View user access analysis and configure catalog exclusion condition

Redwood Platform

You can now benefit from the following enhancements in Access Control Lists:

  • User access analysis: Analyze a user's access to a specific object based on permissions defined in teams.

  • Exclusion operator for catalogs: Create conditions using the exclusion (Is Not) operator for the catalog and category attributes, with support for exclusions based on the catalog hierarchy.

User access analysis

You can now analyze a user's access—to a secured object instance—that's configured through access control lists.

On the Search Teams page, select Actions > Analyze User Access to open the Analyze User Access drawer.

In the Analyze User Access drawer, select up to two users and the object type for which you want to analyze access. The search results display access details for the selected users and object instance.

The analyze user access action on the search teams page

The analyze user access action on the search teams page

Details of access granted to users through access controls lists

Details of access granted to users through access controls lists

The screenshot displays the user access analysis results for users Jerry Walker and Erin Wolf on item INV-100-X.

  • John, a member of the Quality team, has ViewManage, and Delete permissions for INV-100-X.

  • Jan, a member of the Supplier group, has only View permission for INV-100-X.

Permissions are grouped in the following order: Create, View, Manage, Delete, and Publish.

When two users are selected, the analysis compares their access to the same object instance.

You can export the analysis results for offline review and auditing.

Exclusion (is not) operator for catalogs

Use the Is Not operator to exclude a catalog or category hierarchy from a user's access.

For example, consider the following catalog hierarchy:

  • Electronics

    • Smartphones

      • Phone X Series

        • Phone X Pro

    • Laptops

      • Laptop Air

      • Laptop Pro

Exclude a catalog

If you define the condition Catalog Is Not Electronics, users can't access the Electronics catalog or any of its categories. Users automatically receive access to all other catalogs and their categories.

Exclude a category

If you define the condition Category Is Not Phone X Series, users can't access the Phone X Series category or any of its child categories, such as Phone X Pro.

Users can still access:

  • Other categories in the Electronics catalog that aren't under Phone X Series, such as LaptopsLaptop Air, and Laptop Pro.

  • All other catalogs and their categories.

Scheduled processes

  • Refresh the Access Control List for Teams: Run this process manually, if you disable and later enable the profile option Enable Access Control List for Items. This process runs automatically when you save a permission set used in a team or add a permission set to the team.

  • Upgrade Product Management Data: Run this to update existing condition definitions for the Teams work area and enable support for the Is Not operator on the Catalog attribute.

This feature provides the following business benefits:

  • View and compare access permissions across your enterprise easily and efficiently.

  • Quickly identify permission areas that may need further refinement or tuning. 

  • Grant access to catalogs more efficiently by using the exclusion (Is Not) operator. This condition excludes access to the selected catalog or category and its hierarchy, while automatically granting access to all other catalogs and categories outside the excluded hierarchy.

Steps to enable and configure

  • To use criteria-based access control for catalogs, enable the profile option Enable Access Control List for Catalogs.  By default, the profile option is set to No.

  • After enabling the profile option, the catalogs continue to honor the existing security settings until you create a permission set and add it to an active team that impacts at least one catlog or category.

Once the profile option is enabled and a permission is created for a catalog, all catalogs that aren’t assigned to a specific functional area in the application will become private. You must manually assign user permissions to such catalogs.

Tips and considerations

  • In order to exclude a complete hierarchy, use 'Is Not' on catalog and category attribute.

  • You can select a maximum of two users for access analysis at a time.

  • The Object Type list displays only object types for which ACL security is enabled.

  • If a selected user doesn’t have access to the object instance, the drawer displays a no data.

  • The analysis is read-only and is intended for review or troubleshooting.

  • Use the export option to download the analysis results for offline review or audit purposes.

Key resources

  • Oracle Fusion Cloud SCM Using Product Master Data Management Guide, available on the Oracle Help Center.

  • Oracle Fusion Cloud SCM Implementing Product Management Guide, available on the Oracle Help Center.

