Tenant Permissions
Companion reads a tenant through the Cloud Integration OData API, with the service key you connect on the Connect Tenants page. It only reads. The shipped server makes no call that creates, changes or deletes anything on a tenant.
The authorization groups recommended on that page cover every tool. This page is for the case where the key should hold only what is used: it says which API each tool reads and which role that API needs. The roles come from SAP’s Tasks and Permissions for Cloud Integration and the permission sections of the OData API documentation.
The roles
Section titled “The roles”Cloud Foundry role templates, as you enter them in the roles list of the Process Integration Runtime service instance with plan api. The Neo column gives the roles of the OAuth client in the Neo cockpit.
| Role template (Cloud Foundry) | Neo roles | Grants |
|---|---|---|
MonitoringDataRead |
IntegrationOperationServer.read, NodeManager.read |
Message processing logs, deployed artifacts, keystore entries and security material. Every installation needs this one: the connection test reads the message log API. |
WorkspacePackagesRead |
WebToolingWorkspace.Read |
Integration packages and their design-time artifacts, including the download of an artifact’s files. |
MessagePayloadsRead |
esbmessagestorage.read |
Attachments of message processing logs. Without it, logs are archived without their attachments. |
AuthGroup_TenantPartnerDirectoryConfigurator |
AuthGroup.TenantPartnerDirectoryConfigurator |
Partner Directory. SAP offers no read-only role for the Partner Directory API; this role also allows writes, which Companion does not make. |
AuthGroup_Administrator |
IntegrationOperationServer.read, AuditLog.Read |
System log files. For Cloud Foundry, SAP’s documentation names no single role template for the Log Files API; the administrator group is known to work. Leave it out if you do not use System Trace. |
AccessAllAccessPoliciesArtifacts |
AccessPoliciesArtifacts.AccessAll |
Only if you use access policies to protect some artifacts. Without it, Companion cannot see the logs and attachments of protected flows. |
The smallest set for every tool is MonitoringDataRead, WorkspacePackagesRead and MessagePayloadsRead, plus the Partner Directory group and AuthGroup_Administrator only when those two tools are used. The authorization groups on the Connect Tenants page contain all of these: AuthGroup_BusinessExpert holds the first three, and AuthGroup_ReadOnly and AuthGroup_IntegrationDeveloper hold the first two.
Which tool needs what
Section titled “Which tool needs what”| Tool | Reads from the tenant | Role |
|---|---|---|
| Message Logs (Log Extender) | Message processing logs, runs and steps, error information; the list of deployed artifacts and packages for the catalogue | MonitoringDataRead, WorkspacePackagesRead |
| Message Logs, attachments | Attachment content | MessagePayloadsRead |
| Artifacts (Artifact History) | Packages, design-time artifacts and their files; deployed artifacts | WorkspacePackagesRead, MonitoringDataRead |
| Flow Diff, Flow Image, Flow Dependency, Flow Schedules | Nothing. They work on what the Artifacts sync has stored. | As Artifacts |
| Deployment Status | The Artifacts sync, plus the error text of a failed deployment, read live | MonitoringDataRead |
| Credentials Where-used | User credentials, OAuth2 client credentials, secure parameters and keystore entries, read live; references come from the Artifacts sync | MonitoringDataRead |
| Certificate Expiry | Keystore entries, read live | MonitoringDataRead |
| Partner Directory | Partners, string, binary and user credential parameters, alternative partners, authorized users, read live | AuthGroup_TenantPartnerDirectoryConfigurator |
| System Trace | The list of log files and the files themselves, read live | AuthGroup_Administrator |
| Connection test | One message processing log | MonitoringDataRead |
What a missing role looks like: the tenant answers 403, and the tool that needs it says so. The sync tools log the failed call and go on with the rest. Credentials Where-used says that the picture is incomplete when one of the four kinds of security material could not be read, instead of calling a credential unused.
The API calls, for your security review
Section titled “The API calls, for your security review”Every call is an HTTP GET below /api/v1/ on the tenant, with the OAuth token from the service key. The only POST is the token request to the token URL of the key.
| Entity | Used for |
|---|---|
MessageProcessingLogs, with Runs, RunSteps, Attachments, ErrorInformation; MessageProcessingLogAttachments(...)/$value |
Message Logs sync |
IntegrationRuntimeArtifacts, and ErrorInformation/$value of one artifact |
Catalogue of deployed artifacts, Deployment Status |
IntegrationPackages and the design-time artifact sets of a package: integration flows, value mappings, message mappings, script collections, data types, message types, fault message types, service interfaces; ...(Id=...,Version='active')/$value |
Artifacts sync |
KeystoreEntries, UserCredentials, OAuth2ClientCredentials, SecureParameters |
Certificate Expiry, Credentials Where-used |
Partners, StringParameters, BinaryParameters, AlternativePartners, AuthorizedUsers, UserCredentialParameters |
Partner Directory |
LogFiles, and LogFiles(...)/$value |
System Trace |
Companion never reads message payloads from the message store, data store entries, queues, or user roles, and never deploys, undeploys or changes an artifact.