Managing the Access Control List
Use
The Access Control List (ACL) defines the permissions to particular principals to execute particular business object operations.
Prerequisites
- Open the SAP NetWeaver Administrator tool, Configuration → Security → Identity Management → Composite Application Framework Authorization Tool and choose a business object and a business rule.
- You have opened the Access Control List tab page.
- You have the SAP_CAF_ADMIN role assigned.
Procedure
Adding a Principal
- Select the principal you want to add.
You can do this in one of the following ways:
- By searching
- In the Principal Name field, enter a name.
You can also use asterisk (*). For example, by entering*ministr* , the Administrator entry is found.
- Choose
with the quick info text Check Entries. - Select the principal from the results table.
- Choose OK.
- In the Principal Name field, enter a name.
- By browsing
- Choose
with the quick info text Browse Users. - Enter a filter string for the principals.
- Choose
- By searching
To see all principals, enter an asterisk (* ).
- To see results only for a particular principal type, select it from the Principal dropdown box.
- Choose Search.
- Browse until you find the principal you want to add and select it.
You can sort the principals by type or by name.
To do this, choose the top of the relevant column.
- Choose OK.
- Choose Add Selected to ACL
A new entry is added to the ACL.
Setting Principal Permissions
- From the ACL, choose the entry you want to modify.
- From the Permission column, select the permission you want to set.
You can assign the following permissions:
Permissions Descriptions fullcontrol
Full access rights (create, read, update, delete)
read
Access rights only for reading
update
Access rights for reading and updating
create
Access rights for creating a new instance
delete
Access rights for reading and removing an existing instance
- Choose Save Business Rules to confirm the changes made.
Removing a Principal
- From the Access Control List, choose the entry you want to delete.
- Choose
with the quick info text Remove.
The principal and permission are removed from the list.
- Choose Save Business Rules to confirm the changes made.