Sun Identity Manager Deployment Guide

Authorization Subtype Permissions

Identity Manager uses the extends attribute to define the supertype of an authorization type. Supertype permissions are inherited by the subtype. For example, if a user has view rights on TaskDefinition, they would also have view rights on UsageReportTask and all other subtypes of TaskDefinition.

Although you can edit the AuthorizationTypes object only in XML, you can define permissions that reference authorization types from the Capability page. (You can access this page under the Capabilities subtab of the Security tab.)