Configuring ERM workflow in CUP issue (GRC AC 5.3)

Hi once again fellow SAP Security Folk,
Using GRC AC CUP 5.3 SP 13 I am trying to configure ERM workflow for the following scenario :
Every role change made via ERM requires approval from relevant Business Process (BP) area.  If the role change contains an SOD conflict of Medium or higher then approval is required from a 2nd central approver (basically regardless of the business process area). 
I have not been able to configure ERM workflow within CUP to be able to do this u2013 I have only been able to configure it for dual approval, i.e. every change must have approval from both BP approver and Central approver before request can progress.  I did this by assigning the Central approver to all Business Processes as an additional approver. This means that the conditions for the scenario above are met but the drawback is that all other requests also require approval from Central approver even though they donu2019t need to, generating additional workload.
Can anyone advise if this is possible and how to do it ?
Further info:-
I have setup in CUP an ERM Initiator, an ERM Custom Approver Determinator (CAD), an ERM Stage.
I have setup in ERM I have defined Business Process Approval Criteria for each Business Process approver.
I tried creating a 2nd ERM stage using a separate 2nd ERM CAD but this meant all changes required 2nd approval before request can continue.
I tried modifying the 1st Stage to Approval type All Approvers but this meant all changes required approval from all possible BP Approvers (instead of any one) before request can continue.
I tried creating a Detour/Fork but could only see within the Workflow Type selection criteria non ERM workflow types.
Thanks
Steve

You can either type in the configuration, like the what option you selected for approver (CAD or role or...etc), or other way is to capture the change log which shows what was the configuration for that stage....
(Configuration -< Change Log -> Search Change log)
Cheers !!
Zaheer

Similar Messages

  • ERM - Workflow Approval Configuration in ERM and CUP

    Hi Experts,
    I'm in the midst of configuring the workflow approval for ERM and have some queries.
    I followed the post-installation guide part 1 for ERM on the workflow configuration and have sucessfully done the following:
    1. Verified that the "AE_init_append_data_RE.xml" has been uploaded in CUP with Append option
    2. Verified that request type "RE_ROLE_APPROVAL" with workflow type "RE" exists
    3. Verified that priority "RE_HIGH" with workflow type "RE" exists
    4. Created a workflow initiator for ERM called "ROLE_APPROVAL" in CUP -> Configuration -> Workflow -> Initiator (with the said details as per the post-installation guide)
    5. Created a CAD called "ERM_ROLE_APPROVER" for ERM in CUP -> Configuration -> Workflow -> Custom Approver Determinator (with the said details as per the post installation guide, filling in the necessary URI, uname/pw for admin with UME roles)
    6. Created TWO stages , one stage for the role owner called "ERM_ROLE_APPROV", and one stage for the internal control owner called "ERM_ROLE_APPRO2", both with workflow type "RE" and Approver Determinator "ERM_ROLE_APPROVER" which was created in step 5 earlier.
    7. Created a path for ERM Role Approval Workflow in CUP -> Configuration -> Workflow -> Path, with workflow type "RE", Number of Stages "2", Initiator "ROLE_APPROVER", Active "checked" and I put Stage 1 as "ERM_ROLE_APPROV" and stage 2 as "ERM_ROLE_APPRO2".
    8. Configured the Exit Web Service (followed the details as per the post-installation guide for ERM)
    As my role approval is pretty straight forward (i.e. based on business process attribute defined, with each role owner being responsible for their business process), I did the following:
    1. Create approval criteria "Role Approver for Business Process FI"
    2. For that criteria, I based it on attribute "Business Process"
    3. I clicked on "Assign Approvers" to define who is the approver (i.e. the respective role owner responsible for Process FI)
    4. I defined the condition for this criteria, Condition = AND, Attribute = Business Process, Value = FI
    My queries:
    1. Is the approval criteria which I created in ERM, referring to 1st stage or 2nd stage of the path in CUP?
    2. I'm assuming that for query 1, the approval criteria which I created is for 1st stage (i.e. ERM_ROLE_APPROV), where can I configure the 2nd level approval for the internal control owner (i.e. ERM_ROLE_APPRO2, in the path which I defined in CUP)?
    Thanks!

    Hi Baldwin,
    All workflow paths in CUP are triggered by an Initiator.  Once the request from ERM meets "Initiator" ("ROLE_APPROVAL") requirements in CUP, the request will go to the first stage defined in the respective path. Approvers defined in each stage of the path can approve request. Once the request is approved in CUP, approval information will be sent to ERM and then the role in ERM will be moved to the next stage.
    Best Regards,
    Sirish Gullapalli.

