SAP Knowledge Base Article - Public

3196136 - Onboarding Role-Based Permission- Main KBA

Symptom

Onboarding Role-Based Permission

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP SuccessFactors Onboarding

Resolution

Role-Based Permissions (RBP) is a security model that allows you to restrict and grant access to your SAP SuccessFactors HXM Suite. RBP controls access to the applications that employees can see and edit. After setting up Onboarding / Offboarding, it is important to identify/create the user groups you want to provide access to, and then accordingly enable the required role-based permissions for each group.

Role-based permissions contain three main elements: permission groups, permission roles, and target populations

  • Create a Permission group with External user population- When creating a group of External user populations. Apart from the regular method of selecting the people pool. You would also need to select the user type as “External Onboarding User”
  • Create a role for the External User- In manage permission roles, you could use “Create New Role for External User” for creating a new role for the new hires (“Onboardee”). This is for creating a role for new hires. This should not be used for internal users.
  • Defining a target Population for a role- Select the appropriate Grant role/Grant Group and then choose the Target population as Everyone or based on the Department/Division/Location. The target decides for which group of employees the Role (From the granted group) can view/edit data. It is recommended to always keep the target limited so that data privacy and segregation of work and be well established. You can assign External User Target Populations to Responsible Users' Permission Role. For Managers, the target population is direct reports of type external users .

Role-based permissions for Admin User, Hiring Manager, and New Hires (as External Users)

 
Permission groups for onboarding/Offboarding-
There are permission groups that are created by default by the system. The task of adding the people to this groups must be done before starting the onboarding process/Offboarding process • OnboardingBPEServiceUser: Service user to execute Business Process Engine related tasks
• SAP_ONB2_RehireCoordinator: User who will perform the rehire verification task from the To-Do tile on the Onboarding home page.
• SAP_ONB2_ErrorFlowAdmins: users in this group will be shown the validation errors that occurred during the Onboarding process.
 
Known Role-based permission issues
 
1. The onboarding dashboard is not available for certain roles.
  • Review the below permissions-

General User Permission:

  • Company Info Access > User Search

Onboarding or Offboarding Object Permissions:

  • ONB2Process

Employee Data:

  • First Name
  • Last Name
  • Status
  • Location

Employee Central Effective Dated Entities:

  • Job Information > Location
  • Job Information > Job Classification

  • Target Population of the end-users should be external users
  • At least one user the onboarding process needs to be started

2. Names are showing for some and not for others in the dashboard

Employee Data:

  • First Name
  • Last Name
  • Status
  • Location

Employee Central Effective Dated Entities:

  • Job Information > Location
  • Job Information > Job Classification

Employee Central API:

  • Employee Central Foundation SOAP API
  • Employee Central Foundation OData API (read-only)
  • Employee Central HRIS OData API (read-only)
  • Employee Central Foundation OData API (editable)
  • Employee Central HRIS OData API (editable)

General User Permission:

  • Company Info Access > User Search

Onboarding or Offboarding Object Permissions:

  • ONB2Process

NOTE: The following permissions are recommended to not be included for Managers/HRs

Manage User:

  • Employee Export

Metadata Framework:

  • Admin Access to MDF Odata API
    One more reason could be that the HRIS sync has not been run. Do not forget the schedule the HRIS sync
     
    3. Future dated access of new hires to admins and managers based on job information entity
    Using dynamic group filter, filters can be applied to the Job Information entity. For example, you can provide an admin with access to new hires only from a specific department or division.
    1. Go to manage Business Configuration.
    2. Under Filters, select Dynamic Group Filters Create New.
    3. The Dynamic Group Filters page appears. Enable the filter.
    4. Select HRIS Elements -> Job Information. The filter defaults.
    5. Enter the number of days that the receiving parties (admins or managers) can see the employment records before the organizational change. Enter values like 30,60 or 90 denoting the number of days before the organization change that the admin can view the new hire.

    4. Viewing profile after MPH before the start date

    Below permission should be provided to the RBP role of the users viewing the profile-

    • Employee Views access of Employment, Me (Personal Info) for the target population of external users
    • General User Permission:

               Company Info Access > User Search

    5. Candidates are not visible in MPH after completing ADC

    If the Manager/HR does not have access to the below mentioned permissions, then the candidate will not be available in MPH.

    Employee Central API:

    • Employee Central Foundation SOAP API
    • Employee Central Foundation OData API (read-only)
    • Employee Central HRIS OData API (read-only)
    • Employee Central Foundation OData API (editable)
    • Employee Central HRIS OData API (editable)

    6. Compliance Form and Compliance Object Permissions – For External Users (error: Unable to see form data)

    Compliance Object Permissions:

    • AssignedComplianceForm
    • ComplianceDocumentFlow
    • ComplianceFormData
    • ComplianceProcess
    • ComplianceProcessResponsible
    • ComplianceUserData
    • ComplianceProcessTask

    Employee Data:

    • Employment Details MSS

    See Also

    KBA:

    IDP:

    Implementation guide:

    PDC:

    Keywords

    RBP, permissions, Role Based Permissions, Manage Permission Role, Onboarding, BPE , KBA , LOD-SF-OBX-ACC , Accessibility , How To

    Product

    SAP SuccessFactors Onboarding

    Attachments

    Pasted image.png