Roles for SAP Cloud Platform - Cloud Foundry Environment

SAP Asset Strategy and Performance Management provide the following two predefined role templates:
  • ASPM_ORG_DATA_EXPERT - for reading, editing, and deleting data

  • ASPM_ORG_DATA_READ - for reading data

The role template ASPM_ORG_DATA_EXPERT has the following predefined roles:
Role Name Description
TEMPLATE_DELETE Templates application.
MODEL_DELETE Create, update, view, or delete a model using the Models application.
EQUIPMENT_DELETE Create, update, view, or delete a piece of equipment using the Equipment application.
INSTRUCTION_DELETE Create, update, view, or delete an instruction using the Instructions application.
ANNOUNCEMENT_DELETE Create, update, view, or delete an announcement using the Announcements application.
DOCUMENT_DELETE Create, update, view, or delete a document using the Documents application.
COMPANYPROFILE_DELETE Create, update, view, or delete your organization details using the Company Profile application.
IMPROVEMENT_DELETE Create, update, view, or delete improvement cases using the Performance Improvement application
FUNCTIONAL_LOCATION_DELETE Create, update, view, or delete locations using the Locations application
PART_DELETE Create, update, view, or delete locations using the Spare Parts application
CONFIGURATION_DELETE Perform all configuration tasks using the Application Settings application
FAILURE_MODE_DELETE Create, update, view, or delete failure modes using the Failure Modes application
GROUP_DELETE Create, update, view, or delete groups using the Groups application
SYSTEM_DELETE Create, update, view, or delete systems using the Systems application
INDICATOR_DELETE Create, update, view, or delete indicators.
USER_AUTH_DELETE Create, update, view, or delete user authorizations using the User Authorizations application.
RISK_ASSESSMENT_DELETE Create, update, view, or delete assessments.
ASSESSMENT_TEMPLATE_DELETE Create, update, view, or delete assessment templates.
FUNCTION_DELETE Create, update, view, or delete functions.
The role template ASPM_ORG_DATA_READ has the following predefined roles:
Role Name Description
TEMPLATE_READ View a model template using the Templates application.
MODEL_READ View a model using the Models application.
EQUIPMENT_READ View an item of equipment using the Equipment application
INSTRUCTION_READ View an instruction using the Instructions application.
ANNOUNCEMENT_READ View an announcement using the Announcements application.
DOCUMENT_READ View a document using the Documents application.
COMPANYPROFILE_READ View your organization details using the Company Profile application
IMPROVEMENT_READ View an improvement case using the Performance Improvement application.
FUNCTIONAL_LOCATION_READ View a location using the Locations app
PART_READ View a spare part using the Spare Parts app
CONFIGURATION_READ View all configuration-related settings using the Application Settings app
FAILURE_MODE_READ View a failure mode using the Failure Modes application
GROUP_READ View a group using the Groups application
SYSTEM_READ View a system using the Systems application
INDICATOR_READ View indicators.
USER_AUTH_READ View user authorizations using the User Authorizations application.
ASSESSMENT_TEMPLATE_READ View assessment templates
RISK_ASSESSMENT_READ View assessments
FUNCTION_READ View functions
There are additional roles that do not belong to any of the role templates. The following table lists these roles:
Role Name Description
ANNOUNCEMENT_EDIT Create, update, or view an announcement using the Announcements application.
COMPANYPROFILE_EDIT Create, update, or view your organization details using the Company Profile application.
DOCUMENT_EDIT Create, update, or view a document using the Documents application.
EQUIPMENT_EDIT Create, update, or view an item of equipment using the Equipment application.
INSTRUCTION_EDIT Create, update, or view an instruction using the Instructions application.
MODEL_EDIT Create, update, or view a model using the Models application.
TEMPLATE_EDIT Create, update, or view a model template using the Templates application.
IMPROVEMENT_EDIT Create, update, or view an improvement case using the Performance Improvement application.
FUNCTIONAL_LOCATION_EDIT Create, update, or view a location using the Locations application.
PART_EDIT Create, update, or view a spare part using the Spare Parts application.
CONFIGURATION_EDIT Perform all configuration tasks using the Application Settings app.
FAILURE_MODE_EDIT Create, update, or view a failure mode using the Failure Modes application.
GROUP_EDIT Create, update, or view a group using the Groups application.
SYSTEM_EDIT Create, update, or view a system using the Systems application.
INDICATOR_EDIT Create, update, or view indicators.
USER_AUTH_EDIT Create, update, or view user authorizations using the User Authorizations application.
RISK_ASSESSMENT_EDIT Create, update, view, or delete assessments.
ASSESSMENT_TEMPLATE_EDIT Create, update, view, or delete assessment templates.
FUNCTION_EDIT Create, update, view, or delete functions.

As an administrator you can assign users to the above-mentioned roles or role templates. Additionally, you can create your own groups, assign individual roles (from any of the above-mentioned role templates and roles) to the groups and assign users to these groups.

DPP_AUTH role is available for data protection and privacy officers to access the Blocked Users and Logs section in the Data Protection and Privacy application.

For more information, see Start of the navigation pathSAP Cloud Platform Next navigation step Managing RolesEnd of the navigation path at http://help.sap.com/. As an administrator you can also create users and assign any of the above-mentioned roles.