Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

BI Analysis restriction

Former Member
0 Likes
1,404

We are implementing BI security sales hierarchy, now we have created analysis role as billing, booking etc .

Now in analysis role we have are giving default characterstics (actvt, validity, infoprovider) . In infoprovider characterstic (WANT TO RESTRICT BILLING PROVIDER ) .

selecting hierarchy and selecting the node

Hierarchy INFOAREAHIER/89991231/INFOPROV

Nodes zdb_bill

Type of authorization - 2

Hierarchy Level -2

validity -2

If i am giving 2,2,2 or 1 ,0, 1 it is working , Here not able to understand how the hierarchy level and type of authorization working . and values need to be given . and in hierarchy node we have only one node INFOAREAHIER do we need create any separate

hierachy nodes other than INFOAREAHIER.

For region we have created separate role and giving all characterstics -zarea,zregion(with *),etc . but user heierarchy is giving in Ztable thru se16 and assigning as developer created this z hierachy table .

Edited by: rao M on Jul 16, 2010 4:52 PM

We are implementing BI security sales hierarchy, now we have created analysis role as billing, booking etc .

Now in analysis role we have are giving default characterstics (actvt, validity, infoprovider) . In infoprovider characterstic (WANT TO RESTRICT BILLING PROVIDER ) .

selecting hierarchy and selecting the node

Hierarchy INFOAREAHIER/89991231/INFOPROV

Nodes zdb_bill

Type of authorization - 2

Hierarchy Level -2

validity -2

If i am giving 2,2,2 or 1 ,0, 1 it is working , Here not able to understand how the hierarchy level and type of authorization working . and values need to be given . and in hierarchy node we have only one node INFOAREAHIER do we need create any separate

hierachy nodes other than INFOAREAHIER.

For region we have created separate role and giving all characterstics -zarea,zregion(with *),etc . but user heierarchy is giving in Ztable thru se16 and assigning as developer created this z hierachy table .

Edited by: rao M on Jul 16, 2010 4:52 PM

11 REPLIES 11
Read only

Former Member
0 Likes
1,340

Here is some notes I am sharing from my side see if it helps:

It is Equivalent to value

authorizations in SAP BI security

Look at a, b, and C

a. You can have hierarchy options as below:

1.Only the selected nodes

2.Subtree below nodes

3.Subtree below nodes to level (incl.)

4.Complete hierarchy

5.Subtree below nodes to (and including) level (relative)

& set Validity range with options as follows:

Validity Range gives you Which authorization hierarchy is checked against the currently used hierarchy (strictness of check)?

1.Name, Version Identical, and Key Date Less Than or Equal to

2.Name and Version Identical

3.Name Identical

4.All Hierarchies

b. you can also Add 0TCAIFAREA as

an external hierarchy

characteristic to

0INFOPROV

C. In OTCAIPROV technical object:

You can have Selection of InfoProviders based on InfoArea hierarchy

Read only

Former Member
0 Likes
1,340

Rao,

Now in analysis role we have are giving default characterstics (actvt, validity, infoprovider) . In infoprovider characterstic (WANT TO RESTRICT BILLING PROVIDER ) .

You have to look for BILLING PROVIDER info object and add it to this analysis object ad restrict it on the hierarchy nodes.

Thanks,

Sri

Read only

Former Member
0 Likes
1,340

Thank you frank and sri for your quick help

Frank you have given hierarchy options, but i have seen if you give 1,3 (typer of authorization) than default it is taking as 0 (zero) hierarchy . and if am giving 2 than it is allowing me to give some - type of authorization (either 1,2,3 ..). Not able to understand what exact values to maintain .

As per your C type i am giving characterstic INFOPROVIDER , select hierarchy - INFOAREAHIER/89991231/INFOPROV - selection giveing values , still i was not clear going in right way or not .

Sri, I am confused here to restrict billing or booking heirarchy whether i have to request developement team to create

seperate auth relavent infoobject for billing or bokking (as we are not using adding infoobject ex:adding infoobject in resecadmin and giving values like z*) . But i have created separate analysis roles for billing , booking (z_io_billing) etc giving INFOPROVIDER, activity, validity . In INFOPROVIDER iam giving node which is related to billing or booking etc thru characterstic infoprovider and g INFOAREAHIER hierachy .

