!--a11y-->
Authorizations for Tasks 
You use this function to grant various privileges for accessing consolidation tasks to persons who work with the SEM System.

You want to grant the following authorizations to a group of users in consolidation area 01 in all versions:
· For data collection tasks and for consolidation groups A – C you grant the following authorizations:
o Block
o Unblock
o Execute in test mode
o Execute in update mode
o Change task status
· For all other tasks and all other consolidation groups (D - H) you grant the following authorization:
o Execute task in test mode

To grant authorizations for the Customizing of tasks, follow the steps described in Authorizations for Master Data.
The authorization concept of consolidation is embedded in the SAP authorization concept.
You have created at least one consolidation area for which you want to customize the authorizations for tasks.
You have completed the Customizing settings for the tasks of consolidation. This means that:
· You have customized the individual tasks.
· You have set up the Task Hierarchy and Sequence as well as the hierarchy of consolidation units to be able to execute the tasks in update mode.
You can grant authorizations for:
· Executing tasks in both update mode and test mode
· Blocking and unblocking tasks
· Changing the status of tasks
The authorizations apply to each separate consolidation area.
You can restrict authorizations to the following, status-relevant characteristics:
· Specific versions
· Specific consolidation groups
· Specific consolidation units
The authorizations you grant for higher-level consolidation groups also apply to that group’s lower-level consolidation groups and units.
You use authorization object R_UC_TASK to make the assignments. This authorization object has the following fields:
· Activity, which has the following attributes:
o Block task
o Unblock task
o Execute task in update mode
o Execute task in test mode (simulation)
o Change status of task
· Consolidation area
· Task
All tasks within the consolidation area are available.
· Fields 1 through 7
All characteristics with roles version, consolidation group, or consolidation unit are available.
If more than seven fields exist for restricting an authorization (for example, if you have 4 characteristics for versions, 2 for consolidation groups, and two for consolidation units), then in Customizing of the consolidation area you should explicitly specify each and every characteristic you want to use for restricting the authorization. Then, these characteristics will be available automatically when you maintain the roles.
The consolidation monitor checks the authorizations of the user for the respective activities.
· If the user possesses the necessary authorization, the system carries out the activity.
· If the user does not possess the necessary authorization, the system does not carry out the activity and, instead, displays an error message.
To assign authorizations for tasks, you make the following Customizing settings:
If you have more than seven fields for restricting task authorizations, proceed as follows:
...
1. Go to the process view of the workbench and choose Data Model ® Consolidation Area.
2. Select the desired consolidation area using change mode.
3. On the Fields tab page, go to the column Use Characteristic for Authorization Checks of Tasks and select the indicator for those characteristics you want to use to restrict authorizations. (You can do this for up to seven characteristics.)
4. Save the consolidation area.
...
1. In the local system, start role maintenance in the SAP menu by choosing Tools ® System Administration ® User Maintenance ® Roles.
2. Specify an existing role or create a new role.
3. In role maintenance, go to the Authorizations tab and choose Authorization Data.
4. Go to Strategic Enterprise Management ® SEM-BCS: Authorization Check for Task and define the authorizations for the following:
· Consolidation area (single value only)
· Activity (or combination thereof; wildcard (*) possible)
· Task (or multiple tasks; wildcard (*) possible)
· If applicable, other characteristics for version, consolidation group, and consolidation unit (combination and wildcard (*) possible)
See also the example below.
Caution:
Up to Release 3.1B, the space characters ( ) and asterisks (*) were used as wildcards for all values. Starting in Release 3.2, entering an asterisk (*) for the consolidation unit grants authorization to all existing consolidation units for posting levels 01 through 10.
5. Save the authorizations.
6. Generate the role.
Once you have completed the customizing settings, the system is able to perform authorization checks for the activities in the consolidation monitor according to your definitions.
Let's use the example stated at the beginning of this topic.
You can achieve the authorization assignments by making the following Customizing settings: In Role Maintenance you specify the following parameters for the desired role (under Strategic Enterprise Management ® SEM-BCS: Authorization Check for Task):
Manual: Authorization check for task
Activity |
Block, unblock, simulate, execute in update mode, change task status |
Consolidation area |
01 |
Task |
Collection of
reported financial data; |
1st Characteristic |
Consolidation group A - C |
2nd Characteristic |
* |
3rd Characteristic |
* |
4th Characteristic |
* |
5th Characteristic |
* |
6th Characteristic |
* |
7th Characteristic |
* |
Manual: Authorization check for task
Activity |
Execute in test mode |
Consolidation area |
01 |
Task |
Balance carryforward, validation of reported financial data, standardization of reported financial data, reconciliation, currency translation and rounding, validation of standardized financial data, elimination of IU payables/receivables, elimination of IU profit/loss in inventory, consolidation of investments, reclassifications, allocation, validation of consolidated data |
1st Characteristic |
Consolidation group D - H |
2nd Characteristic |
* |
3rd Characteristic |
* |
4th Characteristic |
* |
5th Characteristic |
* |
6th Characteristic |
* |
7th Characteristic |
* |
The authorizations you grant for higher-level consolidation groups also apply to that group’s lower-level consolidation groups and units.
Initial situation:

Settings affect the authorizations as follows:
Posting Level |
Task |
Cons Group |
Cons Unit |
Result |
00-10 |
T1 |
CG2 |
<blank> |
Authorization to execute task T1 for consolidation unit C1000 |
00-10 |
T1 |
CG1 |
<blank> |
Authorization to execute task T1 for consolidation units C1000 and C2000 |
00-10 |
T1 |
CG2 |
C2000 |
Authorization to execute task T1 for consolidation units C1000 and C2000 |
02,12,20,22,30 |
T2 |
CG2 |
<blank> |
Authorization to execute task T2 for consolidation group CG2 |
02,12,20,22,30 |
T2 |
CG1 |
<blank> |
Authorization to execute task T2 for consolidation groups CG1 and CG2 |
· Authorizations for Master Data
·
The SAP Authorization
Concept
