Function documentationDefining Authorizations

 

Object-related authorizations (access control lists (ACLs)) allow assignment of authorizations to carry out certain activities in folders and documents.

These authorizations are inherited top-down (see Inheritance) and can be overridden at lower levels.

Caution Caution

You use the authorization object ACO_SUPER to give certain users, such as system administrators, authorization to override the ACLs.

End of the caution.

Note Note

Linked documents do not inherit the authorizations of the folder to which they are linked. These documents only inherit ACLs that result from their original use, that is, from the folder in which the documents are actually located and not from a folder by means of a link.

End of the note.

Features

You can assign the following authorizations to users, user groups, and roles:

  • Administrator

  • Delete folder

  • Delete document

  • Change

  • Delete subfolder

  • Create document and subfolder

  • Read metadata

  • Read originals

  • No authorizations

These authorizations are described in detail in the following table:

Authorization/Activity

Object

Description

Admin

Document, folder

Allows you to display, change, rename, copy, and delete documents, folders, and linked files. When objects are created, the object owner also defines whether other users are to receive authorizations for these objects.

DeleteFol

Folder

Allows you to delete an entire folder and therefore an entire document structure. The folder must be completely emptied before deletion.

Delete

Document

Allows you to delete a document. This authorization does not allow you to delete folders.

WriteFile

Document, folder

Allows you to create, delete, and change originals, and to change the metadata. The document itself cannot be deleted.

Write

Document, folder

Allows you to change metadata of documents and folders. The authorization does not allow you to check in, edit, or delete an original.

DelChild

Folder

Allows you to delete documents from a document structure. This authorization refers to the superior folder below which you want to delete subfolders or documents. You must create a separate authorization for deleting the subfolders and documents.

CreateDoc

Folder

Allows you to control the creation of documents with originals and subfolders. The authorization is linked to the superior folder below which you want to create subfolders and documents.

ReadFile

Document, folder

Allows you to display metadata and originals. The original can be exported, but cannot be changed or deleted.

Read

Document, folder

Allows you to display metadata and the document structure. Changes are not possible.

NoAuth

Document, folder

No authorizations are assigned. NoAuth cancels all other authorizations. The folders or documents are not visible to the user and the user has no authorization for the affected object. Inherited authorizations are overridden by NoAuth.

The authorizations apply to the following actions:

  • Create

  • Copy

  • Move

  • Change

  • Delete

  • Send documents

For more information, see Inheritance.

Check for Access Control Lists (ACLs)

When processing documents and folders in SAP Easy Document Management, the system checks the authorizations related to these objects as follows:

  • The system checks whether an ACL exists in the document.

  • If no ACL has been defined in the document, the system checks the superior folder.

  • If no ACL has been defined there, the system checks the folder above that folder.

  • The system continues checking until it finds an ACL.

  • If no ACL is found, the user does not have authorization.

  • The more comprehensive authorization for a single layer applies as follows:

    User —> User Group —> Role —> HR Object

  • Authorizations assigned to a superior folder are inherited by all subfolders at all levels

For more information, see Precedence.

Activities

Use Object-Related Authorizations

To use object-related authorizations (ACLs) in SAP Easy Document Management, you do the following steps:

  • Create a PFCG role or use an existing role

    The PFCG role ensures access to document management in the back-end system. The system first checks the PFCG roles of a user. If the user has authorization for document management, the system carries out the check for ACLs as outlined above.

  • Assign a user to the role

  • Create document info records (DIRs) in the backend

  • In SAP Easy Document Management you define the administrator authorizations for a folder or document under SAP Properties (SAP Properties) on the Authorizations tab page using Create Admin Authorization pushbutton. These authorizations allow the user to edit documents and folders and assign authorizations to other users, user groups, and roles.

    Note Note

    You use the registry entry AutoInheritedAuth to control whether a user automatically receives administrator authorization when he or she creates a DIR or whether this authorization must be explicitly assigned to the user in SAP Easy Document Management using Create Admin Authorization. For more information about registry entries, see Centrally Controlled Registry.

    End of the note.
  • You define authorizations for other users, user groups, roles, and HR objects in SAP Easy Document Management under SAP Properties (SAP Properties) on the Authorizations tab page for a folder or document, by choosing (Add).

    You can also undo these authorizations by choosing (Delete).

  • If you selected the authorization holder type User Group, you can define new user groups or change or delete existing ones under Authorization Holder in the SAP Properties (SAP Properties).

    Note Note

    ‘ACO_SUPER’ is the only PFCG object for working with ACLs in SAP Easy Document Management.

    PFCG roles (objects) and ACLs are independent of each other. If both PFCG objects and ACLs are maintained, the system takes both of them into account, but PFCG roles are given preference.

    End of the note.
Display Changes to an ACL

To display changes made to an ACL for documents, proceed as follows:

  • Select a document in SAP Easy Document Management and choose Display with SAP GUI from its context menu.

  • The document opens in display mode in SAP GUI. Choose Start of the navigation path Environment Next navigation step Display Changes End of the navigation path.

    Note Note

    To activate the Display Changes option in the backend, you must select the Change Docs checkbox for your document type in Customizing for Document Management System (CA-DMS) under Start of the navigation path Control Data Next navigation step Define Document Types End of the navigation path.

    End of the note.