웨비나:
SuccessFactors 데이터의 편리하고 안전한 복사 및 마스킹
Good morning, everyone, and welcome to the fifth and final episode of our webinar series. Today with us, we have, Paul Hammersley, Senior Vice President for the ALM Product Portfolio at EPI-USE Labs. In today's session, we'll do a brief recap of what we've learned so far during this series and then Paul will take over and dive into hybrid copying and masking with SuccessFactors data. He'll do a brief demo of the product and we'll have a Q and A session at the end for all your questions. By now, people who have been attending the previous webinars might be familiar with this HCM business journey that we have been analyzing through the series. In Episode one, we have seen the importance of good quality data before, during, and after implementation with things like comparing legacy HR and payroll data, checking for replication errors, and testing non production with real data. Then in episode two, we analyzed the meaning of compliance for HR data and how the HCM productivity suite helps you with this challenge. In episode three, we looked at real time reporting in automation and support backtesting with Query Manager and Document Builder, which are part of our suite. Then in episode four, we spoke about how to adapt to business and technological changes that are inevitably present in our business journey, such as mergers and acquisitions, decouple HR from ECC, and then the technological changes like upgrade to S4HANA and move payroll to ECP. In today's session, we will focus on Object Sync for HCM, which is part of our HCM productivity suites, and how the integration for SuccessFactors works, allowing us to do hybrid copying and masking of data. Before I hand over to my colleague, I would like to remind you that the lines will be muted for the whole duration of the webinar. And if you have any questions at any time, please feel free to enter them in the control panel question box and we will answer at the end of this session. So without further ado, I will hand over to you, Paul. Thank you all and enjoy. Thank you very much, Maria, and thank you to everybody who's joined us today. It's good to have you here. So Object Sync HCM is a part of the Data Sync Manager Suite. So it covers test data management across your entire SAP needs, and it's always been particularly useful for the HCM teams because the data changes so frequently on the HR side. So every week, every month, there's changes happening to the data, people joining, people leaving, people being paid, and so on. Whereas in some of the other modules, the data is more static. It just doesn't change as frequently. So for over twenty years, Object Sync has been providing this capability for organizations to be able to just go get what they need when they need it. So that's why I tend to refer to it as the data on demand solution. The business benefits for this are mainly four areas, I would say. So the first one is for production support issues. Something's not working in production. We need to very accurately recreate the problem, And it may be complex data that is part of the problem so that we can then test it in a system where we can perhaps make changes or debug, find the solution, and then perhaps even copy the data down again in order to test that solution. So when we say yes, we've definitely fixed that issue, it's going through to production, we can be pretty sure that we really have, fixed that issue, that it will be resolved. Then secondly, for people who are working in development systems, it gives you the ability to test any changes that you've made in those systems. So you can bring real examples of data down. Personal data obviously being scrambled, so there's nothing, sensitive visible in development systems. But you can then test your change potentially even before you release the transport. So it can mean a reduction in transports leaving your development system because people are properly unit testing in those systems. And thirdly, for training environments, being able to take a particular record or even make a record and then use object sync to actually clone that record to make multiple copies of it. So everybody who attends the training has their own version of the data, and they can go through the same training scripts, and they should have the same outcomes. Finally, for support pack and upgrade testing, Object Sync allows you to move data from a lower support pack level or a lower SAP version into a higher support pack level or a higher SAP version. So you can leverage, Object Sync with Variance Monitor, take the data into a sandbox, let payroll run as it always would in production, run the same payroll period in the sandbox, but on the highest support pack level and see what's the impact and use Variance Monitor to see that impact. Doing it outside of the normal landscape like that also allows you an early look at the spout report. So when you actually then start putting support packs through the landscape, you already know what's going to happen in the spout report, and you can apply those changes. Everything is ready. So what we've come to now is the next step with SuccessFactors, and I'd like to show you a little video that actually shows the process of how the data is being copied. So when you put in your selections in the ABAP stack system, we go get that data, the input types, payroll, and so on. But we then use the employee there to go and get the corresponding SuccessFactors data via an API call. That data then becomes part of the sync. So we put the two sets of data together. We extract it from the system, and then data secure can apply the masking logic to both sets of data together. So the values that are applied to the info types, the name, address, and so on, are the same values if the data is the same on the SuccessFactors side as well. So we now have a set of files or an RFC call where the data is already scrambled consistently. And on the target system, we take