Vision User Guide
Vision User Guide
Vision User Guide
In addition, Approva:
Roles Workflow
Requestor
The Requestor is an authorized staff member who initiates the creation of a VISION Transaction System
user account, modification of role assignments, de-provisioning or re-provisioning of a user account.
Historically, the PRoMs Apps Admin created the account. The new process required that the Section
Chiefs will be creating the requests in Approva.
Approver
The Approver is an authorized staff member designated to approve the request for a new VISION
Transaction System user account, de-provisioning of a user, or other changes of user role and functions
in line with office policy and segregation of duties.
Historically the Approver has been in NYHQ. The new process requires the UNICEF Representatives
“Reps” will now be the Approver. They can delegate approval duties for example to the Deputy
Representative or Chief of Operations.
Note: Delegation of this responsibility must be approved by the Controller.
Local Site Admin
IT Officer
This person is an authorized staff designated to assign user roles and functions in Approva to existing
users such as Requestors and Approver, and Analysts. See the LSA Guide found on the ilearn site.
5
Analyst
Reporting
Security Administrator
Deep level support
E-mail Notifications
All e-mail notifications sent by Approva will list the sender as “[email protected].”
Document Information
http://iconprep.unicef.org:44444/NYHQ/ITSS/Vision/Shared Documents/9. APPROVA/Training
Documentation/User Provisioning Processv2.docx
Authors: Kelly Neal and Michael Thurlow
UNICEF Manager: Jorge Torres
Cover photograph © UNICEF/Chulho Hyun
Version: 1.0
6
Chapter 1 | Requestor
The Requestor will be creating the following scenarios for both staff and consultants. For a visual and
high level description of the User Provisioning processes, see Appendix 2.
Request for SAP Access
Modification of SAP Role
De-Provisioning SAP Access
Re-Provisioning SAP Access
Before you begin
Approva Role = Requestor
You must have access to Approva. Contact your local site admin for access.
The Staff new user you are requesting access for must have a Personal Number (PA).
The Consultant new user you are requesting access for must have their LAN access and e-mail
account.
b. Type in any part of the user’s last or first name or the LAN ID you are requesting, and click
or press Enter.
Valid From
Enter a start date. This date must be at least today’s date.
Valid Through
Enter the contract expire date.
Note: This date is the same for either staff or consultant. Staff user - the date will be automatically
pulled from the HR system. The HR system will override your date if different.
Consultant - This field will be brought from LDAP so it will be over written with the LDAP value
rather than what is filled in BizRights.
Approver
a) Click to search the Approver’s name.
c) Search for the user, select the User ID, and click .
Note: This field is for Consultants only. You must not assign new functions to a staff user.
Use the Modify SAP Access process to assign new functions to an existing Staff user.
Staff roles are assigned based on their position from an automated SAP background job
on a daily basis.
a) Select one of the following menu items to search functions to assign to new user. Consultants
must be assigned roles from all three: Enabler, Common, and Functional.
Organization – ALL Lists all of the functions possible.
Common Lists functions common to all users such as display and printer use.
Enabler Lists the country the functions are to be assigned. Each consultant is
required to have at least one enabler.
Functional Lists functions grouped together such as AP or AR.
c) Select the functions to be added, and click . This will automatically populate the
functions into the New Functions to be Assigned section.
Note: you must select all Functions Names. For example, if there are five Account Payable L1
Function Names, you must check all five line items. See Figure 4.
Comments
Choose the comment from the drop down menu.
4. Complete the following optional fields:
Assign roles as this user
Use this field to copy and assign roles to a new user from an existing Consultant user. This is used
only for new Consultants, and never for Staff.
Note: Staff roles are assigned by their position in SAP in a nightly batch job.
5. Click to create the request. The request will now be processed through the Approva
system for the What if analysis. The request now will show up on your dashboard in the VISION
Access (Transaction System). See Figure 5. The request status will display one of the following
messages:
10
The status will change as the request moves through the process. For example, when the Approver
approves the request, the status will change to Approved.
SAP Role Assignment Management Staff – If additional functionality other than is what is in their
position is needed.
Consultant – If additional functionality is needed.
SAP User Re-provisioning Unlocks a user’s ID that was previously locked by the system
administrator.
SAP User De-provisioning Locks a user’s ID.
a) Click to search for User ID. The Select User dialog box opens. Figure 10.
b) Do one of the following:
Scroll all users to find the existing user.
Valid From
This date is populated by Approva. Change if applicable.