Access requirements

Users who are assigned a configured job role that contains these privileges can access this feature:

Privilege status

Privilege name and code

Existing

To configure conditions for catalogs or categories using a filtered list:

  • Use REST Service - Identity Integration (ASE_REST_SERVICE_ACCESS_IDENTITY_INTEGRATION_PRIV)

  • Use Atom Feed - Employees Workspace (PER_ATOM_WORKSPACE_ACCESS_EMPLOYEES_PRIV)

  • Manage HCM Lists (HRC_MANAGE_HCM_LISTS_PRIV)

  • Human Capital Management Application Administrator (ORA_HRC_HUMAN_CAPITAL_MANAGEMENT_APPLICATION_ADMINISTRATOR_JOB)

Existing

   To configure teams, permission sets, and conditions:

  • Manage Landing Page Layout (EGP_MANAGE_LANDING_PAGE_LAYOUT_PRIV)

  • Access Clipboard (ACA_ACCESS_CLIPBOARD_PRIV)

  • Access HCM Common Components (HRC_ACCESS_HCM_COMMON_COMPONENT)

  • Manage Search Consumer Applications Rest (EGP_MANAGE_SEARCH_CONS_REST_PRIV)

  • Monitor Product Development (ACA_MONITOR_PRODUCT_DEVELOPMENT_PRIV)

  • Configure Access Control Teams, Permission Sets, and Conditions (EGP_ACCESS_CONTROL_TEAMS_PRIV)

  • Use REST Service - Identity Integration (ASE_REST_SERVICE_ACCESS_IDENTITY_INTEGRATION_PRIV)

  • Use Atom Feed - Employees Workspace (PER_ATOM_WORKSPACE_ACCESS_EMPLOYEES_PRIV)

  • Manage HCM Lists (HRC_MANAGE_HCM_LISTS_PRIV)

  • Manage HCM Rules (HRC_MANAGE_HCM_RULES_PRIV)

  • Run Scheduled Processes (HEY_RUN_SCHEDULED_PROCESSES_PRIV)

  • Manage Scheduled Processes (FND_MANAGE_SCHEDULED_PROCESSES_PRIV)

  • Access Product Management Landing Page (EGP_ACCESS_LANDING_PAGE_PRIV)

  • Manage Scheduled Job Definition (FND_MANAGE_SCHEDULED_JOB_DEFINITION_PRIV)

  • Access Users (EGP_ACCESS_USERS_PRIV)

Existing

To access catalogs and categories in Redwood

  • Access Redwood Catalogs (EGP_RW_READ_ONLY_CATALOGS_PRIV): Give access to users that have read only access.

  • Manage Redwood Catalogs (EGP_RW_MANAGE_CATALOGS_PRIV): Gives full access to users.

Existing

To access journeys setup and configure the roles in role hierarchy:

  • Manage Journey (ORA_PER_MANAGE_JOURNEY_TEMPLATE)

  • Manage Guided Journeys (ORA_PER_MANAGE_GUIDED_JOURNEYS)

  • Use REST Service - Guided Journeys Read Only (ORA_PER_REST_SERVICE_ACCESS_GUIDED_JOURNEYS_RO)

  • Use REST Service - Journey Categories List of Values (ORA_PER_REST_SERVICE_ACCESS_JOURNEY_CATEGORIES_LOV)

Existing

To access business rules:

  • Administer Sandbox (FND_ADMINISTER_SANDBOX_PRIV) 

Existing

Additionally, add the following to access an object report:

  • Product Catalog Transaction Analysis Duty (FBI_PRODUCT_CATALOG_TRANSACTION_ANALYSIS_DUTY)Product Transaction Analysis Duty (FBI_PRODUCT_TRANSACTION_ANALYSIS_DUTY) BI Consumer Role (BIConsumer)

The duty role Redwood Item Catalogs (ORA_EGP_RW_ITEM_CATALOGS_DUTY) contains both the Access Redwood Catalogs and Manage Redwood Catalogs privileges and can be used directly with Administration users or modified to use with other job roles.