Defining Authorizations
Object-related authorizations (access control lists (ACLs)) allow assignment of authorizations to carry out certain activities in folders and documents.
These authorizations are inherited top-down (see Inheritance) and can be overridden at lower levels.
Caution
You use the authorization object ACO_SUPER to give certain users, such as system administrators, authorization to override the ACLs.
Note
Linked documents do not inherit the authorizations of the folder to which they are linked. These documents only inherit ACLs that result from their original use, that is, from the folder in which the documents are actually located and not from a folder by means of a link.
You can assign the following authorizations to users, user groups, and roles:
Administrator
Delete folder
Delete document
Change
Delete subfolder
Create document and subfolder
Read metadata
Read originals
No authorizations
These authorizations are described in detail in the following table:
Authorization/Activity |
Object |
Description |
|---|---|---|
Admin |
Document, folder |
Allows you to display, change, rename, copy, and delete documents, folders, and linked files. When objects are created, the object owner also defines whether other users are to receive authorizations for these objects. |
DeleteFol |
Folder |
Allows you to delete an entire folder and therefore an entire document structure. The folder must be completely emptied before deletion. |
Delete |
Document |
Allows you to delete a document. This authorization does not allow you to delete folders. |
WriteFile |
Document, folder |
Allows you to create, delete, and change originals, and to change the metadata. The document itself cannot be deleted. |
Write |
Document, folder |
Allows you to change metadata of documents and folders. The authorization does not allow you to check in, edit, or delete an original. |
DelChild |
Folder |
Allows you to delete documents from a document structure. This authorization refers to the superior folder below which you want to delete subfolders or documents. You must create a separate authorization for deleting the subfolders and documents. |
CreateDoc |
Folder |
Allows you to control the creation of documents with originals and subfolders. The authorization is linked to the superior folder below which you want to create subfolders and documents. |
ReadFile |
Document, folder |
Allows you to display metadata and originals. The original can be exported, but cannot be changed or deleted. |
Read |
Document, folder |
Allows you to display metadata and the document structure. Changes are not possible. |
NoAuth |
Document, folder |
No authorizations are assigned. NoAuth cancels all other authorizations. The folders or documents are not visible to the user and the user has no authorization for the affected object. Inherited authorizations are overridden by NoAuth. |
The authorizations apply to the following actions:
Create
Copy
Move
Change
Delete
Send documents
For more information, see Inheritance.
When processing documents and folders in SAP Easy Document Management, the system checks the authorizations related to these objects as follows:
The system checks whether an ACL exists in the document.
If no ACL has been defined in the document, the system checks the superior folder.
If no ACL has been defined there, the system checks the folder above that folder.
The system continues checking until it finds an ACL.
If no ACL is found, the user does not have authorization.
The more comprehensive authorization for a single layer applies as follows:
User —> User Group —> Role —> HR Object
Authorizations assigned to a superior folder are inherited by all subfolders at all levels
For more information, see Precedence.
To use object-related authorizations (ACLs) in SAP Easy Document Management, you do the following steps:
Create a PFCG role or use an existing role
The PFCG role ensures access to document management in the back-end system. The system first checks the PFCG roles of a user. If the user has authorization for document management, the system carries out the check for ACLs as outlined above.
Assign a user to the role
Create document info records (DIRs) in the backend
In SAP Easy Document Management you define the administrator authorizations for a folder or document under
(SAP Properties
) on the Authorizations
tab
page using Create Admin Authorization
pushbutton. These authorizations allow the user to edit documents and folders and assign authorizations to other users, user groups, and roles.
Note
You use the registry entry AutoInheritedAuth
to control whether a user automatically receives administrator authorization when he or she creates a DIR or whether this authorization must be explicitly assigned to the user in SAP Easy Document Management using Create
Admin Authorization
. For more information about registry entries, see Centrally Controlled Registry.
You define authorizations for other users, user groups, roles, and HR objects in SAP Easy Document Management under
(SAP Properties
) on the Authorizations
tab
page for a folder or document, by choosing
(Add
).
You can also undo these authorizations by choosing
(Delete
).
If you selected the authorization holder type User Group
, you can define new user groups or change or delete existing ones under Authorization Holder
in the
(SAP Properties
).
Note
‘ACO_SUPER’ is the only PFCG object for working with ACLs in SAP Easy Document Management.
PFCG roles (objects) and ACLs are independent of each other. If both PFCG objects and ACLs are maintained, the system takes both of them into account, but PFCG roles are given preference.
To display changes made to an ACL for documents, proceed as follows:
Select a document in SAP Easy Document Management and choose Display with SAP GUI
from its context menu.
The document opens in display mode in SAP GUI. Choose .
Note
To activate the Display Changes
option in the backend, you must select the Change Docs
checkbox for your document type in Customizing for Document Management System
(CA-DMS) under .