AC 5.3 CUP - authorization for CUP's users

Dear Friends,
We are trying to see what are the authorizations that we should give the users who are going to use the CUP system.
We have some users who are approvers. We want to give them the authorizations maintain and view only the request that they are involved in.
As far as we can see, according to the default approver role, the approver can view all requests in the reports - not only those that he is involved in.
could any one support this issue ?
Thanks
Yudit

Hi Yudit,
The ViewApprove action will allow a person to view the approve button.
When the user logged into the CUP system he can see request which is assigned to him in Request for Approval screen.
He can search request in Search Request screen which are not assigned to him and he can't approve those request.
So what is the problem of giving the Approve button to approvers.
Regards,
Sudip.

Similar Messages

  • WEB UI- only Display authorization for LEADS to users

    Hi Gurus,
    I have a requirement like i need to give only display authorizations for users to leads.
    I have created a new business role and assigned only search links. but in that search link we have Create New option. How i need to disable this.
    Users needs only display authorizations for Leads.
    Waiting for reply...
    Regards,
    Ajay.

    Hi Ajay,
    First of all, It is possible to disable the New button on the Search page without any code change. There is an SPRO setting which is to be done in order to achieve this.
    You might have created a new z navbar profile as you have created a new business role as per your business requirement.
    Lets take an example, you want to disable the New button on Contact Search Page. follow these steps:
    1.Go To T. code /ncrmc_ui_nblinks
    2. Select the Z navbar profile you have created for your business role
    3. Double Click on "Define Generic OP Mapping" in left hand side
    4. Select Object Type as BP_CONTACT and remove the Following entry
    BP_CONTACT     D Create     MD-BPCP-CR          MD-CONP-SR
    Please note the Obj. Action here D Create, if you remove this entry it means you are disabling the Create Action for this business role for object Contact.
    Hope this will help you.
    Regards
    Ajay

  • Authorization for web shop users

    Hi Experts,
    How can we Control the users at webshop level?. Can anybody explain me the step by step process to set up authorization group for web shops.
    Regards,
    S Reddy

    Hello,
    In each web shop there is an authorization group.  If left blank, any user can enter the web shop.  If it is populated with a value, only users with special authorization can enter the web shop.
    The authorization set is:  CRM_ISA_SP
    You maintain a value for the authorization object in role maintenance and assign it to your web show (as described above).
    You also to a user to control the user access to a particular web shop.
    The way it works is the system checks any user attempting to enter the shop.  If the user has the authorization object value assigned to it, the user can enter the shop. Otherwise, he is denied access.
    I hope this helps.
    Deb

  • Authorization for changing the user status

    Hi all,
    I need to give authorization in such a way that after the initiator has creataed a DIR...:
    1. When it goes to the next approval, the person should be only able to change the user status and save.
        he should not be allowed to change anything else.
    I have tried using different authorization objects but none of them worked. Is there any tcode in DMS for just approving the DIR (changing it to next available user status), similar to release strategy. For ex ME29N for approval of PO (Purchase order) ?
    Thanks
    Anish

    Hi Anish,
    Based on your requirement, I would like to suggest to go by workflow to approve the document..
    With the help of workflow, you can approve the document in workflow inbox itself (workitem), no need to go to DIR, the status will get automatically change in the DIR.
    for this you have to use function mudule (set/get next status).
    you can do this by taking the help of Workflow consultant and abap.
    regards,
    nitin
    award point if useful

  • What Authorization for a S-User to setup an Early Watch Alert?

    Dear Friends,
    Could you tell me please that what kind of Authorization (type of user) a S-User must have to setup an Early Watch Alert by that S-User details?
    Scenario tested by me as follows -
    I have setup EWA in two places, but only one is sending me the report, where I have setup the EWA by the Customer S-User ID, which directly came from SAP. It was a Super Admin type S-User. But, in other location I have setup the EWA with a S-User ID with limited Authorization "Edit Messages" only, and from where still now I have not received any EWA alerts / reports.

    I am afraid you could only use the Customer S-User ID which directly came from SAP.
    Thanks,
    Gordon

  • How to give authorization for create and change particular Condition Type

    Hi...
       In my requirement is , Only one user can be authorized to create and change a particular condition type 'ZABC' in vk11 and vk12 .
    For remaining condition type can be used as in normal .
    How to do this ? How to give authorization for a particular user for particular condition type ?
    Plz guide me ..
    Thanks in advance .
    Deepa .

