Viewing, Assigning, and Revoking Access Policies

Managing Roles 12-21

12.5.2.8.2 Explicit Permission Not Required

Data objects for which explicit permission is not required are the ones for which permissions do not need to be defined because either there are no permissions enforced or they simply follow parent data object permissions. Data objects that use parent data object permissions follow a simple paradigm that if a role has update permissions on a parent data object, the same role will have insert, update, and delete permissions on child data objects. Explicit permissions are required only for the objects mentioned in Table 12–7, Data Objects Requiring Explicit InsertUpdateDelete Permissions . The rest of the data objects either have derived or implicit permissions. While assigning data objects or fine-grained permissions to roles, Oracle Identity Manager uses the following permission model: ■ To modify an insert data permission, a user who is logged in must have the insert and update permissions. ■ To modify an update data permission, a user who is logged in must have the update permissions. ■ To modify a delete data permission, a user who is logged in must have the insert, update, and delete permissions. com.thortech.xl.dataobj.tcRUE Rule Element com.thortech.xl.dataobj.tcSDC User defined columns on system user-defined forms com.thortech.xl.dataobj.tcSDH Parent child hierarchy of user defined forms com.thortech.xl.dataobj.tcSDL Form Definition Version Label com.thortech.xl.dataobj.tcSDP Form Definition Properties com.thortech.xl.dataobj.tcSPD IT Resources Type Parameter Definition com.thortech.xl.dataobj.tcSRE Association between user defined columns and pre-populate adapters com.thortech.xl.dataobj.tcSRS IT Resource Link com.thortech.xl.dataobj.tcSUG IT Resources Administrators com.thortech.xl.dataobj.tcSVD IT Resources Type Definition com.thortech.xl.dataobj.tcTDV Process Event Handlers com.thortech.xl.dataobj.tcTLG System Log com.thortech.xl.dataobj.tcTSA Schedule Task Attributes com.thortech.xl.dataobj.tcTSK Scheduled Tasks com.thortech.xl.dataobj.tcUHD Users Objects History Details com.thortech.xl.dataobj.tcUPL User Defined Field Lookups com.thortech.xl.dataobj.tcUPT User Defined Field Values com.thortech.xl.dataobj.tcUPY System Configuration Users com.thortech.xl.dataobj.tcWIN Form Information Table 12–7 Cont. Data Objects Requiring Explicit InsertUpdateDelete Permissions Data Object Type Entities