1 Overview

This document covers the aspects of security that are mentioned in the Merchandising Cloud Services Security Guide and describe them in more detail as well as outline how they are used in Fiscal Management.

Application Functional Security

Fiscal Management functional security supports a role-based, declarative model where resources are protected by roles that are assigned to users. Roles are associated to a logical grouping of duties, which in turn are associated to a set of privileges which provide different access rights. In this manner, an application role becomes the container that grants permissions to its members to access the application tasks, screens, and functionalities within.

Roles

Roles, also referred to as Job Roles, align with titles or jobs within a retailer’s organization, such as a Fiscal Analyst or Fiscal Manager. Roles are used to classify users based on job responsibilities and actions to be performed in the application. One or more duties as well as individual privileges, if desired, can be assigned to roles. When a user logs into the application, based on the roles assigned to the user, the system determines which privileges have been granted to the user, and the system features are enabled accordingly.

Duties

Duties are tasks one must perform in the context of their job. Duties in Fiscal Management are logical groupings of privileges or other duties that grant users access to a set of functionally related tasks within the cloud service.

Privileges

Privileges are used to grant permission to access links into workflows, screens, actions, and in some cases specific fields within the application. Privileges that grant access to related functionality are grouped together into duties that permit a user to perform a complete task to fulfill responsibilities within the context of their job.

Data Filtering

Oracle Retail Merchandising Cloud Services offer an optional layer of data filtering in the application user interface, which limits the data end users see by levels in the merchandise and organizational hierarchies. Whether or not this is used in your environment is controlled by a system option in the Merchandising Foundation Cloud Service, which is also where all the configuration for this functionality is managed.

Within Fiscal Management, there is not any additional configuration needed. However, all Fiscal Management users need to be included in the user/group relationships configured in Merchandising so that they are able to access the data needed to perform their jobs. With data filtering enabled, users will only be able to view items that are part of the merchandise hierarchy to which they have been given data filtering access. This will be applicable to the Fiscal Data Management set of features within RFMCS scope.

To implement data filtering in Merchandising, see the Managing Data Filtering chapter in the Merchandising Cloud Services Administration Guide.