2 Post Installation Configuration

After installing Retail Home, you must configure administrator permissions.

Configuring Administrator Permissions

Administrator users for Retail Home must be assigned the following roles through the authentication provider for the environment:

  • RETAIL_HOME_ADMIN

  • PLATFORM_SERVICES_ADMINISTRATOR

All users for Retail Home must be assigned the PLATFORM_SERVICES_ADMINISTRATOR_ABSTRACT role. This role no longer grants administrator permissions but is required for all users due to a bug.

The rhbiuser and rhbiuser2 users in IDCS must be assigned the roles <tenant ID>-BIConsumer_JOB and <tenant ID>-BIImpersonate_JOB to display the integration status for Retail Home BI Service in Retail Home’s Integration Status page. The <tenant ID>-BIConsumer_JOB role also grants permission to view reports, dashboards, and visualisations in OAS (Analytics and Publisher).

The data privacy services require the DATAPRIV_ADMINISTRATOR_REST_API_ROLE to use and this must be assigned to appropriate users.

Note:

Do not enable multi-factor authentication (MFA) for the rhbiuser and rhbiuser2 Retail Home BI impersonation users in IDCS or OCI IAM. These users are used for automated Retail Home BI integration and cannot respond to an MFA challenge. Enabling MFA for either user can prevent Retail Home from accessing BI services and can cause the Retail Home BI Service integration status to report a failure.

Non-Production Environments

In a non-production environment (for example, staging), Retail Home uses separate preproduction roles. These roles are identical to the production roles except for the addition of the _PREPROD suffix (for example, RETAIL_HOME_ADMIN_PREPROD). For these environments, users must be assigned the corresponding preproduction role for the cases listed above.