Parallel workflows in CUP

Hello Experts,
our environment has SAP HR , GRC CUP (5.3) and Active directory(connected to IBM tivoli Manager).
I have a requirement where I need to provision user IDs to SAP systems through GRC CUP after the Hire event is completed in SAP HR.  To provision in SAP, we need to first create  Active directory ID ( network ID) before we can use this ID as sap user ID. we are planning to use position based security in SAP HR.
Question: After the Hiring event is completed,can I initiate 2 paths in  GRC CUP workflow where one path creates the Active directory ID and then provides that Active directory ID to the second path which will then use this to provision in SAP systems.
The Active directory is connected to IBM Tivoli Identity manager.  so we have to create Active Directory account through IBM Tivoli Manager.
Can you share your thougts on this. can we build a workflow like that. If not, any other alternative thoughts ??
Thanks

My 2 cents on SAP IdM and GRC integration scenario (draft):
1.     HR will create an employee record in HCM
2.     IdM monitors changes and create a network (AD) id and email id (Assumption : Network id and SAP UserIds same)
3.     IdM updates the email address back to the HCM systems
4.     Hiring manager enters the required roles. 1* (one more option, manager may add the business role and the business roles are mapped to the technical roles in IdM)
5.     IdM sends the SAP systems requests to GRC 5.3 RAR
6.     If there are no violations, the request returns to the IdM and IdM completes the provisioning process and roles need to be approved.
7.     If there are violations in the request(CUP approval), after the role owners approval, request returns to the IdM and then IdM completes the provisioning process.
8.     Manager (Only) gets the notification of user creation and logon credentials will be given to the new employee If non-SAP (AD) provisioning process not happened prior to SAP provisioning process. (not clear yet)
Questions:
1.     1* Does IdM complete creation of network id? If it does, then manager could enter the new employeeu2019s email id. (Not sure whether manager only able to add roles or adding roles and email id)
2.     Not sure whether IdM completes the non-SAP systems (like AD, etc) prior to SAP systems in the same request.
Reference:
Page 11/14:
http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/60a4802f-b6cd-2b10-1ebf-e269d127a634?quicklink=index&overridelayout=true
Page 8/48:
http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/30027e41-b5cd-2b10-4593-df65027f8c55?quicklink=index&overridelayout=true
Thanks
Himadama

Similar Messages

  • Configuring ERM workflow in CUP issue (GRC AC 5.3)

    Hi once again fellow SAP Security Folk,
    Using GRC AC CUP 5.3 SP 13 I am trying to configure ERM workflow for the following scenario :
    Every role change made via ERM requires approval from relevant Business Process (BP) area.  If the role change contains an SOD conflict of Medium or higher then approval is required from a 2nd central approver (basically regardless of the business process area). 
    I have not been able to configure ERM workflow within CUP to be able to do this u2013 I have only been able to configure it for dual approval, i.e. every change must have approval from both BP approver and Central approver before request can progress.  I did this by assigning the Central approver to all Business Processes as an additional approver. This means that the conditions for the scenario above are met but the drawback is that all other requests also require approval from Central approver even though they donu2019t need to, generating additional workload.
    Can anyone advise if this is possible and how to do it ?
    Further info:-
    I have setup in CUP an ERM Initiator, an ERM Custom Approver Determinator (CAD), an ERM Stage.
    I have setup in ERM I have defined Business Process Approval Criteria for each Business Process approver.
    I tried creating a 2nd ERM stage using a separate 2nd ERM CAD but this meant all changes required 2nd approval before request can continue.
    I tried modifying the 1st Stage to Approval type All Approvers but this meant all changes required approval from all possible BP Approvers (instead of any one) before request can continue.
    I tried creating a Detour/Fork but could only see within the Workflow Type selection criteria non ERM workflow types.
    Thanks
    Steve

    You can either type in the configuration, like the what option you selected for approver (CAD or role or...etc), or other way is to capture the change log which shows what was the configuration for that stage....
    (Configuration -< Change Log -> Search Change log)
    Cheers !!
    Zaheer

  • Parallel workflow with final Reviewer in 10.1.3

    Hi,
    I am looking how to implement the equivalent of Parallel workflow with final Reviewer (used in 10.1.2) in our 10.1.3 BPEL version.
    when i used Group Vote + Sigle Approver, it does not give me what i want ............. and how to access the subtasks from a given parent task?
    How to create a parent task with subtasks ???
    thanks
    BG.

    Hi Karl!
    I've the same problem! Did you find any solution for that problem ???
    Thanks,
    Nuno Sénica.

  • Trigger mitigation workflow within CUP

    Hi,
    I have configured the necessary workflow types, Mitigation controls and Mitigation objects. I am able to trigger workflow when I create a control in RAR. How do I go about triggering workflow within CUP?
    Currently, when I create a request, in one of the stages a risk analysis is mandatory. I am able to create or assign an existing mitigation control before the workflow process can continue. This works well. However, I would like a workflow to be triggered when somebody clicks on the 'create' mitigation control button as well as when somebody assigns an existing mitigation control.
    Any input would be highly appreciated.
    Thanks
    Mo

    Hello Muhammad,
      What you are saying is that you wish to trigger workflow from within CUP itself when you are assigning/creating mitigation control from within CUP, right? If i got that right then i would say that it is not possible. For mitigation control creation/assignment the trigger is only RAR application and be done through that only. Since for such workflows the request types would be type MITCTRL  and MITOBJ and not CUP..
    I nice feature though if it would have been there. In case i got anything wrong, then kindly elaborate so that i could get clarity.
    Regards, Varun

  • AE 5.1 and 5.2 - Configuring parallel workflows for "Delete" Request type

    Has anyone configured parallel workflows for the "Delete" Request type?  I want to configure 1 for SAP and 1 for non-SAP applications, but have been unable to do it successfully. 
    The initiators I have created that do not work are:
    1 - SAP initiator:
    SAP application with "OR" condition
    Request Type = Delete with  "AND" condition
    2 - Non-SAP initiator:
    Non SAP application 1 with "OR" condition
    Non SAP application 2 with "OR" condition
    Non SAP application 3 with "OR" condition
    Request Type = Delete with  "AND" condition
    When I create a request to Delete a user with SAP app and Non SAP app I get the error:  "Error in creating request. Multiple Initiators, [NON SAP DELETE, SAP DELETE] Found."
    Based on what I am reading on p. 58 of the AE52ConfigGuide.pdf, this should be possible to do.  Does anyone have any suggestions?

    This is my understanding.,
    A request cannot have more than one initiator. You cannot trigger multiple initiators for one single request. In your case both attributes SAP & Non SAP application are given with OR condition which makes both the initiators alike. As mentioned in the documentation the request for deletion can be made to happen in both SAP & Non SAP application by having forked path (for this the initiator should be OR Application SAP OR Non SAP Application AND Request Type Delete). Given the other option then it should have different initiator for SAP and Non SAP applications by giving them with AND condition.

  • Equivalent in 10.1.3 Parallel workflow with final Reviewer

    Hi,
    I am looking how to implement the equivalent of Parallel workflow with final Reviewer (used in 10.1.2) in our 10.1.3 BPEL version. it 's very urgent plz.
    when i user Group Vote, it does not give me what i want .............
    thanks
    BG.

