GRC 10: How to upload Org Level Rules in GRC 10?

Hello Friends,
we have implemented GRC 10 recently but missed to move org level rules from GRC 5.3 to 10. I don't see an option to load org rules in SPRO. Can you please let me know how can i load org rules from 5.3 to 10 with out disturbing the existing risks / functions? or is there an option to update tables directly for org rules?

Hi Colleen Lee,
Thank you for your response. Yes i see Master Data > Exception Access Rules > Organizational Rules and i am able to create org rules but i am trying to find an option to upload all at a time as we have around 50 org rules and have 2600 lines in it. creating manually will take so long and looking for alternate.
Thanks & Regards 
Pradeepthi

Similar Messages

  • AME line level rule creation ?

    Hi,
    Kindly let me know how to create line level rules in Approval Management Engine.
    Requirement is such that I have a header and there are lines associated with it. Each line follows a different approval flow.
    Once all the lines are approved the header should become approved.
    Kindly let me know how this could be achieved using AME.
    Thanks.

    Hello,
    Primarily the job of AME is to provide you with a list of approvers based the way you have configured the same.
    Now, it is possible that you can check the requisition lines and check whether a line is project based or Task based
    and you will also be able to pull the approver list.
    But, the question is (as mentioned earlier PranitSaha), how do you break the requisition into different lines and send them for different approvals?
    I mean, how do you generate different transaction_id for each of the requisition lines if the requisition is at the header level.
    Though you can get the list of approvers, the requisition may be going for approval only once.
    For Eg, in Payables the workflow is designed to send the invoice for approval at the line level.
    So, how do you handle it if the requisition is submitted for approval at the header level. You may have to check if the Product allows you to do that.
    What is possible in AME is you can review the requisition lines whether they are Project based or Task based and you can bring in all the approvers
    in the approver list.
    Thanks and Regards
    Niru

  • GRC AC ARA v10 SP13 - Org Rule Org Level Missing

    Hi Experts!
    Testing ARA Organization Rules soon and have noticed that one of my key Org Levels, $BUKRS, is missing. I have not yet used this functionality on this system. I am already doing the following:
    running the authorization sync job daily (we are in the middle of multiple project builds)
    checked the target systems USORG table for Org Level $BUKRS entry.
    active ruleset function has that Org Level $BUKRS entry and it appears on the Risk Analysis reports
    All other Org Levels are available to use except for this one. Any ideas!
    Thanks in advance.
    -john

    Alessandro,
    Ran both sync jobs again, but it is still not (see below). Checked the logs to be sure it completed.
    We do have two different ECC system connectors (One Production landscape, the other Project landscape), but both have the USORG table for Org Level $BUKRS entry.
    Any other ideas? Is there a GRC ARA GRAC* table I can update or check for this?
    Thanks,
    -john

  • GRC BRM: Update Org Levels of derived roles

    Dear GRC experts,
    we are using the GRC BRM Master Derived concept and have around 100 Master roles in place.
    I understand that the Org Levels of derived roles are only once set per Org Value Map during the initial (Mass) Derivation.
    If we add a transation like VA01 to a Master role this also adds some new Org Levels to the Master role. Via "Propagate to Derived roles" the new transaction and object values are added into the Derived roles.
    For the new Org Levels these are added also but the values are not the one from the Org Value Map of the Derived role but exactly the same values of the Master Role.
    Using "Derived Role Org. values Update" does not help us here to update the corresponding Derived roles as no change to the Org Value Map has been done.
    In case a Master role has 40 different Derived roles associated this would require to update manually any of the Derived roles for adjusting the new Org Levels.
    Does anybody know how to automate this task?
    Many thanks for your help!
    Regards,
    Markus

    Hi Markus Richter
    Once you maintain the imparting role and propagate to the derived role, the derived roles will inherit the new org values from the imparting. So that at least has the org values in the derived roles but not the correct values
    Next up is to try to use the Mass Maintain Roles to update the derived roles with correct values from the org map (ensure org maps were updated first) mentioned in post
    Mass Child role Org value update in GRC 10
    Does this work for you as an approach?
    Regards
    Colleen

  • How to Inactive Item Status at Org Level

    How to Inactive Item Status at Org Level and what are the implications of doing so.
    What are the prerequisits before inactivating an item status.
    The Procedure I am following is
    Changing the Item Attribute control to Org Level for Item Status
    Log on to Organization Items and Selecting the Item Status as Inactive.
    Can any one please let me know what are the pre requisits before Inactivating an Items and The procedure I am following is correct.
    Thanks
    Srinivasa Garikipati

    Hi;
    Please check serial attribute and org attribute problems with item master and see its helpful
    Also you can check:
    http://oz1-n.blogspot.com/2009/06/interview-questions-for-oracle-11i-apps.html part
    1. Once an item is assigned to an organization, is it possible to remove this association at a later time?
    2. How do I inactivate an item?
    Regard
    Helios

  • How to use "Adjustment Level " in automatic adjustments rule

    Now we are setting up BPC for legal consolidation.
    we use BPC 7.0MS SP4 Version.
    I want to use some result of automatic adjustment rules for source data, so I tried to use adjustment level in automatic adjustments rules.
    I was setting up A rule's (to use source data) adjustment level is 0 and B rule's level is 1,
    the result of SPRUNCONSO were "Error" CSD-150 and CSD-160.
    Please let me know how to use adjustment level option.
    Thanks.
    Edited by: tae-youn.kim on Dec 14, 2009 3:20 AM

    Hello :
    CSD-150
    Check the method between METHOD Table and your ownership Cube. Check your Rules between the RULES Table and The ELIM Table. Check The INTCo.
    Regards,
    SANJAY

  • Cannot upload Predefined Virsa Rules in ABAP stack. How to move on ?

