Create a Succession Plans Super User Job Role

In this example, you learn how to create a job role that provides access to all succession plans in the Succession Plans work area.

The following table summarizes key decisions for this scenario.

Decisions to Consider

In This Example

What's the name of the job role?

Succession Plans Super User Job

What's the code of the job role?

SUCCESSION_PLANS_SUPER_USER_JOB

What are the names of the data security policies?

  • Succession Plans Custom Policy

  • Succession Candidate Custom Policy

  • Succession Person Detail Custom Policy

What's the enterprise suffix for copied roles?

Custom

Is there an enterprise prefix for copied roles?

No

What's the name of the role mapping?

Access All Succession Plans

How do users acquire the role?

Users with the human resources representative responsibility can provision the role to other users.

Summary of the Tasks

Enable access to all succession plans in the Succession Plans work area by:

  1. Copying the predefined Succession Plan Management duty role and editing the copy

  2. Creating a job role

  3. Granting data security policies to the job role

  4. Creating a role hierarchy for the job role

  5. Creating a role mapping

  6. Optionally, editing the job role to enable access to Oracle Transactional Business Intelligence (OTBI) subject areas for Succession Management

Copy the Succession Plan Management Duty Role

You copy the predefined Succession Plan Management duty role and edit it to remove the existing data security policy.

  1. Sign in with the IT Security Manager job role or privileges and select Navigator > Tools > Security Console.

  2. On the Roles tab of the Security Console, search for the predefined Succession Plan Management (ORA_HRM_SUCCESSION_PLAN_DUTY) duty role.

  3. In the search results, select Copy Role on the role's Actions menu.

  4. In the Copy Options dialog box, select Copy top role and click Copy Role.

    On the Copy Role: Basic information page, the name of the copied role is Succession Plan Management Custom (HRM_SUCCESSION_PLAN_DUTY_CUSTOM).
  5. Click the Data Security Policies train stop.

    On the Data Security Policies page, the Grant on Succession Plan Detail policy is listed.
  6. On the Actions menu for the data security policy, click Remove Data Security Policy.

  7. In the Warning dialog box, click Yes.

  8. Click the Summary and Impact Report train stop.

  9. On the Summary and Impact Report page, click Submit and Close to create the duty role.

  10. Click OK to close the Confirmation dialog box.

Create a Job Role

You create the Succession Plans Super User Job role.

  1. On the Roles tab of the Security Console, click Create Role.

  2. On the Create Role: Basic Information page, enter the role name Succession Plans Super User Job.

  3. Enter the role code SUCCESSION_PLANS_SUPER_USER_JOB.

  4. In the Role Category field, select HCM - Job Roles.

  5. Click the Data Security Policies train stop.

Grant Data Security Policies to the Job Role

You create three data security policies for the Succession Plans Super User Job role.
  1. On the Data Security Policies page, click Create Data Security Policy to open the Create Data Security Policy dialog box.

  2. In the Create Data Security Policy dialog box, enter the policy name Succession Plans Custom Policy.

  3. Search for and select the database resource Succession Plan Detail (HRM_PLANS).

  4. Select All values in the Data Set field.

  5. Select these values in the Actions field:

    • Add Worker to Succession Plan

    • Create Succession Plan for Worker

    • Manage Succession Plan

    • View Succession Plan

  6. Click OK to close the Create Data Security Policy dialog box.

  7. Repeat from step 1 to create two further data security policies. Complete the fields as shown in this table.

    Policy Name

    Database Resource

    Data Set

    Actions

    Succession Candidate Custom Policy

    Succession Plan Candidate (HRM_PLAN_CANDIDATES)

    All values

    • Manage Succession Plan Candidate

    • View Succession Plan Candidate

    Succession Person Detail Custom Policy

    Person Detail (PER_ALL_PEOPLE_F)

    All values

    • Add Worker to Succession Plan

    • Create Succession Plan for Worker

    • View Succession Plan

    You now see the three data security policies listed on the Data Security Policies page.

