Function documentation Authorizations for Tasks Locate the document in its SAP Library structure

Use

You use this function to grant various privileges for accessing consolidation tasks to persons who work with the SEM System.

Example

You want to grant the following authorizations to a group of users in consolidation area 01 in all versions:

§         For tasks for data collection and for consolidation groups A - C:

-         Blocking

-         Unblocking

-         Execution in test mode

-         Execution in update mode

-         Changing of the task status

§         For all other tasks and all other consolidation groups (D - H):

-         Execution in test mode

Note

To grant authorizations for the customizing of tasks, follow the steps described in section Authorizations for Master Data.

Integration

The authorization concept of consolidation is embedded in the SAP authorization concept.

Prerequisites

You have created at least one consolidation area for which you want to customize the authorizations for tasks.

You have completed the customizing settings for the tasks of consolidation. This means that:

·        You have customized the individual tasks and…

·        You have set up the Task Hierarchy and Sequence to be able to execute the tasks in update mode.

Features

You can grant authorizations for:

·        Executing tasks

·        Blocking tasks

·        Changing the status of tasks

The authorizations apply to each separate consolidation area.

You can restrict authorizations to the following, status-relevant characteristics:

·        Certain versions

·        Certain consolidation groups

·        Certain consolidation units

You use authorization object R_UC_TASK to make the assignments. This authorization object has the following fields:

·        Activity, which has the following attributes:

¡        Block task

¡         Unblock task

¡        Execute task in update mode

¡        Execute task in test mode (simulation)

¡        Change status of task

·        Consolidation area

·        Task

All tasks within the consolidation area are available.

·        Field 1 through 7

All characteristics with roles version, consolidation group, or consolidation unit are available.

If more than seven fields exist for restricting an authorization (for example, if you have 4 characteristics for versions, 2 for consolidation groups, and two for consolidation units), then in customizing of the consolidation area you should explicitly specify each and every characteristic you want to use for restricting the authorization. Then, these characteristics will be available automatically when you maintain the roles.

The consolidation monitor checks the authorizations of the user for the respective activities. If the user…

·        Possesses the necessary authorization, the system carries out the activity.

·        Does not possess the necessary authorization, the system does not carry out the activity and, instead, displays an error message.

Activities

To assign authorizations for tasks, you make the following customizing settings:

A. Customizing of the consolidation area—only if more than seven fields exist for version, consolidation group, and consolidation unit

If you have more than seven fields for restricting task authorizations, proceed as follows:

...

       1.      In the process view of the workbench, choose Data Model ® Consolidation Area.

       2.      Select the desired consolidation area using change mode.

       3.      Go to the Fields tab and select the indicator for restricting authorizations in the Authorizations column for the appropriate characteristics.

       4.      Save the consolidation area.

B. Customizing settings in “Role Maintenance” (transaction PFCG)

...

       1.      In the local system, start role maintenance in the SAP menu by choosing Tools ® System Administration ® User Maintenance ® Roles.

       2.      Specify an existing role or create a new role.

       3.      In role maintenance, go to the Authorizations tab and choose Authorization Data.

       4.      Go to Strategic Enterprise Management ® SEM-BCS: Authorization Check for Task and define the authorization for each combination of…

¡        Activity (or combination thereof)

¡        Consolidation area

¡        Tasks (or multiple tasks)

¡        Other characteristics for version, consolidation group, and consolidation unit—if applicable

You can specify single values or ranges of values. You can also use an asterisk ("*") as a wildcard.

See also the example below.

       5.      Save the authorizations.

       6.      Generate the role.

D. Authorization checking (system activity)

Once you have completed the customizing settings, the system is able to perform authorization checks for the activities in the consolidation monitor according to your definitions.

Example

Let's use the example stated at the beginning of this topic.

You can realize the authorization assignments by making the following customizing settings: In Role Maintenance you specify the following parameters for the desired role (under Strategic Enterprise Management ® SEM-BCS: Authorization Check for Task):

Manual: Authorization check for task

Activity

Block, unblock, simulate, execute in update mode, change task status

Consolidation area

01

Task

Collection of reported financial data;
collection of additional financial data

1. Characteristic

Consolidation group A - C

2. Characteristic

*

3. Characteristic

*

4. Characteristic

*

5. Characteristic

*

6. Characteristic

*

7. Characteristic

*

Manual: Authorization check for task

Activity

Execute in test mode

Consolidation area

01

Task

Balance carryforward, validation of reported financial data, standardization of reported financial data, reconciliation, currency translation and rounding, validation of standardized financial data, elimination of IU payables/receivables, elimination of IU profit/loss in inventory, consolidation of investments, reclassifications, allocation, validation of consolidated data

1. Characteristic

Consolidation group D - H

2. Characteristic

*

3. Characteristic

*

4. Characteristic

*

5. Characteristic

*

6. Characteristic

*

7. Characteristic

*

See also

·        Authorizations for Master Data

·        The SAP Authorization Concept