Stitchflow
SAP SuccessFactors logo

SAP SuccessFactors User Management Guide

Manual workflow

How to add, remove, and manage users with operational caveats that matter in production.

UpdatedMar 16, 2026

Summary and recommendation

SAP SuccessFactors user management can be run manually, but complexity usually increases with role models, licensing gates, and offboarding dependencies. This guide gives the exact mechanics and where automation has the biggest impact.

SAP SuccessFactors is an enterprise HCM platform covering core HR, performance, learning, and compensation.

User access is governed entirely by Role-Based Permissions (RBP), which separates what a user can do (Permission Roles) from which employee population they can act on (Permission Groups).

Every app in your stack that depends on employee data-downstream directories, collaboration tools, payroll connectors-is only as accurate as the user records and permission assignments maintained here.

Quick facts

Admin console pathAdmin Center > Manage Users (for individual user management); Admin Center > Import and Export Data (for bulk operations); Admin Center > Set User Permissions (for Role-Based Permissions)
Admin console URLOfficial docs
SCIM availableYes
SCIM tier requiredEnterprise
SSO prerequisiteYes

User types and roles

Role Permissions Cannot do Plan required Seat cost Watch out for
System Administrator Full access to Admin Center, all modules, user management, permission role configuration, and system settings. Can grant and revoke permissions for all other users. Cannot bypass audit logging; certain SAP-reserved system configurations require SAP support intervention. System Administrator access is controlled via Role-Based Permissions; the role must be explicitly assigned through a Permission Group. There is no single built-in 'super admin' account outside of the initial provisioning admin.
HR Administrator Access to employee data management, onboarding/offboarding workflows, compensation, and reporting as granted by assigned Permission Roles. Scope is typically limited to specific employee populations via Permission Groups. Cannot access system-level configuration or grant permissions beyond their own assigned scope unless explicitly permitted. HR Admin capabilities vary significantly based on which modules are licensed and which Permission Roles are assigned. There is no single standard HR Admin role out of the box.
Manager (Self-Service) Access to direct report data, performance reviews, goal management, and approval workflows for their team, as defined by Permission Groups targeting their reporting hierarchy. Cannot access employees outside their defined reporting structure unless additional Permission Groups are configured. Manager permissions are dynamically scoped using 'target population' rules in RBP. Misconfigured org hierarchies can result in managers seeing incorrect employee populations.
Employee (End User) Access to personal profile, self-service HR tasks (address updates, benefits enrollment), assigned learning, and performance forms as permitted by their Permission Roles. Cannot access other employees' data, administrative settings, or reporting unless explicitly granted. All employees consume a named user license. Inactive users may still count toward licensing depending on contract terms; verify with SAP account team.

Permission model

  • Model type: role-based
  • Description: SAP SuccessFactors uses Role-Based Permissions (RBP). Administrators create Permission Roles (defining what actions are allowed) and Permission Groups (defining which users are granted those roles and which target population they apply to). A user's effective permissions are the union of all Permission Roles assigned to them via Permission Groups. RBP replaced the legacy permission model and is the current standard across all modules.
  • Custom roles: Yes
  • Custom roles plan: Not documented
  • Granularity: Permissions are configurable at the module, feature, field, and action level (view, edit, create, delete). Target populations can be scoped by org unit, location, job classification, or custom criteria, enabling fine-grained data access control.

How to add users

  1. Log in to SuccessFactors as an administrator.
  2. Navigate to Admin Center (gear icon or top navigation).
  3. Under 'Manage Users', select 'Add New User' (for individual creation) or use 'Import and Export Data' for bulk.
  4. Enter required user fields: User ID, First Name, Last Name, Email, Username, and Status.
  5. Assign the user to the appropriate company (if multi-company instance).
  6. Save the user record.
  7. Navigate to Admin Center > Set User Permissions > Manage Permission Groups.
  8. Add the new user to the relevant Permission Group(s) to grant module access.
  9. Optionally assign the user to an org structure (department, division, location) via the employee profile or import.

Required fields: User ID (unique identifier, typically employee ID), Username (used for login), First Name, Last Name, Email Address, Status (Active/Inactive)

Watch out for:

  • Creating a user record in 'Manage Users' does not automatically grant any system access; Permission Group assignment is a separate required step.
  • User ID and Username must be unique across the instance and cannot be changed after creation without data migration steps.
  • In instances using Employee Central, the authoritative user record is the Employee Central profile, not the standalone 'Manage Users' tool. Creating users only in Manage Users without an EC record can cause data inconsistencies.
  • Password policies and login methods (SSO vs. username/password) are configured separately in Provisioning or Admin Center and affect whether a newly created user can actually log in.
  • New users do not receive a welcome/activation email by default unless the email notification is explicitly configured.
Bulk option Availability Notes
CSV import Yes Admin Center > Import and Export Data > Import User Data (select 'User' entity and upload CSV following the required template format)
Domain whitelisting No Automatic domain-based user add
IdP provisioning Yes Requires SAP Cloud Identity Services (Identity Provisioning Service). Available as part of SAP BTP or bundled with SuccessFactors enterprise agreements; verify entitlement with SAP account team.

