Role Category Entity Role Entity Definition

Managing Roles 12-9 SOD ADMINISTRATORS Members of this role can claim a SoD check task and approve it. Default approval tasks are assigned to this role. SELF OPERATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. It contains one user, XELSELFREG, who is responsible for modifying the privileges that users have when performing self-registration actions within Oracle Identity Manager. Note: Oracle Identity Manager recommends that you do not modify the permissions associated with the SELF OPERATORS user role. In addition, you should not assign any users to this role. SCHEDULER ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. The user with this role can perform all scheduler jobs administration. ROLE ADMINISTRATORS Members of this role have access to the UI to administer and manage roles in Oracle Identity Manager. RESOURCE ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to manage resources. REQUEST TEMPLATE ADMINISTRATORS The user with this role can perform all request template administration. REQUEST ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage requests. REPORT ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to manage reports in BI Publisher. RECONCILIATION ADMINISTRATORS The user with this role can perform reconciliation administration. PLUGIN ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Member of this role have permissions to register and unregister plugins to Oracle Identity Manager. OPERATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the pages related to organizations, users, and Task List. These users can perform a subset of functions on these pages. NOTIFICATION TEMPLATE ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to create and manage notification templates. IT RESOURCE ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to create and manage IT resources. IDENTITY USER ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage users in Oracle Identity Manager. IDENTITY ORGANIZATION ADMINISTRATORS Members of this role have access to the UI to perform various tasks to create and manage organizations in Oracle Identity Manager. Table 12–5 Cont. Default Roles in Oracle Identity Manager Role Description 12-10 Oracle Fusion Middleware Users Guide for Oracle Identity Manager You can modify the permissions associated with the default roles. You can also create additional roles. However, you cannot assignremove menu items tofrom any roles.

12.5 Role Management Tasks

This section discusses the following topics: ■ Creating Roles ■ Managing Roles ■ Creating and Managing Role Categories GENERIC CONNECTOR ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to configure generic connectors. DEPLOYMENT MANAGER ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the Deployment Manager to import and export deployment configurations from an Oracle Identity Manager deployment to another. Administrators This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. It is the administrators role for SOA. ATTESTATION EVENT ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to manage attestation events. ATTESTATION CONFIGURATION ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to configure attestation. APPROVAL POLICY ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role have access to the UI to perform various tasks to create and manage approval policies. ALL USERS Members of this role have minimal permissions, including the ability to access the users own user record. By default, each user belongs to the All Users role. ACCESS POLICY ADMINISTRATORS This role is for internal use only, meaning it is for OIM users and other users can only view it on UI. Members of this role can access the UI to perform various tasks to manage access policies. Table 12–5 Cont. Default Roles in Oracle Identity Manager Role Description