SAP Knowledge Base Article - Public

3698059 - Users suddenly lose their roles in SAP Analytics Cloud

Symptom

  • Roles and/or teams are unexpectedly unassigned from users without an obvious manual action.
  • While actively working on a story, model, data model, or other SAC resource, the user initially continues working without errors. After refreshing the browser, navigating to another page, or reopening the resource, the user may see a 404 Not Found error.
  • The resource may appear as missing or inaccessible, even though it still exists in the system.
  • Access is restored only after the required roles and/or team assignments are re-assigned to the user.

Environment

SAP Analytics Cloud Enterprise 2026

Cause

This behavior can be caused either by a manual action, such as an SAC Administrator maintaining roles, or by an automatic role provisioning job running in the background. The latter being more likely when the unassignment is unexpected.

Resolution

How to identify the source of role or team unassignment in SAP Analytics Cloud

To investigate whether roles or teams are being unassigned automatically, you can analyze the Activity Log in SAP Analytics Cloud (SAC):

  1. From the left navigation panel, go to Security > Activities.
  2. In the Activity Log, click the filter icon in the top-right corner.
  3. Add the following filters:
    • Activity > Unassign.
    • If the approximate date is known, add Timestamp and select the relevant day.
  4. Review the filtered log entries.

Analyze the User Name column in the log entries. If the user name appears as a long alphanumeric string (for example: 68D8B1D1B1D4F35B266F2919445098A), this strongly indicates that the action was performed by an OAuth client rather than a standard user. This typically means that user provisioning via API is configured in the SAC tenant.

To confirm this once again from the left navigation panel, go to System > Administration > App Integration. In the Configured Clients section, look for a client with a technical name matching the one shown in the Activity Log. Check the client’s settings, if API Access: User Provisioning is enabled, this confirms that this user is being used for a provisioning job.

If this behavior is confirmed, note down the technical name of the OAuth client and contact your Identity Administration or Provisioning team to investigate the provisioning configuration and source system (for example, IAS, IPS, or an external IdP).

Other possible causes to check

If the unassignment is not linked to an OAuth client, consider the following possibilities:

  1. Verify whether an SAC administrator may have manually removed roles or team assignments.
  2. If SAC users are provisioned from IAS/IPS or another identity system, changes to group membership or role mappings in the source system can trigger unassignments.
  3. Recent changes to role or team mappings in IAS or the provisioning service may result in role removal during the next synchronization cycle.

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Analytics Cloud, SAC, role, removal, team, unassignment, authorization, access, lost, 404, not, found, resource, story, model, refresh, activity log, security, activities, OAuth client, user provisioning, identity provisioning, IAS, IPS, API user provisioning, technical user, automatic, role removal. , KBA , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud all versions