SAP Knowledge Base Article - Public

3568592 - Story Filter shows Dimensions that shouldn't be accessible to user in SAP Analytics Cloud

Symptom

When selecting a Story Filter, end users can see dimensions that they were not granted permission to see via Data Access Control in the Model.

Environment

SAP Analytics Cloud Enterprise 2024.21.14

Reproducing the Issue

Reproducing the Issue (Affected User):

  1. Log into the affected tenant with User A (Affected User Access);
  2. Open the Story in question;
  3. Note that for the Company Code filter (e.g.), all values are visible and selectable, which is not expected based on the DAC set in the Model.

Checking Configuration (Admin User):

  1. Log into the same tenant with User B (Admin Access);
  2. Open the Model being used in the Story;
  3. Navigate to the Company Code Dimension (e.g.);
  4. Filter for User A on Read column;
  5. Filter for User A on Write column;
  6. You will see that the user does not have rights to access any dimension.

Cause

When the story filter Available Members setting is set to All Members, users will see all dimensions from the model listed in the story filter. However, even if a user selects values from dimensions they do not have view rights for, the corresponding data will not be displayed to them.

If your business requirement is to restrict users from seeing dimensions they don't have access to while interacting with the story filter, you should change the Story Filter Available Members setting to Booked Members. This ensures that only values the user has access to will be listed in the filter, improving data security.

This is by SAP's Analytics Cloud design.

Resolution

Change the Story Filter settings according to your business requirement.

About Story and Page Filters (Classic)
About Story and Page Filters (Optimized)

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

Log in, Tenant, settings, User, Story, Stories, SAP Analytics Cloud, SAC, filter, available, Data Access Control, DAC, values, visible, Selectable, Not expected, Model, Log in, Same tenant, Admin Access, Modeler, SAP Analytics Cloud, Company Code Dimension, Filter, Write column, access, dimension. , KBA , LOD-ANA-DES , Story Design & Visualizations , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud 1.0