Secure Access to Value Sets

This topic shows how to grant data security policies to the predefined Custom Data Security Policies for Application Identities duty role. These data security policies secure access to value sets.

Follow these steps:

  1. Sign in with the IT Security Manager role or privileges.

  2. Select Navigator > Tools > Security Console.

  3. On the Roles tab of the Security Console, search for the Custom Data Security Policies for Application Identities (ORA_HRC_APPLICATION_IDENTITY_CUSTOM_DSPS) duty role.

  4. Select the role in the search results.

  5. From the Actions menu for the role, select Edit Role.

    Tip: You can add data security policies to a predefined role without first having to create a copy of the role. This type of modification survives upgrade.
  6. On the Basic Information page, click the Data Security Policies train stop.

  7. On the Data Security Policies page, click Create Data Security Policy.

  8. In the Create Data Security Policy dialog box:

    1. Enter a policy name, for example, Access Secured Value Sets VISION_SECURED_VALUE_SET.

    2. In the Database Resource field, search for and select the name that you defined for your value set.

      Tip: You created this value on the Create Value Set page after selecting Security enabled for the value set.
    3. Enter a start date. Use a value on or before today's date so that you can test user access to the value set.

    4. Set Data Set to All values.

    5. Set Actions to Read.

    6. Click OK.

  9. Repeat from step 7 for additional value sets.

  10. On the Data Security Policies page, click the Summary and Impact Report train stop.

  11. Review the summary of your changes.

  12. Click Save and Close.

  13. Click OK to close the confirmation dialog box.

Processes running with any of the APPIDs that inherit Custom Data Security Policies for Application Identities now have secured access to relevant value sets.