SAP GRC AC Email Notifications - Customization
Overview
In GRC Access control as part of Workflow approvals and reviews, access control users like Managers, Role Owners, FF ID Owners and Controllers, Function/Risk/Mitigation Approvers, Monitors, Users, Requestors etc. receive various Email notifications. Based on the customer sepcific requirements these Email notifications are enhanced and maintained. This blog is to discuss about various customizing options available for GRC notifications as well as notification variables and their limitations and scope :smile:
For beginners below document gives details on how to customize email notifications templates in GRC
AC 10.0 - How to Customize Notification Templates for AC Workflow
Email Notification Templates - HTML Tags
1. HREF (For Email ID and URLs)
Business Scenario:
Notification variables which gets converted to URLs in the notification emails will have a very big URL with Path ID, Stage ID etc. Basically when the URL is not maintained as HREF using HTML tags, in most of the cases Emails get routed to JUNK folder in mailbox because of various special characters in the URL. Hence it is suggested to use HREF tag and make these GRC URLs as links which will avoid routing to JUNK folder issue as well as avoids end users directly seeing all technical details of the URL. Below are some of the variables which gets converted to URLs in notification Emails.
LINK_APPROVE_REJECT Link to Approve/Reject by Email
LINK_GET_APPROVERS Link to get Approvers
LINK_GET_REQ_STATUS Link to get Request Status
Example: How the above variables look in notification emails with and without HTML tags
a. %LINK_APPROVE_REJECT%
b. Click <A HREF = %LINK_APPROVE_REJECT% > here </A> to approve/reject the request
2. To Include GRC Help-desk Email
Business Scenario:
When end users receive email notifications for GRC related requests then most of the times we observed that users will have queries with the Emails or about their GRC requests and wanted to contact concerned GRC Admin/Help-desk for clarifications. In order to make it easy for end users to contact HELP-DESK, we can include Email ID in notification emails.
Example: How to include Email link in notifications
Please contact GRC Admin at <A href="mailto:
Test@test.com"> GRC Helpdesk </A>
3. BOLD, UNDERLINE and ITALICIZE
Reason behind sharing details about BOLD, UNDERLINE and ITALICIZE tags is because these doesn't work with traditional HTML tags like <B> <U> and <I> in notification templates.
Example: <strong> <span style="text-decoration: underline;"> Quick Reference for approvers: </span> </strong>
Example:
<span style="font-style: italic;">
Select the approval status as "REJECT" beside the role that you wish to reject.
</span>
How to insert Company Logo in Email Notification Templates
First you need to store the Logo which you want to use in Email notifications in GRC MIME repository
Go to SE80 Tcode and click on MIME REPOSITORY. Import the Logo which you wanted to use into MIME objects repository as shown below:
Once the above activities are completed, the next step is to use the LOGO in Email notification Templates.
Note: URL for logo is no transportable and need to be individually changed in each system when notification template is transported.
Use the image source tag as shown below:
<img src = "
http://my_server.my_domain/sap/public/bc/ur/MyLogo.png">
For image source URL, you can follow below approach:
Go to Tcode SICF and select service name as "UR"
When you click on "Test Service" a URL popup will be shown. You can just use that URL and append it with your image details:
Example: <img src = "
http://hostname:portnumber/sap/public/bc/ur/MyLogo.png">
How to create New Message Class for Notification Templates
How to create new Message Class for any workflow in GRC ?
Very common requirement is customers request to have specific Email notifications at each stage individually and for such scenarios it might require creation of Custom message classes to be used at various stages in workflow and you can follow below process for creating new message classes :smile:
Example: For EAM Log Review Workflow there are no FORWARD and RETURN Message Class available.
