Skip to Content

idm 8.0 integration with GRC, jumps ARM approval

Jan 24 at 04:25 PM


avatar image

Hi experts,

on IDM 8.0 that is integrated with GRC AC, is there any way of in some cases a privillege goes to aproval on GRC and other not?


The privelege z_role when an automatically job assign the role its not passed for GRC approval, but if it was request on User interface this needs to be approval on GRC


10 |10000 characters needed characters left characters exceeded
* Please Login or Register to Answer, Follow or Comment.

1 Answer

Chenyang Xiong Jan 26 at 05:53 AM

Hi Arivind,

I think it is possible. I assume the difference is if the privilege is a direct assignment it should go through GRC, but if it is an indirect assignment via a business role, then bypass the GRC approval.

If my understanding is correct, you can modify "AC Validation" process, and add a condition pass to detect indirectly assignment in the beginning.

Another possibility is to modify pass [Submit AC Request]. there is a script named sap_grc10_getContextVar(ALL_ROLE_DATA). You can basically modify this script and filter out privileges you do not wish to send to GRC.

Hope it helps.


10 |10000 characters needed characters left characters exceeded