cancel
Showing results for 
Search instead for 
Did you mean: 

GRFN_API-

Former Member
0 Kudos

Hi gurus,

I am trying to limit the Control Owner role depending on the following requirements:

1-The responsible of the organization can changed everything from the Organization.

2-Inside the subprocesses linked to the Organization, this person can apply changes to the controls he is responsible of.

3-This person can also apply changes to the central controls he is responsible of.

The limitation I found is that even though I am working with object GRFN_API, if I set the actvt to 2, the control owner can change everything but I need him only to change his control. How is it possible to do it?

Thanks!!

Regards,

Accepted Solutions (0)

Answers (1)

Answers (1)

former_member205878
Contributor
0 Kudos

Hi John,

The authorization in GRC PC/RM goes top to down.

If the user has the authorization to display / edit the organization and the control , then all the entities under

the organization will be available for him to work over.

But in the case he is just responsible for the control, then he wont have access to any other control for which he is not responsible.

Consider the SAP Note 1572360 to have more clarity over the authorization concept.

Regards,

Silky Sharma

Former Member
0 Kudos

Thanks for your reply Silky,

The point is that even though the user is the responsible of the control, he can not change the central control if he has not the authorization GRFN_USER=02. Is it correct? Am I doing something wrong?

Thanks,

Kind regards,

Former Member
0 Kudos

it looks like system is not going at GRFN_API when GRFN_USER has activity 16. as per note it should work. but its not working i checked in GRC 10.1. did you solve this issue?

Thanks