8.4 Employee and Manager Self-Service Permissions

Key Takeaways

  • Employee Self-Service uses a permission role granted to all employees with the target population set to the granted users themselves.
  • Typical ESS changes are marital status or name, home address, dependents, and emergency contacts.
  • Manager Self-Service lets managers start transactions for their direct reports, usually with approval workflows.
  • Granting Edit Link Edit/Insert without block-level Edit/Insert lets users edit the current record but not create history records.
  • Access to inactive employments uses the User Status field (Inactive) in the Grant Access To step, for Employee access only.
Last updated: September 2026

8.4 Employee and Manager Self-Service Permissions

Quick Answer: Employee Self-Service (ESS) lets employees maintain their own personal data. It is granted with a role whose target population is the granted users themselves. Manager Self-Service (MSS) lets managers start job, pay, and organizational transactions for their team, usually with workflows. Fine-grained block and field permissions decide whether users can edit current data, create history records, or see specific fields.

Why Self-Service

SAP's rationale: employees update their personal information, and managers handle employment, compensation, and organizational changes such as new positions or promotions. HR Operations reviews and approves changes and serves as a backup when employees and managers cannot make updates. RBP ensures that each group changes only what is relevant, and approval workflows can act as guardrails even when a user has permission to change data.

Employee Self-Service

An ESS grant has three parts. The granted population is all employees, the role is the permission, for example to view and edit the phone number, and the target population is the employees themselves. Typical ESS options:

  • update marital status or name
  • update home address
  • update dependents
  • update emergency contacts

Employees reach their data through Home > My Employee File, or View My Profile in Quick Actions.

Worked Example: Tuning the ESS Role

THR81 first proxies as an employee (Larry Ye) to test the current state, then changes the Employee Self-Service role:

Permission categorySectionFieldPermission
Employee DataHR InformationNational ID CardView and Edit
Employee Central Effective Dated EntitiesPersonal InformationAll fieldsView Current and View History
Employee Central Effective Dated EntitiesPersonal InformationEdit LinkEdit/Insert

Result: the employee can now add National ID information. In Personal Information, the employee can no longer create a historical record but can edit the current information through the pencil icon, because only the Edit Link has Edit/Insert.

Access to Inactive Employments

Active employees can see their inactive employments through self-service. Examples are rehired employees viewing past employments, and employees back from a global assignment viewing the host assignment.

  • In the role's Grant Access To step, use the User Status field and choose Inactive.
  • User Status is available only for the Employee access user type.
  • Employees need at least one active employment and must be able to log in.
  • They must belong to the relevant permission groups, otherwise the Inactive option does not work.
  • SAP recommends separate permission roles for inactive users, for example view but not edit.

Manager Self-Service

MSS lets managers start transactions for their direct reports, typically followed by workflows. Common MSS transactions:

  • update Job Information
  • update salary information
  • initiate transfers

The Actions button (Take Action), in the employee's profile or quick card, is the usual starting point, for example Change Job and Compensation Info. Managers can also start EC Quick Actions from Manage My Team (Section 10.1).

Worked Example: Restricting the Manager Role

ACE's requirements:

  • Managers can start Job Information updates except Supervisor and Pay Grade.
  • Managers can start Compensation Information updates except Pay Type and Pay Group.
  • Managers must not Create (Insert New Record), Correct, or Delete historical records.
  • Managers can start Job Relationship updates.
CategorySectionFieldsPermission
EC Effective Dated EntitiesJob Informationall fieldsView Current and View History
EC Effective Dated EntitiesJob Informationall fields except Job Information Actions, Supervisor, Pay GradeEdit/Insert
EC Effective Dated EntitiesCompensation Informationall fieldsView Current and View History
EC Effective Dated EntitiesCompensation Informationall fields except Compensation Information Actions, Pay Type, Pay GroupEdit/Insert
EC Effective Dated EntitiesJob Relationshipsall fieldsView Current and View History
EC Effective Dated EntitiesJob Relationshipsall fields except Job Relationships ActionsEdit/Insert

Because the block-level Actions rows have no Edit/Insert, Correct, or Delete, the History window gives managers no Create, Correct, or Delete buttons. They can still edit the current information through the Edit Link or Take Action, which runs event reason derivation and workflows (Chapter 9). Test by proxying as the manager (Carla Grant) and opening a direct report's Job Details, Job Relationships, and Compensation History.

Why History Access Stays with HR

Changes made from History (Insert New Record, Correct, Delete) do not trigger workflows, even when workflow derivation rules exist. With event reason derivation active, History inserts require choosing the event and reason manually, and the save takes effect immediately. SAP calls this an HR Edit and reserves it for administrators. Managers and employees should work through the pencil icon or Take Action, which apply derivation rules and approvals.

Quick Reference

RequirementConfiguration
Employees edit their own addressESS role with the Addresses permission, target The Granted Users Themselves
Employees edit the current record but not historyEdit Link Edit/Insert only; no block-level Edit/Insert
Managers change job data for their teamMSS role with EC Effective Dated Entities for Job Information, granted for direct reports
Rehired employees view old employment dataRole with User Status = Inactive (Employee access user type)
Employees terminate their own employmentPermission with target population The Granted Users Themselves (Section 8.1)
Test Your Knowledge

Which target population is used for Employee Self-Service roles?

A
B
C
D
Test Your Knowledge

After an ESS change, an employee can edit the current Personal Information record but cannot create a historical record. Which configuration produces this?

A
B
C
D
Test Your Knowledge

A company wants rehired employees to view data from their previous, inactive employment. What is required?

A
B
C
D