Managing User Roles for Oracle Analytics Cloud

The following section documents the minimum configuration required to start using Oracle Analytics Cloud service. These steps are required for new customers and customers that have been migrated from Oracle Analytic Server.

User Access to Oracle Analytics Cloud is controlled by assigning users to Identity Cloud Service Groups. OTM users who need to view, create, or modify reports or use Analytic Dashboards, will need to be assigned to an Identity Cloud Service Group with the corresponding Oracle Analytics Cloud application role. This can be done manually within the Oracle Cloud console, but you are strongly encouraged to enable the OTM User Synchronization feature, which will avoid the need to manually assign IDCS Groups. If you are migrated from Oracle Analytic Server, you will need to assign the Groups manually to your existing users or enable the synchronization feature and run the “Synchronize Users” action for all users that need access to Oracle Analytics Cloud.
Note: Users can run reports from within OTM without needing access to Oracle Analytics Cloud. Refer to the Enable Report Generation from within Oracle Transportation Management section for more details on how to configure this option.

The Oracle Transportation Management Business Intelligence roles in the OTM User Manager are associated with Oracle Analytics Cloud application roles via Identity Cloud Service Groups. Each Business Intelligence Role in OTM is mapped to an Identity Cloud Service Group, which is in turn mapped to an Oracle Analytics Cloud application role.

There is an important difference with how Business Intelligence Roles work with environments of type DEVELOPMENT in Oracle Analytics Cloud. The Oracle Identity Cloud Service is common for all the OTM environments (PRODUCTION, TEST, LNM and DEVELOPMENT) in a customer tenancy. User who have access to multiple DEVELOPMENT environments will have same Business Intelligence roles in all DEVELOPMENT Environments.

Suppose a customer has two Environments of type “DEVELOPMENT”, DEV1 and DEV2. Regardless of which OTM Environment you sign in to assign the user the Business Intelligence Role, they will be assigned to a Group that is common to all Environments of type “DEVELOPMENT”. For example, if a User is assigned the BIADMINISTRATOR role in “DEV1”, they will also have the BIADMINISTRATOR role in “Dev2”. In the Identity Cloud Service console, you will see that the user is assigned to a single Group named “OTMBIAdministrator_DEVELOPMENT”. This behavior is intentional and cannot be modified.