Configuring Data Locking

Use data locking in SAP Analytics Cloud to prevent changes to specific data at different stages of the planning process. As a planning modeler, you can set up data locking and specify areas of model data to lock, restrict, and unlock, and you can also delegate ownership of data locks to other planners.

Prerequisites

  • Data Locking must be enabled in model settings before you can start configuring it. For details, see Set Up Model Settings.

  • You must have the appropriate permissions to work with data locking. For details, see Data Locking Permissions.

Context

When to Use Data Locking

There are several ways to secure data in your model. Use data locking on model data that needs to be unlocked at certain stages of the planning process and then locked again, and when you want to delegate data security to other users who aren’t admins. For an overview of other data security features like validation rules and data access control, see Learn About Data Security in Your Model.

If you're looking for information about value locks, see About Value Lock Management instead. This is a separate feature that lets users control how data entry in a table is disaggregated.

How Data Locking Works

You configure data locks in a grid layout, by choosing driving dimensions and setting combinations of their members as locked, open, or restricted.

In a story, locked and restricted cells for public versions appear as read-only, and cannot be changed by data entry or other planning operations. You can plan on these cells by selecting Ignore Data Locks from the table context menu, but data locks will still be enforced when you publish the version. You can only select Ignore Data locks if the story is planning enabled.

Video: How to Plan Using Data Locking

In this video, you will apply data locking on the dimensions of a planning model to prevent unwanted changes during the planning process.

Open this video in YouTubeInformation published on non-SAP site

Delegating Ownership of Data Locks

You can also delegate ownership of the data locks on members of a dimension. For example, you might do this to let managers for specific products or regions handle these data locks. Data locking owners gain a few privileges for the data that they own:
  • They can make changes to data in a restricted state.

  • For members that are children or descendants of the member that they own, they become data locking managers. They can open restricted or locked data that they manage. For example, as the data locking owner for Footwear in EMEA, you become the data locking manager for Sneakers in Germany. You can't change the overall value for Footwear in EMEA once it's locked, but you can unlock different products and countries to change the distribution of that value.

  • They can set locks to a more restrictive state, such as from open to restricted, open to locked, or restricted to locked, but not in the other direction. A manager can change the lock state in both directions.

Users with the appropriate permissions can also change the state of data locks from a story. To do so, right-click the table or select (More Actions), then choose Manage Data Locks....

For example, if your organization is carrying out a forecast across different regions for 2018 Q4, this feature lets you lock all the model data for regular users, and grant permission only to regional managers to update their own region’s data for the Forecast version in 2018 Q4. For a detailed workflow based on this example, see Example: Applying Data Locks to a Regional Forecast.

Scheduling Data Locks

If you're using data locking frequently in your planning processes, you can create manual data locking task in the calendar to establish a schedule and coordinate with data locking owners. You can also schedule data locking tasks that lock the data automatically at a certain time. For details, see Schedule Data Locks in the Calendar.

Data Locking Permissions

A few different permissions are required to set up and work with data locking. In general, users with the planning modeler or planning admin role will configure data locking, and users with the planner reporter role may be able to change the state of data locks.

The following table shows the permissions for data locking, the roles that include them, and the required license types. For background information, see Privileges and Permissions.

Permission Description Standard roles License requirement

Create

Lets you turn on data locking for a model.

Admin, Modeler

SAP Analytics Cloud for planning, professional edition

Update

Lets you set up data locking for a model, including turning it off.

Admin, Modeler

SAP Analytics Cloud for planning, professional edition

Delete

Lets you turn off data locking for a model.

Admin, Modeler

SAP Analytics Cloud for planning, professional edition

Maintain

Lets you change the state of data locks.

Admin, Modeler, Planner Reporter

SAP Analytics Cloud for planning, professional edition or standard edition

Read

Lets you see the data locks in a table.

Admin, Modeler, Planner Reporter, Viewer

SAP Analytics Cloud for planning, professional edition or standard edition

Data locking tasks can also require permissions for the specific model and dimensions involved:

Detailed Permissions for Data Locking Tasks
 

Data Locking Permission

Model Permission

Dimension Permission

Task

Create

Read

Update

Delete

Maintain

Read

Update

Read

Update

Turn data locking on

X

X

     

X

X

   

Turn data locking off

 

X

X

 

X

X

   

Change the default lock state

 

X

X

   

X

X

   

Change the driving dimensions

 

X

X

   

X

 

X

 

Turn ownership on or off for a dimension

 

X

     

X

 

X

X

Change responsible users for a dimension

         

X

X

X

X

Change owners from the data locking dialog

 

X

     

X

 

X

X

Change any lock state

 

X

X

 

X

X

 

X

 

Change locks that you own or manage

 

X

   

X

X

 

X

 

View locks

 

X

     

X

 

X

 

Data Disaggregation to Locked Child Members

Data disaggregation occurs when a value from a parent member is automatically spread to the child members that aggregate up to it. As a default, locked child members will still receive values from data disaggregation when data changes occur to the parent member.

