FOUNDATION 02 · NAVIGATION & ACCESS

Fiori, SAP GUI, apps, roles—and why they differ

A user experience presents work; an authorization permits work. SAP Fiori launchpad, SAP GUI, business roles, catalogs, spaces, pages, services, and business authorizations participate at different layers.

FINDLaunch and navigate

Spaces, pages, search, app finder, tiles, links, menus, and favorites help a user locate work.

RUNStart the application

Catalog content, target mappings, services, and technical activation help resolve and launch an app.

ACTUse business data

Business authorizations constrain which activities and organizational values the user can access.

TWO USER-EXPERIENCE MODELS

The interface depends on product, role, and task

Do not teach a screen path without naming the relevant user experience and system context.

MODELPRIMARY IDEAPRACTICAL IMPLICATION
SAP Fiori launchpadRole-based entry point to apps, search, notifications, and insightsSpaces and pages organize selected apps; catalogs and roles influence available content. Responsive behavior and features vary by app.
SAP GUIClassic interface for ABAP transactionsTransaction codes provide direct entry to functions. Availability depends on product edition, deployment, role, and supported use case.
Other clientsMobile, office integration, portals, APIs, and specialized applicationsThe same business object may be consumed through several channels with different interaction and authorization layers.

FIORI CONTENT MODEL

A tile is not the authorization model

The exact technical setup differs by edition, but the conceptual separation remains essential.

UISpace and page

Organize selected apps for a work profile. They shape the launchpad layout but do not by themselves grant all business permissions.

CATBusiness catalog

Groups launchable applications and navigation targets for a business capability and participates in assigning access through roles.

APPTile, link, and target mapping

Present and resolve navigation to an application. Object pages may be reached from another app rather than from their own tile.

SRVService and application activation

The application and its data services must be available and correctly configured for the landscape.

AUTHBusiness authorization

Controls allowed activities and organizational values—for example display versus change, or access to particular company codes or plants.

ACCESS DIAGNOSIS

“I cannot use the app” describes several different failures

NOT VISIBLE

Check role assignment, launchpad content, space and page assignment, personalization, device support, and whether search or app finder exposes the app.

DOES NOT START

Check target resolution, activation, required services, system alias or destination, connectivity, and technical logs.

STARTS, THEN DENIES

Check business authorization objects or restrictions, activity values, organizational values, and the application’s authorization trace.

RUNS, BUT DATA IS MISSING

Check filters, default values, organizational restrictions, business status, analytical authorizations, draft ownership, and actual data availability.

ROLE DESIGN

Start from responsibility, not from app accumulation

A good role supports a coherent job while respecting least privilege and separation of duties.

BUSINESS ROLEWhat work belongs together?

Define tasks, decisions, approvals, exceptions, and information needs for a recognizable work profile.

ACCESS BOUNDARYWhere may it act?

Constrain activities and organizational scope; distinguish display, create, change, approve, post, reverse, and administer.

CONTROLWhat must remain separate?

Evaluate sensitive access and combinations such as creating a supplier and paying it, or entering and approving the same journal.

WORKED EXAMPLE

The purchaser sees “Manage Purchase Orders” but cannot change one order

The tile proves only that launchpad content is available. The app launching proves more of the technical path. The remaining question is business access and document state.

  1. Capture the user, app ID, document, intended activity, timestamp, and full error.
  2. Confirm whether the order is editable at all: status, workflow, lock, draft, source-system ownership, and document type matter.
  3. Compare organizational values such as purchasing organization, purchasing group, plant, and company code with the user’s restrictions.
  4. Use the supported authorization trace or error-log tools for that edition; do not broaden the role blindly.
  5. Retest the narrow change and review separation-of-duties impact before transport or production assignment.

USER HABITS THAT SCALE

Navigate by business object and evidence

Use context

Record system or tenant, client if applicable, role, app or transaction, object key, organizational scope, and time.

Preserve filters

Unexpected results often come from variants, defaults, date ranges, semantic dates, saved views, or personalization.

Follow links

Object pages, related apps, document flow, attachments, change history, and messages usually explain more than returning to the home page.

Authoritative reference pointsSAP Help — SAP Fiori Launchpad Content and Authorization ConceptSAP Help — Spaces and Pages

Role administration differs across SAP S/4HANA editions. Use the product-specific implementation guidance and security tools for the landscape in scope.