

9.16 Posted invoice reversal with a new DP workflow


start
OpenText VIM for SAP provides a utility that allows selecting an invoice posted,
cancel it, and start a new DP workflow with a document containing the same data.
DP process log, approval log and entered comments are copied and linked to the
new DP document. This allows restarting a process, keeping the history easily
available for reference.

This utility includes an authorization check in reporting. For more information, see
Section 14 “Posted invoice reversal with a new DP workflow start” in OpenText
Vendor Invoice Management for SAP Solutions - Scenario Guide for Invoice Solution
(VIMZ-CCS)

9.17 Translation
Roles For information about authorization aspects of the SAP developer role and the
translator role, see Section 12.1 “Roles and responsibilities” in OpenText Vendor
Invoice Management for SAP Solutions - Scenario Guide for Invoice Solution (VIMZ-CCS).

Translator When creating translator profiles, each profile can include one or more
profiles authorizations. For more information, see Section 12.3.5 “Creating a translator
profile” in OpenText Vendor Invoice Management for SAP Solutions - Scenario Guide for
Invoice Solution (VIMZ-CCS).

VIMZ230402-GSM-EN-02 Security Guide 47


Glossary
AAK

See: SAP Add-On Assembly Kit (AAK)

After Image
Technical option to realize an delta upload from the source systems into the SAP
NetWeaver BW system. A data record loaded as After Image provides the status
of the record after it has been changed, or after data has been added.

Aging Report
Part of the Central Reporting infrastructure. The Aging Report reports about the
aging of documents and work items in the current system.

Application Component Hierarchy


Hierarchy of folders to structure DataSources in SAP NetWeaver BW.

Approval chart of authority (COA)


The Approval chart of authority (COA) determines first approver and next
approver for an invoice by combinations of Company Code (specific or range),
Expense Type (marketing expense, utility), Cost Objects (G/L account, Cost
Center), and HR objects (Position, Job code).

Approval Portal
Web interface for approving invoices.

Archive system
Computer system that enables storage, management and retrieval of archived
data and documents

ArchiveLink document types


Document types that need to be customized for ArchiveLink

ArchiveLink
Service integrated in the SAP NetWeaver Application Server ABAP for linking
archived documents and the application documents entered in the SAP ERP
system.

Authorization profiles
The SAP administrator assigns authorizations to the users that determine which
actions a user can perform in the SAP system. These authorizations are stored in
Authorization profiles.

VIMZ230402-GSM-EN-02 Security Guide 49


Glossary

Automation Report
Tool that provides data about automated and manual processing steps of
documents

BAdI

See: Business Add-Ins (BAdI)

BAPI®
SAP programming interface: Business Application Programming Interface

Baseline
Set of functionality with predefined configuration and the starting point to
implement OpenText VIM for SAP.

BasisCube

See: InfoCube

BDC ID
Business Data Communication ID. The BDC ID is used by the system to process
an SAP transaction to create an SAP Document in user context.

Block
Situation where an invoice has a price or quantity variance that prevents invoice
from posting

BSP

See: Business Server Page (BSP)

BTE

See: Business Transaction Event (BTE)

Business Add-Ins (BAdI)


Business Add-Ins (BAdI) is an SAP enhancement technique based on ABAP
objects. BAdI can be inserted into the SAP system to accommodate user
requirements too specific to be included in the standard delivery.

Business rules
Rules that describe the operations, definitions and constraints that apply to an
organization

50 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Glossary

Business Server Page (BSP)


SAP term: An HTML-coded user interface of an Internet application of
Application Server ABAP.

Business Transaction Event (BTE)


Event used for extending a Non PO invoice functionality to call a custom program

Capture
Common technical term for both of the following products: OpenText Core
Capture for SAP Solutions and OpenText Capture for SAP Solutions.

Central Audit Report


Part of the Central Reporting infrastructure. The Central Audit Report is a
slimmed VIM Analytics (VAN). The main difference to VAN is that the Central
Audit Report serves as a single point of access in a multiple backend scenario.

Central Reporting
Reporting infrastructure that provides several reports that enable you to measure
certain properties of documents and their work items, in order to optimize
working with OpenText VIM for SAP. Central Reporting comprises the following
individual reports: Aging Report, Central Audit Report, Exception Analysis Report,
Key Process Analytics Report, Productivity Report, and Summary Report.

Characteristic
Type of InfoObject in SAP NetWeaver BW that represents descriptions of fields,
such as Vendor ID, Invoice Number, Unit of Measure, and Posting Date.

COA

See: Approval chart of authority (COA)

Coding
Coding allocates an invoice to G/L account and cost object if required.

Dashboard
User interface that organizes and presents information in a way that is easy to
read. Users can also perform actions from the dashboard.

Data Transfer Process (DTP)


Object in SAP NetWeaver BW to transfer data from source objects to target objects

Data View (View)


Dynamic part of a perspective. A set of views is shown in the template at specific
locations at runtime. For each perspective, you can define which view appears at
which location in its template. You can insert each view only once in each
perspective.