You can change this behavior by enabling Data Disaggregation based on Data Locking in model settings if you want locked values to remain fixed. For more information, refer to Set Up Model Settings.

Redeploy Data Locks

If you want to regenerate your data locks, you can use the Redeploy Model option in model preferences. In the rare case that the data locking configuration cannot be recovered, it must be reset manually. For more information, see the Redeploy Model section of Data and Performance.

Exceptions and Restrictions

Check the following points to make sure that data locking works for your use case:

  • Power users: Data locks do not apply to users with the admin role, or the user who created the model. These users can import data, delete data, and publish their changes to public versions, even if it affects locked data.

  • Models with measures: When measures are added as a driving dimension, a data lock on one measure will impact data management in the modeler for all other measure values that belong to the same set of dimension members. This issue affects importing and deleting fact data in the modeler. For details about this behavior in models with measures, see Treatment of Measures from the Same Set of Dimension Members.

  • If there are data locks on members of single column dimensions that have been removed from the model, a warning appears in the Data Locking page. From there you can remove these members and clean up the data locking configuration.

  • Advanced filters: If you need to use data locking on tables with advanced filters, make sure your filter is compatible. For more information, see Data Locking with Advanced Filters.

  • Multiple hierarchies in the modeler: Data locks can only be set on the default hierarchy. If the default hierarchy of any driving dimension is changed in the modeler, some of the data locks might be lost and you will need to reapply them.

  • Multiple hierarchies in stories: If you are viewing data locks in a non-default hierarchy, the data locks will be based on the default hierarchy and may be different than they appear in the non-default hierarchy. If a non-leaf member in this hierarchy is a leaf member in the default hierarchy, changing the data locks in this hierarchy will not change the data locks in the default hierarchy.

  • Restricted measures and accounts: Data locks cannot be directly set on restricted measures or accounts. Their lock states come from the locked states of their source’s measures or accounts, based on existing restrictions. If you want to change the lock state of a restricted measure or account, you need to change the lock state of the source measure or account. This is also true for conversion measures.

  • Other calculated measures and accounts: Data locks can't be directly set on calculated measures or accounts. The lock state of these cells is unknown and they won't appear locked when displayed in a table.
    • If data locking-based data disaggregation is enabled in the model, your data entry is rejected if the value can't be distributed accordingly, for example, from 2025 to every month of that year.

    • If data locking-based data disaggregation is disabled, data locks are enforced on publish, when changes to locked values can't be published.

Procedure

  1. Select (Configure Data Locks).

    The Data Locking page is displayed, with the driving dimensions prefiltered based on the members of the ownership-enabled dimensions that are owned by the current user.

  2. Set the driving dimensions.

    If you are configuring data locking for the first time for this model, the driving dimensions are displayed. Otherwise, select (Edit Driving Dimensions) to show them.

    You can apply data locks to sets of members from each driving dimension. For example, if you want to lock the 2018 Forecast for North America, you can use version, date, and organization as your driving dimensions.

    1. To add a new driving dimension, select + Add a new Driving Dimension and choose the dimension from the list. A maximum of six driving dimensions is allowed.
    2. To delegate ownership of the locks applied to specific members of the dimension, select the checkbox in the Enable Ownership column.
    3. If a Responsible Person column has been set up for the dimension to identify responsible users for each member, you can select Copy Responsible Users to set these users as data locking owners.

      These settings can be edited later, on the Data Locking page or in the Modeler.

    4. When you have finished configuring driving dimensions, select Finish Editing.
  3. Drill, filter, and hide the driving dimensions as necessary.
    • To filter the members of a driving dimension, select the dimension.

    • To set the drill level, select Drill dimension next to the dimension name.

    • To hide dimensions from the grid, select  (Show / Hide Driving Dimensions)) and deselect the dimension. Any changes to the lock states will apply to all members of the hidden dimensions.

  4. The (Apply the ownership-based filters) button can be used to apply and reset the filters.
    It behaves as follows:
    • If the button is selected, clicking it resets all existing filters (all filters will be removed from all dimensions).

    • If the button is not selected, clicking it applies the ownership-based filters. For driving dimensions without ownership enabled, empty filters are applied.

    • If the button is selected, and you manually change any filters, the button becomes deselected.

    • If there are no ownership-based driving dimensions, or if you don't own any members of the existing driving dimensions, the button is disabled.

