You use the SAP User Management Engine in SAP ERP to assign SAP Manufacturing Integration and Intelligence (SAP MII) roles to actions. These actions give users permission to certain services. Some actions allow permissions on system screens. For more information about screen permissions, see Actions for Permissions.
The default SAP MII roles and their permissions are the following:
SAP_XMII_User
Users assigned to this role have read access but no access to administration screens or the SAP MII Workbench.
SAP_XMII_Developer
Users assigned to this role have access to the SAP MII Workbench and some administration screens, such as Time Periods, Connection Store Editor, and Credential Store Editor.
SAP_XMII_Administrator
Users assigned to this role have the same permissions as users assigned to the SAP_XMII_User and SAP_XMII_Developer roles, plus administration access except for the following: NWDI configuration read and write, encryption configuration, and import and export of configuration data.
SAP_XMII_Super_Administrator
Users assigned to this role have access to everything with no limitations.
SAP_XMII_Read_Only
Users assigned to this role have read permission for administration screens.
SAP_XMII_Approver
Users assigned to this role have access to approve lists under Catalog Services and can approve or reject a change list.
SAP_XMII_ProjectManagement
Users assigned to this role can handle multiple import of files and folders to the target location on SAP MII Workbench.
SAP_XMII_DynamicQuery
Users assigned to this role have permission to run dynamic queries (queries without a query template) and override all query properties. By default, this permission is granted to users assigned to the SAP_XMII_Developer role but not the SAP_XMII_User role. You assign this role to specific or all users. For more information about this role, see Template Security.
Note
Depending on your role in SAP MII, you may not see all SAP MII administration menu options and screens.
You can update role mappings by changing the actions assigned to the role. You also create new roles that have access to a particular screen.