Role-Based Access Control (RBAC)
As of 2026-09-27
What is Role-Based Access Control (RBAC)?
RBAC and DAC answer two different questions that get conflated constantly — RBAC gates whether a user can open an object, DAC filters which rows of that object they can see.
What it is
RBAC (Role-Based Access Control) is the authorization model where permissions attach to roles, and roles attach to users — never permissions to users directly. In the SAP estate this shows up at two distinct layers a senior consultant must never conflate: the ABAP/S-4HANA layer (PFCG roles, authorization objects, composite roles) and the Datasphere/analytics layer (space privileges, scoped roles, and Data Access Controls / DAC — companion C008).
Two layers, two purposes. PFCG roles gate what a user can DO in the source ERP (transaction access, org-level authorizations via fields like company code and plant). Datasphere space-level roles gate what a user can SEE and BUILD inside a space (Viewer, Modeler, Space Administrator, plus custom scoped roles). DAC then filters ROWS within an object the user already has access to. RBAC answers "can this user open this object"; DAC answers "which rows of that object can this user see". Confusing the two is the most common governance design mistake in Datasphere rollouts.
Why role count balloons. A Tier-1 SAP landscape typically ends up with 50-200 distinct roles once org-level authorizations (company code, plant, sales org) are cross-multiplied with functional scopes (Finance, Procurement, Sales) and space-level Datasphere roles. Design discipline — role naming conventions, a role-to-business-function matrix, and a quarterly access review — is what keeps this from becoming unmanageable technical debt.
Why it matters
- PFCG roles (ERP-side transaction access) and Datasphere space roles (Viewer/Modeler/Admin) are two distinct layers — conflating them is the single most common governance design mistake in Datasphere rollouts.
- Role count naturally balloons to 50-200 once org-level scopes (company code, plant, sales org) cross-multiply with functional scopes and space roles — without discipline it hits 500+ and becomes unauditable.
- One-off role exceptions granted per user request, rather than mapped to the existing matrix, is exactly how Tier-1 landscapes end up with roles nobody can audit.
Key points
- RBAC = permissions attach to roles, roles attach to users — never permissions directly to users.
- Two distinct layers: PFCG/ABAP roles (object access) vs Datasphere space roles (space access) — do not conflate either with DAC (row access).
- 50-200 roles is normal at Tier-1 scale once org-level scope × functional scope × space role are cross-multiplied.
- Role matrix (business function × system layer × org scope) must be signed off before go-live, not built ad hoc.
- Only the MCP Server artifact type in SAP Integration Suite supports principal propagation to on-prem/private-cloud systems via SAP Cloud Connector — API-centric artifacts do not, which means an agent's connection TYPE, not its stated intent, decides whether RBAC's guarantee holds.
- SAP's public MCP server for BTP administration authenticates via Authorization Code Flow through SAP's Default Identity Provider specifically so the agent never has more access than the signed-in user — RBAC's core principle, restated for an agent.
- The role matrix needs a fourth dimension once AI agents enter the picture: which artifact type or connection pattern each agent uses to reach a system — decide and document this before the agent is built, not after a penetration test finds it.
Terms used on this page
- PFCG role
- SAP ABAP role-maintenance transaction; bundles authorization objects into a role, then assigns the role to users.
- Authorization object
- ABAP-layer permission unit combining fields (e.g. company code, plant) with activity codes — the atomic unit PFCG roles bundle.
- Space role
- Datasphere space-level role (Viewer, Modeler, Space Administrator) gating what a user can see and build inside a space.
- Data Access Control (DAC)
- Row-level filter applied after RBAC already grants object access; answers 'which rows', not 'which object'.
- Composite role
- PFCG role bundling several single roles into one job profile, easing assignment at scale.
- Role matrix
- Business-function × system-layer × org-scope grid used to design roles before rollout, not after.
- Org-level authorization
- Authorization scoped by an organizational field such as company code, plant, or sales organization.
- Access review
- Periodic (typically quarterly) audit reconciling granted roles against the role matrix and each user's current job function.
Sources
- DAMA-DMBOK — data management body of knowledge
- SAP Community — Principal propagation for MCP servers: SAP Integration Suite to SAP S/4HANA (2026, fetched 2026-09-27)
- SAP Community — Public release of the MCP server for SAP BTP administration (2026, fetched 2026-09-27)
- SAP Help Portal — Connect to MCP server for SAP BTP administration (fetched 2026-09-27)
- SAP News Center — Autonomous Enterprise: SAP AI Agents work at scale, AI Agent Hub (2026-09, fetched 2026-09-27)
- SAP Help Portal — Orchestration service in the generative AI hub, SAP AI Core (fetched 2026-09-27)
- SAP Community — Why SAP needs a Knowledge Graph: giving enterprise AI a map of the business (2026, fetched 2026-09-27)
- NIST — Role Based Access Control (RBAC) project overview, Computer Security Resource Center (fetched 2026-09-27)
- SAP Community — SAP Datasphere space management (2021, fetched 2026-09-27)
- SAP Help Portal — SAP Datasphere documentation (fetched 2026-09-27)
- EUR-Lex — Regulation (EU) 2016/679 (GDPR), Article 32 security of processing (fetched 2026-09-27)
- SAP Community — MCP Gateway in SAP Integration Suite: your APIs ready for the age of agents (2026, fetched 2026-09-27)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.
Guides that answer with this page
These guides cite this page as one of the sources their answer rests on.