    Hi Clemens,
    Thanks for your quick response. The Taskmanager and the Taskactionhandler are indeed not deployed so I will do that automatically.
    Still one question/remark left:
    You noticed that you still have to complete the tasks using the old worklist app. . So if i'm correct, you have to use the deprecated 10.1.2 worklist api or build-in worklist app. The 10.1.2 worklist app is not deployed in my 10.1.3 installation. However, 10.1.3 only contains the new worklist app. Is there also a way to deploy it manually?
    Writing this down it al looks a bit clumsy to me. Is it not a better option to invest some time in migrating all tasks scopes manually to 10.1.3, because as far as I can see the human tasks are causing the main issues concerning migration? After this you have a 10.1.3 compliant system. I wonder what your opinion is on this issue.
    Kind regards,
    Tom

  • Parallel workflow in Process controlled workflow

    Dear experts,
    could you please answer -
    is it possible to use parallel worklow in the process controlled workflow?
    for example, there is a requirement that all the department managers should approve the RFx document or contract.
    Is it possible to simulate this process using the process controlled workflow in SRM 7.0?
    It seems, that in the standard it is possible only via sequential approval - i.e. the first manager approves
    the document, then it goes to the second etc.
    Or all the managers receive the work item, but only one manager in fact approves it.
    Both variants are not suitable.
    Maybe there is another way to simulate the parallel worklow process?
    There is an option called decision sets, but it can be used for shopping cart only.
    Thanks a lot in advance,
    Andrey Averin.

    Hi,
       Yes- This is possible through Process controlled workflow. I am doing a smiler kind of workflow development. like category approvers .. Category approval will split by category...but you have to build the logic such a way that read all the items and send to all the approvers.. But now i have noticed that even through all approvers will receive parallel workitem but Approver A can't open his/her workitem if Approver B is in the process of approve/reject the workitem( Meaning when he double click the workitem in detail) then Approver A will receive a Error pop up message saying that Approver B is working on this document.
    John.

  • GRC AC- Workflow in CUP

    Dear All,
    We encountered an issue with one of our customers regarding the definition of WFu2019s path.
    The customer has a WF : START -> risk manager -> business manager 1 -> business manager 2  (**) -> auth. Manager -> FINISH
    (**) u2013 The second approval of business manager is needed only in the case where the Functional area of the role is not the same of the one of the Request.
    We thought about defining CAD approvers for every combination of Role Functional Area & Request Functional Area (for the cases they are not the same).
    The problem is that in the case where both is the same, this stage is not needed at all. So we thought about using an escape rout u2013 but then it will be relevant for all WFs, and this is not what we want.
    Do you have any idea how to deal with this situation ?
    Thanks

    Hi Yudit,
    Unfortunately CUP does not have the sort of functional logic you require in your workflow.
    You will have to try another angle to fulfill the business requirement.
    Hope this helps.
    Rgds,
    Prevo.

  • Approver not found error while configuring workflow in CUP

    While I am configuring SAP CUP workflow,
    Once I create a request and sent it to approve, I am getting the message stating Approver doesn't exist.
    Any help will be appreciated in this regard.
    Regards

    Looking at your posts here so far (8 unresolved out of 10) I'm getting the impression that you're trying to learn how to configure a full Access Control solution without a) having read the documentation or b) having had any kind of training.
    May I suggest you take a start with a) or/and b) instead?
    Frank.

  • Error message when deactivating Mitigation object workflow in CUP

    Hi All,
    I had activated the mitigation object field in the workflow types in Miscelleaneous in CUP. Now when I try to deactivate it I get an error message Cannot deactivate since the field is in use in Custom Fields I had created a custom field for password, Now when I go to delete that field I also end up getting a message Cannot delete since referred in request data header I am not sure if it is referring to this custome field. If I try to change the custom field password, I get an error message Update custom field to non-workflow field failed since it has been used as workflow field.
    I am not sure if it is referring to this custom field, but this field definately seems to have its own share of problems!!
    Thanks,
    CP

    Hi Chinmaya,
    You can not delete a custom field if it is associated with any request or have been used in the workflow.
    If custom field is used in the request, you can archieve the request, than you would be able to delete the custom field.
    If the custom field is used in initiator than you have to delete the initiator. After that you can delete the custom field.
    After deletion of Custom field only you can deactive the mitigation object field in the Misc.
    Kind Regards,
    Srinivasan

