Managing who sees what in a compliance system sounds straightforward – until your organization spans multiple regions, business units, and regulatory frameworks. A role assignment that grants access to all objects (such as all issues or risks) can quickly become a liability.
The Limitation of Roles Alone
SAP Risk and Assurance Management (RAM) ships with a robust role-based model. Assign a user the Compliance Specialist role, and they can work with issues across the board. For organizations where a SOX team should never see tax-related issues, or where risk managers in one entity have no business viewing another's data, this falls short.
A More Granular Option
Authorization Policies offer a policy-based alternative for three services: GRC Issue Management, GRC Risk, and GRC Control. Instead of asking only “what can this user do?”, policies also ask “on which data?”. A specialist handling indirect taxes sees only those issues. A risk manager scoped to one organizational unit works only within that boundary.
Policies are maintained in SAP Cloud Identity Services and assigned to individual users – not groups.
Mixing Models – With One Important Caveat
The two models can coexist in four ways: policies for all supported services, policies for selected services only, policies for selected users while others stay role-based, or roles only. This flexibility makes phased adoption practical.
The caveat: when both a role and a policy are assigned to the same user for the same service, the role authorizations override the policy restrictions. Predefined role collections must be removed from policy-managed users to ensure data restrictions actually take effect.
Reference
For full setup guidance, see https://help.sap.com/docs/risk-and-assurance-management/admin-guide-risk-and-assurance-management/authorization-management in SAP Risk and Assurance Management Administration Guide.
Source link