Xalco Roles Roles and Permissions Table Roles and Users Table Accounts and Users Table

5-50 Oracle Fusion Middleware System Administrators Guide for Oracle Content Server

5.5.3.2 Xalco Accounts

Access varies by location and job function, so this is reflected in the account structure: ■ London has Finance and Sales departments, so it needs two accounts: – LondonFinance – LondonSales ■ New York has only a Finance department: – NewYorkFinance ■ Paris has both Finance and Sales departments: – ParisFinance – ParisSales This results in three top-level accounts London, NewYork, Paris and five lower-level accounts.

5.5.3.3 Xalco Roles

Two roles must be created for each security group one for Consumers and one for Contributors ■ PublicConsumer ■ PublicContributor ■ InternalConsumer ■ InternalContributor ■ SensitiveConsumer ■ SensitiveContributor ■ ClassifiedConsumer ■ ClassifiedContributor

5.5.3.4 Roles and Permissions Table

To give specific users the ability to start workflows, you would need to add Admin permission and Workflow rights to the Contributor role. Role Public Internal Sensitive Classified PublicConsumer R PublicContributor RWD InternalConsumer R InternalContributor RWD SensitiveConsumer R SensitiveContributor RWD ClassifiedConsumer R ClassifiedContributor RWD Managing Security and User Access 5-51

5.5.3.5 Roles and Users Table

5.5.3.6 Accounts and Users Table

It would be sufficient to give David Smith RWDA permission on London, New York, and Paris accounts.

5.6 Access Control List Security

In addition to the standard Oracle Content Server security roles, security groups, and accounts, the Oracle Content Server system can be configured to support access control lists ACLs. An access control list is a list of users, groups, or enterprise roles with permission to access or interact with a content item. When access control list security is configured, three new fields are available for use in several locations in the interface, including checking in content items, updating content items, and searching for content items. The fields are: ■ User Access List ■ Group Access List ■ Role Access List After the access control list security feature is configured for the Oracle Content Server system, you can use Oracle Platform Security Services OPSS to manage the access control lists, including the Oracle Access Manager Authentication provider, which works with the Oracle WebLogic Server domain. For information, see Oracle Fusion Middleware Application Security Guide and Oracle Fusion Middleware Administrators Guide for Oracle Internet Directory. Oracle Content Server access control lists are supported in Oracle Secure Enterprise Search, and users can perform searches using access control list information. For more information, see Section 7.2, Oracle Secure Enterprise Search. Role David Smith Helene Chirac Jim McGuire Catherine Godfrey PublicConsumer X PublicContributor X X X InternalConsumer X InternalContributor X X X SensitiveConsumer SensitiveContributor X X X ClassifiedConsumer ClassifiedContributor X X X Account David Smith Helene Chirac Jim McGuire Catherine Godfrey LondonFinance RWDA R R LondonSales RWDA RWDA NewYorkFinance RWDA RW ParisFinance RWDA R ParisSales RWDA R