cancel
Showing results for 
Search instead for 
Did you mean: 

Escape Routing

Former Member
0 Kudos

Hi All,

Requirement is to set up Escape routing whenever role owner not found or provisioning not happened it should go to security stage with a notification saying " Request forwarded to Security as no role owner found / No provisioning happened .Please investigate and fix."

We already had NO ROLE OWNER path so I just maintained ESCAPE path in process global settings as attached .

Now for sending notification to security team saying " Request forwarded to Security as no role owner found / No provisioning happened .Please investigate and fix."Please suggest on this and correct me if I am wrong somewhere.Thanks!

Accepted Solutions (0)

Answers (1)

Answers (1)

alessandr0
Active Contributor
0 Kudos

Hi Srikanth,

I have a similar business scenario where I have defined a new path ZGRAC_ESCALATION which goes to GRAC_ESCALATION. As notification I use GRAC_AR_ESCALATION which can be defined individually.

Instead of GRAC_POINT_CONTACT you can use GRAC_SECURITY.

Does this help?

Regards,

Alessandro

Former Member
0 Kudos

Hi Alessandro,

I want a custom notification message  to be notified to security team.

For this custom notification I had created a document name ZGRAC_MSMP_AR_ESCALATION and made active. what will be the next step please.

alessandr0
Active Contributor
0 Kudos

Hi Srikanth,

define the template in the MSMP configuration and assign to the stage notification settings.

Variables & Templates:

Maintain Paths (Section Maintain Stages > Notification Settings)

Regards,

Alessandro

Former Member
0 Kudos

Thanks Alessandro it is clear but when I had gone to variables and templates I could n't able to modify Docu. object of GRAC_AR_ESCALATION.

I tried deleting and adding new one but i cannot see an option for docu.object.

Please suggest.Thanks!

alessandr0
Active Contributor
0 Kudos

Hi Srikanth,

first check the notification messages in SPRO (SPRO > GRC > AC > Workflow for Access Control > Maintain Custom Notification Messages). Make sure the template for esclation is available:

In the MSMP workflow you can then select the message class for escalation:

The docu object itself you can configure in SE61.

Alternatively please also check the configuration document from SAP which gives you further information: http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/80088ef0-2590-2e10-7696-fa36bfcff...

Keep me updated.


Regards,

Alessandro

Former Member
0 Kudos

Hi Alessandro,

Now I had done as mentioned but still if no role owner is there my request is stucking with status decision pending after manager approved where this should be come back to security team as I had submitted a role with no owners.

Kindly help on this please..

alessandr0
Active Contributor
0 Kudos

Hello Skrikanth,

for understanding purpose do you have parameter 2039 (Auto Approve Roles without Approvers) activated? It is a difference between "role owner not found" and auto approve roles without approvers.


Regards,

Alessandro

Former Member
0 Kudos

Hi Alessandro,

2039 is not there in our parameters but I found 2038 (Auto Approve Roles without Approvers) was set to YES

alessandr0
Active Contributor
0 Kudos

Sorry - I meant 2038. In this case roles without approvers will be approved automatically. Hence the escalation will only be triggered when the role owner cannot be found or if you have any other escalation (e.g. user who has to be maintained is locked by another user).

Former Member
0 Kudos

escalation will only be triggered when the role owner cannot be found ..Can you please explain in detail please.

If that is the case then in my current request the role does not has approver then it should be approved automatically but not happened and the request was Running.

Former Member
0 Kudos

Awaiting for reply please

madhusap
Active Contributor
0 Kudos

Hi Srikanth,

Approver not found - This condition is applicable to all stages in MSMP workflow. If this condition gets satisified entire request goes to escape path.

No Role Owner Found - This is applicable for role owner stage. You can route roles without owners to security stage as per your requirement.

Do you want the roles to be auto approved if the roles don't have role owners?

For this you can make use of GRAC_MSMP_ROUTE_NO_ROLEOWNER routing rule.

You can enable escalation settings at stage level as below.

Regards,

Madhu.

former_member184114
Active Contributor
0 Kudos

HI Srikanth,

what hat did you find in request audit logs?

if the request is running, please check the audit log. There should be something useful.

Secondly, can you please deactivating 2038 and check?

regards,

Faisal

Former Member
0 Kudos

I had set the parameter 2038 to NO and tried but still no luck the request is running with no logs in audit log .Manager approved then status gone to running.

alessandr0
Active Contributor
0 Kudos

Srikanth,

as I asked already did you check the advanced logs? Tcode: GRFNMW_DBGMONITOR_WD

Regards,

Alessandro

Former Member
0 Kudos

When i click on Debug log it shows Error reading MSMP debug log file.

Former Member
0 Kudos

Hi Alessandro and all ,

Thanks for your inputs , I had removed the routing maintained earlier in manager level and now escape route works.

But the custom notification which I created for NO_ROLEOWNER stage was not working.

I had created custom document ZGRAC_MSMP_AR_ESCALATION and maintained the same in 0MSMP_AR_ESCALATION i.e in Maintain custom notification settings.

And also maintained notification even in GRAC_SECURITY stage under NO_ROLEOWNER path but still no luck.

Other notification are working fine.

Please suggest.Thanks.

Former Member
0 Kudos

Hi Madhu,

Role owner is a also a type of approver.So, the clause 'Approver not found is satisfied'. So, if 2038 is 'YES', then Request will not go to Escape path. So, can you clarify, this.

Regards

Plaban

Former Member
0 Kudos

This message was moderated.

Former Member
0 Kudos

Hi Alessandro,


Your valuable inputs on this please .