Manage roles
Assign roles, inspect existing assignments and use the Global Role Table to find where a role is used.
Applies to userXpress 1.9.5.50
On this page
Role assignments grant access. Check the selected accounts, role names, clients and validity dates before confirming a change.
Inspect current assignments
Select the users in the Global User Table and choose Role Assignment. Wait for the application to retrieve their assignments. This opens a report; it does not assign new roles. Use Export To to save the report in an offered format, and protect the exported authorization information.

Expand an account to inspect its role assignments and validity dates.
Assign roles from the Global Role Table
- Select the target users in the Global User Table. Filtering alone does not select them.
- Filter the Global Role Table and select the roles to assign. Check the system and client for each role.
- Choose Assign, or drag the selected roles onto the Global User Table.
- In Assign Roles, check the target user list and Roles to be assigned, then set the validity dates.
- Leave the overwrite option clear if existing assignments must be retained. Enabling it replaces existing role assignments with the new set; this can remove access and may be disabled by your installation’s feature configuration.
- Choose OK and inspect Results for each user and client.
Add and remove assignments together
- Select the target users and open Update Role Assignment.
- Add the required role rows. Choose the add/remove action and system/client scope for each row. Common roles can apply to all selected clients; client-specific rows apply only to their indicated target.
- Use Paste Roles or Ctrl+V to bring in a clipboard list, then check every pasted row and its scope.
- Use Clear Selected to remove selected rows from this proposed change, or Clear Table to empty it. These buttons edit the proposal, not the users’ existing SAP assignments.
- Review Change all on first row change before editing: when enabled, changing the first row’s action can change the other rows too.
- Choose Change Roles and inspect Results. Do not assume an addition succeeded merely because a removal did.
For example, a change can add a common demo role to the selected users in all clients, add another role only in one client, and remove a third role. Check each row rather than applying an all-client scope by default.

Review add/remove actions and validity dates in Update Role Assignment.
Remove expired assignments
Removing an assignment is different from deleting its role definition. Check your organization’s retention and access-review process before removing assignments.
- Open Expired Roles from the Global User Table. The window is titled Expiring Roles.
- In Select Systems, select the clients to examine. Do not assume the previous user selection limits this client-wide search.
- Choose All expired Roles, or All Roles with an expiry date if you also need to review future expiries. Inspect the returned dates yourself before selecting assignments for removal.
- Choose Get Roles and inspect the returned user, role, system/client and expiry details.
- Select only the assignment rows to remove, then choose Remove Roles.
- Review the row results and Messages. Resolve failures before repeating the operation.
Date-filter limitation: Due to expire by does not reliably filter assignments by the selected date in this version. Use the other criteria and inspect the returned dates before removing assignments. Contact Support if you need help identifying assignments due before a particular date.

Select assignment rows deliberately and inspect any row messages before removing roles.
Copy role assignments
Select the source account, right-click and use Copy Roles. Then select the destination users and choose the corresponding Paste Roles action. In Paste Roles, review Roles to paste and Paste to the following users, and select only the roles you intend to assign before choosing OK.
Check Overwrite currently assigned roles carefully: it replaces the destination assignments instead of retaining the old set. Copy Roles From Source Client is a separate choice concerning the role definitions in the target client; do not enable it when you intend only to change user assignments. Inspect Results afterward.
Do not assume that identical role names across systems represent identical access. For copying the role definitions themselves, follow Copy roles between clients.
Use the Global Role Table
The Global Role Table lists roles from connected clients. Filter its columns to narrow the selection.
- Where Used identifies users assigned to the selected roles. Check the returned system/client rows, including clients with no matching users; export the report when needed.
- Assign applies the selected roles to the intended users in the Global User Table.
- PFCG, or double-clicking a role, opens that role in SAP GUI, subject to your installation and permissions.
- Export saves the current role view in an offered format for further analysis.
Before Assign, check both tables: the selected roles in the role table and the selected target users in the user table. Review client-specific results after the operation.
Check a failed assignment
Confirm that the role exists in the target client, that its validity dates are appropriate and that your SAP account is authorized to maintain assignments. Read the returned message before retrying. Repeating the whole selection can obscure which assignments already succeeded.