  • 0 risks found in while approving role in workflow of CUP

    Hi All,
    I am using one stage work flow. I created one change request to add one role  , it is created and while manager is approving the role, he ran the risk analysis, but it is showing zero risks. where as in RAR/CC for the same role we have 2 risks.
    I configured all steps of  integration of CUP , RAR .(i.e WSDL Updation).
    Please suggest me , where i am going wrong.
    Thanks,
    Joseph

    Have you checked whether there isn't a mitigation somewhere for the role assignment or the RAR check has some critical risks only checked?
    Another possibility (just speculating here..) is that RAR can check for risks within a single role (which is where you found these 2) however the CUP workflow is checking for risks associated with the user's existing roles and the new one in the request. But I would class this as a functional deficiency and hope it is not the case.
    Cheers,
    Julius

  • Implement Parallel workflows in UCM

    Hi,
    Requirement : Whenever a content is checked in by the contributor, it needs be approved by members from two different teams parallely before proceeding to the next step.
    Suppose lets say the content needs to be approved by 2 groups 1 and 2 and each grp has 2 members. For the content to go to the next step atleast 1 member from each group has to approve it. Can you please help me to achieve this functionality. I tried the one which was mentioned in oracle docs .. but cud not get it implemented.
    My workflow details:
    Two steps - Reviewer and Approver
    Reviewer Step has 4 users.
    MIN Approvers : 2
    Code in Entry Step:
    <$wfSet("set1", "0")$>
    <$wfSet("set2", "0")$>
    <$group1 = "user1, user2, user3,"$>
    <$wfSet("group1", group1)$>
    <$group2 = "user8, user9, user10,"$>
    <$wfSet("group2", group2)$>
    Code in Update Step:
    <$if wfAction like "APPROVE"$>
    <$if strIndexOf(wfGet("group1"), dUser) >=0$>
    <$set1 = toInteger(wfGet("set1"))+1$>
    <$wfSet("set1", set1)$>
    <$endif$>
    <$if strIndexOf(wfGet("group2"), dUser)>=0$>
    <$set2 = toInteger(wfGet("set2"))+1$>
    <$wfSet("set2", set2)$>
    <$endif$>
    <$endif$>
    Code in Exra Exit Step:
    toInteger(wfGet("set1")) >= 1 AND
    toInteger(wfGet("set2")) >= 1
    Regards,
    Boopathy

    First of all, parallel processing in workflows in UCM in general is impossible - an item can be in a single state only (you cannot 'fork' the workflow and synchronize it again to a single flow). You could do this in BPEL workflows, though.
    Particularly, your use could be faked - a simple workflow step could serve as an approval step for both groups.
    One implementation could look like:
    Min. approvers - ALL
    In Update, or Additional Exit Condition you will create an idocscript code, which will check whether necessary number of users from each group approved the document. You will most likely need the idocscript function wfComputeStepUserList, which "Computes the list of users from the current step in the workflow."

  • Parallel workflow instances

    Hi Experts,
    Need help for the scenario on which i am working..
    SAP System: ECC 5.0
    Scenario:
    1) Material master workflow is triggered through a customized event and  we are passing material number
    and Sales Org as the object key for Business Object.
    3) Based on the Sales Org, plants will determined using a background task.
    2) After this we have to send tasks(for creating a view) to the agent, for a plant and material combination
    and these tasks should be in parallel. number of plants can be more than 100.
    3) Once all these parallel tasks is completed then workflow should continue .
    4) other workflow task based on material and sales org combination...
    For sending parallel task for a material and plant combinations (Point 3), i can trigger a seperate workflow.
    so there will be n instance of this new workflow based on material and plant combination.
    But my concern is How workflow will know that all the workflow instances of new workflow is completed
    for the material for which main workflow is triggered.
    Please suggest.
    Please let me know if there is a some other way for sending parallel task from the workflow..
    Thanks,
    V

