Role-Based Access Control
The concept submitted is undefined, so no specific SAP developer concept was provided to define. Based on the available sources, the closest identifiable topic is Identity and Access Management (IAM) on SAP Business Technology Platform.
Identity and Access Management (IAM) enables developers to control who can access applications and what actions they are permitted to perform. The SAP Authorization and Trust Management Service is a core component of this, allowing developers to manage user authorizations and establish trust with identity providers in the Cloud Foundry environment. Developers use these capabilities to secure applications by defining roles, assigning permissions, and controlling access at both the organization and application level.
Tutorials that teach this
- Tutorial Use mocking to embrace auth in your domain model from the outset
- Tutorial Add Authentication and Authorization to the Application
- Tutorial Add Authorization
- Tutorial Grant Access to Calculation Views
- Tutorial Integrate Your UI Integration Card from the Content Package Into Your Site
- Tutorial Security and Backups in SAP HANA Cloud, SAP HANA Database
- Tutorial Create a New User and Assign Permissions
- Tutorial Assign the User Roles
- Tutorial Integrate an SAPUI5 App to SAP Build Work Zone
- Tutorial Create a New User and Assign Permissions
- Tutorial Create Users and Manage Roles and Privileges
- Tutorial Access a Standalone Data Lake in SAP HANA Cloud
Docs explaining this concept
Prerequisites
- Concept Business Role Assignment The concept name was not provided, so a precise definition cannot be determined. Based on the available sources, the content relates to **Business Users** in SAP Business Technology Platform — individuals whose user data (such as user name) can be maintained, mass-updated, or locked when inactive. Developers and administrators manage business users by [maintaining user data](https://help.sap.com/docs/btp/sap-business-technology-platform/db1d0b4119d74dc6970adde9c85069b4?locale=en-US&state=PRODUCTION&version=Cloud) and assigning business roles that control access and authorizations, or by using the [inbound service `MANAGEBUSINESSUSERIN`](https://help.sap.com/docs/btp/sap-business-technology-platform/a631f4ead22743598f1d14474384beb3?locale=en-US&state=PRODUCTION&version=Cloud) to synchronously replicate and manage business user data programmatically.
- Concept SAP HANA In-Memory Relational Database The concept name was not provided (marked as "undefined"), and the available source snippets do not contain sufficient detail to construct a grounded, accurate reference definition. Only one source ([S1]) references a relevant topic — setting up database artifacts using SAP HANA — but without a named concept to define, a precise and accurate definition cannot be written per the documentation guidelines.
- Concept SAP HANA Cloud Instance Provisioning The concept provided is `undefined`, so no valid concept name was supplied. Based on the available sources — which cover topics such as SAP HANA Cloud free tier, SAP BTP Cloud Foundry deployment, Terraform automation, the SAP HANA Database Explorer, and SAP SuccessFactors extensions — it is not possible to determine which specific concept should be defined. Please provide a valid concept name so an accurate, source-grounded definition can be written.
- Concept SAP Fiori Launchpad Administration The concept provided is **undefined** — no specific SAP developer concept was supplied for definition. Based on the available sources, these snippets cover topics such as maintaining business roles and business users, creating communication arrangements in the ABAP environment, developing and deploying [SAP Fiori applications](https://help.sap.com/docs/btp/sap-business-technology-platform/97df0a6022a14ce180440d6fae1dd3cd?locale=en-US&state=PRODUCTION&version=Cloud) using tools like Visual Studio Code and SAP Business Application Studio, and [providing access to SAP Fiori applications](https://help.sap.com/docs/btp/sap-business-technology-platform/b569abb158934306a65f3eb38f86ffba?locale=en-US&state=PRODUCTION&version=Cloud) through role assignments. Please supply a specific concept name so an accurate and grounded definition can be written.