VIMZ230402-GSM-EN-02 Security Guide 51


Glossary

DataSource
Set of fields in SAP NetWeaver BW that provide the data for a business unit for
data transfer to the SAP NetWeaver BW system; technically, it contains an extract
structure and an extraction function module.

DataStore Object (DSO)


Storage location for consolidated and cleansed data in SAP NetWeaver BW

DocuLink
OpenText™ DocuLink for SAP Solutions enables the archiving, management and
retrieval of SAP CRM or SAP S/4HANA documents from within the SAP
infrastructure.

Document Processing (DP)


Component that captures invoice metadata including line items for PO and
performs preconfigured business rules

Document type
Type of document such as PO, Non PO, OCR, Non OCR

DP

See: Document Processing (DP)

DSO

See: DataStore Object (DSO)

DTP

See: Data Transfer Process (DTP)

EDI

See: Electronic Data Interchange (EDI)

Electronic Data Interchange (EDI)


Method for transferring data between different application systems in the form of
messages. SAP applications support EDI with messages sent in an SAP
Intermediate Document (IDoc) format. OpenText VIM for SAP supports the
creation of vendor invoices through the EDI/IDoc interface.

Event Type Linkage


Error handling method. Event Type Linkage determines what the application
should do in case an error could not be handled.

52 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Glossary

Exception Analysis Report


Part of the Central Reporting infrastructure. The Exception Analysis Report
reports all work items with exceptions, grouped by exception, company code or
vendor.

Exception
Action that is not part of normal operations or standards

FI

See: Financial Accounting (FI)

Financial Accounting (FI)


SAP module for the Finance and Accounting department

Fiori Task App


Light-weight web application following the design principles of SAP Fiori. It
provides an inbox showing the items that have been assigned to the logged-in
user. The user then is able to complete items by performing dedicated actions,
entering comments, and editing the data.

IAP

See: Invoice Approval (IAP)

IDoc

See: Intermediate Document (IDoc)

IE

See: Invoice Exception (IE)

Inbound Configuration
Connection to various inbound channels, for example scanned paper documents,
fax, email, or IDoc, and the corresponding configuration.

Indexing
Process of entering or storing data into the system

InfoArea
Folder in SAP NetWeaver BW to organize InfoCubes, DataStore Objects, InfoObjects,
and InfoObject Catalogs

VIMZ230402-GSM-EN-02 Security Guide 53


Glossary

InfoCube
Self-contained dataset in SAP NetWeaver BW, for example, of a business-oriented
area; an InfoCube is a quantity of relational tables arranged according to the
enhanced star schema: A large fact table in the middle surrounded by several
dimension tables

InfoObject Catalog
Folder structure in SAP NetWeaver BW to organize InfoObjects

InfoObject
Smallest information unit in SAP NetWeaver BW. Key figures and Characteristics
are collectively called InfoObjects.

InfoPackages
Object in SAP NetWeaver BW that specifies when and how to load data from a
given source system to the SAP NetWeaver BW system

InfoProvider
Object in SAP NetWeaver BW for which queries can be created or executed.
InfoProviders are the objects or views that are relevant for reporting.

Intermediate Document (IDoc)


Standard SAP message document format for the EDI interface.

Invoice Approval (IAP)


Component that enables users to perform coding, approving and rejecting
invoices

Invoice characteristic
A value specific to each invoice (for example country) that allows flexible
processing. An invoice characteristic is determined during runtime and depends
on the corresponding index data of the document.

Invoice coder
Person who enters the accounting info on invoices to allocate the cost

Invoice Exception (IE)


Component that handles the exceptions that arise after an SAP invoice is created

Invoice requester
Person who requested goods and services for Non PO invoices

Key Figure
Type of InfoObject in SAP NetWeaver BW that represents numeric values or
quantities, such as Number of Invoices and Gross Invoice Amount.

54 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Glossary

Key Process Analytics Report


Part of the Central Reporting infrastructure. The Key Process Analytics Report
reports about a variety of key figures regarding the process: It shows the
accumulated amounts of all documents in the DP workflow, in parked state and
in posted state.

LIV

See: Logistic invoice (LIV)

Logistic invoice (LIV)


purchase order invoice

Materials Management (MM)


Materials management module of the SAP S/4HANA software package. Materials
management is used for procurement and inventory management.

MM

See: Materials Management (MM)

Mobile Approval Portal


Component for approving invoices on mobile devices.

MultiProvider
Object in SAP NetWeaver BW that is based on InfoCube(s), DataStore Object(s),
and/or InfoObject(s). A MultiProvider is used as a layer for the creation of end user
queries; the MultiProvider itself does not contain any data; rather, data resides in
the BasisCubes.

