Role Collection Mapping
The concept name was not provided, but based on the sources, the most prominent concept is Role Collection Mapping on SAP Business Technology Platform. A role collection mapping allows developers to assign role collections to identity provider user groups or user attributes, enabling dynamic authorization management. Developers use it to map role collections to user groups or user attributes so that users automatically receive the appropriate permissions based on their identity provider group membership or attribute values, without requiring manual assignment per user.
Tutorials that teach this
Docs explaining this concept
Prerequisites
- Concept SAP Build Work Zone configuration The provided sources do not contain enough information to define this concept, as the concept name is listed as "undefined" and the source snippets do not converge on a single, clearly identifiable SAP developer concept. Please provide a valid concept name or additional source content to generate an accurate definition.
- Concept Role and Role Collection Management The concept name is not defined in the provided sources, and no sufficient information is available to construct an accurate, grounded definition.
- Concept Role Templates and Role Collections The concept name was not provided (`undefined`), and the single source snippet supplied does not contain enough detail to produce a fully grounded, accurate definition. Please provide the specific concept name and any additional relevant source snippets so a precise definition can be written.
- Concept SAML Identity Provider Trust Configuration The provided sources do not contain enough grounded information to define a concept labeled "undefined." Based on the available sources, they collectively describe **SAML trust configuration** on SAP BTP — a mechanism that allows developers to establish federated trust between SAP BTP subaccounts and identity providers (such as [SAP Cloud Identity Services](https://help.sap.com/docs/btp/sap-business-technology-platform/7c6aa87459764b179aeccadccd4f91f3?locale=en-US&state=PRODUCTION&version=Cloud) or SAP SuccessFactors) using the SAML 2.0 protocol. Developers use it to enable single sign-on, map identity provider groups to platform roles, and configure OAuth 2.0 SAML Bearer Assertion grants for secure service-to-service communication. It can also be [restored after replacement](https://help.sap.com/docs/btp/sap-business-technology-platform/21d86cf36ce94da7b2f2db8271e0b539?locale=en-US&state=PRODUCTION&version=Cloud) to recover a previous trust setup in a subaccount.
- Concept Trust configuration between SAP Cloud Identity Services and SAP BTP The provided sources do not contain enough information to define a specific, named SAP developer concept, as the concept supplied is "undefined." The sources relate to custom identity providers on SAP BTP, but without a concrete concept name or sufficient descriptive snippets, a grounded definition cannot be accurately composed.
- Concept SAP BTP SaaS Application Subscription The provided sources do not contain enough grounded information to define a specific SAP developer concept, as the concept name is listed as "undefined." Based on the available source snippets, the content relates to subscribing to SaaS solutions and managing consumer subaccounts on [SAP Business Technology Platform](https://help.sap.com/docs/btp/sap-business-technology-platform/975bd3e54cbe4e52af346740658d1a4a?locale=en-US&state=PRODUCTION&version=Cloud), but no single named concept can be accurately defined without additional context.
- Concept BTP Service Entitlements Configuration The concept name is missing or undefined, so a precise definition cannot be provided. Based on the available sources, the provided snippets cover topics such as [SAP BTP trial account setup](https://help.sap.com/docs/btp/sap-business-technology-platform/fa5deb9cc4be4ca58070456cd2c47647?locale=en-US&state=PRODUCTION&version=Cloud), free service plans, the btp CLI, Kyma environment management, and [account administration via the SAP Cloud Management Service APIs](https://help.sap.com/docs/btp/sap-business-technology-platform/17b6a171552544a6804f12ea83112a3f?locale=en-US&state=PRODUCTION&version=Cloud), but no specific concept is identified for definition. Please provide a valid concept name to generate an accurate reference definition.
- Concept Identity Provider Groups The concept name is not defined in the provided sources, so a precise definition cannot be grounded solely in the supplied snippets. Based on the available context, an **Identity Provider (IdP) User Group** is a grouping construct used within an identity provider to organize users — such as developers — so that they can be collectively managed and assigned roles or permissions on SAP Business Technology Platform. Administrators [create these groups and assign users to them](https://help.sap.com/docs/btp/sap-business-technology-platform/a9bd926e9ae2470f816854c99d980db7?locale=en-US&state=PRODUCTION&version=Cloud), then map the groups to role collections in SAP BTP to control access to platform resources and services.
- Concept Identity Provider (IdP) Trust Configuration The concept provided is **undefined**, and the available source snippets do not contain sufficient grounded content to produce a reliable, accurate definition. All sources relate to trust configuration, SAP BTP setup tutorials, or SAP Document AI — none of which define a specific named developer concept. Without a valid concept name and supporting source material, a documentation-quality definition cannot be responsibly generated.
- Concept Role Collections and Authorization Artifacts The concept name provided is "undefined," and the available source snippets do not contain sufficient grounded information to define a specific, identifiable SAP developer concept. A meaningful definition cannot be written without a valid concept name and supporting source content.