    Hello,
    we are using SAP GRC, but nevertheless we would like to try to use the ABAP stack to upload function.txt, function_BP.txt and so on.
    In the configuration we have set the option Rule Architect Activation to YES.
    Despite that, we don't see the yellow button to go beyond 1). 
    It seems that still something is wrong : either in the configuration options (because that is what 1) says)  or somewhere else.
    any ideas to move forward to 2) Upload Predefined VIrsa Rules
    Thanks a lot
    Sam
                             Rule Architect
    This Wizard guides you through Rule Architect Process to
    generate Predefined Virsa TCode and Object Rules.
    1) Check Rule Architect Configuration
    2) Upload Predefined Virsa Rules
    3) Assign Transactions              ( Include Coupled Transactions )
    4) Assign Objects                   ( Enable / Disable New Objects )
    5) Generate Transaction Code and Object Rules
    6) Sucessful Completion of Rule Architect Process

    Hi Frank,
    thanks for the quick reply
    CVERS table says
    COMPONENT                   RELEASE    EXT       RELEASE COMP_TYPE             DESC_TEXT
    VIRSANH                        530_700     0005       C                                               SAP GRC Access Controls 5.3 for 700 HR a
    SSM_CUST says the following on VIRSA-like entries
    SAP_AFTER_PROF_GEN      /VIRSA/Z_AFTER_PROF_GEN
    SAP_BEFORE_PROF_GEN   /VIRSA/Z_BEFORE_PROF_GEN
    SAP_EXIT_USERS_SAVE    /VIRSA/Z_EXIT_USERS_SAVE
    SAP_SINGLE_USERPROF    /VIRSA/Z_SINGLE_USERPROF

  • Mass Role Import  -- 9000 derived roles with 9 org Levels, how to get TXT

    Hello,
    I hava a problem.
    I want to use the (Mass Role Import) Bulk Role Import element in the ERM  (SAP GRC AC 5.3 )for importing SAP roles (I only found that way to import roles from SAP).
    I have 100 primary roles and more or less 9000 derived roles with 9 org Levels.
    Is there a way to get this 9000 derived roles with their 9 org Levels in a TXT file?. Or do I have to do it manually this part to insert it in the "Bulk Role Import ".
    Can someone help me?
    Thank you in advance.
    Pablo Mortera.

    Hi Mike,
    what kind of TA´s are in your role. Is it possible to integrate a "dummy" TA (without conflicting
    your SOD)?
    In my example I have CO TA´s bundled in a role:
    Role:   ZXXXX_O:CO_ORDERMANAGER_CRE - CO Order Manager Pflege
    with
    KO01 Create Internal Order ...
    KO02 Change Order ... 
    KO04 Order Manager ... 
    KOK2 Collective Proc. Internal Orders ... 
    KOK4 Aut. Collect. Proc. Internal Orders
    update this role with TA KO01 and KOKRS will be available for derivation.
    Done this manually without import in ERM.
    Reg,
    Ulrich

  • How to upload the batch stock to bin level

    Dear gurus
    My client are going to implement WM  i want to know how to upload existing batch stock to bin  level.
    regards
    sam
    Edited by: Csaba Szommer on May 25, 2011 12:10 PM

    Hi,
    You can use LSMW for Tcode LT01 to upload inital stock in WH.
    So here u can enter all relevant data required like material, qty, batch, plant, Sloc etc..
    Hope this helps you...
    Rgds,
    Kris.

  • How to upload Ruleset to GRC CC5.2

    Hello,
    How to upload ruleset to the compliance calibrator 5.2.
    Thanks in advance
    Eric

    You can refer to Compliance Calibrato 5.2 User Guide page 176;
    In a nutshell, go to the administration tab, expand "Rule upload"
    then one by one, upload the provided text files that came with the install package.
    You upload the text files in the same order as the tree structure in the menu. Once they are all uploaded, click on the last link under "Rule upload" and generate the rules. Generate them in background.
    have a nice day

  • How to transport a value in the same level rule

    I want to transport a value in the same level rule,but failed. Would you please give me some idea to finish it? Thank you!

    the sample about rule zz01 as the fllowing:
    zz01
           4001 deduction for absent from work
            SETIN R=3 
             SETIN A=01    'NUM=3
              ADDWTI4Z03   '4Z03=3
        4002 sick leave
                  SETIN R=3
                  SETIN A=01
                  ADDWTI4Z09    'set 4Z09=3
    I want to transport the value of NUM in wagetype 4001 to  the variable in wagetype 4002.
      Thank you!