  • Load approvers, solicitors & workflows to the CUP (SAP GRC AC 5.3)

    Hello,
    I want to know if there is a way to load the approvers, solicitors & workflows to the CUP (SAP GRC AC 5.3) massively.
    Best Regards.
    Pablo Mortera.

    Most of the configuration screens in CUP have an export button and an associated excel/text upload template. Use this template to mass create/update configuration data.
    Regards,
    Alpesh

  • Warnings while activating BC SETs in  configuring ERM on  GRC 10.0

    Hello ,
    We are trying to configure GRC 10.0 , when I tried to configure ERM and tried to active the given BC Sets as per the Config Guide , We found that one of the BC SETS " GRAC_ROLE_MGMT_LANDSCAPE" is throwing a warning.All the other BC SETS are activated Successfully.
    Please let me know if any one tried the same and getting the warnings.
    Regards,
    Jagadish

    Dear Rajan,
    Today I tried to activate in Expert mode , still its throwing Warning !!.
    Regards,
    Jagadish Bhandaru

  • Enterprise Portal Configuration Issue - GRC 10.0

    Hi All,
    I am following AC10EP Configuration guide to integrate portal and GRC 10.0.
    According to the configuration guide i need add any entry for SPML under AUTH integration scenario as shown below.
    When I am trying to add the same in my system i am getting the issue as "Choose the key from allowed namespace" as shown below.
    Please suggest if there is any solution to get this fixed.
    Regards,
    Sai.

    Hi Prasant,
    Thanks for the details.
    I have made all my configuration correctly. Just now my issue got fixed. I got the same message as shown above and when i clicked on ENTER button it just accepted and went through.
    It is just a warning message and i stopped seeing it without clicking on ENTER button
    Though its not a issue, I made it an issue for myself
    Hopefully if anyone come across the same should correct it seeing this post
    Regards,
    Sai.

  • Is it possible to configure ERMS in Multi Client environment

    Hi All,
    I am currently working on a requirement where in we have a single CRM Instance connected to multiple back end ECC Systems. We have a client set up in CRM fore each ECC System. Each ECC System address the requirements specific to a region. Coming to the issue, can we have ERMS set up to handle e-mails sent by contact persons/business partners from different ECC Systems and route this to appropriate agent in CRM. Say a customer from region2 has sent a complaint via e-mail, in this case it should go to  Agent created in Client2. Any pointers on how this can be modelled... do we have any limitations on ERMS being extended to multiple clients.
    Thanks,
    Udaya

    Hi Udaya,
    Sounds Interesting requirement !
    From the very fact that the BP Master data is client specific, which means that all the client specific customer will be stored in those respective clients, so the emails which come into the CRM system should be destined directly to the ERMS email ids created for multiple clients.
    That is, you need to configure ERMS receiving email ids in your CRM system for all the clients.
    Then, you need to map all these email ids in the transaction SO28 against the ERMS BOR.
    In this way, the email from the customer can be sent to that specific client.
    But, there is a problem:
    Let say, the customer from client2 had sent an email to the ERMS email id in the CRM system client 100, then as per the mapping in the transaction SO28 the ERMS workflow can be triggered. This will perfectly work !
    But if the customer is restricted to send his/her emails only to a common unique customer care id, then there will be problem of differentiating the clients.
    Other possible way could be to configure ERMS email ids for all the clients and map the same in SO28.
    But again, the problem is, if the customer from all the clients can send emails to only one ERMS email id, then this unique email id should be mapped with different ERMS client email ids in the SMTP Plug-In level itself (I am not sure if this can be possible to map different emails ids in the SMTP level) and
    there should be some logic/rule to distingush the CRM client(based upon the customer email id) and then based upon the mapping in the SMTP level, the SAPConnect can then trigger the respective ERMS workflow for the ERMS email id, as maintained in transaction SO28.
    The above discussed information are subjected to probability and am not sure whether all the stated information can be possible, but just thought of a way for your requirement from ERMS perspective.
    So now the point that we need to know is, whether an email id can be mapped with multiple client specific ERMS email ids in the SMTP plugin level ? If yes, then is there a logic/rule can be impossed for this mapping, based upon the incoming customer email id or something like that ?
    Sorry Udaya, I could think only to this much from the ERMS side and couldn't reach out till the STMP level.
    Hope these information will help you in your further researches for your requirement.
    Thanks & Best Regards,
    Vinod

