1.3 Instances, Provisioning, and Company Settings
Key Takeaways
- The instance is the customer-facing front end; users log in with a company ID, username, and password.
- Provisioning is the back end for enabling features and modules, creating administrator accounts, uploading templates, and enabling language packs.
- Customers never access Provisioning; only trained SAP employees and partners receive Provisioning accounts.
- Admins view, grant, and remove Provisioning access with the Manage Provisioning Access tool, separately in each instance.
- Changes in Provisioning Company Settings are saved with Save Feature and confirmed by entering the company ID.
1.3 Instances, Provisioning, and Company Settings
Quick Answer: An instance is the front end of SAP SuccessFactors, identified by a Company ID. Provisioning is the back end, where implementers switch on features and purchased modules, create administrator accounts, upload templates, and enable language packs. Customers never use Provisioning. Customer administrators control who may reach Provisioning for their instance with Manage Provisioning Access in Admin Center.
The Instance
An instance is the customer-facing view of the SAP SuccessFactors platform. Each company has a URL and a Company ID. Each user signs in with the Company ID, a username, and a password. Consultants, administrators, and end users see the same interface. What differs is which tools each person's configuration and permissions expose. The login page offers a question-mark icon that links to a support FAQ for account and login problems.
During implementation, consultants use the Admin Center in the instance to set up basic features. Examples include the look and feel (colors, logo, home page), e-mail notification templates, and text replacement. After go-live, customer administrators use the Admin Center to adjust those features and to run processes: launching forms, importing and updating users, and resetting passwords.
Provisioning
Provisioning is the key configuration tool SAP uses to control many aspects of an instance. It is effectively the system's back end. Implementers, consultants, and support representatives use it to:
- modify company settings, such as enabling new features
- turn purchased modules on or off
- create administrator accounts
- download and upload templates that contain custom configuration
- enable language packs
After logging in, a consultant sees the list of company instances they may access. They select the company name and then Company Settings. The page is long, so SAP suggests using the browser search (Ctrl + F). After changing a section, choose Save Feature. Provisioning then asks for the company ID to confirm. The page has several Save buttons but only one Save Feature button per section.
Instance Versus Provisioning
| Instance | Provisioning | |
|---|---|---|
| Who has access | Implementers, administrators, end users | Implementers, SAP SuccessFactors Customer Support |
| Typical uses | Customize tiles, manage permissions, oversee user information, generate reports, run processes and cycles | Configure system features, enable purchased modules, upload templates |
For example, deciding who can access Compensation is done in the instance through RBP. Turning on the Compensation module is done in Provisioning.
Who Gets Provisioning Access
Provisioning access is strictly controlled. Only SAP employees and partners who have completed the required training receive a Provisioning user account. THR80 also notes that an SAP SuccessFactors certification is required before implementation consultants gain Provisioning access to customer instances.
Customers stay in control through Manage Provisioning Access in Admin Center, which requires the Manage Provisioning Access permission. With it, an administrator can:
- view the users who have Provisioning access to the instance, using filters
- approve (add) a Provisioning user. Approval alone does not grant access; the user still submits an internal access request in which SAP verifies training and other requirements
- remove Provisioning access from one or more users
Provisioning access is instance-specific. A customer with Development, Test, and Production instances must manage access separately in each one. A consultant may have Test access long before Production access is approved.
Creating an Administrator Account in Provisioning
Provisioning can create new administrator accounts. SAP notes that backup admin accounts help if the regular administrator account is locked out. In Company Settings, the consultant scrolls to the admin section (Ctrl + F for "Admin Username") and completes:
- admin username and password (the two must differ, and the username must be unique in the instance)
- first name, last name, and e-mail
- the confirmation checkbox that the customer has approved Super Admin user account creation, and the customer contact's e-mail address
Then choose Create Admin and confirm with the company ID. If the username already exists, Provisioning shows an invalid-username error. If the instance uses the single recipient e-mail feature, creating a Super Admin fails with an exception that the e-mail could not be sent. SAP's workaround is to disable that feature temporarily.
Settings Moving Out of Provisioning
SAP is moving settings from Provisioning into Admin Center so customer administrators control more of their own system. Before migrating a setting, SAP checks four things:
- Is the action already in Admin Center? If so, SAP removes the Provisioning copy to keep one source of truth.
- Is the switch meaningful, or an edge case that should be removed or kept SAP-only?
- Does the experience need improving before it moves?
- Does the switch control a purchase? License-controlling switches stay out of Admin Center.
You will see this pattern throughout Employee Central. Position Management, for example, can be enabled either in Provisioning Company Settings or in Admin Center under Manage Employee Central Settings. In contrast, importing the Succession Data Model XML still requires Provisioning.
A customer HR administrator asks for a Provisioning login so they can enable a purchased module themselves. What is the correct response?
A customer has Development, Test, and Production instances and wants to remove a former consultant's Provisioning access everywhere. What must the administrator do?
According to SAP's criteria for moving settings from Provisioning to Admin Center, which switch will not be moved into Admin Center?