cancel
Showing results for 
Search instead for 
Did you mean: 

Changing rules in GRC - best practice

Former Member
0 Kudos

Hi Everyone

Please advise on the following. We have built a user exit for transaction MIGO and this user exit checks whether the user have access to a customized Auth Object before proceeding to execute MIGO. This means all the current rules and functions that reports SOD's on MIGO is not valid anymore. What is best practice to follow : Do we change the existing functions and add the custom Auth object for all functions and rules checking MIGO or do we disable the current rules and create new custom rules that includes the custom object?

Your advice will be appreciated.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Personally I would copy the original rules, modify the copies and disable the originals. You may need to modify the functions too, I suppose. This makes it easier to see changes from the standard ruleset - non-standard rules and functions have names that start with a 'Z'. Our internal and external auditors prefer it this way.