Symptom
You have set restricted access in Edit-> Access Rights view for a certain user but the user is still able to access supplier invoice which belongs to a different company.
Environment
SAP Business By Design
Reproducing the Issue
- Go to Application and User management work center
- Select Business Users view
- Edit Access Rights for user A (A refers to a user)
- Navigate to Access Restrictions view and restrict only to the specific company Q to which the user A belongs to.
- Now login as the user A
- Select Supplier Invoicing work center->Invoices and Credit memos view
- User A is still able to access invoices belonging to different company say R
Cause
Restriction rules are not created in this system.
Resolution
To restrict users from creating supplier invoices which do not belong to their company, you have to create Restriction rules.
Steps:
- Go to application and user management work center
- Select view Business role
- Edit/create a business role.
- Assign Invoices and Credit Memos view in work center and view assignments tab.
- Click on access restrictions tab and select view Invoices and Credit Memos and assign restricted read and No access to write.
- Scroll down and select rule "Restrict to Employee's Company".
- Assign business role to required users and confirm.
Now the users who are assigned to this business role can only access the invoices belonging to their company.
If the above does not work as expected kindly perform the below actions as well:
- Afterwards Perform Update Access Rights of the business user ID and then verify that the SRM_INVOICESCANNING restriction settings of role and user match.
- In case the issue remains, perform Actions > Check Access Rights Consistency for the user for any related inconsistencies. The effective access rights consist of the sum of the different access restrictions. If permission is granted in any view of an activity group, it will overrule restrictions of other views in the same activity group.
Keywords
access restrictions, supplier invoice access based on company, business role, Restrict to Employee's Company , KBA , AP-SIP-SIV , Supplier Invoice , How To
SAP Knowledge Base Article - Public