Inherit security for reference organization items

Update 26C introduced a centralized security inheritance model for reference organization items. With this enhancement, you no longer need to maintain separate security grants for items in each reference organization. Instead, security access is managed at the definition organization level and is automatically inherited by all associated reference organizations.

When this capability is enabled, users who have access to an item in the definition organization automatically gain access to the corresponding item in its associated reference organizations.

With this update, this security inheritance model is extended to the Redwood user experience for items secured using Access Control Lists.

This capability is supported across Product Management interfaces and services, including:

  • Item search pages

  • Item pages across the following:

    • Attributes

    • Attachments

    • Structures and where-used analysis

    • Categories

    • Relationships

  • Workflow pages

    • Affected Objects Tab

  • Delete group

  • REST and backend services

How to enable security inheritance

To enable security inheritance in Redwood, you must enable the existing profile option ORA_EGP_INHERIT_DEF_ORG_SECURITY. You can automatically enable or disable the profile option by running the Upgrade Product Management Data scheduled process. For information about enabling this option, see Optimized Security for Reference Organization Items.

Here are some details of how access is inherited across the following:

  • Item search

  • Items

  • Problem reports and corrective actions

  • Delete groups

  • REST services

Item search across definition and reference organizations

  • On the Product Management Search Items page, users can search for items in the definition organization as well as its associated reference organizations.

  • In the Select and Add Items drawer, users can search for and select only the items they're authorized to access in the definition organization and its associated reference organizations.

Items

Access granted to an item in the definition organization (on the Redwood Items page) is inherited by the corresponding item in the related reference organization. This inherited access applies to attribute groups, structures, attachments, and other item tabs, such as Where Used, Categories, and Relationships.

For example, if a user is granted permission to manage Basic Attributes and Attachments for an item in the definition organization, the user has the same permissions for the corresponding item in the related reference organization. However, the user can't access Structures, Where Used, or any other item tabs unless those permissions are also granted for the item in the definition organization.

Problem reports and corrective actions

Affected items in reference organizations that are included in problem reports or corrective actions are accessible to users who are granted access to the corresponding item in the definition organization.

For example, if a Problem Report is created in organization REFV1, which is a reference organization for organization V1, a user with Manage permission for items in organization V1 can select and add the corresponding REFV1 item as an affected object and update its change line values.

Delete group 

Users can access and add reference organization items to a Delete Group if they have the required access to the corresponding definition organization item.

For example, if an item in reference organization REFV1 is associated with a definition organization item in V1, and a user has the required Delete permission for the definition organization item, the user can select the REFV1 item when adding items to a Delete Group.

REST services 

REST services use the same access inheritance model as the Redwood user experience. Access granted to an item in the definition organization is inherited by the corresponding item in the related reference organization for REST operations, just as it is on the Redwood Items page.

Access to reference organization items is controlled through inherited access control lists, together with service-level validations for GETPOSTPATCH, and other supported REST operations.

This feature provides the following business benefits:

  • Simplifies security administration: Manage item access once at the definition organization level instead of maintaining duplicate security grants across every reference organization, significantly reducing administrative effort.

  • Provides consistent and secure access: Automatically inherits permissions from definition organizations to associated reference organizations, ensuring users have the appropriate level of access across Redwood pages, workflows, REST services, and Product Management capabilities.

  • Improves user productivity: Enables users to seamlessly search, view, update, and manage reference organization items without requiring additional security setup, reducing access issues and speeding up day-to-day tasks.

  • Reduces maintenance and improves governance: Centralized security minimizes configuration errors, keeps access policies consistent across organizations, and simplifies ongoing security management while leveraging the Access Control Lists (ACL) security model.

Steps to enable and configure

These are not new configuration steps. However, they're required for this feature to function.

  1. Enable the profile option ORA_EGP_INHERIT_DEF_ORG_SECURITY for inheritance of definition organization security.

    For information about enabling this profile option, see Optimized Security for Reference Organization Items.

  2. Enable the profile option ORA_EGP_ITEM_ACL for access control list on items.

Tips and considerations

  • Review existing access control list configurations before using this feature.

