2087311 - Proxy Management - BizX Platform

SAP Knowledge Base Article - Public

2087311 - Proxy Management - BizX Platform

Symptom

In this article you will find a description of the options available on Admin Tools > Manage Employees > Proxy Management page:

  • Assign Proxy Rights;
  • Look up Existing Proxy Assignments;
  • Change Proxy Settings for the Company (enable/disable proxy lookup);
  • Importing Proxy Settings;
  • Using the Proxy Now feature.

Environment

SAP SuccessFactors BizX Platform

Resolution

The following actions can be performed from the Proxy Management screen under Admin Tools:

  • Assign Proxy Rights;
  • Look up Existing Proxy Assignments;
  • Change Proxy Settings for the Company (enable/disable proxy lookup);
  • Delete Proxy;
  • Always enable proxy lookup.
      

Disabling Proxy

If you do not want the Proxy button to show for users via "Options > Proxy" ,then you can disable it on Admin Tools > Manage Employees (or "System Properties" in old Admin Tools) > Disable Proxy access for users without Proxy rights.

Assigning Proxies Via Import File

You now have the option to use a Proxy Import File to quickly assign one person as the Proxy for multiple Account Holders.
For example, you might want to assign "Joe Admin" as the designated Proxy for all users in the Boston Office. Previously, you would have to manually link "Joe Admin" to each employee in the Boston Office individually, but now, you can do it all at once using the Proxy Import File. To use this feature, go to Admin Tools > Manage Employees (or via "Manage Security" in old Admin Tools) > Proxy Import > Download the Proxy Import File template > Add your Proxy assignments >Then upload the file back into SuccessFactors.

To assign proxy rights

For a particular user via Admin Tools follow the steps below:

  1. Go to "Admin Tools";
  2. Under Manage Employees, click "Proxy Management";
  3. In the Make Assignment section, enter the USERNAME of the person who will act as proxy in the first box (use the "Find User" feature if necessary);
  4. Put the USERNAME of the person the proxy will act on behalf of in the second box (use the "Find User" feature if necessary);
    NOTE: If you want the proxy to be able to access Private Goals, check the "Grant Access to Private Goals" checkbox.
  5. Click save.

Proxy rights can be set-up either by the Administrator or at the employee level (if permissions are set-up to allow this).

Proxy Now

Once Proxy has been assigned, below are the steps the user will need to take in order to act as Proxy for another user:

Note: Admins will now potentially see 2 new links at the top of the page by their name: Proxy Now, which lets the Admin act as a Proxy, and Become Self, which only displays when the Admin is acting as a Proxy to let them return to their own account.

  1. Admin user can click "Proxy Now" and search for the user whose account they want to access;
  2. The page will list everyone the Admin is eligible to manage even if they haven't manually been assigned to each person.
    Note: Previously, the list only showed the users that the Admin were explicitly assigned to.
  3. Select the name and click OK and the system takes the Admin to the user's account;
  4. When the Admin is finished and wants to access another user's account, the Admin can click Proxy Now again and select a different name. This way, the Admin can move from account to account without having to go back to their own account each time.
  5. When the Admin is ready to return to their own account, they can click the Become Self link.

Additionally, Admins can also see the Proxy Now link on people's Quick Card profiles. Clicking the link will give them access to the account.

To use these new options, go to Admin Tools > Manage Security > Proxy Management and select the Enable Advanced Proxy Management (Proxy Now and Proxy Import) checkbox. Please note that each Admin must also be granted Proxy Management permission.

Who Will Show in My Find Users Results?

Selecting the Become Proxy link should open up a small dialog box equivalent to "Find User" capabilities. The find user scope of searchable accounts should be restricted to:

  1. If the system detects that you have implicit proxy rights for a population of users in the system, you are no longer required to explicitly grant yourself proxy access to a target. There are three implied proxy rights scenarios:
  • User has Proxy Management permission in Admin Tools (for RBP enabled instances);

 

  1. In each of these scenarios, a user may grant themselves access as “Proxy” for all users in the system by virtue of having been granted with any of the three permissions listed above.  The new Proxy Now feature allows users with Proxy Management permission access to quickly proxy in as any user in his/her target population without first requiring an explicit proxy assignment.  
     
