Subject: SAP CoPilot in the SAP Ecosystem
Article ID: 086
SAP CoPilot is SAP's digital assistant and bot integration platform designed to enhance user productivity through conversational interfaces. It allows users to interact with SAP applications using natural language, collaborate in real time, and automate routine tasks. A crucial aspect of implementing and maintaining SAP CoPilot in any organization is user management—specifically, creating and managing user accounts to ensure secure and personalized access to the system.
This article provides a detailed overview of how to manage user accounts within the SAP CoPilot environment, with a focus on best practices, configurations, and administration in SAP Fiori and SAP BTP (Business Technology Platform).
SAP CoPilot leverages existing SAP user management infrastructure. It does not maintain a separate identity management system, but integrates with:
Users accessing SAP CoPilot must be authenticated and authorized based on predefined roles and permissions in SAP systems.
Before creating users, ensure the following prerequisites are met:
If you're using SAP CoPilot on-premise (e.g., S/4HANA):
Create users in the SAP GUI via transaction code SU01.
Assign necessary roles for Fiori and CoPilot access, such as:
SAP_BR_EMPLOYEESAP_BR_ADMINISTRATORTip: Ensure the user has access to SAP Fiori Launchpad, as CoPilot is accessed through it.
For SAP CoPilot in a cloud environment:
Navigate to your BTP Cockpit → Select your Subaccount → Go to Security > Users.
Add a new user and assign them to the appropriate role collections.
Role collections should include:
CoPilotUserCoPilotAdmin (for admin users)You can manage users via the SAP Cloud Identity Services – Identity Authentication tenant, where users are registered and mapped to roles.
CoPilot uses RBAC to determine what users can do:
In Fiori, administrators can:
| Issue | Possible Cause | Resolution |
|---|---|---|
| User cannot access CoPilot | Missing role or incorrect user mapping | Check BTP or SAP GUI user roles |
| CoPilot tile not visible | Fiori catalog/group misconfiguration | Reassign CoPilot catalog to the user |
| Authentication fails | SSO or IAS misconfiguration | Verify IdP integration and user existence in IAS |
| Cannot use certain skills | Missing skill-specific authorization | Review and assign required business roles |
Efficient user management in SAP CoPilot is key to maximizing the productivity and collaboration benefits of the platform. Whether you deploy CoPilot on-premise or via SAP BTP, the core principles of identity, access control, and role management remain critical.
By following structured procedures for creating and managing user accounts, and by aligning user roles with business needs, organizations can ensure a secure, scalable, and user-friendly CoPilot experience.
Next Article (087): Integrating Custom Skills into SAP CoPilot with SAP Conversational AI