Authorizations
The XBRL Reporting (FIN-FB-XR) application component uses the authorization concept provided by SAP NetWeaver. Therefore, the corresponding security recommendations and guidelines for authorizations also apply to XBRL Reporting.
The SAP NetWeaver authorization concept is based on assigning authorizations to users based on roles. For role maintenance, use the profile generator (transaction PFCG) when using ABAP technology, and the Administration Console for the User Management of the User Management Engine (UME) when using the Portal.
The following table shows the standard roles used by XBRL Reporting.
Role |
Description |
SAP_FIN_ACC_XBRL_ADMIN |
Processing of the XBRL configuration |
SAP_FIN_ACC_XBRL_INST |
Creation of reports using XBRL standards |
The following list contains links to the documentation of security-relevant authorization objects used by XBRL Reporting:
● Authorizations for Master Data
● Authorizations for Creating Instance Documents
For accessing characteristics and key figures in XBRL Reporting, you typically need to consider both the specific authorization for XBRL Reporting and the authorizations for InfoObjects of SAP NetWeaver BI. This enables you to define authorization profiles that permit or limit the access to characteristics and key figures in different ways.

If a user has the reporting authorizations of SAP NetWeaver BI but not those of XBRL Reporting, he or she is able to execute queries but is not able to use the reporting features of XBRL Reporting.
