Data Access Management
The Data Access Management sub-module controls all Access Management operations at the platform level.
Crawl
An instance-level Data Access Admin can crawl users, roles, groups, and associated permissions across stories and folders on all SAP Analytics Cloud connectors configured within the same instance.
Folders: Provides checkbox options to select specific folders for crawling. The interface displays selection status in the format (selected/total).
Schedule: In addition to manual crawls, instance-level Data Access Admin can schedule crawls at defined intervals. This enables periodic sync with the source system and supports consistent access governance.
Grouping of connectors by instance
The created connectors are grouped in the Data Access module according to the associated server instance, shown in a hierarchical tree view on the left side of the page. The tabs displayed for each instance level vary depending on the type of connector.
For SAP Analytics Cloud, the connectors tab lists all connectors hosted under this instance. Connectors are visible in addition to the Instance Details.
Instance Details
The Instance Detail screen provides a consolidated view of all SAP Analytics Cloud connectors configured within the instance, along with high-level metadata, access control, and configuration insights.
Instance Summary Tab
The Instance Summary tab serves as the landing page for SAP Analytics Cloud connectors at the instance level. It displays all the connection parameters configured during connector setup. Parameters such as Access Token URL, Connection String, Username, Password, Database, and Credential Manager can be modified if required. Parameters such as Proxy Enabled, Tenant URL, and Credential Manager cannot be modified.
Instance Data Access Admins
Instance Data Access Admins display a list of all Instance Data Access Administrators associated with different connectors in the instance.
To add or modify Instance Data Access Admins:
In the Instance Data Access Admins section, click the pencil icon.
Select one or more roles from the list.
Click Save to apply changes.
Connectors Tab
The Connector tab displays a list of all configured SAP Analytics Cloud connectors associated with an instance.
Attributes:
Connector ID: Shows the unique identifier for the connector.
Connection Name: Shows the configured name of the Redshift connection.
Last Crawled Date: Captures the most recent date and time of metadata crawl.
The system displays a hierarchical tree where all connectors appear under the instance. Click the connector name to open the connector-level screen.
Users Tab
The Users tab lists all users detected during the metadata crawl from the SAP Analytics Cloud source. This tab allows Data Access Admins to view user identities, email addresses, associated groups, roles, and synchronization status with the application.
Attributes:
User ID: Displays the user ID as defined in the source system.
Display Name: Shows the full name of the user retrieved during crawling.
Email: Displays the email address associated with the user in the source system.
Groups: Indicates the groups to which the user is associated in the source.
Roles: Displays the roles assigned to the user in the source system.
Application User: Indicates whether a user with the same name already exists in the application. If a match exists, the users are synchronized and treated as a single entity across the system.
Groups Tab
The Groups tab lists all groups detected during the metadata crawl from the SAP Analytics Cloud source. This tab allows Data Access Admins to view group names, associated users, and role synchronization status with the application.
Attributes:
Group Name: Displays the name of the group as defined in the source system.
Users: Lists the users associated with the group.
Application Role: Indicates whether a role with the same name already exists in the application. If a match exists, the roles are synchronized and treated as a single entity across the system.
Connector Level
The following tabs are displayed for each connector level. Navigate to a connector under each server instance in the left-side hierarchical Data Access Management grouping.
Connector Details
Below are its listed sub-tabs:
Summary Tab
The Connector Data Access Admin (DAA) can configure access management settings for the SAP Analytics Cloud connector from the Summary tab. This includes managing permissions for metadata objects and defining synchronization settings between SAC and the application.
Click the pencil icon to enable or disable specific permission controls. Select the required options and click Save to apply the changes.
Access Management
Enable the Access Management checkbox to manage SAC permissions on folders and stories within the application.
This setting ensures access-related metadata, including users, roles, groups, and their assigned permissions, is collected and displayed.
Sync SAC Permissions to Application Permissions
Enable this option to map SAC source permissions to application-specific permissions. This ensures the application reflects the same access settings as defined in the SAC source system.
Connector Data Access Admins
Displays the list of Data Access Admins at the connector level.
Click the pencil icon next to the connector to open the admin configuration.
Choose one or more roles from the list to assign as Data Access Admins.
Click Save to confirm and apply the changes.
Permissions Tab
The Permissions tab displays the mapping of SAP Analytics Cloud (SAC) permissions to folders and stories, corresponding to application-specific permissions. This mapping provides a unified view of access control, making it easier to understand and manage user privileges across both systems.
For example, a Read permission on a folder in SAC corresponds to a Meta Read permission within the application. This ensures that source-level access aligns with the application’s internal permission model for consistent governance.
Folders Tab
The Folders tab provides a consolidated view of groups and users with access to each folder. It allows administrators to monitor and review access assignments at the folder level.
Attributes:
Folder Name: Displays the name of the folder as defined in the source system.
Groups/Users: Lists the groups and users that have access to the folder.
Permissions: Displays the specific permissions assigned to each group or user.
Application Crawl Date: Shows the date & time when the folder and its access details were last crawled into the application.
Stories Tab
The Stories tab provides a consolidated view of groups and users with access to individual stories organized under folders. It helps administrators assess access assignments and permission levels at the story level.
Attributes:
Folder Name: Displays the name of the folder where the story is located.
Story: Shows the name of the story as defined in the source system.
Groups/Users: Lists the groups and users that have access to the story.
Permissions: Displays the specific permissions assigned to each group or user for the story.
Application Crawl Date: Shows the date & time when the story and its access details were last crawled into the application.
Copyright © 2025, OvalEdge LLC, Peachtree Corners GA USA
Last updated
Was this helpful?

