1.4 Administrator Types, Super Admin Access, and Admin Center Navigation
Key Takeaways
- SAP defines three administration levels: Super Administrator, Security Administrator, and Administrator.
- When a new Super Administrator first logs in, only Manage Super Admin Access is visible in Admin Center.
- Manage RBP Admin Access grants View Role, View Group, Edit Role, Edit Group, and change-notification rights to RBP admins.
- There is no separate permission for the Admin Center page; any admin permission makes it available.
- Tool Search returns only Admin Center tools, while Action Search returns broader results.
1.4 Administrator Types, Super Admin Access, and Admin Center Navigation
Quick Answer: A Super Administrator is created in Provisioning. At first login only Manage Super Admin Access is visible, and the Super Admin uses it to authorize others. Security Administrators manage RBP groups and roles, and Administrators reach the Admin Center tools their roles allow. People need at least View Group and View Role from Manage RBP Admin Access before they can open the RBP tools.
Three Levels of Administration
| Level | What it does |
|---|---|
| Super Administrator | Created initially in Provisioning. Grants others permission to become Super Administrators or Security Administrators. |
| Security Administrator | Manages all security through permission roles and permission groups in the Role-Based Permissions framework. |
| Administrator | A user with access to Admin Center pages, granted by the Security Administrator through administrative permissions. |
The First Login
When a Super Administrator created in Provisioning first logs in, the Admin Center shows one link only: Manage Super Admin Access. From there the Super Admin assigns an employee to act as Security Administrator. Nothing else can be configured until the security chain is established. This is the correct bootstrap sequence: Provisioning creates the Super Admin, the Super Admin grants RBP administration, and RBP administrators build roles and groups.
Manage Super Admin Access
This tool lists two categories:
- Super admins: a broad administrative role with access to Manage Super Admin Access, Manage RBP Admin Access, User Search, and Manage Provisioning Access.
- Admin overseers: a high-privilege oversight role with access to Manage Super Admin Access, Manage RBP Admin Access, and User Search. It does not include Manage Provisioning Access.
You can add, modify, or remove super admin access. The system prevents you from deleting yourself as a super admin. SAP recommends revoking super admin rights when an employee leaves. Audit logs for super admin and admin overseer data are available through the Viewer for SAP Audit Log service and the Audit Log Search API.
Manage RBP Admin Access
Use this tool to add, update, and remove RBP administrators and to grant them:
- View Role and View Group
- Edit Role and Edit Group
- Notify this user of RBP changes
To open Manage Permission Groups, Manage Permission Roles, and RBP Troubleshooting, a user needs at least View Group and View Role. To change groups and roles, they also need Edit Group and Edit Role. For role changes that affect many users, you can enable double-confirmation pop-ups and e-mail notifications and set a threshold. For example, a threshold of 80% triggers notifications when a change affects 80% or more of employees.
Common Platform Terms
| Term | Meaning |
|---|---|
| Instance | The front end, customer-facing view of the system |
| Provisioning | The back-end configuration tool; customers have no access |
| Admin Center | The central access point for administrative features; customers do have access |
| Role-Based Permissions (RBP) | The permission model built from permission roles and permission groups |
| Proxy | Lets one employee act on behalf of another |
| Home Page | The default starting page showing tasks, activity, and quick access |
| Org Chart | An interactive view of the hierarchy and reporting relationships, including matrix managers |
| Picklist | A configurable set of options, usually a drop-down |
| Metadata Framework (MDF) | The platform capability used to extend the suite; its building blocks are Generic Objects |
| User Data File (UDF) | A CSV file used to add or change employee records |
Navigating the Admin Center
Anyone with administrative privileges sees Admin Center in the Home navigation menu and the name menu. The page shows only the tools the administrator is permitted to use. There is no separate permission for the Admin Center page itself: permission to any admin tool or setting is enough.
Key Admin Center features are the Admin Homepage, Admin Tools, Tool Search, Admin Favorites, Upgrade Center, Execution Manager, Performance Metrics, Integration Center, and Intelligent Services.
- Tool Search auto-completes as you type and shows a description of the highlighted tool. Its results are limited to Admin Center tools.
- Action Search (in the global header) returns broader results. For example, a search for "homepage" returns more than one result, while the Tools tile returns only Manage Home Page.
- Admin Favorites: hover over a tool and select the star. If a tool appears in several categories, each instance shows a star. Recently used tools also appear.
- See All on the Tools tile lists every tool available for your permissions and enabled modules.
- System notifications appear as one combined banner with a summary and a link to a pop-up of actions that need attention. Notifications are not displayed in any specific order.
Exam Relevance
In a practical task you are usually an administrator whose permissions were set up in advance. Still, when a tool you expect is missing from Action Search, the explanation is almost always a missing permission. The fix is to grant it in Manage Permission Roles and then log out and back in.
A Super Administrator created in Provisioning logs in to a new instance for the first time. What does the Admin Center show?
A new RBP administrator cannot open Manage Permission Roles or RBP Troubleshooting. Which minimum access must be granted in Manage RBP Admin Access?
What distinguishes Tool Search in the Admin Center from Action Search in the global header?