Authorization Administration in the Account Management System
The concept of authorization administration in the Account Management
system is based on the authorization administration in the SAP system. You can find the documentation for this authorization administration in SAP Library under Users and Roles (BC-SEC-USR).
You use authorization administration to represent authorizations and areas of expertise. In Account Management
, authorization objects are provided for
Dialog transactions
Customizing transactions
BAPIs
You can use them to restrict the creation, changing, display, locking, deletion, reversal, transfer posting, return, execution, and simulation of data or processes.
Thanks to the system's modular authorization concept, you can define authorization profiles and roles to suit your employees' work centers. For example, you can adapt an authorization to suit a work center at which private customers or corporate customers are serviced, or to suit processing staff working in payment transactions.
Within these profiles and roles there are several authorizations that you can use to define which business objects your employees are allowed to edit (authorization objects), and which editing functions are then permitted.
The business objects to which you assign the authorizations are defined in the system as authorization objects and grouped together in object classes. You can find these user-defined authorization objects in the system in the following object classes:
FICO, Financial Services - Financial Conditions
FPCO, Financial Services - Posting Control Office
FSAM, Financial Services - Account Management
FSDH, Financial Services - Posting Lock Management
FSMD, Financial Services - Market Data
FSPR, Financial Services - Product Configurator
PP01, Postprocessing Office
Note that cross-application authorization objects such as Basis objects are also checked.
These authorization objects are documented in the system.
You can proceed as follows:
Create a concept detailing which authorization profiles and roles you require and how you want their tasks to appear.
Execute the activities in Customizing for Account Management
under :
Maintain authorization types
You can use authorization types to determine maintenance authorizations for contracts, financial conditions, and standing orders based on the fields of the respective object.
Define field groups relevant to authorizations
Maintain authorization groups
Define authorization check in BAPIs
Generate and assign authorizations
In this last step you generate the required roles and profiles and assign the users.
For more information about the procedure in this step, see the initial screen in the Information
transaction.
The system users receive the authorizations they require.