  • How to distribute new object from org level

    Hi Expert,
    I'm trying to create a new object: MATKL to org level through program: PFCG_ORGFIELD_CREATE. But I find there are only distribute to all roles. Could you advice if it can be distribute by selected role instead of all roles? Any advice on hierarchy problem?
    Rdgs,
    Emily

    Hi Colleen,
    Actually I want to grant authorization on MM section by separate material group. It's to fulfil some special users are able to access particular material group. So I'm thinking to create new material group org value and distribute from the top level (org level). Could you advice if there is any method can achieve my purpose more safety or easily?
    If I want to control some users access some particular material number which limited by control different material group. Can I just assign object: M_MATE_WGR and control the value for access? If yes, where to assign?
    Rdgs,
    Emily

  • How to create new org.level and further actions?

    Hi experts!
    I need help on the follwing situation.
    For better separation of industries for the marketing staff we do use the branch (e.g. food, energy, ...).
    For that we want to adjust the authorizations to branch specific.
    The questions are:
    1) Is it possible to create a new organisational level "branch"?
    2) If I have a new org.level I think I have to adjust existing authorization objects. Do I only have to extend the belonging auth.objects with the new org.level?
    3) What else do I have to do if a new org.level branch is created to check authorizations on that?
    Thanks for your help in advance.
    Regards,
    Alex

    If I read your question correctly I think you want to create a new authorization field. To get that to work you'd need to adapt a lot of software. Definately not a path to follow.
    All authorization cheecks need to hard-coded into the software. Changing SAP standard software is something one wants to stay away from as long as possible. It'll keep haunting you when patching, upgrading etcetera.
    If you want to 'upgrade' an existing field to become organizational a forum serach on PFCG_ORGFIELD_CREATE should give you pointers.

  • ERM -- unable to determine matching org. level for BRGRU in the system

    Hello,
    I have a problem.
    When I trY to import in the ERM (SAP GRC AC 5.3 SP5) a mass import of roles (derived roles) using the template Organizational Template.
    Some of the roles gives me this error:
    "Role not imported; unable to determine matching org. level for BRGRU in the system".
    In the file I put for example
    ZAPVAPINTE     BUKRS     0083
    Am I doing it right? or do I have to put $BURKS?
    Best regards.
    Pablo Mortera.

    I have found that when you run the background job "syncronization of the organizational values" it pulls the org value name and all "values" assigned to it.  If you don't have values specified (on the table level) for the org name, you get this error.  We have many fields that we use values for these fields but they aren't specified in the table.
    For example:  We have the org value "PLVAR" with the values "AL", "01", "02", "03", and "GB" assigned to it.  You can actually see these values in the backend system using SE11.  We do not get this error on this org value.  However, we have another org value "SACHZ" that we use, but we do not have any values assigned to it on the table level, so it is giving us this error.  We are trying to find out how to populate the "values" field since this was not done through configuration.
    Here are the steps:  (1) Go to SE11 in your backend system.  (2)  Put your org value (example:  PLVAR) in the "DATA TYPE" field and click display. (3) Double click on the Domain name.  (4)  Go to the Value Range Tab and click on the "Value Table" name if there is one.  This is the table that has the org values assigned in it - normally done through configuration. (5) go to Utilities --> table contents --> display.  (6) execute the table contents.  These are the values that the sync job pulls over.  If there are no values there or if there is no "values table" name, you get the error.  If there are values there, you don't get it.
    We are working with our technical team to get the values in these fields to see if that works.  Another quick way to see if there are values assigned to the org field is to use "Org Value Mapping" in ERM.  Select the "derived org level field" you want to see and click on the "org value from" magnifying glass.  If no values are there, a "values table" hasn't been populated in SE11. 
    It doesn't make much sense to me though because we can still use values for these fields for our derived roles....we just don't populate the table with them.
    I'll update this message if we find a solution.
    Thanks,
    Peggy

  • User group [$CLASS] not an Org level field in IA, whereas it is in DA

    Hi All,
    We have an authorization problem that we faced while SAP Upgrade. In the development system while we upgraded all the roles, we did not face any issue. User group field [$CLASS] was actually an org level field in that system and the roles were upgraded based on that condition.
    When the Integration system was up and the upgraded roles were transported to IA, we noticed that they ended with a warning. On checking the logs we found out that User group [CLASS] actually was not an Org level value in the INtegration system, whereas it was an org level field in the development system.
    Can someone tell me the reason why it is different? Is there any settings we have to change to make User group  an org level field in IA. Thanks a lot for your help.
    Vijith

    Hello, I ran into this also and found these notes to explain why this is suddenly an org value and how to fix it:
    http://search.sap.com/notes?id=0001580048
    http://search.sap.com/notes?id=0001739055
    Basically, GRC 10 add-on makes the user group an org value and the note instructs how to undo this manually, but there is a required pre-requisite because you cannot modify this for SAP delivered fields normally.
    You know what else would be nice.... maybe there's a note that explains why Account Type is an org value.  It REALLY should not be, IMO.

Maybe you are looking for