SAP HCM权限控制-工资核算范围与权限对象解释
发布时间:2026/9/12 15:16:37 锦皓数字建站

工资核算范围是SAP HCM模块的一个特殊名词控制的核算周期是薪酬核算的重要颗粒度但是这个重要的颗粒度在HCM的权限体系中缺没有单独授权的字段从这个点来看HCM的字段授权不是字段级。今天我们就用两种方式去实现工资核算范围的单独授权。1 权限对象介绍1.1 结构化权限设置AUTSW ORGPD HR: Structural Authorization Check - 3393671.2 0001信息类型设置AUTSW ORGIN HR: Master Data - If this parameter is set to 1, P_ORGIN authorization object will be checked.1.3 0001信息类型设置AUTSW ORGXX HR: Master Data - Extended Check. If this parameter is set to 1, P_ORGXX authorization object will be checked.上面两个都控制信息类型0001的字段只是控制不同的字段而已。1.4 自定义权限对象启用AUTSW NNNNN HR: Customer-Specific Authorization Check. If this parameter is set to 1, customer authorization object will be checked. In order to know the name of this authorization object (it should be in the customer namespace), just check the coding of include MPPAUTZZ. There, under the authorization-check statement you will have the name of that authorization object. Customer authorization object must contain fields INFTY Infotype and SUBTY Subtype. It is possible also to use any of the fields from infotype 0001 organizational Assignment or in PA0001 structure, and customer-specific additional fields as long as they are NUMC or CHAR type fields. In addition field TCD Transaction Code and INFSU Infotype/subtype (4 characters for the infotypes and 4 for the subtype) can be used. These are the only fields allowed for the customer authorization object. In case different field is used, issues could arise. In order to generate the coding, report RPUACG00 should be run for this custom authorization object.1.5 单独授权账户AUTSW PERNR HR: Master Data - Personnel Number Check - If this parameter is set to 1, authorization object P_PERNR will be checked. Check that users do not have the object P_PERNR set with the SIGN *. This might lead to an undefined state. The only possible values here must either be E or I.典型使用场景由于每个企业员工数量可能成百上千手动为每个用户维护一个员工编号列表几乎不可行。因此P_PERNR通常只用于特殊、小范围的场景高管或特殊人员的数据隔离仅允许极少数特定用户如CEO秘书、薪酬总监访问某些高层员工的编号其他所有人都不能访问。系统用户 / 超级用户为某些后台作业用户如ALEREMOTE、SAPSYS赋予特定员工编号的读取权限用于批量数据处理。临时例外授权当一名HR需要临时处理某个非其管理范围内的员工数据如跨部门借调、紧急事务但不想调整其复杂的组织权限时可用P_PERNR直接授权该员工编号。1.6 AUTSW DFCON HR: Default Position (Context). Same possible values as AUTSW ORGPD结构化权限混合使用。例如设置3标准检查0001信息类型的组织ID是否是设置的结构化权限内数据.1.7 AUTSW INCON HR: Master Data (Context) - If this parameter is set to 1, context authorization object P_ORGINCON will be checked.1.8 AUTSW XXCON HR: Master Data - Enhanced Check (Context) - If this parameter is set to 1, context authorization object P_ORGXXCON will be checked.1.9 AUTSW NNCON HR: Customer-Specific Authorization Check (Context) - If this parameter is set to 1, context customer authorization object will be checked. Customer context authorization object must contain fields INFTY Infotype, SUBTY Subtype, AUTHC Authorization Level and PROFL Authorization Profile. It is possible also to use any of the fields from infotype 0001 organizational Assignment or in PA0001structure, and customer-specific additional fields as long as they are NUMC or CHAR type fields. In addition field TCD Transaction Code and INFSU Infotype/subtype (4 characters for the infotypes and 4 for the subtype) can be used.1.10 系统权限容差AUTSW ADAYS HR: Tolerance Time for Authorization Check. This setting has by default value 15.跨单位调动2 工资核算范围实例2.1 su21创建自定义权限对象自定义权限对象Z:ORGIN其中权限字段可以参考p_orgin权限对象新增abkrs的字段是控制核算范围因为标准的权限对象是没办法通过工资核算范围来控制人群。2.2 生成自定义权限对象上步骤只是创建自定义的权限对象但是标准程序并不会读取自定义的权限对象要想系统读自定义的权限对象需要用标准报表RPUACG00重新生成MPPAUTZZ的结构。2.3 自定义权限启用生成后的结构系统还是不会默认读取我们还需要在T77S0中配置几个参数AUTSW NNNNN要设置成1系统才会去读取MPPAUTZZ生成的结构。2.4 PFCG配置限制的工资核算范围字段
锦
锦皓数字建站
深耕本土企业品牌数字化升级,专注原创端正雅致商务官网,从视觉设计到稳定运维全程保驾护航。