Show TOC

Define Authorizations

1. EH&S installations based on a 3.X standard release

In this IMG activity, you check the authorization objects that are delivered for the individual functions in the R/3 component Product Safety in the standard system, and maintain the authorizations for these objects as required.

Standard Settings

In the SAP standard system, authorizations are supported for all authorization objects in the application.

Maintenance authorizations exist for the authorization objects.

The authorizations delivered are valid for all organizational unit.

The following authorization objects must be checked for each function in the R/3 Environment data component.

Functions for... Authorization object
Substance maintenance
Change, display C_SHES_TRH Substance header
substance header
Change, display
C_SHES_TVH Substance characteristic
substance characteristic
with ref. to substance
Change, display,
C_SHES_TDU Substance characteristic usage
substance characteristic
usage
Phrase maintenance
Change, display C_SHEP_TPP Phrase item
phrase translation
with ref. to substance
Change, display,
C_SHEP_TPG Phrase library/groups
phrase library & group
Substance reports
Distribute, export, C_SHER_TDH Substance reports
maintain
substance reports

Classification System

In the R/3 component Classification System, EH&S users must have authorization for class type 100. If EH&S users use the Classification System for other objects in the R/3 System, they also require authorization for these class types. For class type 100, all other authorizations must be set up with "*" or ALL.

See also: Maintain authorizations .

Activities

1. Check if the authorizations delivered satisfy your requirements:
a) Call the IMG activity.
b) For the R/3 component Environment data, choose the object class Production planning .
A list of authorization objects appears. You can display the technical names by choosing Utilities -> Technical name .
c) Choose an authorization object (C_SHE* or EHS: *).
An authorization list for this object appears.
d) Position the cursor, and choose Authorization -> Change, to check the allocated fields and values.
2. If necessary, create new authorizations:
a) Choose Authorization -> Create in the authorization list.
b) Enter an authorization and a short text.
c) Choose a field to maintain the individual field values.
d) Save your settings.
e) Aktivate the new authorization.

Notes

To start master data adjustment, you must have the following authorizations:

C_SHEP_TPG EHS: phrase library and phrase group
Field values:
ACTVT '*'
ESECATPIN '*'
ESEPHRGRP '*'
and
C_SHER_TDH EHS: substance reports
Field values
ACTVT '*'
ESEAUTHGRP '*'
ESEREPTYPE '*'
DOKST '*'
ESERVLID '*'
ESEVACLID '*'
and
C_SHES_TRH EHS: substance header
Field values
ACTVT '*'
ESEAUTHGRP '*'
and
S_TABU_DIS table maintenance (using standard tools like SM31)
Field values
DICBERCLS 'CSHE'
ACTVT '*'

Notes on transport

You transport authorizations as follows:

1. Display the list of authorizations.
2. Select the object class.
3. Choose Authorization -> Transport.
4. Select the authorizations you wish to transport.
5. Confirm your selections and enter the correction number.

2. EH&S installations based on a standard release of 4.5A or higher

The following description is valid only if you base your EH&S installation on a standard release of 4.5A or higher.

This step is used to createActivity groups an generate authorization profiles using the Profile Generator.

Activities

To assign an authorization profile to a user, do the following:

1. Create an activity group
2. Enter a description
3. Select transactions
4. Create and edit authorizations
5. Assigns users and compare the user master (in doing so, the profile is entered in the user's master record)
6. Transport activity groups, if desired

Detailed documentation

For more information about the procedures, see transaction documentation

Note

You can also use authorization profiles you created manually or were delivered by SAP, in activity groups. You can create an activity group without a menu and include the corresponding profile in the authorization data of the activity group.

In the fourth step, choose "Edit -> Add authorization -> From profile" to add the authorization profile data to the activity group.