SAP MDG · COMMUNITY

How do I restrict the requestor from approving their own SAP MDG change request?

Use the MDG validation BAdI / Check_entity to compare the logged-on user with the change request requestor and raise an error if they are the same, so the request fails at Check time.

Use the MDG validation BAdI / Check_entity to compare the logged-on user with the change request requestor and raise an error if they are the same, so the request fails at Check time.

Use the MDG validation BAdI / Check_entity to enforce a 4-eye principle in the change request check. The logic reads the requestor from the CR context, compares it with `sy-uname`, and raises an error if the same user is trying to check or approve the request. A revision-step exception can be handled by checking the workflow step or revision status.

Process flow

  1. Identify the Check_entity validation exit used during MDG Check.
  2. Read the current user using `sy-uname`.
  3. Read the requestor from the CR header or request context.
  4. Compare the requestor with the current user.
  5. If they match, append an error message to the BAdI message table.
  6. Optionally skip the rule for a revision step or revision status.
  7. Use a dedicated message class such as `ZMDG` and message number `001`.
  8. Test the Check action to confirm the CR is blocked for self-approval.

Referenced tables

ObjectPurpose
TADIRRepository object directory information relevant to ABAP development objects, mentioned in the related source for class editing and transport ownership concepts.

ILLUSTRATIVE ABAP SAMPLE

ABAP sample for preventing requestor self-approval in Check_entity

Adapt the interface fields and CR read API to your SAP release. The example follows the source pattern and raises an error when the current user matches the requestor, excluding a revision step.

1METHOD if_ex_your_check_entity~check_entity. 2 3 DATA: lv_requestor TYPE syuname, 4 lv_current TYPE syuname. 5 6 lv_current = sy-uname. 7 8 "Get requestor from the CR header / passed-in context 9 lv_requestor = is_crequest-created_by. "Adjust to your BAdI signature 10 11 IF lv_requestor IS NOT INITIAL 12 AND lv_current = lv_requestor 13 AND lv_step <> '51'. "Change as per your revision step or check by status 14 15 APPEND VALUE #( msgty = 'E' 16 msgid = 'ZMDG' 17 msgno = '001' 18 msgv1 = 'Requestor cannot check/approve own change request' ) TO et_message. 19 RETURN. 20 ENDIF. 21 22ENDMETHOD.

The remaining configuration, implementation details, and testing guidance continue from this answer more…

Related questions and keywords

Alternative questions

  • Requestor cannot be approver
  • Remove requestor from approver list
  • Implement 4 eye principle

Possible questions

  • How to implement a 4-eye principle in SAP MDG?
  • How to stop self-approval in MDG workflow?
  • How to validate that the approver is not the requestor in MDG?
  • How to use Check_entity for MDG self-approval prevention?
  • How to configure a step-specific check in MDG change request workflow?

Keywords

complianceauditown requestself approve4 eye principletwo touchdouble touchvalidation BAdICheck_entityMDG workflow