  • Trigger mitigation workflow within CUP

    Hi,
    I have configured the necessary workflow types, Mitigation controls and Mitigation objects. I am able to trigger workflow when I create a control in RAR. How do I go about triggering workflow within CUP?
    Currently, when I create a request, in one of the stages a risk analysis is mandatory. I am able to create or assign an existing mitigation control before the workflow process can continue. This works well. However, I would like a workflow to be triggered when somebody clicks on the 'create' mitigation control button as well as when somebody assigns an existing mitigation control.
    Any input would be highly appreciated.
    Thanks
    Mo

    Hello Muhammad,
      What you are saying is that you wish to trigger workflow from within CUP itself when you are assigning/creating mitigation control from within CUP, right? If i got that right then i would say that it is not possible. For mitigation control creation/assignment the trigger is only RAR application and be done through that only. Since for such workflows the request types would be type MITCTRL  and MITOBJ and not CUP..
    I nice feature though if it would have been there. In case i got anything wrong, then kindly elaborate so that i could get clarity.
    Regards, Varun

  • Error in ERMS Workflow

    Hi,
    I tried to configure ERMS. We can receive e-mails and the standart ERMS workflow is triggered but we got he following errors:
    - Agent determination for step '0000000004' failed
      - Workflow WS00200001 no. 000000002022 activity 0000000004 role 'AC00200136': No agent found
        - Resolution of rule AC00200136 for task TS00207914: no agent found
    The first task is set as General Task.
    The trace from SCOT contains the following lines:
    SO28 entry found
    Recepient BOR Object
    Structure: SWOTOBJID
    Technical Recipient: ferudun.atakan-at-ybpcrm.astron.grp
    Internal Recipient Found: CRTCLNT304ERMSSUPRT2FERUDUN.ATAKAN-at-YBPCRM.ASTRON.G
    Internal Recipient Found: RP                                      <OBJECT>
    Address Type: OBJ
    Start of Delivery to Internal Recipients
    where is the problem?
    - ferudun
    End of Delivery to Internal Recipients
    SUBMIT: TO ALL

    Hi Pieter,
    Thanks. But my rule policy is simple as stated below.
    If
    E-Mail orginal recipient contain "contactusatabc.com"
    Then
    Route EMail ( Organizational Object = Assistant Manager/Executvie )  and
    Create Service Request ( Process type = ZR )
    Service manager profile ZSRQMROUTING is created and assigned with below services.
    1     SVC_PARAMS
    5     FG_WEBFORM
    7     FG_EMAIL
    10     UT_WORKITEMTEXT
    50     RE_RULE_EXEC
    70     AH_DEF_ROUTING
    800     UT_ERMS_REPLICAT
    And RE_RULE_EXEC assigned with
    DEF_ROUTING     O:50000008
    LOG_LEVEL     0
    POLICY     ZSTC
    Whenever a mail sent from SBWP, recipient as contactusatabc.com" and receiver type is Business Object.
    After mail has been sent and ERMS processing log shows sender id as blank ( even my user id maintianed email address in SU01)  in tcode CRM_ERMS_LOGGING
    compiled Rule: <or><not_contain case="" multivalue=""> <xpath provider="CL_CRM_E
    RMS_ADD2FB_DOCUMENT" accessor=""><constant value="/parts/SENDER_ADDRESS/text()"/
    </xpath> <constant value="abcatannon.com"/></not_contain></or>
    path address:/parts/SENDER_ADDRESS/text()
    Kindly advise me incase of any missing configuration.
    Thanks
    Shan

  • Connect CUP (in GRC 10.0) with ABAP CUA

    Hi ,
    Has anyone a short guide how to connect the CUP in GRC 10.0 with an ABAP CUA?
    We would like to use the CUP to trigger the CUA for the deployment of the CUP assigned authorisations.
    Thank you in advance!
    Br,
    Frank

    Hi Frank,
    There is one for SAP GRC 5.3 that you can access with the below link:
    http://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/80ee8c81-7812-2a10-ce91-e1be55f43491
    The GRC AC10 documentation is not available.
    May be this can be an input for the BPX team to create one
    Regards,
    Raghu

  • Document for configuring Early watch alerts And issue tracking system

    Hello Experts,
    Iam on SAP Solution Manager 4.0 and need step wise step procedure document for configuring Early watch alerts and Issue tracking system in solman 4.0 . I hv checked Help site and other standard config docs by SAP but getting confused and things are not working ,so help shall be appreciated.
    My Email id is [email protected] .
    Requested to revert at earliest as iam in urgent need of it .Points guaranteed.
    Thanks and Regards,
    Somya

