Monitoring Oracle BAM Performance

Managing Oracle Business Activity Monitoring 24-5 The enterprise-level roles are global to Oracle WebLogic Server, and they are applicable to all applications running on that server, including Oracle BAM. The application-level roles are specific to each application. See Section 24.3.5, Configuring Oracle WebLogic Server Embedded LDAP Server for example instructions about using Oracle WebLogic Server Administration Console to create users and groups.

24.3.2 Using Previously Seeded Group Members

The following Oracle WebLogic Server groups have been previously seeded in the Oracle BAM application policy: ■ BamAdministrators: Member of application role Administrator. ■ BamReportArchitects: Member of application role Report Architect. ■ BamReportCreators: Member of application role Report Creator. ■ BamReportViewers: Member of application role Report Viewer. Note: When you delete a user you cannot re-use that user name until you resolve the old instance with Oracle BAM. Oracle BAM will mark the deleted user inactive when you delete the user in Oracle WebLogic Server. If you attempt to reuse the same user name for a new account, Oracle BAM does not consider the newly added user to be the same user as the one previously deleted. You must delete the original user from Oracle BAM using Oracle BAM Administrator and optionally transfer the user’s Oracle BAM objects to another valid user. Once the inactive user is removed from Oracle BAM you can reuse the user name. See Section 24.3.8, Removing Invalid Users from Oracle BAM Administrator for information about removing users from Oracle BAM. 24-6 Oracle Fusion Middleware Administrators Guide for Oracle SOA Suite and Oracle BPM Suite These members are a convenience. If you define these groups in your configured security provider, you can then assign Oracle BAM application-level roles to specific users and groups by placing them into these groups. All of this can be done from your security provider and does not require any Oracle BAM application policy modifications. You must create these groups manually in the security provider because Oracle BAM does not automatically seed users or groups in the configured security provider.

24.3.3 Adding Members to Application Roles

The Oracle BAM application policy defines the Oracle BAM application-level roles described in Section 24.3.4, Introduction to Oracle BAM Application Roles including role membership. The Oracle BAM application policy is managed in Fusion Middleware Control. The default policy store provider is the XML file-based policy store. To add members to the Oracle BAM application-level roles, you must add entries to the membership list of the desired role using Fusion Middleware Control. Shown here is the navigation required to open the Oracle BAM Application Roles page in Fusion Middleware Control: Managing Oracle Business Activity Monitoring 24-7 Select a role in the Role Name list: Add a member to the role: