You can use the role administration functions to manage roles and authorization data. The role management tool creates authorization data automatically based on selected
menu functions, and presents it for postprocessing. It is also integrated with organizational management.
We recommend you use the role maintenance functions (transaction PFCG) to maintain your roles, authorizations and profiles. Although you can continue to create profiles
manually, you need detailed knowledge of all SAP authorization components.
The role administration functions support you in performing your task by automating various processes and allowing you more flexibility in your authorization plan. You can
also use the Central User Administration functions to centrally edit the roles delivered by SAP or your own, new roles, and to assign the roles to any number of users.
The roles (previously: activity groups), which are based on the organizational plan of your company, form the basic framework of the tool. These roles form the link between
the user and the corresponding authorizations. The actual authorizations and profiles are stored in the SAP system as objects.
With the roles, you assign to your users the user menu that is displayed after they log on to the SAP system. Roles also contain the authorizations that users can use to
access the transactions, reports, Web-based applications, and so on that are contained in the menu.
When you work with the role administration tool, you work with a level of information that is a step away from the actual objects in the SAP system. Role Administration