    Hi Deepa ,
    u can check A.Object V_KOND_VEA, in user profile u can assign condition type or tables.
    have a word with ur basis guy , so he can help u in better way.
    aand also ref FM SD_COND_AUTH_CHECK
    Regards
    Prabhu

  • Authorizations for variants

    Hi All,
    I have created may own transaction that calls ABAP query and gives some report. It has its own variant for selection screen. Now as I am creating roles, I get the message that the authorization for variant is missing. So, I know how to create/edit roles in PFCG but I don't know how to add authorization for variant to existing role.
    Thx.

    Dear Suad,
    I think, the best place for your query is [Forum: ABAP, General|ABAP Development; or [Forum: SAP NetWeaver Administrator|SAP NetWeaver Administrator;
    Instead, Best way is, to Contact BASIS-Admin.
    There are few Transactions, that could be referred:
    T. Code: SE93
    You have created Z - VARIANT Transaction Code, using the Transaction and the Transaction Variant. Based up BASIS-Admin will assign the authorizations (for the respective users).
    T. Code: SU53 or ST01 - for missing Authorization
    T. Code: SU21 - Create Authorization Object
    T. Code: SUIM - Roles by Authorization Object (which is not relevant, as your's is Z-Transaction for Screen Variant)
    Best Regards,
    Amit
    Note: There are few relevant threads, it might help you
    [Roles - Authorization Issue|Re: Roles - Authorization Issue]
    [Missing Authorization|Missing Authorization] - Albert's Post
    [Authorization Object|Re: Authorization objects and Roles]

  • SM35 error, No authorization for FB05

    Hi Experts,
    User is trying run J3RFUM26 , Which creates job in sm35, Later they will run the job in foreground, job runs successfully for RUB, ZUSD & EUR but for ZEUR it says no authorization for FB05, Actually users not given access for this tcode, checked exchange rates in OB08, they are maintained, Please help me resolve this issue. Find screenshots attached.

    Your screen shot has not given much information.
    Check the missing authorization from /nSU53, then give the authorization from PFCG for the role (which is assigned to the particular user)
    Have a look into the document MM Related Authorization Objects - How to Find out & Assign

  • Authorization for user

    Hi ,
    The minimum authorization for the Sales user in Sales Department..

    Neetu,
    Your question at least needs to be: If I would like our Sales user in Sales Department can do their job, what will be their least authorization?
    Am I right for your puzzle?
    If it is true then there is no minimum you can define.  No company has exaclty the same process.  You have to articulate what your Sales users need.
    Thanks,
    Gordon

  • Authorization for Intercompany Sales

    Hi,
    I have an intercompany situation, company A and company B. UserA can perform sales transaction for company A only. Now with intercompany sales, i want UserA to view sales order for company B but cannot see the pricing condition for company B.
    May I know how to perform authorization for this?
    UserA have authorization for sales org A. How to restrict pricing condition to sales org A only, but still can view sales order for sales org B?
    regards,
    zl

    Hi,
    VA03.
    UserA can VA03 for all Sales Order for Sales Org A. For Sales OrgB, UserA can view using VA03 but the pricing condition tab should not be accessible.
    How to do this?
    Thank you.
    regards,
    zl

  • Authorization for BI Reports

    Hi All,
    I am new to BI Authorizations. In my Project there are 150 Users are there.So for each user,Authorization Object
    is created in RSECADMIN and Roles are created in PFCG Tcode.
    Initially we have created 9 Reports and it is running in BI PRD. In all 9 reports we are using the Info Object
    "0CRM_PRCTYP - Business Transaction Type" and Authorization Relvent is Unchecked in this Case.
    Now the Client wants some more reports and need to provide Authorization for this Field "0CRM_PRCTYP - Business
    Transaction Type".And these new reports will be used by "New Users".
    So i have Checked the Authorization Relvent for the Info Object "0CRM_PRCTYP - Business Transaction Type" and
    Created Authorization Variable in Reporting Level.After doing this, I have executed the report by logging with new
    Users and it is working fine for new reports.
    Then i have checked the Old reports (9 Reports) ion RSRT and found that the error "NO AUTHORIZATION" for all 150
    users.
    Can you please help me how to rectify this error.
    Thanks,
    Jelina.

    Hello Jelina,
    First, try to check the reports by running them with the user account in transaction RSECADMIN -> tab Analysis -> Execute as user.
    If this will return an error please go with transaction SU53 and check what role/authorisation has generated the error. Afterwards, launch PFCG, go to Authorisation tabs, Display authorisation and add the reports BOTH under -> Business Warehouse-> Business Explorer Components  and ->Business Warehouse -> Business Explorer Components - Enhancement to the Owner.
    After this press the Generate button (looking like nuclear hazard but in red&white) and SAVE. Go to the TAB Users in PFCG and press the button USER COMPARISON and afterwards SAVE.
    Now it should work. Let us know if you still have problems.
    br,
    Dan

