Roles for SAP BTP for the Neo Environment

SAP Asset Intelligence Network provides the following three predefined groups:

  • ORG_ADMIN - for the administration role
  • ORG_DATA_EXPERT - for reading, editing, and deleting data
  • ORG_DATA_READ - for reading data

The group ORG_ADMIN has the following predefined roles:

Role Name Description
TEMPLATE_DELETE

Create, update, view, or delete templates using theTemplates application.

MODEL_DELETE

Create, update, view, or delete a model using the Models application.

EQUIPMENT_DELETE

Create, update, view, or delete an item of equipment using the Equipment application.

INSTRUCTION_DELETE

Create, update, view, or delete an instruction using the Instructions application.

ANNOUNCEMENT_DELETE

Create, update, view, or delete an announcement using the Announcements application.

DOCUMENT_DELETE

Create, update, view, or delete a document using the Documents application.

PARTNERS_DELETE

Create, update, view, or delete a business partner using the Business Partners application.

COMPANYPROFILE_DELETE

Create, update, view, or delete your organization details using the Company Profile application.

SHARING_DELETE

Share business objects such as a model templates, or models, or items of equipment with other business partners and grant write or read permissions using the Authorizations application.

IMPROVEMENT_DELETE

Create, update, view or delete improvement cases using the Performance Improvement application

FUNCTIONAL_LOCATION_DELETE

Create, update, view or delete functional locations using the Locations application

PART_DELETE

Create, update, view or delete spare parts using the Spare Parts application

CONFIGURATION_DELETE

Perform all configuration tasks using the Application Settings application

MODEL_REQUEST_DELETE

Create, update, view or delete model requests using the Model Requests application

FAILURE_MODE_DELETE

Create, update, view or delete failure modes using the Failure Modes application

GROUP_DELETE

Create, update, view or delete groups using the Groups application

SYSTEM_DELETE

Create, update, view or delete systems using the Systems application

INDICATOR_DELETE

Create, update, view or delete indicators.

USER_AUTH_DELETE

Create, update, view or delete user authorizations using the User Authorization application.

FUNCTION_DELETE Create, update, view or delete functions.

The group ORG_DATA_EXPERT has the following predefined roles:

Role Name
TEMPLATE_DELETE
MODEL_DELETE
EQUIPMENT_DELETE
INSTRUCTION_DELETE
ANNOUNCEMENT_DELETE
DOCUMENT_DELETE
PARTNERS_DELETE
COMPANYPROFILE_DELETE
SHARING_DELETE
IMPROVEMENT_DELETE
FUNCTIONAL_LOCATION_DELETE
PART_DELETE
CONFIGURATION_READ

MODEL_REQUEST_DELETE

FAILURE_MODE_DELETE

GROUP_DELETE

SYSTEM_DELETE
INDICATOR_DELETE
USER_AUTH_DELETE
DIGITAL_SERVICE_EDIT
FUNCTION_DELETE

The group ORG_DATA_READ has the following predefined roles:

Role Name

Description

TEMPLATE_READ

View a model template using the Templates application.

MODEL_READ

View a model using the Models application.

EQUIPMENT_READ

View an item of equipment using the Equipment application

INSTRUCTION_READ

View an instruction using the Instructions application.

ANNOUNCEMENT_READ

View an announcement using the Announcements application.

DOCUMENT_READ

View an document using the Documents application.

PARTNERS_READ

View business partners' details using the Business Partners application.

COMPANYPROFILE_READ

View your organization details using the Company Profile application

SHARING_READ

View content in the Authorization application, and view sharing information on business objects, i.e. which business partners an object is shared with and with which privileges.

IMPROVEMENT_READ

View an improvement case using the Performance Improvement application.

FUNCTIONAL_LOCATION_READ

View a functional location using the Locations app

PART_READ

View a spare part using the Spare Parts app

CONFIGURATION_READ

View all configuration-related settings using the Application Settings app

MODEL_REQUEST_READ

View a model requests using the Model Requests application

FAILURE_MODE_READ

View a failure mode using the Failure Modes application

GROUP_READ

View a group using the Groups application

SYSTEM_READ

View a system using the Systems application

INDICATOR_READ

View indicators.

USER_AUTH_READ

View user authorizations using the User Authorization application.

FUNCTION_READ View functions.

There are additional roles that do not belong to any of the groups. The following table lists these roles:

Role Name

Description

ANNOUNCEMENT_EDIT

Create, update, or view an announcement using the Announcements application.

COMPANYPROFILE_EDIT

Create, update, or view your organization details using the Company Profile application.

DOCUMENT_EDIT

Create, update, or view an document using the Documents application.

EQUIPMENT_EDIT

Create, update, or view an item of equipment using the Equipment application.

INSTRUCTION_EDIT

Create, update, or view an instruction using the Instructions application.

MODEL_EDIT

Create, update, or view a model using the Models application.

PARTNERS_EDIT

Create, update, or view a business partner using the Business Partners application.

SHARING_EDIT

Share business objects such as a model templates, or models, or items of equipment with other business partners and grant write, or read permissions using the Authorizations application.

TEMPLATE_EDIT

Create, update, or view a model template using the Templates application.

IMPROVEMENT_EDIT

Create, update or view an improvement case using the Performance Improvement application.

FUNCTIONAL_LOCATION_EDIT

Create, update or view a location using the Locations application.

PART_EDIT

Create, update or view a spare part using the Spare Parts application.

CONFIGURATION_EDIT

Perform all configuration tasks using the Application Settingsapp

MODEL_REQUEST_EDIT

Create, update or view a model request using the Model Requests application

FAILURE_MODE_EDIT

Create, update or view a failure mode using the Failure Modes application

GROUP_EDIT

Create, update or view a group using the Groups application

SYSTEM_EDIT

Create, update or view a system using the Systems application

INDICATOR_EDIT

Create, update, or view indicators

USER_AUTH_EDIT

Create, update or view user authorizations using the User Authorization application.

FUNCTION_EDIT Create, update, view or delete functions.

As an administrator you can assign users to the above mentioned groups. Additionally, you can create your own groups, assign roles to the groups and assign users to these groups.

DPP_AUTH role is available for data protection and privacy officers to access the Blocked Users and Logs section in the Data Protection and Privacy application.

For more information, see Start of the navigation pathSAP Business Technology Platform (SAP BTP) Next navigation step Managing RolesEnd of the navigation path at http://help.sap.com/. As an administrator you can also create users and assign any of the above mentioned roles.