Oracle Global HR Cloud · Subject 3 · 16 lessons

Managing HCM Security and Users

How Oracle decides what a user can do and which records they can do it to: role types, security profiles, data roles and the provisioning that ties them to real people.

All 16 lessons, free to read in full. No sign-in required.

What this course covers

  1. Role-Based Access Control
  2. Five HCM Role Types
  3. Role Inheritance
  4. Function vs Data Security
  5. HCM Data Roles
  6. Security Profiles
  7. Person Security Profiles
  8. Areas of Responsibility
  9. Role Mapping & Provisioning
  10. User Accounts & Lifecycle
  11. Custom Roles
  12. Security Console
  13. Security Processes & Synchronization
  14. Audit & Troubleshooting
  15. Securing HCM Reporting
  16. Role Delegation

Lesson 01

Role-Based Access Control

Fundamentals

TECHNOVA STORY

TechNova hires Priya as an HR specialist. Her access is not one switch. Oracle combines her roles, inherited privileges, and scoped data access to decide what she can do and whose records she can see.

What does it control?

Who: the signed-in userWhat: functions granted through privilegesWhich data: records selected by security policies and profiles

Important distinction

Function security opens a task or action; data security limits the records on which that action can operate.

Easy exam definition

RBAC grants access through roles that combine function and data security.

Memory line WHO → WHAT → WHICH DATA

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Role-Based Access Control, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Function security opens a task or action; data security limits the records on which that action can operate.

Implementation

Consultant sequence

  1. 1Identify business persona
  2. 2Select function-bearing role
  3. 3Define data scope
  4. 4Provision and validate

Acceptance evidence

  • Can the user open the task?
  • Can the user see only intended records?

Technical Details

Technical Details

01

Setup & navigation

Tools → Security Console; My Client Groups → Workforce Structures → Data Access

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Who: the signed-in user · What: functions granted through privileges · Which data: records selected by security policies and profiles

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Can the user open the task? · Can the user see only intended records?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

A visible menu does not prove the user can access every record.

Certification

Certification trap

A visible menu does not prove the user can access every record.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor RBAC grants access through roles that combine function and data security.

Revision

60-second revision

The governing model: who can do what on which data.

WHO → WHAT → WHICH DATA

Say it aloud

RBAC grants access through roles that combine function and data security.

Do not confuse

Function security opens a task or action; data security limits the records on which that action can operate.

Lesson 02

Five HCM Role Types

Fundamentals

TECHNOVA STORY

Priya is an Employee, performs HR Specialist duties, and supports only TechNova India. Oracle represents these needs using different role layers rather than one oversized role.

What does it control?

Abstract role: enterprise identityJob role: functional jobData role: job role plus data scopeDuty role: related privilegesAggregate privilege: indivisible task bundle

Important distinction

Users receive abstract and data roles. Duty roles are normally inherited, not assigned directly.

Easy exam definition

A data role combines a job role with one or more security profiles.

Memory line IDENTITY → JOB → DATA; DUTIES underneath

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Five HCM Role Types, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Users receive abstract and data roles. Duty roles are normally inherited, not assigned directly.

Implementation

Consultant sequence

  1. 1Classify the requirement
  2. 2Inspect inherited hierarchy
  3. 3Avoid direct duty-role assignment
  4. 4Assign user-facing role

Acceptance evidence

  • Correct role type?
  • No unnecessary inheritance?

Technical Details

Technical Details

01

Setup & navigation

Tools → Security Console → Roles

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Abstract role: enterprise identity · Job role: functional job · Data role: job role plus data scope · Duty role: related privileges · Aggregate privilege: indivisible task bundle

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Correct role type? · No unnecessary inheritance?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Job roles provide functions but do not by themselves provide the HCM data scope usually needed.

Certification

Certification trap

Job roles provide functions but do not by themselves provide the HCM data scope usually needed.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor A data role combines a job role with one or more security profiles.

Revision

60-second revision

Abstract, job, data, duty, and aggregate privilege roles.

IDENTITY → JOB → DATA; DUTIES underneath

Say it aloud

A data role combines a job role with one or more security profiles.

Do not confuse

Users receive abstract and data roles. Duty roles are normally inherited, not assigned directly.