the ABAP stack data and apply it as we always have. And then we use the OData API to push those new values for all of the entities that were related to our particular employee so that data is then present in the SuccessFactors QA system. So we're not leveraging the replication. We're actually taking control of the transfer of the data and using the ABAP stack as essentially the engine to do that transfer. But before it does, it gathers the data on the source. And then on the target, it posts that data into SuccessFactors. So let's go take a look at how that works. So I'm going into a SAP system here, and I'm using the HR launchpad. So with DSM5, we have a dedicated launchpad specifically for the HCM team, and I'm gonna choose to export employees. It now takes me through to a road map for me to follow that process in order to extract my data. So I can start by making selection options on the data and I have a particular employee that I know has some interesting data. And then underneath, we have a new data group visible for SuccessFactors employee central data. So this tells the solution I want to make those o data calls and include SuccessFactors data. I'm then gonna set this to overwrite, so we will replace the data. And on the left hand side, we have the integration points. So this is anything that we, may have that references our employee that we also want to copy. So it could be a business partner. It could be a finance cost center that we need in order to run payroll on the target system. So any referenced objects can then be included. I can then go through to the preview. And in the preview, we can see the name of our employee, and that will be important in a moment. And I'm gonna go through and have a look at the masking options. So in here, we have different policies, and this is coming from our data secure engine. Now I'm going to choose the SuccessFactors masking demo policy. So in here, we can see we've got a few rules. I've got the technical names on and the descriptions. We just got some basic things, including, importantly, changing the employee name. When we come through to the execution options, we can send the data to a target system via an RFC, or we can export the data to a file. So if I'm taking a small set of data, I'd normally just send it via an RFC. But if I want to be able to reimport the data to maybe keep testing something in a different way, then I might use the file export. I'm just gonna do a file export for now, and we can run either in the foreground or the background. I'm gonna choose to run-in the background. Now if I was copying thousands and thousands of employees, I could use parallel processing. So that would split the work over multiple background processes. So I'm gonna kick that off, and it now takes me through to the monitor desk where I can see activity within this particular component. While that's running, I'm just gonna take us to SuccessFactors, and we can see there the employee is still there. It's got the same name, Candy Barnes. So this is the corresponding, SuccessFactors employee central data for the employee that we are currently extracting. And that extract is taking all the usual ABAP stack data, and then it's using the o data API for SuccessFactors to come and get all of the entities. And those the entities that are required are now defined as part of our business object workbench. I'll show you that in just a moment. We come back to the monitor desk and refresh. We can see that run is finished. If I double click into that run, I can now go to the messages log. And in the messages log, I can see specific information for that employee around the o data entities that have actually been pulled back. So we can see we picked up one record for user, one for employment, and so on through there. So that data is all now sitting, in a file. And because I don't have a target SuccessFactors system, what I'm gonna do is I'm going to import the data back in. So, typically, you would now be moving to your QA system or your development system to do the file import, but I'm just gonna do this directly back in the same system. So I can choose from the files that are available to me, and it will then show me the selections that I've made as part of the extract. So we can see the data groups that were chosen. We can see if there's been any filtering on PA data or if I've selected any of these additional ones, and we can see the insert behavior. But there's only a few things we can change here because the selections and so on have already been set as part of the extract process. So I'm gonna go straight through to the execution options. And in here, again, I can choose from foreground or background, and I'm just gonna let this run-in the background now. So it's now taking that data from the file, and the data's already been masked in the file. And it knows which part of that stream of data is actually relevant for the ABAP stack, so the payroll cluster information, the PAM for types, and so on. And it's starting to apply those values to that database. And then it's using our technology to make o data API calls to up cert the records to the corresponding SuccessFactors system. So within the administration of Data Sync Manager, we actually define the OData identities for each SAP client, and that's how it knows which systems it should be making those calls to in order to either get the data on the source system or push the data on the target system. If we refresh now, we can see that run has completed. If we go in and have a look at the message log, we can see in here for our employee import, we've got a few standard messages at the top. And then when we come down, we can see each of the entities that we've sent, and we can see a status against them. So for example here, we can see there was an issue with the job record. If we expand this, we'll get back the message that came from the OData API. So it's basically telling us that there's a value that's stored in