Namespace
Name range reserved by SAP for customer objects and SAP objects to make sure
that objects are not overwritten by SAP objects during the import of corrections or
an upgrade

Non purchase order (Non PO)


Order that is not based on a PO

Non purchase order (Non PO) invoice


Invoice based on a Non purchase order (Non PO)

Number range
Array of numbers that can be used for an object in the SAP S/4HANA system

OCR

VIMZ230402-GSM-EN-02 Security Guide 55


Glossary

See: Optical character recognition (OCR)

OpenText VIM for SAP


Packaged business solution that solves a business problem – paying correct
amount to vendors on-time and with the lowest cost. OpenText VIM for SAP
delivers not technology but best-practice business processes. OpenText VIM for
SAP provides values to customers in process efficiency, visibility and compliance.

Optical character recognition (OCR)


Mechanical or electronic translation of images of handwritten, typewritten or
printed text (usually captured by a scanner) into machine-editable text

Park
Situation where an invoice is not posted and is waiting for further processing

Parked invoice document


Temporary document that the AP processor can change and post. SAP assigned
document number becomes real number when posted.

Persistent Staging Area (PSA)


Data staging area in SAP NetWeaver BW. It allows to check data in an
intermediate location before the data is sent to its destinations in SAP NetWeaver
BW.

Perspective
Web Services element that defines which item related data is displayed in the
Fiori Task App and where. A perspective defines the content and visual
appearance of items for a specific area of the screen in the Fiori Task App. The
Fiori Task App displays only one perspective at the same time.

PO

See: Purchase order (PO)

Posted invoice document


Invoice that has already been posted in SAP S/4HANA. Only free-form text fields
can be changed. Related documents such as POs or good receipts may be created
or changed to effect the invoice. If the document is not needed, it must be
cancelled ( PO invoice) or reversed ( non-PO invoice).

Price variance
Situation where the price on the invoice is different from the price in the purchase
order

Process Chain
Sequence of processes in SAP NetWeaver BW that are scheduled to wait in the
background for an event; used to automate, visualize and monitor the processes.

56 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Glossary

Process Configuration
Easy and technically simplified configuration of complex business scenario
aspects. Process Configuration covers profile configuration, profile assignment,
and authorizations.

Process Foundation
Flexible framework to configure and run processes. It utilizes generic workflow
definitions, which are processed by the SAP Business Workflow engine.

Process options
Processing options for the user in the dashboard, such as Referral, Authorization,
and Actions

Process type
Process type for a document. The process type determines the initial actor and
various collaboration options available to the various actors during the process
flow.

Productivity Report
Part of the Central Reporting infrastructure. The Productivity Report reports
about the productivity of users/roles and the activities of users/roles.

PSA

See: Persistent Staging Area (PSA)

Purchase order (PO) invoice


Invoice based on a Purchase order (PO)

Purchase order (PO)


SAP module. PO indicates a document sent from a buyer to a seller. The purpose
of the document is to order the delivery of goods or services.

Quantity variance
Situation where the quantity on the invoice is different from the quantity in the
purchase order

Roles
Set of predefined roles for the SAP user

SAP Add-On Assembly Kit (AAK)


Standardized delivery procedure for software

SAP Customer Relationship Management (SAP CRM)


SAP application that provides software for ticket systems, for example in the
Accounts Payable department.

VIMZ230402-GSM-EN-02 Security Guide 57


Glossary

SAP NetWeaver Business Warehouse (SAP NetWeaver BW)


SAP application that allows to integrate, transform, and consolidate relevant
business information from productive SAP applications and external data
sources.

Scan operator
Person who scans the invoices into images (may not have a SAP ID)

Summary Report
Part of the Central Reporting infrastructure. The Summary Report provides a
summary of all documents processed through OpenText VIM for SAP.

Technical catalog
SAP term: Repository for creating role-specific business catalogs

Transformation (TRF)
Object in SAP NetWeaver BW to connect source objects to data targets; it allows
to consolidate, cleanse and integrate data

TRF

See: Transformation (TRF)

VAN

See: VIM Analytics (VAN)

VIM Analytics (VAN)


Component that gives users a clear data report on their invoices in progress. VIM
Analytics allows to track the documents routed through SAP workflows via
OpenText VIM for SAP.

VIM Central Workplace


Central tool to process work objects. It provides an inbox with personal and
shared work item lists to the user. It also provides access to different business
objects and status information for all objects in process. The user can switch
between work centers and navigate in a process-dependent tree.

VIM Invoice Workplace


Tool for super users, which allows users to display lists of their work items that
meet a selection they have entered before. Users also can display work items of
other users and of their team as a whole.

58 OpenText™ Vendor Invoice Management for SAP® Solutions VIMZ230402-GSM-EN-02


Glossary

Web Services
Underlying technical concept of the Fiori Task App interface. You configure the
complete content of the Fiori Task App either by customizing or by implementing
an interface for the Web Services.

Work object type


Processing object in the VIM Central Workplace. It can represent a process object,
a SAP business object, or information from any SAP tables.

Workflow
SAP Business Workflows can be used to define business processes that are not yet
mapped in the SAP S/4HANA system.

VIMZ230402-GSM-EN-02 Security Guide 59

You might also like