Inherit security for reference organization items
Update 26C introduced a centralized security inheritance model for reference organization items. With this enhancement, you no longer need to maintain separate security grants for items in each reference organization. Instead, security access is managed at the definition organization level and is automatically inherited by all associated reference organizations.
When this capability is enabled, users who have access to an item in the definition organization automatically gain access to the corresponding item in its associated reference organizations.
With this update, this security inheritance model is extended to the Redwood user experience for items secured using Access Control Lists.
This capability is supported across Product Management interfaces and services, including:
-
Item search pages
-
Item pages across the following:
-
Attributes
-
Attachments
-
Structures and where-used analysis
-
Categories
-
Relationships
-
-
Workflow pages
-
Affected Objects Tab
-
-
Delete group
-
REST and backend services
How to enable security inheritance
To enable security inheritance in Redwood, you must enable the existing profile option ORA_EGP_INHERIT_DEF_ORG_SECURITY. You can automatically enable or disable the profile option by running the Upgrade Product Management Data scheduled process. For information about enabling this option, see Optimized Security for Reference Organization Items.
Here are some details of how access is inherited across the following:
-
Item search
-
Items
-
Problem reports and corrective actions
-
Delete groups
-
REST services
Item search across definition and reference organizations
-
On the Product Management Search Items page, users can search for items in the definition organization as well as its associated reference organizations.
-
In the Select and Add Items drawer, users can search for and select only the items they're authorized to access in the definition organization and its associated reference organizations.
Items
Access granted to an item in the definition organization (on the Redwood Items page) is inherited by the corresponding item in the related reference organization. This inherited access applies to attribute groups, structures, attachments, and other item tabs, such as Where Used, Categories, and Relationships.
For example, if a user is granted permission to manage Basic Attributes and Attachments for an item in the definition organization, the user has the same permissions for the corresponding item in the related reference organization. However, the user can't access Structures, Where Used, or any other item tabs unless those permissions are also granted for the item in the definition organization.
Problem reports and corrective actions
Affected items in reference organizations that are included in problem reports or corrective actions are accessible to users who are granted access to the corresponding item in the definition organization.
For example, if a Problem Report is created in organization REFV1, which is a reference organization for organization V1, a user with Manage permission for items in organization V1 can select and add the corresponding REFV1 item as an affected object and update its change line values.
Delete group
Users can access and add reference organization items to a Delete Group if they have the required access to the corresponding definition organization item.
For example, if an item in reference organization REFV1 is associated with a definition organization item in V1, and a user has the required Delete permission for the definition organization item, the user can select the REFV1 item when adding items to a Delete Group.
REST services
REST services use the same access inheritance model as the Redwood user experience. Access granted to an item in the definition organization is inherited by the corresponding item in the related reference organization for REST operations, just as it is on the Redwood Items page.
Access to reference organization items is controlled through inherited access control lists, together with service-level validations for GET, POST, PATCH, and other supported REST operations.
This feature provides the following business benefits:
-
Simplifies security administration: Manage item access once at the definition organization level instead of maintaining duplicate security grants across every reference organization, significantly reducing administrative effort.
-
Provides consistent and secure access: Automatically inherits permissions from definition organizations to associated reference organizations, ensuring users have the appropriate level of access across Redwood pages, workflows, REST services, and Product Management capabilities.
-
Improves user productivity: Enables users to seamlessly search, view, update, and manage reference organization items without requiring additional security setup, reducing access issues and speeding up day-to-day tasks.
-
Reduces maintenance and improves governance: Centralized security minimizes configuration errors, keeps access policies consistent across organizations, and simplifies ongoing security management while leveraging the Access Control Lists (ACL) security model.
Steps to enable and configure
These are not new configuration steps. However, they're required for this feature to function.
-
Enable the profile option ORA_EGP_INHERIT_DEF_ORG_SECURITY for inheritance of definition organization security.
For information about enabling this profile option, see Optimized Security for Reference Organization Items.
-
Enable the profile option ORA_EGP_ITEM_ACL for access control list on items.
Tips and considerations
-
Review existing access control list configurations before using this feature.
-
Validate and compare user access behavior for definition organization items and reference organization items in a test environment before deploying to production.
-
Users without access to a definition organization item can't access the corresponding reference organization item, when the profile option in set to "Yes".
-
Run the Refresh the Access Control List for the Teams scheduled process if you enable access control lists for items.
-
Existing indexing and search processes will require a rebuild when you enable the profile option for access control list on items.
Key resources
-
Oracle Fusion Cloud SCM Using Product Master Data Management Guide, available on the Oracle Help Center.
-
Oracle Fusion Cloud SCM Implementing Product Management Guide, available on the Oracle Help Center.
Access requirements
Users who are assigned a configured job role that contains these existing privileges can access this feature:
| Privilege name and code |
|---|
|
To configure conditions using a filtered list:
|
|
To configure teams, permission sets, and conditions:
|