How to Use
This guide covers day-to-day operational tasks in IWA across User Management, Role Management, Group Management, and Provisioning.
User Management
Create a User
Add User (Detailed)
- Navigate to User Management.
- Click Add User.
- Fill in all required fields: User ID, First Name, Last Name, Email ID, User Type, and any additional profile details.
- Click Save (Draft) or Submit (Activate immediately).
Quick Add User (Bulk)
- Click Quick Add User.
- Enter the minimal required details: User ID, First Name, Last Name, Name, Email ID, and User Type.
- Add multiple rows for bulk creation, then submit.
Import Users
- Download the pre-defined import template (CSV or XLS).
- Populate the template with user data.
- Click Import Users and upload the completed file.
Add User from External Source
- Click Add User from Source.
- Select the source: SAP BTP CIS, SAP BTP Account, or Azure Active Directory.
- Search for and select the users to onboard.
- Confirm the import.
Activate or Deactivate a User
- Locate the user in the User Management table.
- Open the Actions menu for that user.
- Select:
- Activate — to activate a user in Draft status.
- Deactivate — to revoke access from an Active user while retaining their data.
Lock or Unlock a User
- Locate the user in the User Management table.
- Open the Actions menu.
- Select:
- Lock User — to prevent system access immediately.
- Unlock User — to restore system access once the issue is resolved.
Assign a Role to a User
- Open the Actions menu for the target user and select View Details or Edit.
- Navigate to the Roles section in the User Details view.
- Click Add Role.
- Select the Application and then the Role from the dropdowns.
- Save the changes.
Set Up a Substitution
- Open the Actions menu for the user who will be absent.
- Select Substitute.
- Choose the substitute user and define the substitution period.
- Optionally configure a Vacation period to trigger substitution automatically.
- Save the substitution.
Manage Data-Level Access for a User
- Open the user's details via the Actions menu.
- Navigate to Data Level Access & Roles.
- Click Add or Edit on the desired rule.
- Configure role-based or user-specific data restrictions.
- Save the configuration.
View User Logs
- Provision Log — navigate to the user's detail view and open the Provision Log tab to see all role assignment/removal history.
- Audit Log — open the Audit Log tab to see all profile updates, role changes, and login history.
- Activity Log — view operational activity performed by and on the user.
Role Management
Create a Role
- Navigate to Role Management and click Create Role.
- Fill in the mandatory fields: Application Name, Role Name, Role Description, Role Type, Role Segment, and Role Category.
- Configure module and feature access by toggling individual modules/features on or off.
- Optionally configure:
- Data-Level Access (Disabled / Simple / Advanced).
- Source Group mapping.
- Role Collection mapping.
- User Reconfirmation settings.
- Click Save (Draft) or Submit (Active).
Create a Role with Reference
- On the Role Summary screen, open the Actions menu on an existing role.
- Select Create Role With Reference.
- Review the pre-filled configuration (role segment, type, category, modules, features, DLA settings).
- Modify any fields as needed.
- Click Save or Submit.
Sync a Role
- On the Role Summary screen, open the Actions menu for the target role.
- Select Sync Role to manually trigger synchronization with the mapped source groups.
Assign Users to a Role
- Open a role in edit mode.
- Scroll to the Associated Users section.
- Click Add User and select the users to assign.
- Save the role.
Group Management
Create a Group
- Navigate to Group Management and click Add Group.
- Fill in: Group Name, Group Description, Associated Application, and Associated Role(s).
- Click Save (Draft) or Submit (Active).
Add Members to a Group
- Open the group via View Details or Edit from the Actions menu.
- In the Group Members section, click Add Users.
- Search for and select users to add.
- Optionally configure Data-Level Access for each new member.
- Save the changes.
Deactivate or Delete a Group
- Deactivate: Open Actions → De-Activate. The group remains visible but cannot be assigned.
- Delete: Open Actions → Delete (only available for Draft groups or groups with no dependencies).
Provisioning
Provision a Role to a User
- Navigate to Provision and click on the target application.
- Select Manage Role → Provision Role.
- Select the User and then choose the Role from the dropdown.
- If the role has mapped groups, they are displayed automatically.
- Click Preview to review all details.
- Click Submit to complete provisioning.
Bulk Provisioning
- Use Add User to assign the same role to multiple users at once.
- Use Bulk Request to upload an Excel file for mass provisioning.
Revoke a Role from a User
- Navigate to Provision and select the application.
- Select Manage Role → Revoke Role.
- Select the User and the Role to revoke.
- Review data-level access details if prompted.
- Click Submit to revoke the role immediately.
Filter and Search Provisioned Users
In the application's Users section:
- Use the Filters panel to filter by Provisioned Status, Provisioned By, Provisioned On, or Roles.
- Click Apply Filters to refresh the list.
- Click Reset to clear all filters and reload the full list.
View Provision Logs
- Navigate to the application dashboard and select the Roles section.
- Click on a role, then open the Provision Log tab.
- Review entries showing Request No, Associated Users, Initiated By, Initiated On, Provision Type, Provision By, and Request Status.