Anda di halaman 1dari 18

Role Base Security

User

RBAC

Abstract Roles

Predefined Job Roles

Already Supplied

Role Types

Data Roles

Abstract roles
Job Roles

Aggregate Privilages

Duty Role

Duty Roles vs Aggregate Privilage

Role Inheritance
Component of Duty Roles

Duty Role: Manage Work Structure


Data Security Policy
Predefine Duty Roles

Activity: Custom HR Specialist Role


no access to Manage WorkStructure

Custom Line Manager does not have


comp management Privilages

All predefined Role


In cloud Users have roles via which they access Function and Data
Role

Role Base Access Control


Who
What (Do:Function)
Which Data

Contingent Worker
Pending Worker
Employee
Line Manager
Executive Manager
Hiring Manager
Job Application Identity for Recruiting

Payroll Manager, Payroll Admin, HR Specialist etc

Oracle HCM Cloud Security Reference Implementation


Abstract Roles
Application Implementation Consultant
IT Security Manager

Data Roles
Job Roles
Duty Roles
Abstract Roles
Aggregate Privilages

It combines worker's job and data that users with job must access.You define scope in
one/more HCM Security profiles.
Not part of Oracle HCM Cloud Security Reference Implementation, defines all roles locally and
assign them directly to users

Represents worker role in enterprise independently of the job that you hire the worker to do.
Theree main Employee, Line Manager & contingent Worker.
All workers are likely to have at least one abstract role.
Enables user to access standard functions such as managing their own info, searching worker
directory
Can Assign Abstract role directly.

e.g. Payroll Manager, HR Admin


Typically we assign it to data role and data role to user.
IT Security Manager, Implementation Consultant are Job exception as Job role we assign
directly.

Functional Privilage for an individiual task (duty) + Relevant Data Security Policies

Does not inherit other roles.


All are predifined and can not edit them.
You can club in custom job role, abstract role and duty roles.
Can not assign directly to user.

Predefined duty roles is logical grouping of privilages that you many want to copy and edit.

Editable vs Non Editables


Can inherit other privilage and duty roles vs can not
Can create new vs Can not create

Data Role Inherits Job Roles.

Job Role or Abstract roles can inherits few Duty Roles many aggregate Privilages.

Job and Abstract roles = Duty +Aggregate privilages + Functional Security Privilage and Data
Security policies directly
Function Security Privilages
Data Security Policies
May also inherits other duty roles and aggregate privilages

Manage Location, Manage Assignment Grade, Manage Job


Data Security Policies can be granted to Job Role, Abstract Role or aggregate privilages
A data security privilege that defines permitted actions on the data. For example,
Manage Assignment Grade is a data security privilege.
Logical grouping of aggregate privilage

Solution: Copy existing HR Specialist and remove manage work structure duty

Solution: Copy delivered Line manager and remove comp privilage

Prefix ORA_
Function
Data
Job and abstract roles may inherit duty roles either directly or indirectly.
Uses:

Review role hierarchy of any job, abstract, or duty roles


Extract Role Hierarchy to a spreadsheet
Identify the Data Security Policies and Function Security Privilages
Compare Roles to identify difference

Search Role
Edit Role
Copy role
Simulate Navigator
Compare Role
urity Privilages

Task Can be performed:


Create Implementation Users
Manage Applications Security Preferences
Manage Duties
Manage Job Roles
Revoke Data Role from Implementation Users
https://docs.oracle.com/en/cloud/saas/global-human-resources/19a/ochus/an-introduction-to-hcm-security-in-the-cloud.htm
o-hcm-security-in-the-cloud.html#OCHUS1212311
Reports

User and Role Access Audit Reports


XML format report identifies Function Security privilage and Data Security
Policies for specified role, all roles, a specified User or all users

Anda mungkin juga menyukai