Managing Authorization Contexts
Use this app to create and manage authorization contexts to control the access of individual users, or teams of users, to specific business objects used in the processes supported by several integrated SaaS applications.
You use roles to control your users' access to the apps that are provided by different SaaS applications in SAP Integrated Product Development. With authorization contexts, you can narrow down access rights by allowing individual users, or a whole team, to only perform particular activities (for example, read or delete) on business objects with specific object attributes. You can create an authorization context based on one of the following object attributes:
-
BOM usage
-
Plant
-
Specification type
-
Product category
-
Recipe type
-
Document type
-
Design item type
-
Design type
-
Test Category
-
Test Phase
-
Test Scope
You can also restrict access to the following objects:
-
product structures in a specific folder
-
particular properties of a specification
-
different versions of a specification
-
different versions of a recipe
-
different versions of design items
-
different versions of test case, test execution, and test plan
-
Create
-
Read
-
Update
-
Delete
-
Inherit Authorization
You can use the Inherit Authorization option to automatically apply the permissions of a parent product folder to all its subfolders. When this option is enabled, users assigned to the authorization context of the parent folder automatically receive the same access rights for any subfolders created under it.
Authorization contexts control user access across the different apps provided by the integrated SaaS applications that you've subscribed to. When users included in an authorization context open the apps provided by the integrated SaaS applications, their access to the business objects within the apps is already filtered by their assigned authorization contexts.
-
Object attribute restrictions: You control user access for one or multiple object attribute types by assigning activities to specific object attributes.
The following object attribute types are supported:-
BOM usage
-
Plant
-
Recipe Type
-
Document type
-
Design item type
-
Design type
-
Test Category
-
Test Phase
-
Test Scope
When you create an authorization context with multiple object attribute types, the relationship between the different combinations of attribute type and activity is an or-relationship.
If, for example, you give read access for objects assigned to Plant 001 and for objects with BOM usage, 1 (Production), the users restricted by that authorization context can view objects that are assigned to Plant 001 or have production as the BOM usage.
-
-
Authorization groups: You control user access by authorization groups. The currently available authorization group restricts access by combining the following object attribute types:
-
BOM usage and plant
-
specification type and product category
-
recipe type, plant, and product category
-
design item type and design type
The access restriction between the object attribute types in an authorization group has an and-relationship.
If, for example, you create an authorization group in which you give read access when the plant is Plant 001 and the BOM usage is 1 (Production), the users restricted by that authorization context can only view product structures that are assigned to Plant 001 and have production as the BOM usage.
-
-
Business object restrictions: You control user access by granting permissions to business objects such as specific folders, different versions of test cases, test executions, test plans, design items, and others.
The access restriction between the different business objects that are assigned to an authorization context has an and-relationship.
If, for example, you create an authorization context in which you give read access to multiple folders, you give users read access to all objects in the assigned folders.
If, for example, you create an authorization context in which you give read access to version 000001 of the specification with the ID 000001, the users restricted by that authorization context can only view that version of the particular specification.
For information about the creation of authorization contexts, see Creating Authorization Contexts.