Skip to content

Tenant Permissions

Companion reads a tenant through the Cloud Integration OData API, with the service key you connect on the Connect Tenants page. It only reads. The shipped server makes no call that creates, changes or deletes anything on a tenant.

The authorization groups recommended on that page cover every tool. This page is for the case where the key should hold only what is used: it says which API each tool reads and which role that API needs. The roles come from SAP’s Tasks and Permissions for Cloud Integration and the permission sections of the OData API documentation.

Cloud Foundry role templates, as you enter them in the roles list of the Process Integration Runtime service instance with plan api. The Neo column gives the roles of the OAuth client in the Neo cockpit.

Role template (Cloud Foundry) Neo roles Grants
MonitoringDataRead IntegrationOperationServer.read, NodeManager.read Message processing logs, deployed artifacts, keystore entries and security material. Every installation needs this one: the connection test reads the message log API.
WorkspacePackagesRead WebToolingWorkspace.Read Integration packages and their design-time artifacts, including the download of an artifact’s files.
MessagePayloadsRead esbmessagestorage.read Attachments of message processing logs. Without it, logs are archived without their attachments.
AuthGroup_TenantPartnerDirectoryConfigurator AuthGroup.TenantPartnerDirectoryConfigurator Partner Directory. SAP offers no read-only role for the Partner Directory API; this role also allows writes, which Companion does not make.
AuthGroup_Administrator IntegrationOperationServer.read, AuditLog.Read System log files. For Cloud Foundry, SAP’s documentation names no single role template for the Log Files API; the administrator group is known to work. Leave it out if you do not use System Trace.
AccessAllAccessPoliciesArtifacts AccessPoliciesArtifacts.AccessAll Only if you use access policies to protect some artifacts. Without it, Companion cannot see the logs and attachments of protected flows.

The smallest set for every tool is MonitoringDataRead, WorkspacePackagesRead and MessagePayloadsRead, plus the Partner Directory group and AuthGroup_Administrator only when those two tools are used. The authorization groups on the Connect Tenants page contain all of these: AuthGroup_BusinessExpert holds the first three, and AuthGroup_ReadOnly and AuthGroup_IntegrationDeveloper hold the first two.

Tool Reads from the tenant Role
Message Logs (Log Extender) Message processing logs, runs and steps, error information; the list of deployed artifacts and packages for the catalogue MonitoringDataRead, WorkspacePackagesRead
Message Logs, attachments Attachment content MessagePayloadsRead
Artifacts (Artifact History) Packages, design-time artifacts and their files; deployed artifacts WorkspacePackagesRead, MonitoringDataRead
Flow Diff, Flow Image, Flow Dependency, Flow Schedules Nothing. They work on what the Artifacts sync has stored. As Artifacts
Deployment Status The Artifacts sync, plus the error text of a failed deployment, read live MonitoringDataRead
Credentials Where-used User credentials, OAuth2 client credentials, secure parameters and keystore entries, read live; references come from the Artifacts sync MonitoringDataRead
Certificate Expiry Keystore entries, read live MonitoringDataRead
Partner Directory Partners, string, binary and user credential parameters, alternative partners, authorized users, read live AuthGroup_TenantPartnerDirectoryConfigurator
System Trace The list of log files and the files themselves, read live AuthGroup_Administrator
Connection test One message processing log MonitoringDataRead

What a missing role looks like: the tenant answers 403, and the tool that needs it says so. The sync tools log the failed call and go on with the rest. Credentials Where-used says that the picture is incomplete when one of the four kinds of security material could not be read, instead of calling a credential unused.

Every call is an HTTP GET below /api/v1/ on the tenant, with the OAuth token from the service key. The only POST is the token request to the token URL of the key.

Entity Used for
MessageProcessingLogs, with Runs, RunSteps, Attachments, ErrorInformation; MessageProcessingLogAttachments(...)/$value Message Logs sync
IntegrationRuntimeArtifacts, and ErrorInformation/$value of one artifact Catalogue of deployed artifacts, Deployment Status
IntegrationPackages and the design-time artifact sets of a package: integration flows, value mappings, message mappings, script collections, data types, message types, fault message types, service interfaces; ...(Id=...,Version='active')/$value Artifacts sync
KeystoreEntries, UserCredentials, OAuth2ClientCredentials, SecureParameters Certificate Expiry, Credentials Where-used
Partners, StringParameters, BinaryParameters, AlternativePartners, AuthorizedUsers, UserCredentialParameters Partner Directory
LogFiles, and LogFiles(...)/$value System Trace

Companion never reads message payloads from the message store, data store entries, queues, or user roles, and never deploys, undeploys or changes an artifact.