
Authorizations
Documentation
Authorizations and security are covered more fully in the eCATT Security Guide, which can be found in SAPNet.
Access to the eCATT Test System
Access to the eCATT test system should be strictly controlled.

In the eCATT test system, there may be RFC destinations in which the user and password are fully specified.
Authorizations Required at Design Time
You need:
- Developer rights (S_DEVELOP with relevant activities) in the eCATT test system.
- RFC rights (S_RFC) in the eCATT test system.
- The relevant authorizations in the target systems.
Authorizations Required at Runtime
You need:
- A profile containing S_DEVELOP authorization with activity 16 (Execute) and 03 (Display) in the eCATT test system.
- RFC rights (S_RFC) in the eCATT test system.
- A profile containing S_DEVELOP authorization with activity 16 (Execute) in the target systems.
- The relevant authorizations in the target systems.
Security and the SAPGUI Command
The following are some of the security features:
- The administrator can switch GUI Scripting on or off for a particular application server.
- In addition to the server settings, GUI Scripting requires certain components to be installed on the front end. If GUI Scripting is enabled, the user can enable or disable scripting at the front end. Here, you have the option to be notified whenever a script attaches to the SAP GUI or a script opens a connection. eCATT itself never opens a new connection.
- eCATT GUI Scripting does not use Windows Scripting Host.
- The SAPGUI command never records logon screens.
Target Systems
When you record GUI actions in a target system, the security settings of the target system apply. When you replay a SAPGUI command, the security settings of the eCATT system apply.