Read only

0 Likes
1,340

Rao,

I will consult one of our BI Business analyst to give the correct direction , I am not a BI functional expert.

it will take a little time (MST). From what I observe in your postings you are almost in the correct direction

some setting is not done properly

Will get back to you .

When you are maintaining authorizations ( in the Definition of Hierarchy authorization window )

in the NODES ( row ) second button on the right extreme , can you see if you can use Variables ?

Read only

0 Likes
1,340

Hi Rao,

But i have created separate analysis roles for billing , booking (z_io_billing) etc giving INFOPROVIDER, activity, validity . In INFOPROVIDER.

This will work

I am giving node which is related to billing or booking etc thru characterstic infoprovider and g INFOAREAHIER hierachy .

I am not sure if that will work, but try.

Thanks,

Sri

Read only

0 Likes
1,340

Personally the idea provided by Sri has to work.

the objects and attrubutes checked should be structured correctly including your Hierachial levels.

Read only

Former Member
0 Likes
1,340

Additional information/SAP security DOC.

a. If you have still not achieved this you can use Variables in Authorizations for VALUE / Hierarchy.

Even this will not help you then

b. Assign groups of authorizations:

You can group authorizations into

a hierarchy. Use InfoObject

0TCTAUTH for this hierarchy

(youu2019ll have to activate the content

objects for this InfoObject).

Then you can assign one or

several authorization groups to

the selected user

Read only

Former Member
0 Likes
1,340

Thanks you guys for your answers, but again putting my design queries

We have created custom table for Area, subregion Hierarchy , we are planning to assign an user through se16 table .

so that user will get access to region . Is this right way or not

Second question is that if i create billing, booking analysis role .

giving hierarchy through INFOPROVIDER heirarchy node and giving billing/booking node . My question is if we give INFOPROVIDER characterstic is this right way or we have to create separate billing characterstic and should give hierarchy node .

Third question is what values to maintain in node values

Already i have tested with INFOPROVIDER Characterstic it is working, but after i design it should not get an problem . that is reason checking it feasable way or not

Hierarchy INFOAREAHIER/89991231/INFOPROV

Nodes zdb_bill

Type of authorization - 2

Hierarchy Level -2

validity -2

If i am giving 2,2,2 or 1 ,0, 1 it is working , Here not able to understand how the hierarchy level and type of authorization working

Read only

0 Likes
1,340

I will say that this idea is not good, who will maintain the table and why do you want to administer the user through a table?

what is the exact reason to build this table?

Can you list the reasons regarding the table , if you have tried out all options given to you by SAP

I also think table maintenance will be an issue in production ? and who will maintain the table? I mean in production system

Edited by: Franklin Jayasim on Jul 16, 2010 9:38 PM

Read only

0 Likes
1,340

rao,

We have created custom table for Area, subregion Hierarchy , we are planning to assign an user through se16 table .

so that user will get access to region . Is this right way or not ?

First you find out from your ABAers how many region you need to restrict. If it is less than 30 regions,then go with

role base design concept.

If regions are more,ABABer will create a table in that table once colum will be for users / second colum will be nodes and third colum will be users.

So when user executes the query, based on run time variable .

eg1: LEt say that user1 has access to region1, then at run time he gets a popup screen to enter variable..so he see tha data for region1

Eg2: Let say user 2 ,should have access to region 1 to region 50 ? (consolidated data)

if you follow eg1. then its tedious process for this user to enter 50 region one at a time.

So best option is to maintain it in table. i.e In the table it self they will link which user has to access to which regions.

So at run time you need out need to enter values for variable. See the word doc.

PS: while creating a role for restricting query you have to include the variable, so that at run time the user will will get the correct region data.

No need to give se16 access to the users.

Thanks,

Sri

Read only

0 Likes
1,340

Thanks for your explanation, we are taking second example which we have so many regions and subregions - according to our helpdesk ticket we are going to give the region/subregion selection will be given thru se16 by security person not by any other user (No Other person will have access to se16 in production),so that No need to select variable selection . also thinking if we can create zse16 it would be good .