cancel
Showing results for 
Search instead for 
Did you mean: 

SAP GRC AC 10 Workflow

07-25-2011 1:11 PM
1654 views 17 comments
0 Likes
SAP Managed Tags
Subscribe

Hi Experts,

I am new to GRC AC 10 and I need to configure workflow for various modules of AC.

How do I configure the same and are there any documents highlighting the various steps involved in the same.

Thanks,

Arjun

0 Likes

Accepted Solutions (0)

Answers (3)

Answers (3)

Former Member
0 Likes

Hello All,

We are having the same issue. We scoured the posts and SAP documentation. The best out there now is AC 10.0 Customizing Workflows for Access Management  http://scn.sap.com/docs/DOC-1566.

Still just high level with little explanation. SAP Press also puts out BFRplus Business Rule Management for ABAP Application. Still does not hit the mark though.

Functionality this important and complicated should have a how-to-guide more like How to Customize Notification Templates for AC 10.0 Workflow .

http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/80088ef0-2590-2e10-7696-fa36bfcff...

Thanks

Jamie

kevin_tucholke1
Product and Topic Expert
Product and Topic Expert
0 Likes

James:

Not sure what issue you are having, but each of the 'modules' as you call it such as Access Requests, Role Maintenance Approvals, Mitigation assignments, each have their own process ID.  The SAP Course GRC300 goes thorugh this set up.  If you can give me specifics as to what your issues are, then I can help.  It really is not all that complicated once you understand.

BTW --- Customizing Notification Templates is STANDARD SAP Functionality with transaction SE61 and a couple of settings in GRC IMG..

Thanks.

Former Member
0 Likes

Hi Kevin,

Thanks for your reply. I have read through the guides and am having issues just getting the workflow to get to the 1st stage. I have read through the guides but I am still unsure as to what is not properly configured. I'm on the following Version Levels:

Component --> Release --> Level --> Highest SP

SAP_BASIS --> 702 --> 0012 --> SAPKB70212

SAP_ABA --> 702 --> 0012 --> SAPKA70212

PI_BASIS --> 702 --> 0012 --> SAPK-70212INPIBASIS

SAP_BW --> 702 --> 0012 --> SAPKW70212

GRCFND_A --> V1000 --> 0011 --> SAPK-V1011INGRCFNDA

[Step 1] At this point I am using the SAP_GRAC_ACCESS_REQUEST under Step 1 "Process Global Settings" with the default Rule ID "GRAC_AR_INITIATOR".  I only see the 'Enable Escalation' and 'Escalation Date' settings available even though in the guide it talks about EOR Template IDs and Submission Temp IDs which are not showing up under my Step 1. I assume this was updated in a previous release and replaced with the 'Notifications Settings' area that I see now. No Escalation, no escape conditions set.

[Step 2] Under "Maintain Rules" Rule ID 'GRAC_AR_INITIATOR' is the default with the "Rule Results" Value set to 'GRAC_DEFAULT_RESULT'. The Global Rules at the bottom bring in the same default values 'GRAC_AR_INITIATOR' & 'GRAC_NOTIF_VAR_RULE_AR'

[Step 3] Under "Maintain Agents", no changes here just the Standard GRC API Rules

[Step 4] "Variables & Templates" no changes, just left the defaults.

[Step 5] "Maintain Paths" --> Path ID 'GRAC_DEFAULT_PATH' --> "Maintain Stages"

Stage Seq '001' --> Stage ID 'GRAC_MANAGER' --> Routing 'No' Escalation Type 'defaults'

[Stage 6] "Route Mapping" --> Rule ID "GRAC_AR_INITIATOR --> Rule Result Value "GRAC_DEFAULT_RESULT" --> Path ID "GRAC_DEFAULT_PATH"

[Stage 7] "Generate Version" --> Everything is green except the following which are yellow:

> Active version data not stored for table GRFNMWCNPATH process SAP_GRAC_ACCESS_REQUEST

> Active version data not stored for table GRFNMWCNSDEF process SAP_GRAC_ACCESS_REQUEST

> No data is maintained in table GRFNMWCNGLBESR for process SAP_GRAC_ACCESS_REQUEST

> Active version data not stored for table GRACMWCNSACRQ process SAP_GRAC_ACCESS_REQUEST

Can you decipher anything from this content?

I'm able to create requests and I've made myself the manager (I've also enabled Approve Own Request), but after the request has been submitted successfully I don't get the request to show up in my 'Work Inbox'

When I go to 'Search Requests' under Access Request Administration, I'm able to see the requests with a status of "Decision Pending" but when I select one and click 'Administration' it shows the following:

Path ID "GRAC_DEFAULT_PATH" | Seq No. 1  | Stage 001  | Path Status UNKNOWN  |  Stage Status UNKNOWN

Any assistance would be greatly appreciated!

Former Member
0 Likes

Hi Darnell,

Can you check workflow customizing for agent assignment where you make each workflow task as general task. Please follow the IMG path below to do the required settings .