Lesson 03

Role Inheritance

Fundamentals

TECHNOVA STORY

TechNova’s India HR data role inherits the Human Resource Specialist job role, which inherits Person Management duties and aggregate privileges. Priya receives the resulting access through the top role.

What does it control?

Top role granted to userInherited job or abstract roleInherited duty rolesInherited aggregate privileges and privileges

Important distinction

Inheritance is cumulative: every inherited grant can expand effective access.

Easy exam definition

Evaluate the complete hierarchy, not only the role name assigned to the user.

Memory line TOP ROLE → INHERITED ACCESS

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Role Inheritance, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Inheritance is cumulative: every inherited grant can expand effective access.

Implementation

Consultant sequence

  1. 1Search top role
  2. 2Visualize hierarchy
  3. 3Inspect privileges and policies
  4. 4Compare effective access

Acceptance evidence

  • Expected privilege inherited?
  • Unexpected path present?

Technical Details

Technical Details

01

Setup & navigation

Security Console → Roles → Search → Role Hierarchy

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Top role granted to user · Inherited job or abstract role · Inherited duty roles · Inherited aggregate privileges and privileges

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Expected privilege inherited? · Unexpected path present?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Removing one direct grant may not remove access if another inherited path remains.

Certification

Certification trap

Removing one direct grant may not remove access if another inherited path remains.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Evaluate the complete hierarchy, not only the role name assigned to the user.

Revision

60-second revision

How access flows down the role hierarchy.

TOP ROLE → INHERITED ACCESS

Say it aloud

Evaluate the complete hierarchy, not only the role name assigned to the user.

Do not confuse

Inheritance is cumulative: every inherited grant can expand effective access.

Lesson 04

Function vs Data Security

Fundamentals

TECHNOVA STORY

Priya can open Person Management and update a worker, but she should update only India workers. Function security gives the action; data security provides the India boundary.

What does it control?

Function privilege: action permittedData security policy: privilege on a resource under a conditionSecurity profile: HCM-friendly definition of the data set

Important distinction

Function security answers ‘can perform’; data security answers ‘on which instances.’

Easy exam definition

Both layers must succeed for a user to perform a secured action on a record.

Memory line FUNCTION = VERB; DATA = NOUN SET

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Function vs Data Security, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Function security answers ‘can perform’; data security answers ‘on which instances.’

Implementation

Consultant sequence

  1. 1Test page/action access
  2. 2Test record population
  3. 3Trace privilege
  4. 4Trace security profile

Acceptance evidence

  • Task available?
  • Correct population returned?

Technical Details

Technical Details

01

Setup & navigation

Security Console → Roles; Setup and Maintenance → Manage Data Roles and Security Profiles

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Function privilege: action permitted · Data security policy: privilege on a resource under a condition · Security profile: HCM-friendly definition of the data set

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Task available? · Correct population returned?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

If a page opens but records are missing, investigate data access before adding more function privileges.

Certification

Certification trap

If a page opens but records are missing, investigate data access before adding more function privileges.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Both layers must succeed for a user to perform a secured action on a record.

Revision

60-second revision

Separate the action from the records.

FUNCTION = VERB; DATA = NOUN SET

Say it aloud

Both layers must succeed for a user to perform a secured action on a record.

Do not confuse

Function security answers ‘can perform’; data security answers ‘on which instances.’

Lesson 05

HCM Data Roles

Fundamentals

TECHNOVA STORY

TechNova needs two HR specialists with identical tasks but separate India and UK access. The same job role is reused inside two differently scoped data roles.

What does it control?

Job role supplies functionsSecurity profiles supply scopesData role is provisioned to users

Important distinction

Two data roles may inherit the same job role yet expose completely different populations.

Easy exam definition

HCM data roles are customer-defined; select the job role and assign relevant security profiles.

Memory line JOB ROLE + DATA SCOPE = DATA ROLE

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For HCM Data Roles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Two data roles may inherit the same job role yet expose completely different populations.

Implementation

Consultant sequence

  1. 1Name the business scope
  2. 2Select job role
  3. 3Assign each required profile
  4. 4Save and provision

Acceptance evidence

  • Every secured object has a profile
  • Scope matches requirement

Technical Details

Technical Details

01

Setup & navigation

My Client Groups → Workforce Structures → Manage Data Roles and Security Profiles

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Job role supplies functions · Security profiles supply scopes · Data role is provisioned to users

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Every secured object has a profile · Scope matches requirement

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Creating a data role is not enough; it must be provisioned and the security changes must finish processing.