Execute Tcode SM30
Open table GRFNVNOTIFYMSG and click on Maintain button and then click on "NEW ENTRIES" and maintain as below and once done click on SAVE button
Execute Tcode SM30
Open table GRFNVNOTIFYMSGC and click on Maintain button and then click on "NEW ENTRIES" and maintain as below and once done click on SAVE button
Once the above mentioned activities are completed, now the newly created Message Class can be added to your MSMP Variables & Templates Notification Templates section as shown below
How to trigger different email notifications for same Message class?
It is very common requirement where end users expect each email notification for the Access Requests to be customized according to the request instead of having a generic notification template for all requests.
This requirement can be achieved easily using "Message Number" and Custom Template ID. Details are as shown below:
Email Template with Message Number: 000
Email Template with Message Number: 001
MSMP Configuration for the above created email templates. You can use the corresponding template IDs in the stage notification settings
Notification Variables in GRC
Each workflow process provides as set of notification variables that can be used in the notification templates. They are displayed on the bottom of the screen in step 4, ”Variables & Templates”, in the customizing activity Maintain MSMP Workflows.
Few queries regarding Notification Variables customization especially %PROVISIONING% and %PROVISIONING_WITHOUT_PASSWORD%
For ARQ provisioning there are 2 variables which are sent along with END OF REQUEST notification( with Roles and Password details) PROVISIONING and PROVISIONING_WITHOUT_PASSWORD
These variables are standard variables which are calculated run-time and these can be customized by creating your own notification variables function module and adding our own logic but again that require development :smile:
2012041 - Is it possible to suppress the role details in the variable %PROVISIONING%
1854408 - Potential information disclosure relating to user password
How to create custom notification variables in GRC
Copy standard function module "GRAC_NOTIF_VAR_RULE_AR" and create a new custom function module (
e.g. ZGRAC_NOTIF_VAR_RULE_AR)
Add the logic for custom variable in your custom function module and then activate the function module
Example:
Open the MSMP configuration using expert mode transaction "GRFNMW_CONFIGURE" and add custom variables under the process ID "SAP_GRAC_AR". You may get a prompt warning to use customer name space. Just press ENTER button then the change gets saved into transport request.
Open the MSMP configuration using transaction "GRFNMW_CONFIGURE_WD" and goto Step 2. Maintain Rules. Add this newly created 'Z' function module as a Notification Variables Rule. Also maintain this Z Function Module in the Notification Rule under Global Rules in Step 2.
Add the new custom notification variable (e.g. ZXXXX) in step 4 of MSMP workflow configuration
Save and Activate the MSMP workflow configuration.
Once the above steps are completed, you need to write logic for the custom variable in ZGRAC_NOTIF_VAR_RULE_AR:
E.g. If the custom variable you need to include is part of Request Header, then your logic should be as below:
* -----------------------------------------------------------------------------------------------------------------------------
WHEN 'ZXXXX'.
* -----------------------------------------------------------------------------------------------------------------------------
ls_varsout-variable_value = <ls_reqheader>-<Your Custom FieldName>.
APPEND ls_varsout TO lt_varsout.
Finally include the custom variable "ZXXXX" in SE61 email notification template
How to modify URL shown in GRC notification variables to enable SSO
First setup Single Sing On (SSO) between Enterprise Portal and GRC system.
Once done, create a Portal iView in Content Administration -> Portal Content Management using standard GRC Access Control iView Template.
In the template, Application Name, Configuration Name, System, Location etc fields are maintained and once the template is maintained then PERMISSIONS need to be maintained for iView.
Once the above steps for creation of portal iview are completed, modify the URL used in the notification variables by creating a Custom Notification Variable Function module and replace the URL with Portal iView which you can work with ABAPer and Portal guys to get the details.
Once all above steps are done even the approvers can access all Approval Links in Email notifications via SSO without entering UserID and Password :smile:
Note: Deactivate password for all users in GRC System including approvers UserIDs :smile:
How to add custom message on End User Login screen in GRC?
You can follow the instructions mentioned in SAP Note: 1604983 - Add a custom message on the End user Login Screen
Thanks for reading.
Best Regards,
Madhu Babu Sai