8.4 Employee and Manager Self-Service Permissions
Key Takeaways
- Employee Self-Service uses a permission role granted to all employees with the target population set to the granted users themselves.
- Typical ESS changes are marital status or name, home address, dependents, and emergency contacts.
- Manager Self-Service lets managers start transactions for their direct reports, usually with approval workflows.
- Granting Edit Link Edit/Insert without block-level Edit/Insert lets users edit the current record but not create history records.
- Access to inactive employments uses the User Status field (Inactive) in the Grant Access To step, for Employee access only.
8.4 Employee and Manager Self-Service Permissions
Quick Answer: Employee Self-Service (ESS) lets employees maintain their own personal data. It is granted with a role whose target population is the granted users themselves. Manager Self-Service (MSS) lets managers start job, pay, and organizational transactions for their team, usually with workflows. Fine-grained block and field permissions decide whether users can edit current data, create history records, or see specific fields.
Why Self-Service
SAP's rationale: employees update their personal information, and managers handle employment, compensation, and organizational changes such as new positions or promotions. HR Operations reviews and approves changes and serves as a backup when employees and managers cannot make updates. RBP ensures that each group changes only what is relevant, and approval workflows can act as guardrails even when a user has permission to change data.
Employee Self-Service
An ESS grant has three parts. The granted population is all employees, the role is the permission, for example to view and edit the phone number, and the target population is the employees themselves. Typical ESS options:
- update marital status or name
- update home address
- update dependents
- update emergency contacts
Employees reach their data through Home > My Employee File, or View My Profile in Quick Actions.
Worked Example: Tuning the ESS Role
THR81 first proxies as an employee (Larry Ye) to test the current state, then changes the Employee Self-Service role:
| Permission category | Section | Field | Permission |
|---|---|---|---|
| Employee Data | HR Information | National ID Card | View and Edit |
| Employee Central Effective Dated Entities | Personal Information | All fields | View Current and View History |
| Employee Central Effective Dated Entities | Personal Information | Edit Link | Edit/Insert |
Result: the employee can now add National ID information. In Personal Information, the employee can no longer create a historical record but can edit the current information through the pencil icon, because only the Edit Link has Edit/Insert.
Access to Inactive Employments
Active employees can see their inactive employments through self-service. Examples are rehired employees viewing past employments, and employees back from a global assignment viewing the host assignment.
- In the role's Grant Access To step, use the User Status field and choose Inactive.
- User Status is available only for the Employee access user type.
- Employees need at least one active employment and must be able to log in.
- They must belong to the relevant permission groups, otherwise the Inactive option does not work.
- SAP recommends separate permission roles for inactive users, for example view but not edit.
Manager Self-Service
MSS lets managers start transactions for their direct reports, typically followed by workflows. Common MSS transactions:
- update Job Information
- update salary information
- initiate transfers
The Actions button (Take Action), in the employee's profile or quick card, is the usual starting point, for example Change Job and Compensation Info. Managers can also start EC Quick Actions from Manage My Team (Section 10.1).
Worked Example: Restricting the Manager Role
ACE's requirements:
- Managers can start Job Information updates except Supervisor and Pay Grade.
- Managers can start Compensation Information updates except Pay Type and Pay Group.
- Managers must not Create (Insert New Record), Correct, or Delete historical records.
- Managers can start Job Relationship updates.
| Category | Section | Fields | Permission |
|---|---|---|---|
| EC Effective Dated Entities | Job Information | all fields | View Current and View History |
| EC Effective Dated Entities | Job Information | all fields except Job Information Actions, Supervisor, Pay Grade | Edit/Insert |
| EC Effective Dated Entities | Compensation Information | all fields | View Current and View History |
| EC Effective Dated Entities | Compensation Information | all fields except Compensation Information Actions, Pay Type, Pay Group | Edit/Insert |
| EC Effective Dated Entities | Job Relationships | all fields | View Current and View History |
| EC Effective Dated Entities | Job Relationships | all fields except Job Relationships Actions | Edit/Insert |
Because the block-level Actions rows have no Edit/Insert, Correct, or Delete, the History window gives managers no Create, Correct, or Delete buttons. They can still edit the current information through the Edit Link or Take Action, which runs event reason derivation and workflows (Chapter 9). Test by proxying as the manager (Carla Grant) and opening a direct report's Job Details, Job Relationships, and Compensation History.
Why History Access Stays with HR
Changes made from History (Insert New Record, Correct, Delete) do not trigger workflows, even when workflow derivation rules exist. With event reason derivation active, History inserts require choosing the event and reason manually, and the save takes effect immediately. SAP calls this an HR Edit and reserves it for administrators. Managers and employees should work through the pencil icon or Take Action, which apply derivation rules and approvals.
Quick Reference
| Requirement | Configuration |
|---|---|
| Employees edit their own address | ESS role with the Addresses permission, target The Granted Users Themselves |
| Employees edit the current record but not history | Edit Link Edit/Insert only; no block-level Edit/Insert |
| Managers change job data for their team | MSS role with EC Effective Dated Entities for Job Information, granted for direct reports |
| Rehired employees view old employment data | Role with User Status = Inactive (Employee access user type) |
| Employees terminate their own employment | Permission with target population The Granted Users Themselves (Section 8.1) |
Which target population is used for Employee Self-Service roles?
After an ESS change, an employee can edit the current Personal Information record but cannot create a historical record. Which configuration produces this?
A company wants rehired employees to view data from their previous, inactive employment. What is required?