Symptom
- With introduction of Latest People Profile, now we have some behavior that should be explained around how permission works in the New Profile Experience.
- This article provide information on how permission and configuration works on Latest People Profile.
Environment
- SAP SuccessFactors Employee Profile
- SAP SuccessFactors Employee Central
- Latest People Profile
Resolution
Important links:
- Role based permission for Latest People Profile Guide: Role-Based Permissions for Latest People Profile
- Categories permission for Latest People Profile guide: Defining Target Roles for a Full Profile Category
Category Permission:
The Employee Views permissions that allow users to access legacy People Profile sections are no longer supported for Full Profile. You need to use the Configure Latest People Profile tool to configure which user roles can see a Full Profile category. Use the legacy Employee View's Permission Report as a reference. For more information, see Defining Target Roles for a Full Profile Category.
This means that in order to migrate to Latest People Profile the roles should configured as per your business needs.
In order to configure the permission groups you can download the permission roles that grant Employee Views permission to the users. Please check step by step below:
- Please check out the “Download permission roles for legacy People Profile”:
- Download a report that lists which roles have an Employee Views permission that allow them to view a legacy People Profile section.
- Legacy People Profile sections correspond to the Full Profile categories, so use this report as a reference when you configure target roles for Full Profile categories.
- To download the report, go to the legacy admin tool Configure People Profile > General Settings. Select the option Download Employee View’s Permission Report.
-
Then in Admin Center > Configure Latest People Profile > Define target roles for Full Profile categories
Please check for more information guide: Defining Target Roles for a Full Profile Category
Block and Field level permission:
In Latest People Profile the block permission and field level permission have same configuration as Legacy Version.
The main difference between legacy and latest people profile (with latest edit and history UI enabled in configure latest people profile->general settings) is that if user have only View permission to field but have import permission for that entity then the user will be able to Edit the field in the UI too, please check this information in following guide:
Notable Differences in Existing Features
For module specific configuration specified in following page:
Full Profile of the Latest People Profile
Special note:
If more fields are visible than expected, then please check if you granted the user the “Employee Central HRIS OData API (read-only)” and “Employee Central HRIS OData API (editable)” permission under "Employee Central API" permission category. These permissions will expose the user to secured data in Latest People Profile.
We recommend not granting this permission to end users, as it is specifically designed for technical users for integration purposes. Refer to Permission Settings and About technical user for more information.
Note: We understand that in early releases of SAP SuccessFactors Onboarding this set of permissions was needed to view the new hire data in Manage Pending Hire However, starting with 2021 release, these permissions are no longer necessary for Onboarding. Please remove them from all end-user permission roles.
Keywords
latest, people, profile, blocks, cards, category, summary, permission, not, issue, respected, rbp, configuration, migration, , KBA , LOD-SF-EP-FPP , People Profile - Full Profile , How To
SAP Knowledge Base Article - Public