SAP Solution Manager 7.2 · Managing Security
How is Fiori security structured, and what's special about the SAP_SMWORK* roles?
A Fiori catalog (apps + tiles) + a Fiori group (adds the catalog to the launchpad) — both need authorization, plus the SAP Gateway (OData) service.
Key roles: SAP_SM_FIORI_LP_EMBEDDED (base launchpad access, in most composite roles), SAP_SMWORK* (see an area's Fiori tiles). The SAP_SMWORK* are navigation roles, not app access — don't change the authorization objects they open (those optional objects are intentional). From 7.2 they can be copied into Z roles.
This is one card from the KnowCard library. The full way to learn it — spaced-repetition review, progress tracking, and AI explanations — lives in the KnowCard app. We’re in private beta now; iOS & Android are coming soon.
Join the private beta