Couple of things :

1.) Governance, Risk and Compliance->General Settings->Workflow->Perform Task-Specific Customizing (As per the post installation steps for GRC 10.0)

2.) Were you able to generate the MSMP versions properly while configuring your workflow

Regards,


Mayuresh

Former Member
0 Likes

Sorry, quick update to this:

The following has also been defined in Stage 5 which has cleaned up some of the warning indicators during the Generation Version

[Step 5] "Maintain Paths" --> Path ID 'GRAC_DEFAULT_PATH' --> "Maintain Stages"

Stage Seq '001' --> Stage ID 'GRAC_MANAGER' --> Agent ID 'GRAC_Manager' --> Approval Type 'Any One Approver' --> Routing 'No' --> Escalation Type 'No Escalation'

[Stage 7] "Generate Version" --> Everything is green except the following which are yellow:

> No data is maintained in table GRFNMWCNGLBESR for process SAP_GRAC_ACCESS_REQUEST

Former Member
0 Likes

Hi Mayuresh,

2) I was able to generate the MSMP versions successfully while configuring the workflow in [Step 7].

1) I checked the 'Task Specific Customizing' as you suggested and found a few issues:

When I configured this initially I did this with the WF-BATCH ID we created. This was the result (we are only implementing AC and not Using HR):

> Maintain Runtime Environment - [ALL GREEN CHECKMARKS]

> Maintain Definition Environment - [RED X next to "Check Entries from HR Control Table; The Rest are Green]

> Maintain Additional Settings/Services - [RED X next to "Maintain Web Server & Maintain Standard Domain for Internet Mail"; The Rest are Green]

> Classify Tasks as General - [ALL GREEN CHECKMARKS]

> Guided Procedures [ALL RED X; None Green]

However when I look at this configuration when my personal ID, these look the same except "Configure RFC Destination" is showing a RED X. With the WF-BATCH ID it shows GREEN Checkmark.

I have converted the WF-BATCH ID to a System ID after setting this up, but everytime I try to convert it back to Dialog to see the settings I get a 'Too Many Failed Passwords Attempt' and I have to reset the password again.

Former Member
0 Likes

Hi,

Could you please check if the GRC 10.0 post installation steps are done correctly.Please note they are very critical

Thanks,


Mayuresh

Former Member
0 Likes

However when I look at this configuration when my personal ID, these look the same except "Configure RFC Destination" is showing a RED X. With the WF-BATCH ID it shows GREEN Checkmark.

I have converted the WF-BATCH ID to a System ID after setting this up, but everytime I try to convert it back to Dialog to see the settings I get a 'Too Many Failed Passwords Attempt' and I have to reset the password again.

One curious question, why do you want to change the WF-Batch id to dialog. Cant you use any other id to do the configuration or ask your Basis/Security team to do it?

Former Member
0 Likes

I think you should be able to view request in the Audit log post making "Configure RFC Destination" green. Try keeping WF-Batch id as system id and testing your workflow.

Former Member
0 Likes

Mayuresh,

I have gone back through the entire post-install steps even activating the BC set's again. The issue is still the same. Do you have any additional feedback based on the workflow details I have provided? I believe the installation and post install is correct, but I believe something is missing from my workflow configuration.

Former Member
0 Likes

Mayuresh,

The WF-BATCH user kept getting locked out due to insufficient logon attempts. I belive this was because I manually created the WF-BATCH user. I went back and deleted this user and the RFC destination, then I performed the Automatic Workflow Customizing again.

The system recreated the RFC destination and the WF-BATCH ID as a system user, but did not assign any roles so I had to do that manually.

I tried the workflow again and it work.

By manually creating the WF-BATCH ID there was a password sync issue everytime I tried kick off the workflow which would lock the user. All seems to be working now.

Former Member
0 Likes

Darnell,

Wonderful to know that. You might want to mark this thread as answered and close it.

Thanks

Former Member
0 Likes

Hi Mayuresh, this posting is actually not owned by me so unfortunately I don't believe I can close it. But thanks for your assistance!

0 Likes

Hi Darnell

Did you manage to resolve the ERROR below? and what did you do to resolve it? I am getting the same Error but for process SAP_GRAC_ROLE_APPR

( "Generate Version" --> Everything is green except the following which are yellow:

> Active version data not stored for table GRFNMWCNPATH process SAP_GRAC_ACCESS_REQUEST

> Active version data not stored for table GRFNMWCNSDEF process )



Regards

George Mothupi

Former Member
0 Likes

Hi Arjun

Were you able to configure workflows just with this guides?

Cause I am facing the same problem. Already read this guide and another one but cant find a solution.

Basically I dont find where I can set the conditions for each initiator.

Thanks very much.

Former Member
0 Likes

Hi Arjun,

Check at [AC 10.0 Pre-Implementatio From Post-Installation to First Access Request.pdf|http://www.sdn.sap.com/irj/scn/index?rid=/library/uuid/5067e447-5c64-2e10-7d9c-8f7e5953aadb] in the http://www.sdn.s[BPX Documentations|http://www.sdn.sap.com/irj/bpx/grc].

This should help you out.

Regards,

Raghu

Former Member
0 Likes

Hi Raghu,

Thanks for the help.This document gives me more clarity on how to configure the worklfow.

Thanks,

Arjun