  2. The rationale is because the user already has implicit proxy permissions by virtue of having access to Proxy Management and can easily assign themselves as proxy for any user in the system.

   4.  Proxies who do not have Proxy Management permission access, will also see the “Proxy Now” link in every screen.  These proxies may only access target accounts for users for    whom they have been explicitly granted permission.

Controlling What Modules you can Access When Proxied

The following solution shows which features and tabs of the Account Holder's account you can allow the Proxy to access. Which features and tabs of the Account Holder's account you can allow the Proxy to access. Please refer to:


Proxy Import File

Proxy Import: You can schedule Proxy Imports to upload data at regularly scheduled increments to help you keep your Proxy data current. To do so, please engage your Implementation Partner or contact Cloud Product Support to get this job configured on Provisioning (PMT-4225).

You can generate the most current version of the import template from Admin Center > Proxy Import > Download a blank CSV template:

  • Enter YES for ALL coulmns you want to grant access to for each person/row; 
  • If you are granting access to all modules, then you only need to put YES in the ALL column;
  • If you are granting access per module, just enter YES in the columns required.

If your file fails to grant permissions, then you possibly have a conflict in your logic for where you entered YES & NO in the file.

Example (Always use csv format):

  • userID = the proxy target (only supports one user);
    Note: Column A/userID =  the 'Target User', you [or the logged in user] will proxy for & Column B/proxyID =  The user who will click on the 'Proxy Now' button [the logged in user, who will act as proxy].
  • proxyID = the proxy userID (supports multiple proxies delimited by the “|” character);
  • the rest of the columns represent available options for your SuccessFactors application;

Multiple proxies (not proxy targets) are supported in a single row.  Use “ | “ (pipe character) as the delimiter.  Multiple proxy targets are not supported in phase I and will be considered as a future enhancement.

Flag proxy access to specific areas of the application under the appropriate column with “YES”.  An explicit “NO” is not required nor accepted (it will generate an error).  Always leave the field blank to indicate “NO”.

NOTE: There are several selections that are required together (for example, Total Goal Management requires Private Goals and CDP).  This logic is automatically enforced in the Admin Tool UI.  The import file ALSO SUPPORTS THIS ENFORCEMENT logic.  For example, if the import file has “YES” under Total Goal Management, the system will automatically add the selections of the other required components (e.g. Private Goals and CDP).

Template Logic (when in doubt, we always take the more restrictive interpretation).


EMAIL NOTIFCATIONS

A summary email is sent to the administrator that initiated the import with details on the import job.  Due to performance considerations, in the event that there are too many errors found, only the first several hundred errors are listed.

A summary email containing error details will be sent to the administrator that initiated the import job.  The most common error will likely be due to ambiguous intent.  The table above shows scenarios where clear intent cannot be established.  For example, a scenario where both “ALL” and a specific module such as “360” is selected.  Which is the real intention (“ALL” modules or just “360”)?  In such cases, we will always evaluate to the more restrictive of the options (in this example, only “360” will be assigned).

FAQ

Q1: Does the User Directory import file Proxy import still work?

A1: Yes it does. The behavior remains the same. The proxy will have full suite access for the target user.

Q2: Do we charge for this feature?

A2: No, this is a free enhancement.

Q3: Is there a way to export the current proxy assignments to an import-ready format?

A3: No, this is on the roadmap for a future release.

Deleting A Proxy

You need to delete a proxy assignment for a specific user. Possibly a user has moved positions and should no longer have access to a specific user, or maybe the user is no longer an administrator.

  1. A user has moved positions and should no longer have access to a specific user.
  2. A user is no longer an administrator and needs proxy rights.
  3. The proxy assignment was only temporary and now needs to be removed.

Steps:

An administrator assigned the required permissions, can delete an assigned proxy by following these steps:

  1. Access Proxy Management under admin tools;
  2. Under Look up Existing Assignments, populate user information for the person who is the proxy for an account holder or for the account holder(s) assigned to the proxy;
  3. Click Search;
  4. When the results are returned, a delete button will become available for the proxy assignment.

Keywords

proxy assignment , KBA , sf proxy management , LOD-SF-PLT , Foundational Capabilities & Tools , LOD-SF-PLT-PRX , Proxy , How To

Product

SAP SuccessFactors HCM Core all versions