Authorization Policy Management Authorization Policies for Oracle Identity Manager Features

15-26 Oracle Fusion Middleware Users Guide for Oracle Identity Manager – Job Modify – Job pause – Job Resume – Job run now – Job Search – Job stop – Reset Status – Scheduler Search – Scheduler Start – Scheduler Stop – Trigger Create – Trigger Delete – Trigger Modify These permissions do not support fine-grained attribute-level controls. ■ Data security: None ■ Description: Allows users with the SYSTEM ADMINISTRATORS or SCHEDULER ADMINISTRATORS role to access all scheduler actions.

15.3.8 Request Template Management

Any user with the REQUEST TEMPLATE ADMINISTRATORS role has access to all management operations related to request templates, such as creating, deleting, modifying, and searching request templates. For information about the default authorization policy, see Request Creation By Using Request Templates on page 15-26.

15.3.9 Request Creation By Using Request Templates

Each request template can be associated with a set of roles. Only the users with any of these roles are able to create a request by using this template. When a new request template is created with a list of associated roles, a new authorization policy is created internally. In addition, if the role association with any of the existing request templates is modified adding new roles or removing existing roles, then the existing authorization policy for this template is modified. The default authorization policy for creating requests by using request template allows users with the REQUEST TEMPLATES ADMINISTRATORS role to access all operations related to request templates. The policy has the following details: ■ Policy name: Request Template Administration Policy ■ Assignee: REQUEST TEMPLATE ADMINISTRATORS role ■ Functional security: The permissions are: – Create See Also: Chapter 17, Managing Request Templates for information about creating and managing request templates for request creation Managing Authorization Policies 15-27 – Delete – Modify – Search These permissions do not support fine-grained attribute-level controls. ■ Data security: None ■ Description: Allows users with the REQUEST TEMPLATE ADMINISTRATORS or SYSTEM ADMINISTRATORS role to access all request template actions.

15.3.10 Approval Policy Management

The default authorization policy for the approval policy management feature allows users with the APPROVAL POLICY ADMINISTRATORS role to access all approval policy management operations. This policy has the following details: ■ Policy name: Approval Policy Management Policy ■ Assignee: APPROVAL POLICY ADMINISTRATORS role ■ Functional security: The permissions are: – Create – Delete – Modify – Search These permissions do not support fine-grained attribute-level controls. ■ Data security: None ■ Description: Allows users with the APPROVAL POLICY ADMINISTRATORS or SYSTEM ADMINISTRATORS role to access all approval policy management actions.

15.3.11 Notification Management

The default authorization policy for the notification management feature allows users with the NOTIFICATION TEMPLATE ADMINISTRATORS role to access all notification management operations. This policy has the following details: ■ Policy Name: Notification Management Administration Policy ■ Assignee: System Administrators and NOTIFICATION TEMPLATE ADMINISTRATORS roles ■ Functional security: The permissions are: – Add Locale – Create See Also: Chapter 18, Managing Approval Policies for information about the approval policy management feature See Also: Managing Notification Templates in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager for information about the notification management feature