Show TOC

Process documentationAuthorization Administration in the Account Management System

 

The concept of authorization administration in the Account Management system is based on the authorization administration in the SAP system. You can find the documentation for this authorization administration in SAP Library under Users and Roles (BC-SEC-USR).

You use authorization administration to represent authorizations and areas of expertise. In Account Management, authorization objects are provided for

  • Dialog transactions

  • Customizing transactions

  • BAPIs

You can use them to restrict the creation, changing, display, locking, deletion, reversal, transfer posting, return, execution, and simulation of data or processes.

Thanks to the system's modular authorization concept, you can define authorization profiles and roles to suit your employees' work centers. For example, you can adapt an authorization to suit a work center at which private customers or corporate customers are serviced, or to suit processing staff working in payment transactions.

Within these profiles and roles there are several authorizations that you can use to define which business objects your employees are allowed to edit (authorization objects), and which editing functions are then permitted.

Process

The business objects to which you assign the authorizations are defined in the system as authorization objects and grouped together in object classes. You can find these user-defined authorization objects in the system in the following object classes:

  • FICO, Financial Services - Financial Conditions

  • FPCO, Financial Services - Posting Control Office

  • FSAM, Financial Services - Account Management

  • FSDH, Financial Services - Posting Lock Management

  • FSMD, Financial Services - Market Data

  • FSPR, Financial Services - Product Configurator

  • PP01, Postprocessing Office

Note that cross-application authorization objects such as Basis objects are also checked.

These authorization objects are documented in the system.

You can proceed as follows:

  1. Create a concept detailing which authorization profiles and roles you require and how you want their tasks to appear.

  2. Execute the activities in Customizing for Account Management under Start of the navigation path Basic Settings Next navigation step Authorizations End of the navigation path:

    • Maintain authorization types

      You can use authorization types to determine maintenance authorizations for contracts, financial conditions, and standing orders based on the fields of the respective object.

    • Define field groups relevant to authorizations

    • Maintain authorization groups

    • Define authorization check in BAPIs

    • Generate and assign authorizations

      In this last step you generate the required roles and profiles and assign the users.

      For more information about the procedure in this step, see the initial screen in the Information transaction.

Result

The system users receive the authorizations they require.