In October 2023 a fundamental new capability is delivered for SAP Datasphere: the so called ‘Scoped’ Roles’ which will allow Administrators of SAP Datasphere to assign roles to the users of SAP Datasphere on Space level.
This means a user can now be a ‘Modeler’ with all related privileges in one Space whereas he potentially is just a consumer in another Space of the same SAP Datasphere tenant.
This feature is shipped on 4th of October 2023 for SAP Datasphere tenants in Asia Pacific Region. On October 31st 2023 it will be shipped for SAP Datasphere tenants in American and European landscapes.
In general, for your existing Standard- and Custom Roles a Scoped Role is generated. Your existing roles remain and serve as templates to derive the Scoped Role so after conversion there are two types of roles:
The initial role assigned to a user which serves as a template for the Scoped Role and the derived Scoped Role after the conversion.
Those Scoped Roles will be assigned to the users according to the Spaces they were a member of before the conversion. This is an important fact to be considered! The Scoped Roles generated during conversion are only assigned to the users according to their initial Space membership to ensure the original behavior.
If additional Scoped Roles are manually created based on a standard or custom role template the default behavior of Scoped Roles is:
Most of the privileges within a role are Space dependent and will become part of the new Scoped Role generated.
However, there is a fraction of privileges which are still valid on a tenant level. Such Global privileges can be for example found in the standard roles: DW Administrator, Catalog Administrator and Catalog User. Hence, such roles are not converted to Scoped Roles and assigned to the users which had access to those roles as before the conversion so that the Global privileges are still active for such users.
In addition e.g. a user who was a ‘DW Administrator’ and member of certain Spaces before conversion will also be provided with the converted ‘DW Scoped Space Administrator’ role but only for the Spaces he was already a member of before the conversion.
A detailed overview which privileges are considered as global and which are Space dependent can be found in the SAP Datasphere Documentation – Managing Roles and Privileges.
Your existing roles available in the tenant before the conversion will remain as-is from a naming perspective.
Your converted Scoped Roles will follow a certain Naming Convention:
There is also the remark: ‘Created during SDP conversion’.
With Scoped Roles there is a dedicated maintenance UI available to specify the conditions under which the role is assigned to a given user.
First the role where SAML attributes need to be maintained must be selected:
To maintain the SAML conditions the new User Interface need to be executed:
Then the SAML conditions can be maintained:
If a custom SAML attribute for groups of users is maintained in the IdP they can be used in such conditions as well instead of singe users.
There is a new version of the Command Line Interface which also can handle Scoped Roles. Please download it here: npmjs.com
Use the new commands especially introduced for Scoped Roles. More in the SAP Datasphere Documentation.
More detailed information on Scoped Roles can be found in the SAP Datasphere Community (including system demonstration and more information on related topics) as well as in the SAP Datasphere Documentation.