Partner integrations often need read access to a dashboard or a single API for ninety days. Permanent service accounts and shared BI licenses create SoD violations that surface years later.
AccessGuard (AG) and BI Role Management in iDataEngine address partner access as a governed process — not a shared password in a ticket.
What you can enforce
- Role values and user assignment in BI Portal — scope which objects, views, and auth fields a partner user sees
- RM snapshots — capture role and authorization state at grant time for later comparison
- RM sync from SAP — keep platform roles aligned with SAP profiles instead of orphan BI accounts
- Compliance alerts when critical authorizations or SoD rules are touched
For API partners, combine Assign Users and Allowed IPs on the service detail screen with token login. When the project ends, deactivate the service or set rate limits to zero — access stops without a BASIS firefight.
Time-boxed access in practice
- Define the minimum BI view or API field set required — nothing more
- Assign partner users to a dedicated BI role with explicit auth fields
- Record an AccessGuard snapshot before go-live
- Schedule a calendar review to revoke users and rotate API credentials
- Re-sync roles after offboarding and compare to the snapshot
Why it matters
Speed and compliance are not opposites when access is designed to expire. Time-boxed partner exposure reduces audit findings, shrinks breach blast radius, and lets business teams onboard integrators in days — because security teams can prove who had what, when, and that it was removed on schedule.