Roles for SAP Cloud Platform - Neo Environment

SAP Asset Strategy and Performance Management provides the following three predefined groups:

The group ORG_ADMIN has the following predefined roles:

Role Name Description
TEMPLATE_DELETE

Templates application.

MODEL_DELETE

Create, update, view, or delete a model using the Models application.

EQUIPMENT_DELETE

Create, update, view, or delete an item of equipment using the Create, update, view, or delete a model template, equipment and location templates using the Equipment application.

INSTRUCTION_DELETE

Create, update, view, or delete an instruction using the Instructions application.

ANNOUNCEMENT_DELETE

Create, update, view, or delete an announcement using the Announcements application.

DOCUMENT_DELETE

Create, update, view, or delete a model template, equipment andCreate, update, view, or delete a document using the Documents application.

COMPANYPROFILE_DELETE

Create, update, view, or delete your organization details using the Company Profile application.

IMPROVEMENT_DELETE

Create, update, view or delete improvement cases using the Performance Improvement application

FUNCTIONAL_LOCATION_DELETE

Create, update, view or delete locations using the Locations application

PART_DELETE

Create, update, view or delete locations using the Spare Parts application

CONFIGURATION_DELETE

Perform all configuration tasks using the Application Settings application

FAILURE_MODE_DELETE

Create, update, view or delete failure modes using the Failure Modes application

GROUP_DELETE

Create, update, view or delete groups using the Groups application

SYSTEM_DELETE

Create, update, view or delete systems using the Systems application

INDICATOR_DELETE

Create, update, view or delete indicators.

USER_AUTH_DELETE

Create, update, view or delete user authorizations using the User Authorization application.

ASSESSMENT_DELETE

Create, update, view or delete assessments.

FINGERPRINT_DELETE Create, update, view or delete fingerprints.
FUNCTION_DELETE Create, update, view or delete functions.

The group ORG_DATA_EXPERT has the following predefined roles:

Role Name
TEMPLATE_DELETE
MODEL_DELETE
EQUIPMENT_DELETE
INSTRUCTION_DELETE
ANNOUNCEMENT_DELETE
DOCUMENT_DELETE
COMPANYPROFILE_DELETE
IMPROVEMENT_DELETE
FUNCTIONAL_LOCATION_DELETE
PART_DELETE
CONFIGURATION_READ

FAILURE_MODE_DELETE

GROUP_DELETE

SYSTEM_DELETE
INDICATOR_DELETE
USER_AUTH_DELETE
ASSESSMENT_DELETE
FINGERPRINT_DELETE
FUNCTION_DELETE

The group ORG_DATA_READ has the following predefined roles:

Role Name

Description

TEMPLATE_READ

View a model template using the Templates application.

MODEL_READ

View a model using the Models application.

EQUIPMENT_READ

View an item of equipment using the Equipment application

INSTRUCTION_READ

View an instruction using the Instructions application.

ANNOUNCEMENT_READ

View an announcement using the Announcements application.

DOCUMENT_READ

View an document using the Documents application.

COMPANYPROFILE_READ

View your organization details using the Company Profile application

IMPROVEMENT_READ

View an improvement case using the Performance Improvement application.

FUNCTIONAL_LOCATION_READ

View a location using the Locations app

PART_READ

View a spare part using the Spare Parts app

CONFIGURATION_READ

View all configuration-related settings using the Application Settings app

FAILURE_MODE_READ

View a failure mode using the Failure Modes application

GROUP_READ

View a group using the Groups application

SYSTEM_READ

View a system using the Systems application

INDICATOR_READ

View indicators.

USER_AUTH_READ

View user authorizations using the User Authorization application.

ASSESSMENT_TEMPLATE_READ

View assessment templates

FINGERPRINT_READ View fingerprinst.
FUNCTION_READ View functions.

There are additional roles that do not belong to any of the groups. The following table lists these roles:

Role Name

Description

ANNOUNCEMENT_EDIT

Create, update, or view an announcement using the Announcements application.

COMPANYPROFILE_EDIT

Create, update, or view your organization details using the Company Profile application.

DOCUMENT_EDIT

Create, update, or view an document using the Documents application.

EQUIPMENT_EDIT

Create, update, or view an item of equipment using the Equipment application.

INSTRUCTION_EDIT

Create, update, or view an instruction using the Instructions application.

MODEL_EDIT

Create, update, or view a model using the Models application.

TEMPLATE_EDIT

Create, update, or view a model template using the Templates application.

IMPROVEMENT_EDIT

Create, update or view an improvement case using the Performance Improvement application.

FUNCTIONAL_LOCATION_EDIT

Create, update or view a location using the Locations application.

PART_EDIT

Create, update or view a spare part using the Spare Parts application.

CONFIGURATION_EDIT

Perform all configuration tasks using the Application Settingsapp

FAILURE_MODE_EDIT

Create, update or view a failure mode using the Failure Modes application

GROUP_EDIT

Create, update or view a group using the Groups application

SYSTEM_EDIT

Create, update or view a system using the Systems application

INDICATOR_EDIT

Create, update, or view indicators

USER_AUTH_EDIT

Create, update or view user authorizations using the User Authorization application.

ASSESSMENT_EDIT

Create, update, view, or delete assessments

ASSESSMENT_TEMPLATE_EDIT

Create, update, view, or delete assessment templates

FINGERPRINT_EDIT Create, update, view or delete fingerprints.
FUNCTION_EDIT Create, update, view or delete functions.

As an administrator you can assign users to the above mentioned groups. Additionally, you can create your own groups, assign roles to the groups and assign users to these groups.

DPP_AUTH role is available for data protection and privacy officers to access the Blocked Users and Logs section in the Data Protection and Privacy application.

For more information, see Start of the navigation pathSAP Cloud Platform Next navigation step Managing RolesEnd of the navigation path at http://help.sap.com/. As an administrator you can also create users and assign any of the above mentioned roles.