the data, which isn't a valid pick list option for that particular field. So even though the data has come from this system, the system's configuration now doesn't actually support its own data. So this is a, an interesting example of something that we have seen, and I'm gonna show you how we can work around those types of challenges in just a moment. Before we do that, let's go have a look at our data. We can see here we've got a new name for, our employee, the back end. If we go back to the SuccessFactors system and search again, we can see we've got the same name there in SuccessFactors as well. So we've essentially treated this as if it were a target system, applied the data, and we've got consistent data between SuccessFactors and our back end SAP system. Now the way that we've done this is by extending what we call the business object workbench. So the business object workbench is where we can define different data types across all the different types of SAP, ABAP stack system. So we have definitions for ERP data, CRM, SRM, and so on. What we've now done is allowed the business object workbench to also store o data entities and also then the properties that go against them. So if we go across to another session, just have a quick look, if I try to use this session, go across to the business object workbench. And here, we define this in such a way that we can deliver standard content and then customers can extend for their own data. So if you had Z-tables that stored employee data, you could link those Z-tables to your employee by an extension in the business object workbench. What we can do for SuccessFactors is add custom entities. So this is actually the data group that we ticked on the extract. And if I choose to extend this data group, what I can now do is say I'd like to add an entity to this data group as an extension, and it's now reading the metadata that we store for the OData identity. So when we connect the SuccessFactors system, we read the metadata. We also read all the pick list values so that we can deal with pick list options rather than external codes. But this is then visible within the ABAP stack system. So here, I can scroll down and see at the bottom, we've got all these custom entities, and we can come and choose one of these. So now I've added that to the definition of this data group, but what I need to do is tell it, well, how does it actually link? So I can make a direct key mapping. I can link it based on the user or the person ID external from SuccessFactors, or I can look for nav properties. So this is now checking the metadata again to see, is this entity actually referenced anywhere as a nav property? And it's found two places. So both against the user, there's two different nav properties. So I might choose this first one, and that has now linked this entity to the model. So if I copy this data, it will go and include data from that particular custom entity by going through the user nav in order to get that data as well and to bring it across to the target system. What's really powerful about this is once that data is defined inside the business object workbench, we can then use it for the data secure rules as well. So in inside Data Secure, we have with our rules what we call integrity maps, which is where the data is stored, and then we have transformation functions, which is how the data will change. So if I now go look at my integrity maps, I can go to the central person where we start the masking from, and I can go and navigate through our business object model. And through the employee, I can see a particular data group for the integration with Employee Central. And then through that, I can see the data group that we were just looking at. So in here, I can now see all of the different entities that are defined, and I can then choose properties of those entities to make an integrity map for so that we can then include it in a scrambling rule. So if we close that down and come back out and look at the rules, to take a basic example, inside our policy, we had a custom rule for the communications. So on the ABAP stack, you're, input type 105. And if we look at that rule, we can see there's options on the rule. But within each of these options, we have integrity maps for the ABAP stack, and then we have a couple of integrity maps for SuccessFactors, and then we can apply these values. So in this example, we're actually applying the new value that was calculated for input type 105. We're applying that directly as a new value input to the two SuccessFactors entities and their properties. Okay. So from there, what I'd then just like to show you is what we've done with the ability to manage foundation objects and also to deal with some of the challenging cases where the data simply doesn't align. So that example we had for a job where there's a field value that just isn't supported in the target system. So inside this utility, we can specify a source and a target SuccessFactors instance, and it then reads the metadata for those two instances and then allows me to make settings or selections just on specific entities. So in here, I could say I want, Pos* and apply that, and it will then give me a list of all of the entities that fit with my selection. So in this example, I'm gonna choose the position, and it then gives me a selection, screen essentially based on the keys of that particular entity. So I might be looking at a particular position which doesn't exist, and I need the position to exist in order to copy my employee across. So I can put the code in here for my position. And on the left hand side, we have nav properties for that entity. So if I already think, well, I might also need the cost center, I might also need the department, I can preselect those and then query the systems. So it now reads that data from both the source and the target, and we can see the values that it's picked up. So there's one position with a low start date, and then linked to