    Hi Somya,
    setting up EWA is explained in Application help of SAP Solution Manager.
    It would be helpful to know, what you have already done and what is causing problems for you.
    Prerequisite to process EWA is to configure all steps described in the Basic Settings of SAP Solution Manager Configuration guide (tx SPRO).
    The configuration of Issue Tracking is also described in the IMG (Basically, it's required to activate a BC Set).
    Path in IMG: Basic Settings -> Standard Configuration of Basic Settings -> Solution Manager -> Basic BC-Sets for Configuration -> Activate Issue Tracking BC Set
    Access the configuration guide:
    - run transaction SPRO
    - choose SAP Reference IMG
    - expand tree SAP Solution Manager -> Configuration -> Basic Settings
    - follow the steps under
    "Wizard-based Initial Configuration of Basic Settings", if your SolMan system has not been yet configured or
    "Standard Configuration of Basic Settings", if you have done already some configuration.
    Best regards,
    Ruediger Stoecker

  • ORA-12560: TNS:protocol adapter error while configuring ORACLE Workflow

    Hi,
    I am trying to configure ORACLE Workflow. I have given sys password and other parameters in the given format in Workflow Configuration Assistant. My DB Server is in my local network and I connect to it using SID in SQL Plus. But I got the following error while WorlflowCA tries to execute relevant script.
    ERROR:
    ORA-12560: TNS:protocol adapter error
    SP2-0640: Not connected
    WorkflowCA: Non-Oracle10g database detected
    If anybody is having any clues, please help me.
    Thanks in advance
    Ajish M.

    Thanks a lot for your quick reply.
    I've read all the posts mentioned (quite a few more) but I couldn't find any suggested solution to the "non-oracle10g"-problem other than using the global db name instead of the sid - which didn't help in our case:
    However, in a last desperate attempt to solve the problem on my own before launching another cry-for-help-post I did try running the configuration assistant using the correct password for the SYS user 8-} and - strange but true - it did work :-)
    Needless to say: I used the global db name of course, so I can't say what would have happened without it, but I trust your hint was a legitimate one.
    Anyway - I gues that error Message concerning a "non-oracle10g database" was slightly misleading in this case.... grrrr.
    Andreas

  • HI!  I have a new macbook air but having difficulty connecting to a router if I am about 10 meters away.  My iMac, iPad, iPhones and iPods can connect easily.  Is there something that I need to configure?  I have no issues if I am close to it.  Thank you!

    HI!  I have a new macbook air but having difficulty connecting to a router if I am about 10 meters away.  My iMac, iPad, iPhones and iPods can connect easily.  Is there something that I need to configure?  I have no issues if I am close to it.  Thank you!

    Hello, If you are dealing with one of the really thin iMac's that have no superdrive, then the superdrive icon should not appear on the desktop when you plug it in, but when you put in a disk (CD, DVD, etc.) that should appear. If you go into disk utility, and look at superdrive, that should be clickable and not grayed out when you have it plugged in. If this does not show up in disk utility, go to Apple, and ask to speak to their supervisor, speaking to a customer service agent is like talking to a potato, nothing gets done. Good Luck!

  • AE 5.1 and 5.2 - Configuring parallel workflows for "Delete" Request type

    Has anyone configured parallel workflows for the "Delete" Request type?  I want to configure 1 for SAP and 1 for non-SAP applications, but have been unable to do it successfully. 
    The initiators I have created that do not work are:
    1 - SAP initiator:
    SAP application with "OR" condition
    Request Type = Delete with  "AND" condition
    2 - Non-SAP initiator:
    Non SAP application 1 with "OR" condition
    Non SAP application 2 with "OR" condition
    Non SAP application 3 with "OR" condition
    Request Type = Delete with  "AND" condition
    When I create a request to Delete a user with SAP app and Non SAP app I get the error:  "Error in creating request. Multiple Initiators, [NON SAP DELETE, SAP DELETE] Found."
    Based on what I am reading on p. 58 of the AE52ConfigGuide.pdf, this should be possible to do.  Does anyone have any suggestions?

    This is my understanding.,
    A request cannot have more than one initiator. You cannot trigger multiple initiators for one single request. In your case both attributes SAP & Non SAP application are given with OR condition which makes both the initiators alike. As mentioned in the documentation the request for deletion can be made to happen in both SAP & Non SAP application by having forked path (for this the initiator should be OR Application SAP OR Non SAP Application AND Request Type Delete). Given the other option then it should have different initiator for SAP and Non SAP applications by giving them with AND condition.