Certification

Certification trap

Creating a data role is not enough; it must be provisioned and the security changes must finish processing.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor HCM data roles are customer-defined; select the job role and assign relevant security profiles.

Revision

60-second revision

A job role bound to security profiles.

JOB ROLE + DATA SCOPE = DATA ROLE

Say it aloud

HCM data roles are customer-defined; select the job role and assign relevant security profiles.

Do not confuse

Two data roles may inherit the same job role yet expose completely different populations.

Lesson 06

Security Profiles

Fundamentals

TECHNOVA STORY

Priya needs India organizations, positions, people, documents, and an LDG. TechNova uses the matching security profile type for each secured object.

What does it control?

OrganizationPositionPersonDocument typeLegislative data groupCountryPayroll, flow, element, transaction and specialist profiles

Important distinction

A profile identifies data; a data role associates profiles with a functional job role.

Easy exam definition

Use the profile type that matches the secured object and preview access when supported.

Memory line PROFILE = FILTER; DATA ROLE = PACKAGE

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Security Profiles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

A profile identifies data; a data role associates profiles with a functional job role.

Implementation

Consultant sequence

  1. 1Identify secured object
  2. 2Choose delivered or custom profile
  3. 3Define criteria
  4. 4Preview, assign, regenerate if required

Acceptance evidence

  • Preview population correct?
  • Future-dated data considered?

Technical Details

Technical Details

01

Setup & navigation

Setup and Maintenance → Workforce Deployment → security profile task

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Organization · Position · Person · Document type · Legislative data group · Country · Payroll, flow, element, transaction and specialist profiles

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Preview population correct? · Future-dated data considered?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Avoid a view-all profile simply because a targeted profile is harder to design.

Certification

Certification trap

Avoid a view-all profile simply because a targeted profile is harder to design.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Use the profile type that matches the secured object and preview access when supported.

Revision

60-second revision

Reusable rules that identify accessible data.

PROFILE = FILTER; DATA ROLE = PACKAGE

Say it aloud

Use the profile type that matches the secured object and preview access when supported.

Do not confuse

A profile identifies data; a data role associates profiles with a functional job role.

Lesson 07

Person Security Profiles

Fundamentals

TECHNOVA STORY

Priya supports India employees but must not see executives. TechNova creates a person profile driven by her area of responsibility and applies an exclusion rule.

What does it control?

Area of ResponsibilityManager hierarchy and person typePerson-level or assignment-level accessView-all with exclusionsCustom criteria as last resort

Important distinction

Person-level access exposes all assignments of a person; assignment-level security can restrict access based on individual assignments.

Easy exam definition

Area of Responsibility is the recommended scalable method for person security.

Memory line AOR FIRST; CUSTOM SQL LAST

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Person Security Profiles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Person-level access exposes all assignments of a person; assignment-level security can restrict access based on individual assignments.

Implementation

Consultant sequence

  1. 1Choose access method
  2. 2Set person/assignment level
  3. 3Add exclusions
  4. 4Preview access
  5. 5Attach to data role

Acceptance evidence

  • Expected people included?
  • Sensitive groups excluded?

Technical Details

Technical Details

01

Setup & navigation

Setup and Maintenance → Manage Person Security Profile

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Area of Responsibility · Manager hierarchy and person type · Person-level or assignment-level access · View-all with exclusions · Custom criteria as last resort

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Expected people included? · Sensitive groups excluded?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

The person profile and the user’s actual AoR must both be configured.

Certification

Certification trap

The person profile and the user’s actual AoR must both be configured.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Area of Responsibility is the recommended scalable method for person security.

Revision

60-second revision

Control which person or assignment records a user can access.

AOR FIRST; CUSTOM SQL LAST

Say it aloud

Area of Responsibility is the recommended scalable method for person security.

Do not confuse

Person-level access exposes all assignments of a person; assignment-level security can restrict access based on individual assignments.

Lesson 08

Areas of Responsibility

Fundamentals

TECHNOVA STORY

Priya supports the India Software BU today and Cloud Services next month. One AoR-based profile adapts from her dated responsibility records instead of requiring a new data role each time.

What does it control?