  • Authorization problems with oranetb user

    We have set up Apex in an oracle database, that are installed on unix operative. We have problem with the authorization
    for the oranetb user. On the unix system we have one user that can call scripts with for example unix command like ls,
    cp, etc.
    Now we want this oranetb user to run unix commands in scripts, without change the user in unix environment. We have
    been told that we can use something in the script, with PATH’s and authorization for oranetb user. Have you ever done
    something like this? And can you help us with something that you think can help us?
    We also have the same problem to run workflow (Informatica) from a script in unix, when apex is calling the script.
    If you want more information, please send a mail to me.
    Email: [[email protected]]

    hunt3r,
    iTunes Store menu -> View my account... Once you've logged in, there's a button to deauthorize all your current machines and start you back at zero machines authorized. Try that.

  • Role created in ERM is not appearing in CUP request for assignment-GRC 10.0

    Hi,
    We are on GRC 10.0 - SP5
    We have created a role in ERM and it was succesfully created in backend system. However when we tried to assign the same role using CUP request - the role is not appearing.
    1) Do we need to upload roles for CUP  in GRC 10.0 (similar to 5.3) to populate. Will the role doesnot automatically appears in GRC database for CUP as it is created through ERM?
    2) If the roles are imported in ERM with role owner information, does the same reflects for CUP also for role owner approver assignments?
    Thanks and Best Regards,
    Srihari.K

    Hi Sri,
    Is the role status set to "production" ??
    Cheers,
    Diego.

  • One CUP request for assigning role to multiple users

    Hi,
    We assign roles to users in production only through CUP requests.. We use GRC 5.3
    Here we have a case where we need to assign one role to  60 users in production(each user may have different  roles assigned in the back end) . I can raise one CUP request for all users using " multi-user" option in Copy request . But when we want to make a risk analysis , it will not show risks at user level as each user had different roles and may get different risks by adding new role.
    Instead it will give risks if any for only that new role which want to assign. Our manager is not accepting as this is not giving complete picture of risks for each user when we add new role.
    Please suggest me if there is any other way where I can make a risk analysis for each user when I created a CUP request for multiple users.
    Or the only solution is to create 60 CUP requests ?? this would be too manual
    Regards ,
    jaags

    Raghu,
    thanks for the reply, you are right as per the audit .But suppose if it is for 200 users ,creating 200 CUP requests will be impractical right.
    there should be some solution for this , because there will be many situations practically where we have to assign roles to N number of users.
    Is this possible in GRC 10 ? any idea ?
    Regards,
    Jaags

  • Domain name for CUP

    Hi,
    The email addresses in the company I work for are in the format '[email protected]'. 
    I'm wanting to set up presence so that the CUP username matches the email address for consistency.
    What do I set the domain name as in CUP?

    For internal usernames to match you would either need the sAMAccountName attribute to be firstname.lastname (unlikely) or change CUCM, CUP, and Jabber to look at a different attribute for the username.
    For Microsoft Active Directory
    sAMAccountName
    mail
    employeeNumber
    telephoneNumber
    userPrincipalName
    Note that if you use mail or userPrincipalName, both of which contain an @ character, the CUP Presence URI would actually be @. Example: [email protected]@company.com.
    For external IM federation the CUP server has an attribute that allows you to use the email address instead of the internal Presence URI for federated contacts/conversations.
    Please remember to rate helpful responses and identify helpful or correct answers.

Maybe you are looking for

  • Performance issue with Crosstab  report in BIP

    Hi, I have a report to display in cross tab format.... I followed the steps given in the BIP user guide to develop the report. The functionality is working fine and report is in intended format. But the issue is with the performance. The column logic

  • How to remove the extra space in the output pdf file?

    Hi All In our RTF layout template we have both static content and dynamic content. In RTF template we have used many if-else,choose,For each loops. On the account of that,In the output pdf file, we are getting lot of empty space in the place of that

  • Do we have any BAPI to get the Sales quote or Sales order details

    Hi Experts, Do we have any BAPI to get the sales quote or sales order details from my other SAP system. My requirement is to get the sales quote or sales order details from the other SAP system. Please help. Regards, Chitrasen

  • Is OWB 10g exported(EEX) and imported in Dis.Admin (10.1.2) ?

    Hi , I have a problem related to OWB and Discoverer Administrator, both 10G(10.1.2). When I export the output as an .eex file, it says the output is for Oracle 9i Discoverer and does not say 10G. If I still try to import it into Oracle Discoverer Adm

  • Need help to access settings for my ipod 4

    I am getting a message when trying to open my ipod 4:Photos for the icloud account "icloud" can not ve accessed. Review your account information in settings. But how do I do that as can't swip to turn the ipod on>