AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-09-27

What is Role-Based Access Control (RBAC)?

RBAC and DAC answer two different questions that get conflated constantly — RBAC gates whether a user can open an object, DAC filters which rows of that object they can see.

What it is

RBAC (Role-Based Access Control) is the authorization model where permissions attach to roles, and roles attach to users — never permissions to users directly. In the SAP estate this shows up at two distinct layers a senior consultant must never conflate: the ABAP/S-4HANA layer (PFCG roles, authorization objects, composite roles) and the Datasphere/analytics layer (space privileges, scoped roles, and Data Access Controls / DAC — companion C008).

Two layers, two purposes. PFCG roles gate what a user can DO in the source ERP (transaction access, org-level authorizations via fields like company code and plant). Datasphere space-level roles gate what a user can SEE and BUILD inside a space (Viewer, Modeler, Space Administrator, plus custom scoped roles). DAC then filters ROWS within an object the user already has access to. RBAC answers "can this user open this object"; DAC answers "which rows of that object can this user see". Confusing the two is the most common governance design mistake in Datasphere rollouts.

Why role count balloons. A Tier-1 SAP landscape typically ends up with 50-200 distinct roles once org-level authorizations (company code, plant, sales org) are cross-multiplied with functional scopes (Finance, Procurement, Sales) and space-level Datasphere roles. Design discipline — role naming conventions, a role-to-business-function matrix, and a quarterly access review — is what keeps this from becoming unmanageable technical debt.

Why it matters

  • PFCG roles (ERP-side transaction access) and Datasphere space roles (Viewer/Modeler/Admin) are two distinct layers — conflating them is the single most common governance design mistake in Datasphere rollouts.
  • Role count naturally balloons to 50-200 once org-level scopes (company code, plant, sales org) cross-multiply with functional scopes and space roles — without discipline it hits 500+ and becomes unauditable.
  • One-off role exceptions granted per user request, rather than mapped to the existing matrix, is exactly how Tier-1 landscapes end up with roles nobody can audit.

Key points

  • RBAC = permissions attach to roles, roles attach to users — never permissions directly to users.
  • Two distinct layers: PFCG/ABAP roles (object access) vs Datasphere space roles (space access) — do not conflate either with DAC (row access).
  • 50-200 roles is normal at Tier-1 scale once org-level scope × functional scope × space role are cross-multiplied.
  • Role matrix (business function × system layer × org scope) must be signed off before go-live, not built ad hoc.
  • Only the MCP Server artifact type in SAP Integration Suite supports principal propagation to on-prem/private-cloud systems via SAP Cloud Connector — API-centric artifacts do not, which means an agent's connection TYPE, not its stated intent, decides whether RBAC's guarantee holds.
  • SAP's public MCP server for BTP administration authenticates via Authorization Code Flow through SAP's Default Identity Provider specifically so the agent never has more access than the signed-in user — RBAC's core principle, restated for an agent.
  • The role matrix needs a fourth dimension once AI agents enter the picture: which artifact type or connection pattern each agent uses to reach a system — decide and document this before the agent is built, not after a penetration test finds it.

Terms used on this page

PFCG role
SAP ABAP role-maintenance transaction; bundles authorization objects into a role, then assigns the role to users.
Authorization object
ABAP-layer permission unit combining fields (e.g. company code, plant) with activity codes — the atomic unit PFCG roles bundle.
Space role
Datasphere space-level role (Viewer, Modeler, Space Administrator) gating what a user can see and build inside a space.
Data Access Control (DAC)
Row-level filter applied after RBAC already grants object access; answers 'which rows', not 'which object'.
Composite role
PFCG role bundling several single roles into one job profile, easing assignment at scale.
Role matrix
Business-function × system-layer × org-scope grid used to design roles before rollout, not after.
Org-level authorization
Authorization scoped by an organizational field such as company code, plant, or sales organization.
Access review
Periodic (typically quarterly) audit reconciling granted roles against the role matrix and each user's current job function.

Sources

  1. DAMA-DMBOK — data management body of knowledge
  2. SAP Community — Principal propagation for MCP servers: SAP Integration Suite to SAP S/4HANA (2026, fetched 2026-09-27)
  3. SAP Community — Public release of the MCP server for SAP BTP administration (2026, fetched 2026-09-27)
  4. SAP Help Portal — Connect to MCP server for SAP BTP administration (fetched 2026-09-27)
  5. SAP News Center — Autonomous Enterprise: SAP AI Agents work at scale, AI Agent Hub (2026-09, fetched 2026-09-27)
  6. SAP Help Portal — Orchestration service in the generative AI hub, SAP AI Core (fetched 2026-09-27)
  7. SAP Community — Why SAP needs a Knowledge Graph: giving enterprise AI a map of the business (2026, fetched 2026-09-27)
  8. NIST — Role Based Access Control (RBAC) project overview, Computer Security Resource Center (fetched 2026-09-27)
  9. SAP Community — SAP Datasphere space management (2021, fetched 2026-09-27)
  10. SAP Help Portal — SAP Datasphere documentation (fetched 2026-09-27)
  11. EUR-Lex — Regulation (EU) 2016/679 (GDPR), Article 32 security of processing (fetched 2026-09-27)
  12. SAP Community — MCP Gateway in SAP Integration Suite: your APIs ready for the age of agents (2026, fetched 2026-09-27)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →