Security Architect

Design and enforce row-level access controls and audit policies for SAP Datasphere.

25|7|Updated Feb 7, 2026
One-click install
npx skills add https://github.com/MarioDeFelipe/sap-datasphere-plugin-for-claude-cowork --skill security-architect-mariodefelipe
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: Security Architect
Source: https://github.com/MarioDeFelipe/sap-datasphere-plugin-for-claude-cowork/tree/main/skills/datasphere-security-architect
Command: npx skills add https://github.com/MarioDeFelipe/sap-datasphere-plugin-for-claude-cowork --skill security-architect-mariodefelipe

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Provides a structured, auditable approach to design and enforce row-level security, migrate BW/4HANA analysis authorizations, and configure audit policies so users only see permitted data and compliance requirements are met.

Core Features & Use Cases

  • Data Access Controls (DACs): Authoritative guidance to create operator, hierarchy, and combined DACs to enforce row-level filters across tables and views.
  • Authorization Migration (BW → Datasphere): Step-by-step mapping and batch conversion of BW analysis authorizations into Datasphere DAC definitions and user assignments.
  • Audit Policy & Logging: Templates and table schemas to capture detailed read/change logs, retention and partitioning strategies, and SIEM/export integration for SOX/GDPR/HIPAA.
  • Identity Provider Integration: SAML/OIDC attribute mapping checklists and configuration steps to ensure user attributes drive DAC behavior.
  • Use Case: Migrate a global sales team's BW authorizations to Datasphere, apply hierarchy-based filters for regional managers, and enable detailed audit trails for SOX compliance.

Quick Start

Generate Datasphere DAC definitions and an audit policy from my BW analysis authorization export and IdP attribute mapping.

Frequently Asked Questions about Security Architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I migrate BW analysis authorizations to SAP Datasphere Data Access Controls?▼

To migrate BW analysis authorizations to SAP Datasphere, you map existing rules into Data Access Controls using batch conversion steps, creating operator, hierarchy, and combined DACs to enforce row-level filters across tables and views.

How does row-level security work with SAML and OIDC identity provider attributes in Datasphere?▼

Row-level security in Datasphere uses SAML and OIDC identity provider attribute mapping to pass user attributes directly into Data Access Controls, ensuring dynamic row-filtering behavior based on the authenticated user's identity profile.

What is the best way to configure audit logging for SOX compliance in SAP Datasphere?▼

The best way to configure audit logging for SOX compliance in SAP Datasphere is to implement detailed read and change log tables with specific retention and partitioning strategies, enabling seamless export integration for SIEM platforms.

Can I use hierarchy-based Data Access Controls for regional managers in Datasphere?▼

Yes, you can create hierarchy-based Data Access Controls in Datasphere to apply row-level filters for regional managers, ensuring they only access permitted data based on their organizational hierarchy level.

Does SAP Datasphere support combined Data Access Controls for complex row-level filtering?▼

SAP Datasphere supports combined Data Access Controls to handle complex row-level filtering scenarios by merging multiple conditions, allowing you to enforce granular access policies across various tables and views simultaneously.

Why are my Datasphere Data Access Controls not filtering rows correctly after an IdP integration?▼

Datasphere Data Access Controls may fail to filter rows correctly if SAML or OIDC identity provider attributes are mismatched, requiring you to validate the attribute mapping checklist to ensure user attributes properly drive the DAC behavior.