Role Entity Role Entity Definition

12-8 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

12.3.4 Role Parent Relationship

The RoleUserMembership.xml file contains the attribute definitions for role parent relationship. You cannot add your own attributes to the role parent relationship. Table 12–4 lists the default attributes for the role parent relationship.

12.4 Default Roles

Table 12–5 lists the default roles in Oracle Identity Manager: Table 12–4 Default Attributes for Role Parent Relationship Attribute Name Category Type Data Type Properties LOV UGP_KEY Basic Single Reference to role Required: Yes System-Can-Default: No System-Controlled: No Encryption: Clear User-Searchable: Yes Bulk-Updatable: No NA GPG_UGP_KEY Basic Single Reference to role Required: Yes System-Can-Default: No System-Controlled: No Encryption: Clear User-Searchable: Yes Bulk-Updatable: No NA Note: UGP_KEY is a reference to the parent role. GPG_UGP_KEY is a reference to the child role. Table 12–5 Default Roles in Oracle Identity Manager Role Description USER CONFIGURATION ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage entity attributes for user management. SYSTEM CONFIGURATION ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks related to system configuration, such as system properties, scheduled jobs, and notification templates. SYSTEM ADMINISTRATORS Members of this role have full permission to create, edit, and delete records in Oracle Identity Manager, except for system records. These users can control the permissions of other users, change the status of process tasks even when the task is not assigned to them, and administer the system from the highest level. USER NAME ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. SPML_App_Role This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to submit requests via the SPML interfaces. Managing Roles 12-9 SOD ADMINISTRATORS Members of this role can claim a SoD check task and approve it. Default approval tasks are assigned to this role. SELF OPERATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. It contains one user, XELSELFREG, who is responsible for modifying the privileges that users have when performing self-registration actions within Oracle Identity Manager. Note: Oracle Identity Manager recommends that you do not modify the permissions associated with the SELF OPERATORS user role. In addition, you should not assign any users to this role. SCHEDULER ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. The user with this role can perform all scheduler jobs administration. ROLE ADMINISTRATORS Members of this role have access to the UI to administer and manage roles in Oracle Identity Manager. RESOURCE ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to manage resources. REQUEST TEMPLATE ADMINISTRATORS The user with this role can perform all request template administration. REQUEST ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage requests. REPORT ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to manage reports in BI Publisher. RECONCILIATION ADMINISTRATORS The user with this role can perform reconciliation administration. PLUGIN ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Member of this role have permissions to register and unregister plugins to Oracle Identity Manager. OPERATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the pages related to organizations, users, and Task List. These users can perform a subset of functions on these pages. NOTIFICATION TEMPLATE ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to create and manage notification templates. IT RESOURCE ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to create and manage IT resources. IDENTITY USER ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage users in Oracle Identity Manager. IDENTITY ORGANIZATION ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage organizations in Oracle Identity Manager. Table 12–5 Cont. Default Roles in Oracle Identity Manager Role Description