<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Org Level Roles / Authorization Object Roles in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061130#M970738</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a related discussion currently going on [in this thread.|&lt;A class="jive_macro jive_macro_thread" href="https://community.sap.com/" __jive_macro_name="thread" modifiedtitle="true" __default_attr="945203"&gt;&lt;/A&gt;;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far using org-levels in the same single (derived) role seems to be in the lead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Jul 2008 14:39:59 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-07-07T14:39:59Z</dc:date>
    <item>
      <title>Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061129#M970737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi board, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have heard of the concept to use roles with "Organizational Values" only and no other authorization values contained. Similar the idea to exclude special authorization objects from common roles and combine them in dedicated special ones to prevent accidential "double usage". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first may help to control the overall number of roles coming up after deriving single/composite roles for many levels. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Is it technically feasible (for a large-scale company)?&lt;/P&gt;&lt;P&gt;- What is your experience?&lt;/P&gt;&lt;P&gt;- Drawbacks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards and many thanks for your help, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:27:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061129#M970737</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061130#M970738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a related discussion currently going on [in this thread.|&lt;A class="jive_macro jive_macro_thread" href="https://community.sap.com/" __jive_macro_name="thread" modifiedtitle="true" __default_attr="945203"&gt;&lt;/A&gt;;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far using org-levels in the same single (derived) role seems to be in the lead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:39:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061130#M970738</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061131#M970739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a few pointers on the drawbacks in the following post:  &lt;A class="jive_macro jive_macro_thread" href="https://community.sap.com/" __jive_macro_name="thread" modifiedtitle="true" __default_attr="945203"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should answer your questions.  I think it's fair enough to say that in my experience, the majority of companies which have implemented this have increased complexity and reduced security over a standard build.  Some have made it work well as they have put appropriate controls in place.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:41:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061131#M970739</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061132#M970740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julius, Snap &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:42:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061132#M970740</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061133#M970741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My formatting is nicer than yours &lt;span class="lia-unicode-emoji" title=":winking_face_with_tongue:"&gt;😜&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:51:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061133#M970741</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061134#M970742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that was fast, amazing. Thanks a lot and my appologies for not finding the other thread from the beginning. I can see drawbacks, nevertheless it is still temptating due to the fact that derivation for over 30 countries will produce a huge number of roles. Not from the system performance point of view, just to handle this amount will be painful.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given the assumtion that it is not a good idea to use "Org Value Roles", are you deriving on on composite or on single level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:51:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061134#M970742</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061135#M970743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was not even aware that it is possible to derive at composite role level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We make limited us of derived roles, and only in cases where there is certainty that the process is the same accross the orgs and will remain so. Even with that, it still does not work exactly for all fields and all scenarios over time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 14:57:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061135#M970743</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T14:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061136#M970744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE level="1"&gt;&lt;/BLOCKQUOTE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Hi there, &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; that was fast, amazing. Thanks a lot and my appologies for not finding the other thread from the beginning. I can see drawbacks, nevertheless it is still temptating due to the fact that derivation for over 30 countries will produce a huge number of roles. Not from the system performance point of view, just to handle this amount will be painful.  &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; Given the assumtion that it is not a good idea to use "Org Value Roles", are you deriving on on composite or on single level?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; Kind regards, &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; Richard&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a very tempting approach, but completely wrecks the standard auth concept and unless you are 100% tight on controlling it, can get very messy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A good way of looking at it is that you have 2 roles - one contains transactions &amp;amp; the other one a big bucket of authorisations which support those transactions.  That bucket invariably contains more authorisations than the transactions require.  Given that it is at the authorisation object level that the important security is provided, this method has it's drawbacks........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have organisational complexity then you should look elsewhere to simplify.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By consolidating your roles (e.g. if we take a risk based design approach, typically around 80% of an accountants role will be the same anywhere in the business) and building at a higher level, you need to create fewer variants (which you might be able to use derived roles for). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Put the effort in the design stage and it will pay dividends later on down the line.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Building at a higher level than task also forces the business to look at roles and responsibilities and to standardise as much as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 15:15:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061136#M970744</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T15:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061137#M970745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the top of this forum page, there is a "sticky" thread with a collection of memorable discussions and threads which contain usefull information. A number of them are authorization design related, and the one with the subject "Security Design" will also be interesting for you if you have not read it yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It certainly was for me &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 20:41:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061137#M970745</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T20:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Org Level Roles / Authorization Object Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061138#M970746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julius, Alex, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you are gorgeous. Many thanks for your efforts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 20:59:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/org-level-roles-authorization-object-roles/m-p/4061138#M970746</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-07T20:59:31Z</dc:date>
    </item>
  </channel>
</rss>