Define the Role Hierarchy for the Job Role

You add the Create Succession Plan for Worker aggregate privilege and the Succession Plan Management Custom duty role to the Succession Plans Super User Job role hierarchy.

  1. Click the Role Hierarchy train stop.

  2. On the Role Hierarchy page, click Add Role.

  3. In the Add Role Membership dialog box, search for the Create Succession Plan for Worker (ORA_HRM_SUCCESSION_PLAN_CREATE_DUTY) aggregate privilege.

  4. Select the aggregate privilege in the search results and click Add Role Membership.

  5. Repeat from step 3 to add the Succession Plan Management Custom duty role.

  6. Close the Add Role Membership dialog box.

  7. Click the Summary and Impact Report train stop.

  8. Click Save and Close.

  9. Click OK to close the Confirmation dialog box.

Create a Role Mapping

You create a role mapping to enable the Succession Plans Super User Job role to be provisioned to users.
  1. In the Setup and Maintenance work area, go to the following:

    • Offering: Workforce Deployment

    • Functional Area: Users and Security

    • Task: Manage Role Provisioning Rules

  2. On the Manage Role Mappings page, click the Create icon in the Search Results section.

  3. In the Mapping Name field on the Create Role Mapping page, enter Access All Succession Plans.

  4. Complete the fields in the Conditions section as shown in this table.

    Field

    Value

    HR Assignment Status

    Active

    Responsibility Type

    Human resources representative

  5. In the Associated Roles section, click the Add Row icon.

  6. In the Role Name field, search for and select Succession Plans Super User Job.

  7. Select the Requestable option and deselect the Autoprovision option.

  8. Click Save and Close.

    Users with the human resources representative responsibility can now provision the Succession Plans Super User Job role to other users. A user who has the role can manage all succession plans in the Succession Plans work area with the following exceptions:
    • A user who is also the Candidate Manager for a plan can edit only the plan's candidate list.

    • A user who is also the Viewer of a plan can view the plan but not edit it.

Enable Access to OTBI Subject Areas

To enable users who have the Succession Plans Super User Job role to access OTBI subject areas for Succession Management, you edit two of the job role's data security policies and add a role to the role hierarchy.
  1. Sign in with the IT Security Manager job role or privileges and select Navigator > Tools > Security Console.

  2. On the Roles tab of the Security Console, search for the Succession Plans Super User Job role.

  3. In the search results, select Edit Role on the role's Actions menu.

  4. Click the Data Security Policies train stop.

  5. On the Actions menu for the Succession Plans Custom Policy data security policy, select Edit Data Security Policy.

  6. In the Edit Data Security Policy dialog box, select Report Succession Plan in the Actions field.

  7. On the Actions menu for the Succession Person Detail Custom Policy data security policy, select Edit Data Security Policy.

  8. In the Edit Data Security Policy dialog box, select Report on Succession Plan Candidacy, and Report on Succession Plan Incumbent, in the Actions field.

  9. Click OK to close the Edit Data Security Policy dialog box.

  10. Click Create Data Security Policy to open the Create Data Security Policy dialog box.

  11. In the Create Data Security Policy dialog box, complete the fields as shown in this table:

    Policy Name

    Database Resource

    Data Set

    Actions

    Succession Talent Profile Custom Policy

    Talent Profile for Table HRT_PROFILES_B

    All Values

    Report Talent Profile

  12. Click OK to close the Create Data Security Policy dialog box.

  13. Click the Role Hierarchy train stop.

  14. Click Add Role.

  15. In the Add Role Membership dialog box, search for and select the predefined Succession Management Transaction Analysis Duty (FBI_SUCCESSION_MANAGEMENT_TRANSACTION_ANALYSIS_DUTY) role.

  16. Click Add Role Membership.

  17. Close the Add Role Membership dialog box.

  18. Click the Summary and Impact Report train stop.

  19. Click Save and Close.

    Any user who has the Succession Management Super User Job role can now access OTBI subject areas for Succession Management.