cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Multiple Approver for Mitigation control

Former Member
0 Likes
2,391

Dear experts,

I know in GRC 10, there is only one approver for mitigation control and multiple monitors and this is the standard functionality.  I wanted to know if anyone know how to modify this MSMP workflow for mitigating control to have multiple approvers.

Is this possible?  can we make changes in SAP delivered  workflow to make custom stages to have multiple approvers for each control. Thanks in advance.

Regards,

Faisal

View Entire Topic
Former Member

Hi Faisal,

This should be a simple modification.  Within "Modify Task Settings" for the standard approval Stage, change "Approval Type" to "All Approvers" instead of "Any One Approver".  The result, all approvers must approve the request (in parallel) before the request advances past the stage.  You can do this for any type of workflow.

FYI you also need to click "Modify" (instead of Modify Task Settings) and make sure the change is found here too:

Regards,

Ken

Former Member

Thanks a lot Ken,

Have you ever tried this?  did it work? I was under the imprison that SAP delivered MSMP will not be modifiable.  I'll try it and let you know if that works.

Also I wanted ask you another question regarding MSMP workflow.  I'm also in process of configuring ARM the (Access request manager) but do not have solid grasp to configure  SAP_GRAC_ACCESS_REQUEST.  Is there lot of changes I have to do or just minor? Is there any step by step document out there I can use to configure my access request MSMP workflow . I know it is depend on my company requirement but just wanted to find out how to setup for two or three approvers and what  is the best practice around it..

Regards,

Faisal

Former Member
0 Likes

Faisal,

The modification I described above should work.  This modification isn't actually changing any standard delivered SAP content; rather it is modifying Stage Task settings, which are designed to be customizable.  I do not think there will be an issue with making this work.

The ARM configuration is a bit more complex.  I do not have any guides available to share with you, but I can give you some guidance.  What you really need is the GRC 10 training for Access Control, but to help you get started, keep these steps in mind:

Configuring ARM:

  1. All SAP requests in ARM begin with an Initiator rule.  You can try leveraging the standard delivered rule, but I recommend creating one from scratch.  An initiator rule includes a decision table that reads Input and results in Output based on the criteria you configure.  A great starting point is to make an Initiator rule based on Request Type.  Then, you can create different workflow paths and approval stage requirements based on the Type of Request, ex New Account, Change Account, Firefighter, etc.
  2. You must map your Initiator rule to MSMP in Step 2 (at the bottom, called Global Imitator rule).  Keep in mind that the Process ID you select in Step 1 of MSMP will directly relate to ALL other steps following.  For example, all settings in Steps 2-7 relate ONLY to the process ID that you select in Step 1 of MSMP.  The Initiator Rule's ID is not the Decision Table's rule ID; rather it is the "Function" ID # that you find in BRF+ under the application that you created.
  3. For each Rule Result, you can map a workflow path in Step 6 of MSMP.  Here, you choose your initiator rule, the rule result, and then map to a path that you create.
  4. Each path can have approval stages.  These stages have independent Task Settings and Notification Settings that can be configured for your business requirements.
  5. ARM requires you to map Integration Scenarios and Logical Group scenarios in the IMG within tcode SPRO.  Much of the ARM configuration needs to be done from SPRO.
  6. Standard delivered "Agents" will work fine for you.  Agents represent Approvers or Notification Rules.  Each stage needs an Agent to be mapped if approval is required.
  7. You can find any errors in MSMP configuration in step 7 when you "Save and Simulate".  The simulation will call out the areas of MSMP that are not configured properly.

I hope this gets you started in the right direction.  ARM configuration can take 1 day if you know what you are doing, but it can also take months of trial and error if you are new to it. 

Message me directly and I can help you along the way.

-Ken

Former Member
0 Likes

Thank you so much Ken, it is really helpful, I'll let you know how it goes and get back to you if I have issue during the  process of configuring ARM.

Regards,

Faisal

Former Member
0 Likes

Hello Ken again,

I just tried the above changes and still Mitigating control doesn't take more than one approver, when I was setting up I assigned two approvers while I was trying to create control in Access risk tab, it says only one approver can be assigned to mitigating control.  any other suggestion or I'm not doing the right way.

Please let me know, thanks in advance

Regards,

Faisal