Deleting Roles Managing Roles

12-16 Oracle Fusion Middleware Users Guide for Oracle Identity Manager You can also open the roles that are linked parent and child roles like grand parents and grand child roles of the current opened role with the Open Role link in Inherited From and Inherited By section of the Hierarchy tab respectively. To open a parent role: 1. In the Inherited From section of the Hierarchy tab, select the role that you want to open.

2. From the Actions menu, select Open Open Role Detail. Alternatively, click Open

Open Role Detail on the toolbar. A page with details about the inherited role is displayed. In this page, you can view and edit the role attributes, and modify the role inheritance and membership, assign and remove membership rules, access policies and permissions, update permissions and also to view the menu items assigned. To open a child role: 1. In the Inherited From or Inherited By section of the Hierarchy tab, select the role that you want to open.

2. From the Actions menu, select Open Open Role Detail. Alternatively, click Open

Open Role Detail on the toolbar. A page with details about the inherited role is displayed.

12.5.2.4.6 The Members Tab The Members tab displays the members assigned to the

open role. This information is displayed in the following sections: ■ All Members: This section displays all the members, direct and indirect, assigned to the open role. ■ Direct Members: This section displays the members that are directly assigned to the open role. It also displays all members that are assigned via membership rules. ■ Indirect Members: This section displays the members that are indirectly inherited by the role. In the Members tab, you can perform the following: ■ Assigning Members to a Role ■ Revoking Members from a Role ■ Opening Member Details

12.5.2.4.7 Assigning Members to a Role

To assign members to a role:

1. In any section of the Members tab, from the Actions menu, select Assign Assign

Users. Alternatively, click Assign User to on the toolbar. The Assign User to: dialog box is displayed. 2. Search for users by specifying a search criterion in the Search Users field and clicking the search icon. The list of users that matches your search criterion is displayed in the Available list. 3. Select one or more users that you want to assign to the open role. Then, click Move or Move All to move the selected users to the Selected list. Note: An indirect member can be assigned as a direct member. Managing Roles 12-17

4. Click Save. If the XL.RM_REQUEST_ENABLED and

XL.RM_ROLE_ASSIGN_TEMPLATE system properties are set, then after clicking Save, a confirmation message is displayed in the role details page along with the request ID. Otherwise, only a confirmation message is displayed. If a request is created, then the users are displayed as members in the Direct Members section only after the request is approved. Otherwise, the users are displayed as members immediately in the Direct Members section. Also, note that the users are displayed in the All Members section.

12.5.2.4.8 Revoking Members from a Role

To revoke members from a role: 1. In any section of the Members tab, select the member that you want to revoke.

2. From the Actions menu, select Revoke Revoke Members. Alternatively, click

Revoke Members from: on the toolbar. The Revoke User from: dialog box is displayed. 3. Search for members by specifying a search criterion in the Search Users field and clicking the search icon. The list of members that matches your search criterion is displayed in the Available list. 4. Select one or more members that you want to revoke from the open role. Then, click Move or Move All to move the selected members to the Selected list.

5. Click Save. A confirmation message is displayed on the role details page.

6. The members that you have revoked are removed from the list of members in the Members tab.

12.5.2.4.9 Opening Member Details

To open the member user details of the open role: 1. In any section of the Members tab, select the member whose details you want to open.

2. From the Actions menu, select Open Open Member Detail. Alternatively, click

Open User on the toolbar. The user details page for the member is displayed that allows you to view and modify the member details. Tip: ■ If the member users are not displayed in the Members tab immediately after they are added, then refresh the view. ■ If users are created or updated to match membership rules criteria, then they are assigned directly to this role and the table must be refreshed to view those members in both sections, All Members and Direct Members. Note: Only direct members can be revoked except for the members that are assigned via membership rules.