that, we've got cost center, department, and so on. I can now go look at the actual values for those entities, and we can see the source and target value. So I can see if there's already a difference if it does exist on the target. But any of the properties that we found are up certable in the metadata are now open for us to make changes. So if I was dealing with, trying to bring a position across and I had a similar thing to what we'd seen on any job that, say, a particular, pick list value isn't valid on the target system, obviously, we want to highlight that. That needs to be corrected because the test system should have the same pick list values as production. But in the short term, if I just want to be able to test with this data, then I can come and change this value. So maybe it's a b, and I can do the same thing on any of these related entities through the navigation as well. So, again, if there's fields that are or values in the properties that aren't supported, if I need to, I can just make a change here before I send the data in order to be able to carry on with my test. So I can then choose, if I wish to here, I can choose which ones I want to select. But, also, if there was something else that I'd not thought to preselect, I can still navigate through. So for example, I might want to go look at the job code. I can just expand this, and it then makes another OData call to go and bring that part across. So you can essentially browse through the relationships between different entities. And I pick the position. It could be an entity on a user. So it could be that there's a related entity like amp job where I can't bring it across as is with Object Sync. I don't want to create a Data Secure rule because we're going to fix the config in the future. But today, I'm just gonna copy the amp job record using this utility because that will allow me to change the field value. So when you're happy, you can pick the things that you want and then say, Upsert. You then need to choose the order in which it should send those entities and also determine, do you want to do a full purge? So if this position exists but has different start dates on the target system, do we want to purge all the entries for that position code, or do we just want to try and send across this particular one to plug a gap in the data that's already there on the target? So we then submit to send that to the target system. What we can also do in here to help us with this process is we can compare the metadata for this particular entity. So we can see in here the, attributes are the same on both our source and target SF instance, but there's some properties with differences. We can see there's employee class and employee class nav actually have a different pick list configured. So unless they've maintained the same pick list values against the different pick list name, you may have an issue there. That may indicate, actually, there's some data that isn't going to be supported here. But what we can also do, which I think is particularly powerful with this utility, is we can actually run a comparison for the metadata across the whole system. So this is now giving me a HTML output that we can save as a HTML file. And in this, we can see when the metadata was last refreshed from those systems, and then we can see the entities that exist only on the source, and we can see the entities that only exist on target system. And then further down, we can see the ones that have a difference. So similar to what we saw with position, we can see where there's a field that or property that only exists on one and not the other or where there's a difference between the property attributes between the source and target system. So that also can be downloaded as a to HTML. So you can then give that to the functional teams to say, these are the differences that are there. We need to try and align our test systems because we want to make sure when we're bringing down accurate test data, we actually have accurate configuration in those test systems. Otherwise, our test is not, not worth as much to us. But, also, the pick lists is something that, I've seen quite a lot that somebody may be in a hurry. They need to create a new pick list entry, and so they do so directly in production or they do so in one test system and then do it in production. And they don't go back and maintain the pick lists, in the other test systems. So this is another utility that we're providing where it's now comparing the pick lists between the systems. And, again, it gives us ones that only exist in the source, ones that only exist in the target, and then ones that have differences. So this one, as an example, is county GBR. It actually looks more like Irish counties to me. And we can see the external code and the option IDs and the labels. They're similar, but they're by no means the same. So this means we've got a completely different set of options on that particular pick list between the two systems. So, again, really useful to be able to see where has our configuration, become less well aligned, and what do we then need to do to go and resolve it. And the timing of this is good because, SuccessFactors are introducing the configuration center for early adopters, I think, in November, and that is bringing what those of us who come from the ABAP side know as the transport management system. It's bringing that concept to SuccessFactors. So you'll be able to create configuration in a test instance or a development instance and then send that to a QA system, test again there, and then move on to production. So this utility, allied with the configuration center can help organizations to correct any discrepancies in their landscape and then make sure, going forward, they have the right change management process in place. K. So gonna jump back to the slides just to finish off, and then we'll get ready to take any questions that you may have. So just a nice quote there. Just one