  • Validate and compare user access behavior for definition organization items and reference organization items in a test environment before deploying to production.

  • Users without access to a definition organization item can't access the corresponding reference organization item, when the profile option in set to "Yes".

  • Run the Refresh the Access Control List for the Teams scheduled process if you enable access control lists for items.

  • Existing indexing and search processes will require a rebuild when you enable the profile option for access control list on items.

Key resources

Access requirements

Users who are assigned a configured job role that contains these existing privileges can access this feature:

Privilege name and code

To configure conditions using a filtered list:

  • Use REST Service - Identity Integration (ASE_REST_SERVICE_ACCESS_IDENTITY_INTEGRATION_PRIV)

  • Use Atom Feed - Employees Workspace (PER_ATOM_WORKSPACE_ACCESS_EMPLOYEES_PRIV)

  • Manage HCM Lists (HRC_MANAGE_HCM_LISTS_PRIV)

  • Human Capital Management Application Administrator (ORA_HRC_HUMAN_CAPITAL_MANAGEMENT_APPLICATION_ADMINISTRATOR_JOB)

To configure teams, permission sets, and conditions:

  • Manage Landing Page Layout (EGP_MANAGE_LANDING_PAGE_LAYOUT_PRIV)

  • Access Clipboard (ACA_ACCESS_CLIPBOARD_PRIV)

  • Access HCM Common Components (HRC_ACCESS_HCM_COMMON_COMPONENT)

  • Manage Search Consumer Applications Rest (EGP_MANAGE_SEARCH_CONS_REST_PRIV)

  • Monitor Product Development (ACA_MONITOR_PRODUCT_DEVELOPMENT_PRIV)

  • Configure Access Control Teams, Permission Sets, and Conditions (EGP_ACCESS_CONTROL_TEAMS_PRIV)

  • Use REST Service - Identity Integration (ASE_REST_SERVICE_ACCESS_IDENTITY_INTEGRATION_PRIV)

  • Use Atom Feed - Employees Workspace (PER_ATOM_WORKSPACE_ACCESS_EMPLOYEES_PRIV)

  • Manage HCM Lists (HRC_MANAGE_HCM_LISTS_PRIV)

  • Manage HCM Rules (HRC_MANAGE_HCM_RULES_PRIV)

  • Run Scheduled Processes (HEY_RUN_SCHEDULED_PROCESSES_PRIV)

  • Manage Scheduled Processes (FND_MANAGE_SCHEDULED_PROCESSES_PRIV)

  • Access Product Management Landing Page (EGP_ACCESS_LANDING_PAGE_PRIV)

  • Manage Scheduled Job Definition (FND_MANAGE_SCHEDULED_JOB_DEFINITION_PRIV)

  • Access Users (EGP_ACCESS_USERS_PRIV)

  • Manage Item Redwood Items (EGP_MANAGE_REDWOOD_ITEM_PRIV)

  • View product management search (EGP_VIEW_PRODUCT_MGT_SEARCH_PRIV)

  • Get Item Attribute Control REST(EGP_ITEM_ATTRIBUTE_CONTROL_READ_PRIV)

  • Get Item Lifecycle Phases Read Rest (EGP_ITEM_LIFECYCLE_PHASES_READ_REST_PRIV)

  • Get Item Status REST(EGP_ITEM_STATUSES_READ_PRIV)

  • Get Template REST(EGP_TEMPLATE_READ_PRIV)

  • View Global Inventory Organizations List of Values by Web Service (RCS_GLOBAL_VIEW_INV_ORG_LOV_WEB_SERVICE_PRIV)

  • View Units Of Measure List of Values by Web Service (RCS_VIEW_UNITS_OF_MEASURE_LOV_WEB_SERVICE_PRIV)

  • Get Item Class Rest (EGP_GET_ITEM_CLASS_REST_PRIV)

  • View Item (EGP_VIEW_ITEM_PRIV)

  • View Feature States Value by Web Service (RCS_VIEW_FEATURE_STATES_WEB_SERVICE_PRIV)

  • Use REST Service - Users and Roles Lists of Values (PER_REST_SERVICE_ACCESS_USERS_AND_ROLES_LOVS_PRIV)