Hey Sven,
Thanks for your suggestion. We already tried the P_ABAP solution. But P_ABAP only works for reporting where a read authorization can be bypassed without granting direct info type level access. However for update transaction like PU00, P_ABAP doesn't help.
I totally agree with your feedback that only 2-3 ppl should have this access. But our management is reluctant to grant all info type access to a single user. That's why we are checking for other options, if any.
Regards,
Debajit