<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: How do I implement table defined row level security? in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676556#M178630</link>
    <description>&lt;P&gt;It does appear the Live Universe Connection does carry through all of the correct security that is defined in the user profile on the BI Platform.&lt;/P&gt;
  &lt;P&gt;However, using Live Connection to UNX has some huge limitations in SAC, so this wouldn't be an acceptable workaround.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;SAC needs to be able to support table driven row level security, or automatically create the roles and assign them to the users based upon data in the model.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 18:04:16 GMT</pubDate>
    <dc:creator>omacoder</dc:creator>
    <dc:date>2018-07-19T18:04:16Z</dc:date>
    <item>
      <title>How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaq-p/676543</link>
      <description>&lt;P&gt;I understand in SAC you can create roles, and then assign those roles and map them to certain columns.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;However, each user will have different access to different rows in the model.&lt;/P&gt;
  &lt;P&gt;I'm not seeing a way around this without creating a role for each user?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 23:46:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaq-p/676543</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-06-28T23:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676544#M178618</link>
      <description>&lt;P&gt;Hi Brian - I would assume this would work better implementing on the back end; what is your data source?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 10:08:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676544#M178618</guid>
      <dc:creator>TammyPowlas</dc:creator>
      <dc:date>2018-06-29T10:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676545#M178619</link>
      <description>&lt;P&gt;You're right, handling it at the DBMS would definitely be preferred, but I'm trying to do a POC in SAC to present to our enterprise and the only option for a data source is Excel via google drive. So that is the data source that I am working with.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 14:14:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676545#M178619</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-06-29T14:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676546#M178620</link>
      <description>&lt;P&gt;And in planning scenarios, you have to handle this kind of security at the SAC level.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 14:26:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676546#M178620</guid>
      <dc:creator>FCI</dc:creator>
      <dc:date>2018-06-29T14:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676547#M178621</link>
      <description>&lt;P&gt;Not actually sure this is possible directly in SAC. I`m guessing if you connect to a Universe using a users SAP BI credentials that the Universe level row level security would be respected. Not tried though!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jul 2018 08:37:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676547#M178621</guid>
      <dc:creator>former_member435026</dc:creator>
      <dc:date>2018-07-04T08:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676548#M178622</link>
      <description>&lt;P&gt;Hi Brian,&lt;/P&gt;
  &lt;P&gt;By enabling the data access control on a dimension you can define who has the right to read or write on a given value of a dimension.&lt;/P&gt;
  &lt;P&gt;Isn't it what you want to achieve ?&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/170413-right.jpg" /&gt;&lt;/P&gt;
  &lt;P&gt;Regards,&lt;/P&gt;
  &lt;P&gt;Frederic&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 14:56:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676548#M178622</guid>
      <dc:creator>FCI</dc:creator>
      <dc:date>2018-07-09T14:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676549#M178623</link>
      <description>&lt;P&gt;Based upon this implementation, I would have to set up a separate role for each individual user. This is not feasible as the data the user has permission to is controlled within the database itself and is constantly changing with changes to users (eg new users, promotions, demotions, etc). Each time one of these actions occurs, I would need to track and trace that action and then also update that individual user's role.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 15:01:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676549#M178623</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-07-09T15:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676550#M178624</link>
      <description>&lt;P&gt;But you can't handle row security level at a role level. Can you ? &lt;/P&gt;
  &lt;P&gt;AFAIK, it is handled at the dimension level. And yes this has to be maintained manually, I was hoping you could fill these security fields through a dataSource but these fields seem to not be available for mapping.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 07:11:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676550#M178624</guid>
      <dc:creator>FCI</dc:creator>
      <dc:date>2018-07-10T07:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676551#M178625</link>
      <description>&lt;P&gt;Here's the models that I would like to implement in SAC.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/170471-model.png" /&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;5 models. All linked by the keys.&lt;/P&gt;
  &lt;OL&gt;
   &lt;LI&gt;When user123 logs in, it finds all Jobs/Locations/Companies this user has access to see by looking up in tblRowLevelSecurityDim&lt;/LI&gt;
   &lt;LI&gt;Based upon the inner join from this table to tblSalesFact, they will only see the sales amount that is applicable to their jobs/locations/companies&lt;/LI&gt;
  &lt;/OL&gt;
  &lt;P&gt;In order to do this with role based, from my understanding, I would have to create a role for every JobKey and assign each user to be able to view that job key. I would then have to maintain that list of roles and watch for any changes/adds to that JobKey and get the roles updated ASAP. Essentially I'd have to make a role for each user.&lt;/P&gt;
  &lt;P&gt;Currently, in the BI Platform, this is handled via inner joins at the row level at the DBMS by adding a dynamic where clause on tblRowLevelSecurityDim that says where AuthenticatedUserNameAtSQLServer = @UserName&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;We attempted to do this in Lumira in BI Platform, but the performance and defects we keep running us into has SAP Support continuing to push us to use SAC. Because we could have 200 area managers/regional managers/CEO/CIO etc logging into this dashboard, it is MOST IMPORTANT that the users authenticating only see the sales numbers applicable to their region.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 15:15:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676551#M178625</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-07-10T15:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676552#M178626</link>
      <description>&lt;P&gt;I understand perfectly well the business need. But as the SAC roles don't handle row level security, I didn't see how this is going to multiply your roles. Row level security is handled at the dimension level which should be maintained manually (again AFAIK).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
  &lt;P&gt;I'm "amused" by you remark on Lumira (and the pressure to move to the SAC), which version are you using (designer or discovery) ?&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 15:50:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676552#M178626</guid>
      <dc:creator>FCI</dc:creator>
      <dc:date>2018-07-10T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676553#M178627</link>
      <description>&lt;P&gt;Discovery 2.1 SP1.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 15:54:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676553#M178627</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-07-10T15:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676554#M178628</link>
      <description>&lt;P&gt;If I attempt this with a live unx connection, when I set up a new connection in SAC, it asks me for the BI Platform username and password.&lt;/P&gt;
  &lt;P&gt;Is this the username that is passed to the database when a query is ran? If so, then every user who opens a SAC story will still see the same data based upon the username I put in the live connection?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 15:59:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676554#M178628</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-07-10T15:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676555#M178629</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;I think with a live connection it does actually pass the user and password to the BI Platform. You`d still have to setup row level security in the Universe using your SAP BI users and groups for it to work though. Or possibly wondering if the SAP BI username is passed this could be used in a Universe filter. Thinking off the top of my head here, I`d have to try it!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 12:51:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676555#M178629</guid>
      <dc:creator>former_member435026</dc:creator>
      <dc:date>2018-07-19T12:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I implement table defined row level security?</title>
      <link>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676556#M178630</link>
      <description>&lt;P&gt;It does appear the Live Universe Connection does carry through all of the correct security that is defined in the user profile on the BI Platform.&lt;/P&gt;
  &lt;P&gt;However, using Live Connection to UNX has some huge limitations in SAC, so this wouldn't be an acceptable workaround.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;SAC needs to be able to support table driven row level security, or automatically create the roles and assign them to the users based upon data in the model.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:04:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/how-do-i-implement-table-defined-row-level-security/qaa-p/676556#M178630</guid>
      <dc:creator>omacoder</dc:creator>
      <dc:date>2018-07-19T18:04:16Z</dc:date>
    </item>
  </channel>
</rss>

