HANA Security: Roles, Privileges & Data Masking
Catalog and analytic privileges, role-based access control, and dynamic data anonymization/masking in HANA.
HANA security is a distinct topic from ABAP's PFCG authorization concept, and interviewers who ask about it specifically want to confirm a candidate understands database-level access control as its own discipline - relevant for BW/4HANA administrators, HANA-native application developers, and anyone responsible for a side-by-side HANA system where ABAP's authorization layer doesn't apply at all.
Object privileges are like a building's master keys controlling which rooms (tables/views) you can enter at all; analytic privileges are like a shared open-plan office where everyone has room access but each desk's monitor only displays that specific employee's own assigned files; dynamic data masking is a privacy screen over specific sensitive documents on every desk, blurring only the sensitive parts even for people who are otherwise allowed in the room.