    I will create a new step and pass the remaining plants using the same Table-Driven Dynamic Parallel Processing .
    Again i have a issue, there will be multiple parallel task created but how i will know which particular task is related to which plant.
    I want to pass the plant name in the Task description, how i can do that...
    I will a create a new thread for this issue.
    Regards,
    Vargi

  • SAP MDGF Parallel Workflow

    I have requirement where I need to process the change request in the parallel steps, meaning once the request is submitted the CR will go to two specialsts namley specialist A, specialist B. Once both of them approve CR has to go to Steward C.
    Is this something possible in standard MDGF workflows. Can any one share the name of the workflow or do we need to build the custom workflow.

    Hi Rajesh,
    If your Change request work flow does not contains any deadline monitoring steps where you need to monitor the work flow decision tasks in users inbox then this can be accomplished by using BRF.
    Check link:
    https://www.youtube.com/watch?v=zarxavi0MnI
    And if you have deadline monitoring steps then you can create a custom workflow using events and tasks.
    Please let me know if you need any more details.

  • Change Account Workflow in CUP - Doesn't pick up existing values for an Acc

    Hi,
    When using the change account option available in the CUP(5.3 SP 7), I expected the system to populate the user details as they exist in the provisioning system once I enter the account details that need a change. We have the 'Search' and 'User Details' Data source configured to the same SAP R/3 system.
    For eg, when requesting for a new account, I've chosen an Employee Type attribute as 'Non-Employee' (SAP delivered request attribute) and entered some values for my custom attributes .
    And when I chose to change the same user account, I notice that the system doesn't pick up the existing values for any of the attributes and render them. For the Employee Type attribute, it shows the default value and for the custom fields, they are shown blank!!!!
    It does seem like the user attribute values from R/3 are being picked up and displayed correctly, but the ones from GRC Database are left out.
    I believe this to be a bug and does anyone experienced  this issue and found a fix????
    Thanks,
    Anil

    Hi Alpesh,
    Thanks for your response.
    This brings up a basic question on the repository for saving user attribs...ie. does all these need to be saved on R/3? Assuming yes depending on our current configuration(We have the 'Search' and 'User Details' Data source configured to the same SAP R/3 system), do we have a standard field for saving the 'Employee Type' attrib in SAP?. I did perform a field mapping of a custom attirb to one of the SAP fields in the user master, and get it saved during user provisioning. But it doesn't pick it up from there when I perform a change account. Seems it's missing that reverse mapping. And I've chosen the 'Field Type' of the custom filed to Text as to enable free text during new account request.
    Hope you may find something more.
    Regards,
    Anil

Maybe you are looking for

  • How can I create a new Security Domain ?

    Hi everyone, I would like to know how can I create an Security Domain other than ISD ?(If my card support multi SD and delegated management) I read Global Platform v2.1.1 ,but I don't know how can I create new SD practically(how can I write it's code

  • Transfering files to an iPhone 2g from my desktop

    My employer provides me with an iphone 3g, which is great. but I can't put my own apps on it, which isn't so great.  I have an older iphone 2g with no cell phone plan I would like to use for personal apps, documents, photos and such.  I can download

  • Problem connecting to Mysql using JDBC

    Hi Everyone, I am trying to connect Mysql ad java applet and I am using the Mysql jdbc connector. I Took the mysql-connector-java-5.0.8-bin.jar file and put that in the library of jdk. Now i used the following code to connect to the database using Ne

  • FI Posting document - - Function module

    hi, <b>Problem:</b> I've FI parked documents in system, n now i want to post them. I cant use batch input bcoz it inserts duplicate entry in controlling. so i need alternative of batch input, i mean any funcution module which will post all documents

  • PL/SQL Generation Mode by default

    Hello We are switching to OWB 11.1, so I have a simple question I can't find a simple answer. I have to check all properties of modules and mappings. My simple question is: On module level -> Configutre ... 'PL/SQL Generation Mode' beside of some Ora