Set up a HCM authorization soultion, where you decide when structure authorizations are part of the context or not. The business roles have different security needs. You can with this solution decide when structural authorizations are used.
The business roles have different needs for segregation, some roles such as payroll needs a segregation on country level, other roles needs an segregation based on the organisational structure.   The Business Needs The business needds different segregation options for differnt business roles. For payroll roles you will normal see a segregration on the country level. For other roles such as for managers or HR business partners you will see a segregation based on the organisational structure where sectors or divisions dictates what a user is allowed to access or not. But with the restriction of structural profiles we have issues with expatriate and departments which is cross country based. To grant access to employees who for what ever reason is not assigned in the supposed sector or division will end up with a ticket stating the personnel administration does not have access. The use of more and more matrix based organisations gives issues for segregation because it demands a high flexibilkity on the security concept. especially for those who is using the context based authorizations (where normal roles are combined with structural authorizations) The Technical Solution In SAP HCM we have two options as primary authorization object for segregation. The P_ORGIN which is the old authorization object for HCM based on infotype, subtype, personnel area, employee group and subgroup + organisational key. The new authorization objects P_ORGINCON is the context specific where an additional filed has been added. This field is the structural profiles. Whit this set up you can control the access of specific infotype, subtype, employee group, subgroup, pers. area, org key together with the exact objects delivered from a specific structural profile. So you can have many structural profiles assigned to your user but for the P_ORGINCON it is only the profile entered and those objects the profile is delivering, which will be used in the specific P_ORGINCON object. We have in TORC: the OneRoleConcept created an solution for the payroll, compensation,  and time administrators who needs access to run RPCALC, PECM_CREATE_0758 - Create Compensation Program Records or RPTIME00 time evaluation for employees restricted to certain sites or regions with no restriction from where the employees are assigned in the organisational structure. This set up allows you to switch off the structural authorizations for those business roles where you don’t need this check or where the structural athorizations are a burden. At the same time it allows you to use a full blown context based authorization control with structural authorizations for those business roles where this is needed so the solution is highly flexible and does not restrict you from using the structural control at all.
