15.4 Roles and Resources Actions You Can Perform

Here’s a summary of the actions that are available to you by default on the Roles and Resources tab:

Table 15-2 Roles and Resources Actions

Category

Action

Description

Roles and Resources

Role Catalog

Allows you to create, modify, and delete roles. Also lets you define role relationships, associate resources with roles, and assign roles to users, groups, and containers.

For details, see Section 16.0, Managing Roles in the User Application.

Resource Catalog

Allows you to create, modify, and delete resources. Also lets you assign resources to users.

For details, see Section 17.0, Managing Resources in the User Application.

SoD Catalog

Allows you to define Separation of Duties (SoD) constraints. An SoD constraint represents a rule that makes two roles mutually exclusive. If a user is in one role, they cannot be in the second role, unless there is an exception allowed for that constraint. You can define whether exceptions to the constraint are always allowed or are only allowed through an approval flow.

For details, see Managing Separation of Duties in the User Application.

Role Reporting

Role Reports

Enables you to create and view reports that describe the current state of roles and role assignments.

For details, see Section 19.2, Role Reports.

SoD Reports

Enables you to create and view reports that describe the current state of Separation of Duties constraints, violations, and approved exceptions.

For details, see Section 19.3, SoD Reports.

User Reports

Enables you to create and view reports that describe the current state of role memberships and entitlements for users.

For details, see Section 19.4, User Reports.

Configuration

Configure Roles and Resources Settings

Allows you to specify administrative settings for the Role and Resource Subsystem.

For details, see Configuring the Role and Resource Settings.