Metrica
Metrica
✕
  • Home
  • Products
    • Power BI Connector for Salesforce
    • Power BI Connector for SAP
  • Resources
    • Blog
    • Trust Center
Explore Products

Home - Metrica Docs - Application Permissions Setup

Getting Started

  • Welcome
  • Installation Guide
  • Explore Power BI Connector for SAP
  • Quickstart — from Zero to a Power BI Report
  • Installation Guide: Multi-Tenant
  • On-Premise SAP Configuration

Admin Guide

  • Configure the Token Expiry Policy
  • Application Permissions Setup

User Guide

  • Create a Data Source
  • Create an Access Token
  • Connect Power BI Desktop
  • Manage Access Tokens
  • Edit a Data Source
  • Filter Rows
  • Share a Data Source
  • Schedule Refresh in Power BI Service
  • Preview Data
  • Preview the ERD
  • See What’s Been Shared with You
  • Customize the Data Source Page
  • View Activity History
  • View Export History
  • Combine Multiple SAP Services
  • Use Parametrized OData Entities
  • Explore Data Relationships
  • Browse and Search the Data Sources List
  • Transfer Data Source Ownership
  • Clone a Data Source
  • Delete a Data Source
  • Child Entities and Addressability

FAQ & Troubleshooting

  • Troubleshooting
  • Why do my SAP dates show up as text in Power BI?
  • Why do I get 401 from the Power BI service after a successful Desktop load?
  • Why is the SAP catalog showing fewer services than I expect?
  • What happens if I lose a token?
  • Will the recipient see my access token if I share with them?
  • Can a tenant admin see the value of my access tokens?
  • How many data sources can I create?
  • Why is the URL of every data source different?
  • How is Preview ERD different from Data Relationships?
  • Why does the connector limit me to 5 active tokens?
  • What happens to a shared data source if I leave the company?
  • Why does the Basic filter editor sometimes disable itself?
  • Can I share a data source with a user from a different tenant?
  • Why doesn’t the connector cache SAP data?
  • What happens if a service is removed from the destination after I’ve built a data source on it?
  • Can I change the data source URL after creation?
  • Do I have to fill every parameter on a parametrized entity?
  • Can I use the OData URL outside Power BI?

Support

  • Contact Support
  • Pricing and Licensing
  • Subscription Plans and Trial Limits
View Categories
  • Metrica Docs
  • Power BI Connector for SAP Documentation
  • Admin Guide

Application Permissions Setup

2 min read

Power BI Connector for SAP uses two role collections in SAP BTP to control who can do what inside the connector. An administrator subscribes the tenant to the connector, then assigns the role collections to individual users or groups in the BTP cockpit. Without a role collection, a user can sign in but cannot create or view any data sources.

Role collections #

The connector ships two role collections. They are created automatically when the tenant subscribes:

  • Metrica Software Power BI Connector User — sign in, create and edit personal data sources, share them with other users in the same tenant, mint personal access tokens, view your own activity history.
  • Metrica Software Power BI Connector Administrator — everything a User does, plus tenant-wide settings on the Administration page (for example, the token expiry policy), visibility into other users’ activity, and the right to invoke GDPR right-to-erasure on data subjects within the tenant.

The Administrator collection includes the User scope, so administrators do not need both.

i
The role collections must be present in the cockpit by these exact names. If you search BTP’s Security → Role Collections list and don’t see them, the subscription hasn’t completed yet — wait a minute, refresh, and try again.

Where to assign role collections #

In the BTP cockpit:

  1. Navigate to the subaccount where the connector is subscribed.
  2. Open Security → Users.
  3. Open the user, identity provider group, or SAP IAS group you want to grant access to.
  4. Add Metrica Software Power BI Connector User or Metrica Software Power BI Connector Administrator.
  5. Save.
  6. Ask the user to sign out and back in for the new role to take effect.
i
Role collection changes propagate at next sign-in. Existing sessions keep their previous permissions until the user signs out.

Removing access #

Remove the role collection assignment in the BTP cockpit. The user can still sign in (the identity provider still trusts them) but will see You don’t have access on the connector home page.

To revoke any personal access tokens the user has issued, an administrator can use the connector’s Administration view. See Manage Access Tokens.

Updated on June 2, 2026

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Configure the Token Expiry PolicyConfigure the Token Expiry Policy
Table of Contents
  • Role collections
  • Where to assign role collections
  • Removing access
Metrica
Explore Products
Products
  • Power BI Connector for Salesforce
  • Power BI Connector for SAP
Resources
  • Blog
  • Trust Center

Metrica Software builds enterprise data connectors that provide analytics platforms with direct access to complex business systems such as SAP and Salesforce.

The focus is on predictable behavior, controlled access, and long-term operation in production environments.

© 2026. All rights reserved.

Privacy Policy

Terms of Use

    Book a Demo







    Secure & private form

    1-2 min

    ×

      Contact Sales








      Secure & private form

      1-2 min

      ×