> For the complete documentation index, see [llms.txt](https://sealights-docs.tricentis.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sealights-docs.tricentis.com/setup-and-configuration/install-the-abap-agent/generate-authorization-profiles.md).

# Generate Authorization Profiles

You must install the ABAP add-on using client 000, however the authorizations and roles delivered with the add-on are client-dependent. To make the authorizations and roles available to the client where you will run the ABAP agent, follow these steps:

1. Sign in to the SAP system using the client where the ABAP Agent will run.
2. Run transaction PFCG to display the **Role Maintenance** screen.
3. Enter **/TRICE/SL\_AUTHS** in the Roles field and select <img src="https://1120332842-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMsXHfFNCMXIaXf5BTCm6%2Fuploads%2FlbjdoaVQfWEd41sY6D9K%2Fchangebutton.png?alt=media&amp;token=0f1d700b-e7c6-4810-a67c-59ba50e87197" alt="" data-size="original">.
4. In the **Change Roles** screen, select the **Authorizations** tab.
5. In the **Maintain Authorizations and Generate Profiles** section, select **Change Authorization Data**.
6. In the **Change role: Authorizations** screen, select ![](https://1120332842-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMsXHfFNCMXIaXf5BTCm6%2Fuploads%2FgOirXS0XGHJzizvzBXGQ%2Fgeneratebutton.png?alt=media\&token=2e824a84-9c87-4eea-9263-c04ce37f96b3) to generate the authorization profiles.
7. Check that the SeaLights role **/TRICE/SL\_AUTHS** has access to the following authorization objects:

{% hint style="warning" %}
**Upgrading from ABAP Agent 2.0 or 2.0.1:** Regenerate **`/TRICE/SL_AUTHS`** so it includes all **`S_TABU_NAM`** rows marked **Added in version** `2.1` in the table above.
{% endhint %}

## Production system authorizations <a href="#production-system-authorizations" id="production-system-authorizations"></a>

The agent also connects to your Production (PRD) system, through the PRD RFC Destination of each pipeline, to read production usage data. You must set up each PRD system in **one** of the two configurations below:

* **Without the add-on** (default): every pipeline that uses this PRD system has `useaddon = false`, which is the default. Use it when the add-on is not installed on PRD, or to turn off the add-on when it is installed.
* **With the add-on**: the add-on is installed on PRD (see [Install the add-on on your Production system](broken://pages/KA26qNyaJ9N3X9bfhQmb#install-the-add-on-on-your-production-system)), and every pipeline that uses this PRD system has `useaddon = true`.

All pipelines that use the same PRD RFC Destination must use the same configuration. See [Configuration settings — Production usage data source](broken://pages/DZM4uWEu5r51kMDWCmDB#production-usage-data-source).

Grant the RFC user of the PRD RFC Destination the authorizations for the configuration you chose. Create a dedicated role for this user that contains only these authorizations; the `/TRICE/SL_AUTHS` role above is for the QAS system and grants more than PRD needs.

### Without the add-on (`useaddon = false`) <a href="#prd-without-add-on" id="prd-without-add-on"></a>

### With the add-on (`useaddon = true`) <a href="#prd-with-add-on" id="prd-with-add-on"></a>
