Activity Auditing Resources
An administrator in Oracle Cloud Infrastructure Identity and Access Management (IAM) can grant permissions as needed on the following Activity Auditing resources. As an alternative to selectively granting permissions, you can grant permissions on data-safe-audit-family in the relevant compartments, which would include permissions on all of the resources below and target registration permissions.
data-safe-reportsResource (see Common Resources)data-safe-report-definitionsResource (see Common Resources)data-safe-work-requestsResource (see Common Resources)
data-safe-audit-family Resource
The data-safe-audit-family resource represents all Oracle Data Safe resources that pertain to Activity Auditing. The resources are as follows:
- data-safe Resource
- data-safe-private-endpoints Resource
- onprem-connectors Resource
- data-safe-work-requests Resource
- target-databases Resource
- target-database-group Resource
- data-safe-report-definitions Resource
- data-safe-reports Resource
- data-safe-audit-profiles Resource
- data-safe-audit-trails Resource
- data-safe-audit-events Resource
- data-safe-archive-retrievals Resource
- data-safe-audit-policies Resource
- data-safe-unified-audit-policies Resource
- data-safe-unified-audit-policy-definitions Resource
- data-safe-attribute-sets Resource
- data-safe-security-policies Resource
- data-safe-security-policy-configs Resource
- data-safe-security-policy-deployments Resource
The following table describes the permissions that you can assign to a group for the data-safe-audit-family resource.
| Permission | Description |
|---|---|
inspect |
The user group can list all Activity Auditing resources in a specified compartment. |
read or use |
The user group can list and view properties for all Activity Auditing resources in a specified compartment. |
manage |
The user group can do the following:
|
data-safe-archive-retrievals Resource
The data-safe-archive-retrievals resource represents
archive data retrieval objects in Activity Auditing.
The following table describes the permissions available for the
data-safe-archive-retrieval resource.
| Permission | Description |
|---|---|
inspect |
The user group can list archive data retrievals. |
read or use |
The user group can list and view details for archive data retrievals. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) archive data retrievals. The group can also retrieve archive audit data and return it back to the archive. |
data-safe-audit-events Resource
The data-safe-audit-events resource represents audit
events for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-events resource.
| Permission | Description |
|---|---|
inspect |
The user group can list audit events. |
read |
The user group can list and view details for audit events. |
data-safe-audit-policies Resource
The data-safe-audit-policies resource represents audit
policies for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-policies resource.
| Permission | Description |
|---|---|
inspect |
The user group can list audit policies. |
read or use |
The user group can list and view details for audit policies. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) audit policies. |
data-safe-audit-profiles Resource
The data-safe-audit-profiles resource represents audit
profiles for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-profiles resource.
| Permission | Description |
|---|---|
inspect |
The user group can list audit profiles. |
read or use |
The user group can list and view details for audit profiles. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) audit profiles. A user can update the online and offline retention periods and paid usage setting. |
data-safe-audit-trails Resource
The data-safe-audit-trails resource represents audit
trails for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-trails resource.
| Permission | Description |
|---|---|
inspect |
The user group can list audit trails. |
read or use |
The user group can list and view details for audit trails. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) audit trails. |