SAP ERP HCM

Bring your people data from SAP ERP HCM into MuchSkills. Your SAP ERP HCM administrator gives MuchSkills read-only access, and we map the fields and run the sync. The set-up is part of your MuchSkills implementation.

Updated

Custom integrationAdmins and HRIT

Who
Your SAP Basis and HR authorisation team, with our CTO
How it connects
Custom set-up, part of your implementation
Sync
Every 5 hours, or on demand with Sync Now
Access
Read-only

How it works

SAP ERP HCMA read-only OData service your SAP team publishes
Read-only, HTTPS, every 5 hours
MuchSkills readsMaps your field names, blocks sensitive data, applies your scope
Each sync
Your workspacePeople, managers, departments and tags, kept current

MuchSkills reads from SAP ERP HCM on a schedule. New starters, leavers, manager changes and department changes arrive at the next sync, with no manual work on either side. Nothing is written back to SAP ERP HCM.

SAP ERP HCM runs in your own data centre, so your SAP team publishes a read-only OData service through SAP Gateway and makes it reachable over HTTPS. MuchSkills reads that service and nothing else.

Before you start

  • A SAP ERP HCM administrator on your side, or your SAP ERP HCM implementation partner.
  • A list of who should be in MuchSkills: everyone, or a selection by country, company, department or worker type.
  • Your field names. SAP ERP HCM installations name custom fields differently, so have your field list to hand for the technical session.

Steps

In SAP ERP HCM

Your SAP Basis and HR authorisation team will recognise these transactions. Every SAP ERP HCM system is configured differently, so they decide the exact service and roles. SAP ERP HCM documentation

  1. Create a user for the integration. In user maintenance (SU01), create a user with the user type System. It cannot log on with SAP GUI and its password does not expire.
  2. Expose the people data as a read-only OData service. Your SAP team publishes a service through SAP Gateway with the fields listed below and activates it in /IWFND/MAINT_SERVICE with Add Service.
  3. Give the user read-only roles. Create a role from the SAP Gateway user templates /IWFND/RT_GW_USER and /IWBEP/RT_MGW_USR. Add the authorisation object P_ORGIN (HR: Master Data) with authorisation level R (read) for the infotypes the service reads, and nothing that allows changes.
  4. Limit it to the people in scope. Restrict P_ORGIN by Personnel Area, Employee Group or Employee Subgroup, or assign a structural profile in OOSB, so the user can only read employees who should be in MuchSkills.
  5. Make the service reachable over HTTPS. Publish it through SAP Web Dispatcher or your own reverse proxy, and allow access only from the addresses agreed with MuchSkills. Choose an X.509 client certificate or a password for the integration user.
  6. Note the connection details. The service address, in the form https://yourhost/sap/opu/odata/sap/yourservice, the integration user, and its certificate or password.

With MuchSkills

  1. Send us the connection details. The credentials and connection details from the steps above, your field list and your scope, through a secure channel we agree.
  2. Join the technical session. Your SAP ERP HCM administrator and our CTO map the fields and test the connection together.
  3. Check a first sync. We sync a handful of people or one department. You check their names, managers, departments and any tags in MuchSkills.
  4. Widen the scope. We switch the sync on for everyone in scope. From then on it runs every 5 hours.

Check it worked

  • Team/Org › Members lists the people in scope.
  • The people in scope have an invitation to create their MuchSkills profile.
  • Managers see their direct reports in My Circle.

What you get

  • SAP ERP HCM stays the source of truth. People data is entered once, in SAP ERP HCM, and MuchSkills follows.
  • A skills layer on your HR system. Skills, certifications and project history sit next to the people records you already trust.
  • Clean data for planning. Reporting lines, departments and tags arrive ready for filtering, gap analysis and Team Builder.

Important to know

What syncs. Only name and email are required. Sync as many of the other fields as you can, because each one makes MuchSkills more useful.

FieldNeededUsed for
First and last nameRequiredProfiles, search, every view
EmailRequiredMatching and sign-in. Must be the address people sign in with
Job titleRecommendedProfiles, roles, Discover
ManagerRecommendedReporting lines, My Circle, reports. MuchSkills maps it from SAP ERP HCM automatically
DepartmentRecommendedDepartments and filters
Employee statusRecommendedDeactivating leavers
Location or countryRecommendedFilters and scoping
Profile photoRecommendedProfiles and the org chart
Worker typeRecommendedFiltering, for example employee or contractor
AbsenceRecommendedAvailability in Team Builder and My Circle. Dates and percentages only
Other fieldsOptionalAny field can become a filterable tag, for example legal entity, team or cost centre. Agree them with us first

Data MuchSkills does not accept. These are blocked when data arrives and never stored, even if the source includes them: age or date of birth, salary or other compensation data, performance ratings, and political, religious or health data.

Who is included. Limiting what the integration user can see in SAP ERP HCM is the preferred way, so nothing outside your scope leaves your system. The fallback is a country filter in MuchSkills; records outside it are ignored and not stored. Your security or compliance team decides which fits your rules.

Leavers are deactivated, not deleted. Project history and certificates stay on record.

Our IP addresses. MuchSkills always connects from the same two addresses: 13.51.77.53 and 16.170.107.61. If SAP ERP HCM or your network limits access by IP address, add both to the allow list.

Troubleshooting

What you seeWhyWhat to do
Some people are missingThey are outside what the integration user can see in SAP ERP HCM, or outside the scope filterCheck the integration user's permissions and the scope
Managers are missing or wrongThe manager is outside the scope, or has no manager set in SAP ERP HCMCheck that every manager is in scope and that reporting lines are filled in in SAP ERP HCM
A person appears twiceTheir SAP ERP HCM email differs from the address they signed up withAlign the email in SAP ERP HCM, then contact support
The connection is refusedSAP ERP HCM or your network limits access by IP addressAdd 13.51.77.53 and 16.170.107.61 to the allow list
The sync stoppedThe service user's certificate or password changed, or the service was movedRenew the access in SAP ERP HCM and send us the new details securely
SAP ERP HCM is not listed in MuchSkills, or shows as Contact us. Can we still connect it?

Yes. SAP ERP HCM is connected as a custom set-up rather than from a form, because every installation is configured differently. Email support@muchskills.com or use the chat, and we book the technical session.

Do we need middleware or an integration platform?

No. MuchSkills reads directly from SAP ERP HCM over HTTPS. Your team only creates the read-only access described on this page.

Can we leave out some countries, companies or groups?

Yes. The preferred way is to limit what the integration user can see in SAP ERP HCM, so only people in scope ever leave your system. If that is not possible, MuchSkills can filter by country as records arrive and ignore the rest without storing them.

Can we test with a few people first?

Yes. The first sync can be limited to a handful of people or one department. You check the result, then we widen the scope. There are no separate test tenants.

How often does it sync?

Every 5 hours. An Owner or Admin can also run a sync at any time with Sync Now.

What happens to people who leave?

They are deactivated at the next sync, never deleted. Their project history and certificates stay on record, which matters for compliance.

Do you import absence reasons?

No. If you sync absence, MuchSkills takes only the dates and the percentage of time away. Reasons such as sick leave are never imported.

How do we send the credentials safely?

Through a secure channel we agree with you in advance, such as a password manager share. Never by plain email.

Checking Daniel’s calendar...

Ask us anything

A real person replies, usually the same working day.

Live webinar · 13 Oct, 17:00 CEST

How to analyse the Skill Gaps in your organisation

MuchSkills allows organisations to conduct an in-depth skills gap analysis in a matter of minutes and uncover the skill gaps that hurt organisational performance In this webinar, you will learn how t…