How to remove or deactivate users

  • Can delete users: No
  • Delete/deactivate behavior: SAP SuccessFactors does not support permanent deletion of user records through the standard Admin Center UI. The standard practice is to set a user's Status to 'Inactive', which prevents login and removes the user from active workflows. In Employee Central, terminating an employee creates a termination record with an effective date, which triggers the inactive status. Physical deletion of user data may be possible under specific data privacy/GDPR processes via the Data Retention Management tool or SAP support, but this is not a routine administrative action and has strict prerequisites.
  1. Navigate to Admin Center > Manage Users.
  2. Search for the user by name, User ID, or username.
  3. Open the user record.
  4. Change the 'Status' field from 'Active' to 'Inactive'.
  5. Save the record.
  6. For Employee Central users: process a termination event on the employee's Job Information portlet with the appropriate termination date and reason, which will automatically set the user to inactive on the effective date.
Data impact Behavior
Owned records User data, historical records, and transactions associated with the inactive user are retained in the system. The user's employee profile, performance history, and audit trail remain accessible to administrators.
Shared content Content created by the user (goals, learning completions, documents) remains in the system and is not automatically reassigned. Administrators must manually reassign ownership of pending tasks or workflows.
Integrations If the user is provisioned via SAP Identity Provisioning Service or an external IdP, deactivation in SuccessFactors does not automatically deactivate the upstream identity; the IdP or SCIM provisioning flow must also be updated.
License freed Setting a user to Inactive status is intended to free the named user license for reuse, but actual license counting depends on contract terms. Verify with SAP account team whether inactive users continue to count toward licensed user totals.

Watch out for:

  • Deactivating a user in Manage Users does not automatically terminate their Employee Central record; both actions may be required depending on instance configuration.
  • Users with pending workflow approvals or open tasks should have those items reassigned before deactivation to avoid process blockages.
  • Inactive users may still appear in org charts or reports unless filters are applied; administrators should verify reporting configurations after deactivation.
  • GDPR/data privacy deletion requests require use of the Data Retention Management tool and may require SAP support involvement; this is separate from routine deactivation.
  • Reactivating a previously inactive user requires manually setting Status back to Active and verifying Permission Group memberships are still correct.

License and seat management

Seat type Includes Cost
Named User License Access to licensed SuccessFactors modules for a single identified individual. Specific module access (e.g., Employee Central, Performance & Goals, Learning) depends on which module licenses are purchased. Contact SAP for pricing. Indicative published rates vary by module: ~$8/user/month (Professional/core HR), ~$14/user/month (Performance & Goals), ~$22.20/user/year (Learning), ~$28–38/user/month (full suite). These are not guaranteed current rates.
  • Where to check usage: Admin Center > Company System and Logo Settings (for total active user count); detailed license consumption reporting is typically available through SAP for Me (support portal) or via your SAP account executive. Some instances have access to 'License Audit' reports under Admin Center > Reporting.
  • How to identify unused seats: Run a user activity report or last-login report via Admin Center > Reporting > Ad Hoc Reports or via the Analytics module to identify users who have not logged in within a defined period. Filter the Manage Users list by Status = Active and cross-reference with login history.
  • Billing notes: SAP SuccessFactors is licensed on a named-user, per-module basis with annual subscription terms. Implementation fees are typically separate and can equal 100–125% of annual software fees. License counts are typically reconciled annually. Inactive users may or may not count toward license totals depending on contract language; confirm with SAP account team. Multi-module discounts and enterprise agreements are negotiated directly with SAP.

The cost of manual management

Creating a user in Admin Center > Manage Users does not grant any system access; Permission Group assignment is a mandatory second step that is easy to miss and has no automated reminder. Bulk imports via CSV require exact template adherence-a single formatting error fails the entire job with limited diagnostic output.

Deactivating a user sets their SuccessFactors status to inactive but does not cascade to SSO sessions, downstream systems, or, in Employee Central tenants, the EC termination record, which must be processed separately. Each of these gaps compounds across every app tied to SuccessFactors identity, turning routine offboarding into a multi-system checklist.

What IT admins are saying

Community evidence is not specific enough to quote or summarize yet for this app.

The decision

Manual administration is viable for organizations with low user-change velocity and a dedicated HR ops team comfortable with RBP configuration. The process breaks down at scale: bulk import fragility, the absence of cascading deactivation, and opaque license reconciliation all increase error surface as headcount grows.

Teams managing frequent onboarding cycles or multi-module deployments should evaluate whether the manual process can reliably keep every app in sync without automation support. GDPR deletion requests add a separate operational track via the Data Retention Management tool and are outside the standard deactivation workflow entirely.

Bottom line

SAP SuccessFactors manual user management is functional but layered: creating access requires two distinct steps (user record plus Permission Group), removing access requires parallel actions in both Manage Users and Employee Central, and license reconciliation requires SAP account team involvement.

The RBP model is powerful but demands ongoing configuration discipline. Organizations with stable, low-volume user changes can manage this manually;

those with high onboarding or offboarding frequency will accumulate operational debt quickly without a structured process or automation layer to close the gaps between SuccessFactors and every app that depends on it.

Automate SAP SuccessFactors workflows without one-off scripts

Stitchflow builds and maintains end-to-end IT automation across your SaaS stack, including apps without APIs. Built for exactly how your company works, with human approvals where they matter.

Every app coverage, including apps without APIs
60+ app integrations plus browser automation for apps without APIs
IT graph reconciliation across apps and your IdP
Less than a week to launch, maintained as APIs and admin consoles change
SOC 2 Type II. ~2 hours of your team's time

UpdatedMar 16, 2026

* Details sourced from official product documentation and admin references.

Keep exploring

Related apps

15Five logo

15Five

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

15Five uses a fixed role-based permission model with six predefined roles: Account Admin, HR Admin, Billing Admin, Group Admin, Manager, and Employee. No custom roles can be constructed. User management lives at Settings gear → People → Manage people p

1Password logo

1Password

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

1Password's admin console at my.1password.com covers the full user lifecycle — invitations, group assignments, vault access, suspension, and deletion — without any third-party tooling. Like every app that mixes role-based and resource-level permissions

8x8 logo

8x8

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

8x8 Admin Console supports full lifecycle user management — create, deactivate, and delete — across its X Series unified communications platform. Every app a user can access (8x8 Work desktop, mobile, web, Agent Workspace) is gated by license assignmen