About Users and Groups

Identity domain administrators use Oracle Cloud Infrastructure Console to manage users and create user groups for Oracle Analytics Cloud.

After identity domain administrators create user accounts in Oracle Cloud Infrastructure Console, Oracle Analytics Cloud administrators use the Roles and Permissions page in Oracle Analytics Cloud to assign permissions to individual users or groups through application roles. See About Application Roles and Add Members to Application Roles.

About User IDs in Oracle Analytics Cloud

Oracle Analytics Cloud identifies each user by a user ID. In most environments, the user's email address is the user ID.

Oracle Analytics Cloud doesn't associate a user ID with a unique identifier, such as a globally unique identifier (GUID). The tenancy and identity domain aren't part of the user's identity. This design supports migration between Oracle Analytics Cloud environments. When you migrate between environments, Oracle Analytics Cloud preserves references to users by user ID.

For example, Oracle Analytics Cloud treats joe.bloggs@example.com in one environment as the same user as joe.bloggs@example.com in another environment, regardless of the tenancy or identity domain.

Avoid Reusing User IDs

Oracle Analytics Cloud identifies users by user ID. Therefore, reusing a user ID for a different person can result in unintended access.

For example, suppose a user with the user ID joe.bloggs@example.com leaves your organization. If you later assign the same email address and user ID to another person, Oracle Analytics Cloud doesn't distinguish the new user from the previous user.

In this scenario, the new user might inherit access to objects, permissions, and functionality that Oracle Analytics Cloud granted to the previous user unless you remove those grants.

Assign Unique User IDs

Assign each new user a user ID that hasn't previously been assigned to another person. This practice reduces the risk of unintended access.

Email addresses are commonly used as user IDs. Don't reassign an email address that was previously used as an Oracle Analytics Cloud user ID.

Remove Grants and Permissions for Former User IDs

As part of your user offboarding process, remove grants and permissions assigned to users who leave your organization.

Add a User or a Group

Identity domain administrators use Oracle Cloud Infrastructure Console (OCI Console) to add users and assign them to suitable user groups. See Set Up Users and Groups.

Understand How Predefined Application Roles in Your Identity Domain Work in Oracle Analytics Cloud

Your identity domain administrator sets up users and groups for Oracle Analytics Cloud.

Oracle recommends that you assign users to groups in your identity domain and then assign the groups to Oracle Analytics Cloud application roles. This best practice approach, avoids assigning users directly to the predefined identity domain roles described here.

However for convenience, identity domain administrators can assign users and groups to these predefined identity domain application roles:
  • ServiceAdministrator
  • ServiceUser
  • ServiceViewer
  • ServiceDeployer
  • ServiceDeveloper
An Oracle Analytics Cloud administrator (not the identity domain administrator) can then assign these roles to user-defined application roles in Oracle Analytics Cloud.

Note:

Identity domain administrators can't create additional identity domain application roles for the Oracle Analytics Cloud service and assign them to application roles in Oracle Analytics Cloud. For this purpose, Oracle Analytics Cloud supports only ServiceAdministrator, ServiceUser, ServiceViewer, ServiceDeployer, and ServiceDeveloper.

Predefined Identity Domain Application Roles

The following table describes the predefined identity domain application roles available in Oracle Cloud Infrastructure Console for an Oracle Analytics Cloud service and their default permissions in Oracle Analytics Cloud.

Predefined Identity Domain Application Role Default Application Role Membership in Oracle Analytics Cloud Default Permissions

ServiceAdministrator

  • BI Service Administrator
  • BI Data Model Author
  • BI Data Load Author

Administer Oracle Analytics Cloud and delegate privileges to others.

The user who creates the service is automatically assigned this application role.

ServiceUser

  • BI Content Author
  • DV Content Author

Create and share content.

ServiceViewer

  • BI Consumer
  • DV Consumer

View and explore content.

ServiceDeployer

None None assigned.

ServiceDeveloper

None None assigned.

This image shows the predefined application roles available for your Oracle Analytics Cloud service in your identity domain.


Predefined application roles available in your identity domain