cancel
Showing results for 
Search instead for 
Did you mean: 

GRC AC 10.1 - REQUEST_SUBMISSION event issue

Former Member
0 Kudos

Hi experts,

Could enyone please help with following configuration issue with notifications in ARM workflow?

To be exact, the notifications for event REQUEST_SUBMISSION are not being sent (not present in SOST or delivered in e-mails).

These seem to be the only notifications that does not run, we also have END_OF_REQUEST notification event used as well as NEW_WORK_ITEM even used in Paths notification settings. They both run correctly.

Any clue what needs to be checked / fixed to repair that? Could custom initator rule (BRF+) mess anything up?

Thank you!


Minimum information details:

  • Detailed information on your current release and service pack level. It is enough to mention 10.0/SP12, 10.1/SP3, ||| 10.1/SP08
  • Already implemented SAP notes releated to your issue ||| UNKNOWN
  • Elaborate your business case (what you are trying to achieve, etc.) ||| ABOVE
  • Summarise what you have tried and also, if complicated, include a screen shot that helps to understand/explain (but make sure you remove any sensitive information) ||| ABOVE & BELOW

Below screenshots (a mess, because of testing):

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

I think I should assign myself some points, because I've manage to solve this issue - and seen in several topics over the scn forums that this was touched but never solved.

The problem is about some missing authorization values (in my case S_USR_GRP - activity 03) for the requestor user. The access request is normally created and can be processed without this authorization, however no REQUEST_SUBMISSION event notifications will be sent unless the user have those authorizations.

This seems much like some SAP coding error, because authorization should not have an effect on notifications only.

Former Member
0 Kudos

Michal,

I'm sorry to break it to you, but p0ints are not awarded for supplying your own correct answer. In addition, this is not the first such situation in Access Control, where seemingly irrelevant authorizations are required. Be thankful it was just a display authorization;  in a previous SP we discovered an update authorization that was required for doing a Search Requests. When I raised an Incident about it, SAP's response was that they assumed that only GRC admins would be doing Search Requests and would already have that update authorization. Just keep it in mind in the future, that your basic security troubleshooting can lead to surprising results in GRC.

Gretchen

Former Member
0 Kudos

Gretchen,

Hah, it's ok - I don't really care about points - it was supposed to be a joke. I just wanted to mark a correct answer.

Thanks about the story about Search Request - I'll take a mind note to always run authorization checks whenever I have any issue with SAP.

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Michal,

    Have you checked in SE61 if the Template is present? If yes, then this means that there could be some issue with Post Installation Activities. Can you cross check again if every linkage given in the standard document was activated and all steps were carries out properly?

Regards,

Fazil

Former Member
0 Kudos

Yes, the templates are present. They are sent on each other event than REQUEST_SUBMISSION correctly.

I've followed these steps during set up activities, moreover I believe I've cross-checked those yesterday (and right now, event linkages in SWE2 are all active).

These do not seem to be only UAM problem, as on REQUEST_SUBMISSION event notification does not seem to run on EAM log review workflow as well.

We've also run MSMP debugging and in logs details it seems that steps for sending notification on submission are being done, however no notification is sent.