  • Configuring Transport workflow

    Hi all
    I am planning to configure transport workflow in the Solutioin Manager 4.0 box. It already has TMS configured on that.If I configure Transport workflows will the already existing TMS will be deteled?
    Plz reply soon
    Jyoti

    Hello,
    each satellitesystem has his own domain controller.
    The Solman is connected via domain link with these domain controller of each satellitesystem.
    You can create this Links in two Steps:
    1.     - Logon in Solman system where the domain controller is located
             - Tcode: STMS&#8594;Overview&#8594;Systems
             - Mark the satellitesystem where the domain controller is located
             - SAP System&#8594;Create&#8594;Domain Link execute
    Now you only create the request for an domain link!
    2.     - Logon in satellitesystem where the domain controller is located
             - Tcode: STMS&#8594;Overview&#8594;Systems
             - Mark the satellitesystem where the domain controller is located
             - There must be an option to answer the request from the Solman
    You can check the domain link in Solman when you click in STMS on the button „Legend“.
    The Typ „Other Domain Controller“ has a special symbol.
    You get detailed informations about domain link in the SAP Library SAP Solution Manager.
    http://help.sap.com/saphelp_sm40/helpdata/en/ae/64c33af662c514e10000000a114084/frameset.htm
    Please type in the search field "create domain link".
    You will get some detailed documentations for domain link.
    The transport workflow is realized in Solman with CRM and Solman actions.
    Example:
    If the status of service order SDHF (urgent correction) is changed from "In development" in status "To be tested".
    there is an automatic transport into QAS system. Please be sure that you have realized the transport task, before.
    You can create also a backround job for each system/mandant (except the productive system) for automatic import of all realized transport requests. We planed these backround jobs in all of our satellitesystems (except the productive system) every 10 minutes.
    For you productive system you should start the backround job (Import Transport Request (Background) from the maintenance cycle manually. The report is called /TMWFLOW/SCMA_TRORDER_IMPORT.
    This report imported all realized transport requests from the import queue of your system.
    Hope it was helpful
    Best regards
    Thomas

  • CUP Issue in workflow - Approver not found after SP13

    Dear All,
    We are facing an issue after upgrade to SP13 in CUP. The request is not getting saved and throwing an error - Approver not Found.
    We uploaded the xml files also of SP13 after upgrade has completed.
    We have not changed the workflow after upgrade and verified all the attributes of Initiator, CAD and approver is already available in CAD - but still we are receiving the error "Approver Not Found"
    The same workflow is working succesfully in Production system which is under SP9.
    Is this an issue with SP13. If any body has encountered please let us know how to resolve.
    Thanks and Best Regards,
    Srihari.K

    Dear Chinmaya,
    Below is the error log
    Log :
    2011-05-09 08:13:17,375 [SAPEngine_Application_Thread[impl:3]_25] ERROR NoApproverFoundException in Save request
    com.virsa.ae.workflow.NoApproverFoundException: No approvers found for req no : 135, for reqPathId, 209, for path, CHNG_ANZ_Z6 and approver determinator : ANZ_LAC
    Also, we tried with simple workflow as well with just 2 attribute logic. Still we received the same error
    Thanks and Best Regards,
    Srihari.K

Maybe you are looking for

  • Software Updates and SCUP updates are not getting rolled out during system rebuild.

    Hi, I am trying to rebuild the machines for one of my client and i am getting below error during Software update stage as it throws below error, Could someone please let me know why the below updates are getting failed. =======================[ smssw

  • Adobe Premiere Pro Help | What's New in CS6

    strJiveDescriptionhttp://helpx.adobe.com/premiere-pro/using/whats-new-cs6.html

  • Material Lead Time

    Hello Gurus, In MRP2 of master data there is the planned delivery time to get the material from external. Do you think, there is in Sap another field for the shipping time. So the shipping time added to the planned delivery time will give me the tota

  • Uanble to open the App server console after installing the Oracle soa suite

    Hello, after installing the oracle soa suite 10.3.1.0 we are unable to open the application server console. it gives "page not found" error. We have installed on a Win2000 server instance. We have selected all the default values while installing. any

  • Table containing serial number of a material

    Hi Friends, I have activated serial number for materials. When I do GR, i give serial number for the material. I just want to know in which Table does these serial numbers specific to one material is stored. Information for the serial number for each