Help Center / Simulation / Role Simulation

Role Simulation

Test changes to role design itself, independent of who currently holds the role.

Steps

  1. In Analysis, select roles analysis mode
  2. Open the Simulation panel
  3. Build your scenario in the tabs below
  4. Click Run analysis

Simulation Tabs

In roles analysis mode:

TabWhat it simulates
AuthorizationsAdd or remove individual authorizations inside a role
Composite RolesAdd or remove single roles inside a composite
New RolesRoles that do not exist yet, built from scratch

Two more tabs appear when IAM analysis is enabled: Business Role composition and Craft Business Roles. See Business Role Simulation.

Simulating an Authorization Change

Authorization changes are expressed at the same level the analysis works at, so a change can be as narrow as a single field value.

FieldMeaning
Simulation typeAdd or Remove
AuthorizationThe authorization the change belongs to
Permission ObjectThe authorization object, for example F_BKPF_BUK
Permission FieldThe field within the object, for example ACTVT
Value from / Value toThe value or value range
Target rolesThe roles the change applies to

To remove, the permission object is enough. To add, the authorization, object, field and a starting value are all required, because a partial definition cannot be evaluated.

This is what makes it possible to test narrowing an authorization rather than deleting access outright. Restricting ACTVT to display values often resolves a conflict while leaving the user able to do their job, and simulating it first shows whether that is true before anyone touches a role.

Roles Mode or Users Mode

Roles mode answers whether a conflict is built into the role. Users mode answers whether a person has one right now. A conflict visible in roles mode will keep reappearing through provisioning until the role itself is corrected, so fixing role design is usually the more durable change. See Scoping Your Analysis.

Updated on: 2026-08-01

« Back to Simulation