Valid Through
Enter the contract expiration date or the length of time the access needs to be modified. It can be
anywhere from one day to the end of contract.
Approver
a) Click to search the Approver’s name.
c) Search for the user, select the User ID, and click .
If you need to remove a role assigned to a staff user, contact HQ Help Desk. They must
follow the Roles to Position process.
c. Select the functions to be added, and click . This will automatically populate the
functions into the New Functions to be Assigned section.
Note: you must select all Functions Names of the same type. For example, if there are five
Account Payable L1 Function Names, you must check all five line items. See Figure 11.
d. If you want to remove a role, select the function name, and click .
16
Note: Staff roles are assigned by their position in SAP in a nightly batch job.
Comments
Choose the comment from the drop down menu.
De-Provisioning
The steps to complete this process are the same for both Staff and Consultants. This process could be
required when a user moves from one office to another or if a break in a contract exists.
Staff This task locks the SAP user ID. The user still exists in the SAP database.
Consultant This task locks the SAP user ID and removes all roles associated with the user.
SAP System
Select the SAP system.
Existing User
a) Click to search for User ID. The Select User dialog box opens. See Figure 14.
b) Do one of the following:
Select an existing user from the list.
Type in any part of the user’s last name, first name or their LAN ID, and click or
Enter.
Approver
a) Click to search the Approver’s name.
c) Search for the user, select the User ID, and click .
d) Add any comments.
Re-Provisioning
This process is similar to creating a new staff member or consultant. Because the shell account still
exists from when they were De-Provisioned, Approva must handle the request differently.
Re-Provisioning does three basic functions: 1) unlocks the user, 2) brings in data from VISION
Transaction System, and allows the functionality in Approva to re-assign former or new job roles.
1. Log into the VISION access (Transaction System).
http://usaaapva001/ApprovaProvisioning/RequestHome.aspx
2. Mouse over Create Request, and click Modify SAP Access.
SAP System
Select the SAP system.
Existing User
a) Click to search for User ID. The Select User dialog box opens. Figure 16.
b) Do one of the following:
Scroll all users to find the existing user.
Type in any part of the user’s name and click or press Enter.
21
c) Search for the user, select the User ID, and click .
New Functions to be Assigned
This field is for primarily for Consultants.
Note: Staff roles are assigned by their position in SAP in a nightly batch job. Requestors
can add additional Staff Roles If needed.
If you need to remove a role assigned to a staff user, contact HQ Help Desk. They must
follow the Roles to Position process.
a) Select one of the following menu items to search functions to assign to new user.
Organization – ALL Lists all of the functions possible.
Common Lists functions common to all users such as display and printer use.
Enabler Lists the country the functions are to be assigned. Each consultant is
required to have at least one enabler.
Functional Lists functions grouped together such as AP or AR.
Note: The Enabler options assigns functions for a specific country. Consultants must be assigned
roles from Enabler, Common, and Functional.
c) Select the functions to be added, and click . This will automatically populate the
functions into the New Functions to be Assigned section.
Note: you must select all Functions Names. For example, if there are five Account Payable L1
Function Names, you must check all five line items. See Figure 17.
Comments
Choose the comment from the drop down menu.
4. Complete the following optional fields:
5. Click to send request for Re-Provisioning to the Approver. The request will now be
processed through the Approva system.
The request now will show up on your dashboard. See Figure 18. The request status will display one
of the following messages:
a) Submitted For What If
b) What If Completed With Violations
23
c) Pending Approval
d) Approved
The status will change as the request moves through the process. For example, when the Approver
approves the request, the status will change to Approved.
Chapter 2 | Approver
The Approver will be approving one of the following scenarios. For a visual and high level description of
the User Provisioning processes, see Appendix 2.
Request for a SAP Access
Modification of SAP Roles
De-Provisioning
Re-Provisioning
1. Check your e-mail. You will receive an e-mail from [email protected] once the new request
for VISSION/SAP access has been submitted by the Requestor. See Figure 19.
2. Click the Click Here link to open the request in the Role Management.
Note: You may also log into the Role Management, and review any requests waiting for approval
by following menu path Manage > Requests. See Quick Approve / Deny.
3. Review the request. If the request contains SoD violations, you may review the violations and
approve or deny each job role containing any violations.
25
Figure 20 |New user request viewed in the VISION Access (Transaction System)
26
Click .
Click .
Click .
Click .
Note: You must either deny or approve ALL. You can’t approve on and deny another. If one role
is denied, the entire request fails and you will have to insert comments instructing the
Requestor to resubmit the request without the roles you want to deny.