  5. Select Show Grid to display a grid of the driving dimensions where you can set the lock state of each cell.
  6. To set the lock state for a cell, choose the cell that represents the appropriate combination of members, select , and choose the state from the list:
    • Open: Values are unlocked for this combination of members in table, and can be changed by any users who have permissions to enter values for the model.

    • Restricted: Values can be changed only by a user who has effective ownership of locks on this combination of members.

    • Locked: Values cannot be changed for this combination of members in a table.

    When you change the state for a parent member in a dimension, the same state is applied to its child members as well. For example, if you lock North America, then the United States and Canada will also be locked.

  7. If necessary, set data locking owners.

    When you set a cell to Restricted, you can set owners for the member of each driving dimension with data locking ownership enabled.

    1. Select the restricted cell and choose (Select owners of the selected slice).
    2. Select Add Owner under a driving dimension and choose one or more owners for the selected member of that driving dimension.
    3. Select OK.
    4. Continue setting owners for restricted cells as necessary.
  8. When you have finished setting locks in the grid, select Close to return to the model.

Results

The data locks that you configured are applied to the model data in stories.

For the dimensions that have data locking ownership enabled, the Data Locking Owner column is added in the Modeler. You can add data lock owners for each member by adding their IDs in this column.

Data Locking with Advanced Filters

Some types of advanced filters aren’t compatible with data locking. In this case, none of the cells in the filtered table will be locked. Data locks will still be enforced when you publish the version, so you might not be able to publish all of your changes. The table shows the following warning: Data lock visualization is disabled as some of the active filters are not supported: Advanced Filters

Compatible advanced filters need to follow these rules:

  • They can’t explicitly exclude members, either by the (Exclude) option in the table context menu, by an exclude condition, or by a Does not equal operator.

  • They need to contain a certain combination of dimension members, known as a Cartesian product: Each dimension member included in the filter needs to be included for all of the other dimensions’ member combinations in the filter.

    To follow this rule, you’ll usually need to avoid picking members from different hierarchy levels in the filter conditions, too. For example, a condition that includes 2022 H1 isn’t considered equivalent to one that includes 2022 Q1 and Q2.

For these reasons, it’s usually easiest to create a compatible advanced filter by right-clicking a selection of table cells that meets the second condition and selecting (Filter).

For a detailed example of this rule, consider a table that has a Product Group dimension and a Geography dimension added to the rows:

 

A

B

C

D

E

F

1

 

Geography

America

Canada

2

 

Product Group

Cell Phones

Laptops

Cell Phones

Laptops

3

Account

Units Sold

Valid advanced filters for data locking include:
  • Any individual cell

  • Cell Phones and Laptops for both Canada and America (cells C3-F3)

  • Cell Phones and Laptops for America (cells C3-D3) or Canada (cells E3-F3)

  • Cell Phones for America and Canada (cells C3 and E3) or Laptops for America and Canada (cells D3 and F3)

Example: Applying Data Locks to a Regional Forecast

In this scenario, you restrict changes to forecast data using data lock ownership in SAP Analytics Cloud.

Your company is preparing a sales forecast for 2018 Q4, and you want to allow regional sales executives to enter or import data for their own regions. However, you want to prevent users from changing any data that they are not responsible for, and you want to lock all data after the forecast deadline.

  1. Open the model that contains the forecast.

  2. Ensure that the organization dimension has a Person Responsible column, with each sales executive assigned to the appropriate region.

  3. Select Model Preferences.

  4. On the Access and Privacy tab, set Data Locking to ON, and choose Locked as the Default Lock State. Select OK.

    The model data will be locked by default.

  5. Select (Save Model).

  6. Select (Configure Data Locks).

  7. In the Edit Driving Dimensions section of the Data Locking page, select + Add a new Driving Dimension and choose Organization.

  8. Select the Enable Ownership and Copy Responsible Users checkboxes for the organization dimension.

    These settings will create a Data Locking Owner column for the organization dimension, and copy the users from the Person Responsible column to it.

  9. Select Finish Editing.

  10. Select Show Grid.

  11. For the forecast version, drill into the date dimension to show 2018 Q4. In the 2018 Q4 Forecast column, set the lock state for all regions to Restricted.

  12. Select Done.

    When working with the model data in a story, regional sales executives can now make changes to the data for the 2018 Q4 Forecast in their own region. All other changes to public versions are prevented.

  13. When the forecast deadline passes, open the Data Locking page again and change the state of the 2018 Q4 Forecast cells from Restricted to Locked.

Any changes to the public model data are now prevented. Now that the data is locked, the sales executives won't be able to change the lock states, although data locking managers can still reopen the locked members if they need to.