Role Grant Relationship Role Entity Definition

12-10 Oracle Fusion Middleware Users Guide for Oracle Identity Manager You can modify the permissions associated with the default roles. You can also create additional roles. However, you cannot assignremove menu items tofrom any roles.

12.5 Role Management Tasks

This section discusses the following topics: ■ Creating Roles ■ Managing Roles ■ Creating and Managing Role Categories GENERIC CONNECTOR ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to configure generic connectors. DEPLOYMENT MANAGER ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the Deployment Manager to import and export deployment configurations from an Oracle Identity Manager deployment to another. Administrators This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. It is the administrators role for SOA. ATTESTATION EVENT ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to manage attestation events. ATTESTATION CONFIGURATION ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to configure attestation. APPROVAL POLICY ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to create and manage approval policies. ALL USERS Members of this role have minimal permissions, including the ability to access the users own user record. By default, each user belongs to the All Users role. ACCESS POLICY ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role can access the UI to perform various tasks to manage access policies. Table 12–5 Cont. Default Roles in Oracle Identity Manager Role Description Managing Roles 12-11

12.5.1 Creating Roles

When you first create a new role, the Role Details page shows the role name. You can add information to a role by using the Additional Detail menu as described in Managing Roles on page 12-12. To create a role:

1. Login to Oracle Identity Administration.

2. In the Welcome page, under Roles, click Create New Role.

Alternatively, in the Browse tab of the left pane, expand Roles, and from the Actions menu, select Create Role. Otherwise, click the Create Role icon on the toolbar. The Create Role page is displayed.

3. Enter values in the fields.

Table 12–6 lists the fields in the Create Role page. Note that Manage Localizations is displayed with the Display Name fields because these are multi-language fields. This means that you can enter and save attribute values in more than one language. Note: ■ A user cannot be removed from the All Users role. ■ A role, SELF OPERATORS, is added to Oracle Identity Manager by default. This role contains one user, XELSELFREG, who is responsible for modifying user permissions for performing self-registration in the Administration Console. Oracle recommends that you do not modify the permissions associated with the SELF OPERATORS role and do not assign users to this role. Table 12–6 Fields in the Create Role Page Field Description Role Name The name of the role Display Name The role name as displayed in the UI Email The e-mail ID of the role Description The description for the role Role Category The category to which the role belongs If a role category is not specified in this field, then the role is created in the Default category. See Creating and Managing Role Categories on page 12-22 for information about role categories. Owned By The owner of the role The role owner is a user who has permissions to view, modify, and delete the role without having to create custom authorization policies. See Managing Authorization for Roles on page 12-23 for information about authorization policies for role management.