- Concept User Provisioning A **Business User** is a person who interacts with SAP BTP applications and is granted access based on assigned business roles and activities. Developers and administrators use this concept to manage [identity and access](https://help.sap.com/docs/btp/sap-business-technology-platform/51c167750d024d84aaaca699320f6cf8?locale=en-US&state=PRODUCTION&version=Cloud), controlling what actions a user can perform within the system. Business users can be provisioned and managed via the [inbound service `MANAGEBUSINESSUSERIN`](https://help.sap.com/docs/btp/sap-business-technology-platform/a631f4ead22743598f1d14474384beb3?locale=en-US&state=PRODUCTION&version=Cloud), and their attributes can be mapped from a corporate identity provider. Unlike communication users, who are used for system-to-system integration, business users represent human actors whose access is scoped by role-based authorizations.
- Concept Authorization Objects and Activities The concept name was not provided and could not be determined from the available source snippets. The sources cover topics such as authorization default values, business event header data, communication users, and user permissions, but no single defining concept is identified or described in enough detail across these snippets to produce an accurate, grounded definition. Please provide the concept name or more targeted source material.
- Concept SAP HANA Database Administration The concept provided is **undefined**, and the supplied sources do not contain sufficient information to produce a grounded definition. Please provide a valid SAP developer concept name so an accurate and source-supported definition can be written.
- Concept Data Lake Fundamentals The concept provided is **undefined** — no specific SAP developer concept was supplied for definition. The available sources cover topics such as provisioning, accessing, monitoring, backing up, and virtualizing data in [SAP HANA Cloud, data lake](https://developers.sap.com), but without a named concept to define, a grounded definition cannot be written. Please provide a specific concept name to generate an accurate reference definition.
- Concept SAP HANA Security and User Management The concept name provided is "undefined," and the supplied source snippets do not contain enough substantive content to ground a meaningful, accurate definition. A valid concept name and supporting source material are required to produce a reliable reference definition.
- Concept HDI Container and Artifact Management The concept provided is **undefined** — no concept name or supporting source content was supplied, making it impossible to derive a grounded definition. Please provide a valid concept name and relevant source snippets so a definition can be written.
- Concept SAP Build Work Zone configuration The provided sources do not contain enough information to define this concept, as the concept name is listed as "undefined" and the source snippets do not converge on a single, clearly identifiable SAP developer concept. Please provide a valid concept name or additional source content to generate an accurate definition.
- Concept SAP HANA Cloud Data Lake The concept name was not provided, so a precise definition cannot be determined from the available sources. The sources cover topics such as [SAP HANA Cloud integration with Esri ArcGIS as a geodatabase](https://architecture.learning.sap.com/docs/ref-arch/RA0011/readme), the [Medallion Reference Architecture for big data processing](https://architecture.learning.sap.com/docs/ref-arch/RA0012/readme), and various SAP HANA Cloud data lake capabilities including file store access, relational engine connectivity, and data movement scheduling. Please provide a specific concept name so that an accurate, source-grounded definition can be written.
- Concept CAP Service Modeling The concept name provided is "undefined," so no specific SAP developer concept can be identified or defined from the available sources. The sources cover topics such as [CAP services with Node.js](https://developers.sap.com/tutorials/appstudio-cap-nodejs-create.html) and SAP HANA stored procedures, but without a valid concept name, a grounded definition cannot be produced. Please provide a specific concept name to generate an accurate reference definition.
- Concept CAP service development The concept provided is **undefined** and no valid concept name was supplied. Without a specific SAP developer concept to define, and with the available sources covering topics such as CAP services, SAP Build Actions, SAP Business Application Studio, and SAP SuccessFactors extensions, it is not possible to generate an accurate, source-grounded definition. Please provide a valid concept name so a precise definition can be written.
Concepts that build on this
- Concept SAP HANA Security and User Management
- Concept Business Role Maintenance
- Concept SAP HANA Audit Policy Configuration
- Concept SAP Fiori App Access Control (Business Roles & Catalogs)
- Concept OAuth2 User Token Exchange Authentication
- Concept URL App Configuration in SAP Build Work Zone
- Concept Business Role Management
- Concept GitHub Organization Management
- Concept SAP Fiori Launchpad Spaces and Pages
- Concept CAP Mocked Authentication Strategy
- Concept Instance-Based Authorization
- Concept CAP Authorization and Access Control
- Concept SAP HANA Cloud Data Lake
- Concept Business Roles and Launchpad Spaces Configuration
- Concept Space Developer Role Assignment
- Concept BTP Role Collection Assignment