In the left pane, click the Projects tab. Select the ApprovalProcess.bpel file under the DefaultRequestApproval project In the right pane, in the Component Palette, select the Java Embedding task, and Double-click the Invoke_OIM_API Java task. This opens

26-8 Oracle Fusion Middleware Developers Guide for Oracle Identity Manager Part VI Part VI Segregation of Duties This part contains a chapter describing segregation of duties SoD. It contains the following chapter: ■ Chapter 27, Using Segregation of Duties SoD 27 Using Segregation of Duties SoD 27-1 27 Using Segregation of Duties SoD The concept of Segregation of Duties SoD is aimed at applying checks and balances on business processes. Each stage of a business process may require the involvement of more than one individual. An organization can convert this possibility into a requirement for all IT-enabled business processes by implementing SoD as part of its user provisioning solution. The overall benefit of SoD is the mitigation of risk arising from intentional or accidental misuse of an organizations resources. This chapter contains the following sections: ■ Understanding the SoD Validation Process ■ Introducing the SoD Invocation Library ■ Installing the SoD-enabled Connectors ■ Deploying the SIL and SIL Providers ■ Configuring the SoD Engine ■ Enabling and Disabling SoD ■ Enabling SSL Communication ■ Configuring Workflows on Non SoD-enabled Connectors ■ Marking Fields as Entitlements ■ Custom Combination of Target Systems and SoD Engines ■ Performing Role SoD Check with Oracle Identity Analytics ■ Using SoD in Provisioning Workflow ■ Enabling Logging for SoD-Related Events ■ Troubleshooting SoD Check

27.1 Understanding the SoD Validation Process

Oracle Identity Manager is a user provisioning solution with which entitlement requests can also be validated and managed. In the Oracle Identity Manager implementation of SoD, user requests for IT privileges entitlements are checked and approved by an SoD engine and other users. Multiple levels of system and human checks ensure that even changes to the original request are vetted before the request is cleared. This preventive approach helps identify and correct potentially conflicting entitlement assignments before the requested entitlements are assigned. The SoD validation process in Oracle Identity Manager occurs when a user creates a request for an entitlement on a particular target system. The request is funneled