5. Click to approve the request. An e-mail confirmation will be sent to the Requestor and
new user.
6. End of task.
29
De-Provisioning
This task locks the SAP user ID and removes all roles associated with the user. The user exists in the SAP
database but contains no roles assigned. The process is the same for both Staff and Consultants. This
process could be required when a user moves from one office to another or if a break in a contract
exists.
1. Check your e-mail. You will receive an e-mail from [email protected] once the request for
SAP User De-Provisioning has been submitted by the Requestor.
2. Click the Click Here link to open the request in the Role Management.
Note: You may also log into the Role Management, and review any requests waiting for approval
by following menu path Manage > Requests. See Quick Approve / Deny.
Click .
Click .
5. End of Task.
An e-mail confirmation will be sent to the Requestor and de-provisioned user if the request is
approved. If the request is denied, an e-mail will be sent only to the Requestor.
30
Re-Provisioning
This is similar to creating a new staff member but because the shell account still exists from when they
were de-provisioned, Approva must handle the request differently.
1. Check your e-mail. You will receive an e-mail from [email protected] once the request for
SAP User Re-Provisioning has been submitted by the Requestor. See Figure 25.
2. Click the Click Here link to open the request in the Role Management.
Note: You may also log into the Role Management, and review any requests waiting for approval
by following menu path Manage > Requests. See Quick Approve / Deny.
Figure 26 | No Violations
Figure 28 | 47 Violations
34
Discussion
This can be used for communicating anything regarding the request. The communication will send an e-
mail notification to the other user and result in new comments added to the request. See Figure 50.
Note: You must open the request, and click to close the discussion.
This is necessary to submit request for approval.
Figure 50 | Discuss
36
Figure 54 provides an overview of the process of modifying the roles of a staff or consultant.
Requestor
The Requestor logs into VISION Access (Transaction System) and selects Create Request –
Modify SAP User Access.
The Requestor adds and/or deletes roles and functions as needed.
The Requestor submits the request and it goes to Approva’s SoD (Separation of Duties) analysis
process.
SoD analysis flags violation of SoD rules and sends a notification e-mail to the Requestor.
The Requestor clicks on the link in the e-mail to open the Approva system to the record.
The Requestor reviews the violations and adds comments to indicate how these violations will
be handled. Roles may also be deleted to resolve the violations. The request is then submitted
again to SoD analysis.
SoD analysis may find further violations and again send a notification e-mail to the Requestor.
This loop will continue until the Requestor adds no further comments to the request.
Approver
The request is sent via e-mail to the Approver. The Approver clicks on the link in the e-mail to
view the request for modification and any violations that have occurred.
The Approver must approve or deny each violation.
The request for modification is then submitted.
E-mail notifications are sent to the Requestor and the modified user.
42
Re-Provisioning a Consultant
Figure 57 provides an overview of the process of provisioning a consultant.
1. The Requestor logs into Approva and selects Create Request – SAP Consultant Re-
Provision.
2. The Requestor selects the consultant from the drop-down menu. The date fields are
populated from the existing data.
Note: The Valid from Date field shows the original hire date. Do not change this field.
3. Roles are added by the Requestor to the consultant’s functions. Common, functional
and enabler roles need to be added since the consultant has no position data to assign
roles.
4. The Requestor submits the request and it goes to Approva’s SoD (Separation of Duties)
analysis process.
5. SoD analysis flags violation of SoD rules and sends a notification e-mail to the Requestor.
6. The Requestor clicks on the link in the e-mail to open the Approva system to the record.
7. The Requestor reviews the violations and adds comments to indicate how these
violations will be handled. Roles may also be deleted to resolve the violations. The
request is then submitted again to SoD analysis.
8. SoD analysis may find further violations and again send a notification e-mail to the
Requestor. This loop will continue until the Requestor adds no further comments to the
request.
9. The request is sent via e-mail to the Approver. The Approver clicks on the link in the e-
mail to view the request and the comments regarding SoD violations.
10. If the Approver denies the request, they should provide comments on the reason for
rejection. An e-mail is sent to the Requestor.
11. If the Approver allows the request it is sent to Approva which reactivates the account
and assigns the job roles to the consultant.
12. E-mail notifications are sent to the Requestor and the re-provisioned consultant.
48
12/8/2011 2:49:50 PM - Exception occurred during operation. Details: Lock User Failed:
Maintenance of user VOCAMPOBORJE locked by user ATLEEL. Operation will be retried according to
the retry configuration settings.