Symptom
The Access Context for Invoice Documents is currently assigned at the Company level. The requirement is to assign and control the Access Context at the Site level.
However, under Access Restrictions for CRM_INVOICESANDCREDITMEMOS, the Access Context is displayed as 1007 – Company, instead of the required Site-level context.
Environment
SAP Business ByDesign
Reproducing the Issue
- Go to the Application and User Management work center.
- Navigate to the Business Users view.
- In the OWL, select All Business Users.
- Select the required business user and choose Edit and select Access Rights.
- Navigate to the Access Restrictions tab.
- Search for the Work Center View ID CRM_INVOICESANDCREDITMEMOS.
- Observe that the Access Context is set to 1007 – Company and the field is not editable.
Cause
The Access Context is predefined by the standard Work Center/Work Center View for each business object and cannot be configured manually.
For Customer Invoices, the standard Work Center View CRM_INVOICESANDCREDITMEMOS is assigned Access Context 1007 – Company as part of the standard system configuration. This organizational level is fixed and cannot be changed to another organizational level, such as Site.
Resolution
This is standard system behavior.
The Access Context for the CRM_INVOICESANDCREDITMEMOS Work Center View is predefined as 1007 – Company and cannot be reconfigured from Company to Site.
To restrict access to company-level objects such as Customer Invoices, maintain the user's Company assignments under Access Restrictions for the relevant Work Center View.
For objects that use a Site-level Access Context, such as Outbound Deliveries, Shipments, and Warehouse Requests with Access Context 1008 – Site, control access by assigning the appropriate Sites to the user.
Keywords
Invoice Documents; Access Context; 1007 – Company; Company-Level Access; Site-Level Access; CRM_INVOICESANDCREDITMEMOS , KBA , AP-CI , Customer Invoice Processing , How To
SAP Knowledge Base Article - Public