<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security on Qualification Object in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997511#M1494729</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use context sensitive authorisations P_ORGINCON (switch on in tcode OOAC). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTSW INCON 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create structural profile (OOSP) which returns employees of manager and all Q objects what manager should see from his/her subordinates. nnnnnnnn refers to the Qualification Group (QK) which has the qualifications manager should be able to see. Make also sure that all employees and managers have their infotype 0105 subtype 0001 mapped to their user id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;your manager profile&amp;gt;|10|01|O  |                 |X|O-O-S-P      |12| | |D|RH_GET_MANAGER_ASSIGNMENT&lt;/P&gt;&lt;P&gt;&amp;lt;your manager profile&amp;gt;|20|01|QK|nnnnnnnn|   |QUALCATA|12| | |  |&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then assign that to manager user-id (OOSB) and add this object P_ORGINCON to manager role (PFCG):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHC: R&lt;/P&gt;&lt;P&gt;INFTY: 0024&lt;/P&gt;&lt;P&gt;PERSA: *&lt;/P&gt;&lt;P&gt;PERSG: *&lt;/P&gt;&lt;P&gt;PERSK: *&lt;/P&gt;&lt;P&gt;SUBTY: *&lt;/P&gt;&lt;P&gt;VDSK1: *&lt;/P&gt;&lt;P&gt;PROFL: &amp;lt;your manager profile&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;99% of the companies use the "new" assignement of qualifications to employee using relationships (infotype 1001 between objects Q and P). But still authorisation to see which qualifications can be seen is depending on infotype 0024 authorisations. In the future also PLOG_CON object can be used to achieve this but it is not currently supported...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saku&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Sep 2010 04:44:33 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2010-09-16T04:44:33Z</dc:date>
    <item>
      <title>Security on Qualification Object</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997508#M1494726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a requirement to set up security for qualifications such that all qualifications (Q) within a particular qualification group (QK) be visible to the employee who holds the qualification so that they can add, modify and delete qualifications in this group through ESS.  That part is standard.  The tricky part is that managers should NOT be able to see that their employees hold qualificaitons from this qualification group.  Managers must be able to see all other qualificaitons the employee holds, just not any from that qualification group.  All other qualification groups must function as normal where a manager may view, update, modify and delete their employees qualifications through MSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More information that may or may not be useful.  We are deploying the standard delivered qualification managed tools through ESS and MSS that allow an employee to add, modify and delete their own qualifications and also allows managers to do the same.  Qualification groupings (QK) are objects stored in HRP1000 and they are related to employees through HRP1001.  Also, I am almost completely unfamiliar with how security is done in SAP.  Thank you I appreciate any help that can be provided.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whitney&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2010 21:18:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997508#M1494726</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-17T21:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Security on Qualification Object</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997509#M1494727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Whitney,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure to create qualification tasks in such a way that it does not get included in the Qualification catalog before creating the profile which will be assigned to the Employees Manager.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 22:01:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997509#M1494727</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-21T22:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security on Qualification Object</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997510#M1494728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whitney,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let say you have User1 to User3.&lt;/P&gt;&lt;P&gt;Qualigication:  Q1 to Q20&lt;/P&gt;&lt;P&gt;Qualification group:  group1 to group5&lt;/P&gt;&lt;P&gt;Group1 :  Q1 to Q5&lt;/P&gt;&lt;P&gt;Group2 :  Q6 to Q7&lt;/P&gt;&lt;P&gt;group3: Q8 to Q14&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let stay &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User 1 will be able to see group1&lt;/P&gt;&lt;P&gt;User 2 will be able to see  group2&lt;/P&gt;&lt;P&gt;user 3  will be able to see group3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now manger will be able to see &lt;/P&gt;&lt;P&gt;Manager will be able to see  : Q15 to Q20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you can restrict on P_ORGIN&lt;/P&gt;&lt;P&gt;User 1 will get group1 access:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Infotype : Enter your infotype&lt;/P&gt;&lt;P&gt; Subtype: Subtype&lt;/P&gt;&lt;P&gt; Authorization Level : W&lt;/P&gt;&lt;P&gt; Personnel Area&lt;/P&gt;&lt;P&gt; Employee Group: group1&lt;/P&gt;&lt;P&gt;  Employee Subgroup&lt;/P&gt;&lt;P&gt;  Organizational Key&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Manager will get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manager  will get access to Q15 to Q20:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Infotype : Enter your infotype&lt;/P&gt;&lt;P&gt; Subtype: Subtype&lt;/P&gt;&lt;P&gt; Authorization Level : W&lt;/P&gt;&lt;P&gt; Personnel Area&lt;/P&gt;&lt;P&gt; Employee Group: Q15 to Q20&lt;/P&gt;&lt;P&gt;  Employee Subgroup&lt;/P&gt;&lt;P&gt;  Organizational Key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 23:01:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997510#M1494728</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-21T23:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Security on Qualification Object</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997511#M1494729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use context sensitive authorisations P_ORGINCON (switch on in tcode OOAC). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTSW INCON 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create structural profile (OOSP) which returns employees of manager and all Q objects what manager should see from his/her subordinates. nnnnnnnn refers to the Qualification Group (QK) which has the qualifications manager should be able to see. Make also sure that all employees and managers have their infotype 0105 subtype 0001 mapped to their user id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;your manager profile&amp;gt;|10|01|O  |                 |X|O-O-S-P      |12| | |D|RH_GET_MANAGER_ASSIGNMENT&lt;/P&gt;&lt;P&gt;&amp;lt;your manager profile&amp;gt;|20|01|QK|nnnnnnnn|   |QUALCATA|12| | |  |&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then assign that to manager user-id (OOSB) and add this object P_ORGINCON to manager role (PFCG):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHC: R&lt;/P&gt;&lt;P&gt;INFTY: 0024&lt;/P&gt;&lt;P&gt;PERSA: *&lt;/P&gt;&lt;P&gt;PERSG: *&lt;/P&gt;&lt;P&gt;PERSK: *&lt;/P&gt;&lt;P&gt;SUBTY: *&lt;/P&gt;&lt;P&gt;VDSK1: *&lt;/P&gt;&lt;P&gt;PROFL: &amp;lt;your manager profile&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;99% of the companies use the "new" assignement of qualifications to employee using relationships (infotype 1001 between objects Q and P). But still authorisation to see which qualifications can be seen is depending on infotype 0024 authorisations. In the future also PLOG_CON object can be used to achieve this but it is not currently supported...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saku&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 04:44:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-on-qualification-object/m-p/6997511#M1494729</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-09-16T04:44:33Z</dc:date>
    </item>
  </channel>
</rss>