example of a lot of people who have used DSM, on at least a weekly, sometimes daily basis in order to be able to support the HR systems. Now with the SuccessFactors Hybrid, we can help people who've also now got the EC side and SuccessFactors to support as well. Okay. Over to Maria to read out any questions that we may have. Thank you, Paul, for the presentation. So, yes, now we're going to dedicate a few minutes to the Q&A. If you haven't done it already, please enter your questions in the question box. I can see we have already a couple of questions I'm going to read out. Paul, can it copy data that only exists in SuccessFactors, like something in a custom portlet? Yes. So because we've been able to put the OData identity in and then define all of the entities that are required to store the employee's data, we can actually call information that actually doesn't exist at all. So we're not leveraging the replication. We don't need it to be something that exists in both systems. We can directly configure it. This is what we want to bring across and even put in those, those transformation rules in order to be able to scramble something that's sensitive. I have seen a lot of, MDF properties that are, the name stored in a slightly different format. So I think it is quite common that people will have, extended SuccessFactors to have their own fields, their own properties, and it be personal data that needs to be handled. Okay. Thank you. We have another question. Does it support global assignment? It does. So we actually start from the central person to make sure that if there are multiple records linked together, we actually collect them together, and then that anonymization process is happening across both at the same time. Okay. Another question. Does Object Sync work only for SAP cloud and on premise systems or it also works for non SAP systems with SAP SuccessFactors? Example, non-SAP payroll system and SuccessFactors, Object Sync and data comparison. So at the moment, we are running this from an ABAP stack system. So if an organization didn't have an ABAP stack system at all, we don't have anywhere for this to run. So we could potentially if there was a, immediate need to be able to, say, scramble an existing test instance of SuccessFactors, we could do that as a service by leveraging one of our SAP systems in cloud. We just need to do a little bit of work to get a essentially, a work list of the users that we need to process, and then we could carry this out. But in terms of using Object Sync just on a SuccessFactors instance, that's not possible at the moment. It's in our road map, but it's not something that we're doing because a lot of our customers have come from the HR payroll side, and they have the ABAP stack systems, and they've just taken some of their HR functionality across the SuccessFactors, things like payroll and time and so on are still there. But it could also just be a backend finance system. If somebody wanted to leverage this and there was no other HR functionality in the system, if we can connect our finance system to SuccessFactors using, certificates in the SAP system and then the OData API with a HTTP, RFC connection, then we could similarly drive it from a finance system. But we'd again just need to define a work list. How do we get the list of users that can be chosen? But that would be a relatively easy thing to do as an extension within DFS. Okay. Thank you, Paul. One last question. Can we mask positions as well or only employees' information? At the moment, we have limited it to the employee data, so that's how it's connected through the business object workbench. It wouldn't be too difficult to actually link positions in as well with the employee to be able to apply data secure rules to them, but we will in time add the ability to sync things that only exist in SuccessFactors as the starting point for the second because then you would be able to just pick up the position, bring it across on its own without an employee, and also apply scrambling to it. In the short term, you can also use the, utility that we looked at to go and get positions, make changes on the fly, and then send them across. Okay. Fantastic. Right. I don't see any more questions coming in, so I think that's it for the Q&A session. And before we conclude this, webinar, I would like to remind you to keep an eye on your inbox. We're gonna be sending out a follow-up email with the information about our on demand content for this series. In case you want to watch previous sessions that you might have missed or share them with your colleagues. As well, you will get the opportunity to participate in a prize draw for an Amazon Echo Dot fourth generation if you answer to our survey. For us, it's really important to ascertain what your thoughts are on this webinar series and if you have found it useful. Let us know if you would like to discover our HCM Productivity Suite further with a private demo, and you can find more information on our website at epiuselabs. Com. Thank you for your participation, and I hope you'll have a great day.
이 비디오에는 한국어 자막이 있습니다
기록됨: 2020년 11월 12일
마음에 드시나요? 공유하세요:
웨비나 소개:
오늘날 HR 데이터의 일부는 온프레미스에, 일부는 클라우드에 존재하는 것이 일반적입니다. 이번 세션에서는 데이터 품질과 데이터 보호의 중요성을 깊이 탐구하며, 특히 SuccessFactors 및 하이브리드 환경에서의 데이터 복사와 마스킹에 초점을 맞춥니다.
Paul Hammersley
ALM 제품 포트폴리오 수석 부사장 (SVP), EPI-USE Labs
Paul은 오랜 시간 동안 EPI-USE Labs에서 뛰어난 기술력을 발휘해온 인물입니다. ALM 제품 포트폴리오 수석 부사장으로서 그의 포트폴리오에는 시스템 랜드스케이프 최적화(System Landscape Optimization)가 포함되어 있으며, Data Sync Manager를 구현하고 고객들이 SAP 랜드스케이프 전반에서 데이터를 관리할 수 있도록 돕는 그의 실무 경험은 독보적입니다. 그는 데이터 보안 및 GDPR(일반 데이터 보호 규정)이 SAP를 운영하는 기업에 미치는 영향에 대한 전문 지식을 보유하고 있습니다.
더 많은 웨비나 시청
급여 리스크를 낮추세요: 모든 계절에 대한 변동성 모니터
급여 리스크를 낮추세요: 모든 계절에 대한 변동성 모니터
인사 및 급여 데이터는 복잡하기 때문에 실수가 없어야 합니다.
SAP로 RISE에 따른 환경 최적화
SAP로 RISE에 따른 환경 최적화
다니엘 파커가 RISE로 시스템을 이전할 때 얻을 수 있는 인사이트와 비용 절감에 대해 설명합니다.
효율성으로 도약하세요: 인사 및 급여 보고 간소화
효율성으로 도약하세요: 인사 및 급여 보고 간소화
이 웨비나에서 Eben de Lange가 SAP 보고의 효율성을 극대화하기 위한 5가지 모범 사례를 공유합니다.