Responsibility typeScope attributesStart and end datesPerson or organization access

Important distinction

AoR separates the reusable access rule from each user’s changing operational territory.

Easy exam definition

The accessible set is calculated dynamically from the user’s responsibility records.

Memory line ONE PROFILE, MANY USER SCOPES

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Areas of Responsibility, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

AoR separates the reusable access rule from each user’s changing operational territory.

Implementation

Consultant sequence

  1. 1Define responsibility type
  2. 2Create AoR-driven profile
  3. 3Assign AoR to user
  4. 4Run/allow processing
  5. 5Validate

Acceptance evidence

  • Dates active?
  • Scope values correct?

Technical Details

Technical Details

01

Setup & navigation

My Client Groups → Person Management → Areas of Responsibility

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Responsibility type · Scope attributes · Start and end dates · Person or organization access

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Dates active? · Scope values correct?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

An expired or future AoR can make a correct profile appear broken.

Certification

Certification trap

An expired or future AoR can make a correct profile appear broken.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor The accessible set is calculated dynamically from the user’s responsibility records.

Revision

60-second revision

Dynamic responsibility-based scope for people and organizations.

ONE PROFILE, MANY USER SCOPES

Say it aloud

The accessible set is calculated dynamically from the user’s responsibility records.

Do not confuse

AoR separates the reusable access rule from each user’s changing operational territory.

Lesson 09

Role Mapping & Provisioning

Fundamentals

TECHNOVA STORY

When Priya’s assignment becomes HR Specialist in India, Oracle should automatically give the India HR data role. When the qualifying assignment ends, the role should be removed if the mapping is configured for autoprovisioning.

What does it control?

Assignment-based conditionsAssociated rolesAutoprovisionRequestableSelf-requestable

Important distinction

Role mapping decides eligibility and provisioning behavior; it does not define the privileges inside the role.

Easy exam definition

Conditions are evaluated against assignments, and each associated role has its own provisioning options.

Memory line IF CONDITIONS → THEN ROLE

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Role Mapping & Provisioning, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Role mapping decides eligibility and provisioning behavior; it does not define the privileges inside the role.

Implementation

Consultant sequence

  1. 1Define conditions
  2. 2Add associated role
  3. 3Select provisioning options
  4. 4Save
  5. 5Process and validate

Acceptance evidence

  • Qualifying assignment found?
  • Role added/removed as expected?

Technical Details

Technical Details

01

Setup & navigation

Setup and Maintenance → Manage Role Provisioning Rules

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Assignment-based conditions · Associated roles · Autoprovision · Requestable · Self-requestable

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Qualifying assignment found? · Role added/removed as expected?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Multiple qualifying assignments or mappings may preserve a role after one assignment changes.

Certification

Certification trap

Multiple qualifying assignments or mappings may preserve a role after one assignment changes.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Conditions are evaluated against assignments, and each associated role has its own provisioning options.

Revision

60-second revision

Conditions that automatically or manually provision roles.

IF CONDITIONS → THEN ROLE

Say it aloud

Conditions are evaluated against assignments, and each associated role has its own provisioning options.

Do not confuse

Role mapping decides eligibility and provisioning behavior; it does not define the privileges inside the role.

Lesson 10

User Accounts & Lifecycle

Fundamentals

TECHNOVA STORY

Priya is hired, transfers, and later terminates. TechNova’s enterprise options determine account creation and maintenance, while employment events and provisioning processes affect role and account status.

What does it control?

Automatic or bulk account creationEnterprise account optionsUsername and notification rulesSuspension and termination behaviorUser and role synchronization

Important distinction

A person record, user account, and provisioned roles are connected but distinct objects.

Easy exam definition

Employment events can affect account status and roles according to configured enterprise options and processes.

Memory line PERSON ≠ USER ≠ ROLE

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For User Accounts & Lifecycle, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

A person record, user account, and provisioned roles are connected but distinct objects.

Implementation

Consultant sequence

  1. 1Confirm person-worker linkage
  2. 2Check account status
  3. 3Check enterprise options
  4. 4Check provisioned roles
  5. 5Run synchronization if appropriate

Acceptance evidence

  • Account active at correct time?
  • Roles reflect current assignments?

Technical Details

Technical Details

01

Setup & navigation

Setup and Maintenance → Manage Enterprise HCM Information; Security Console → Users

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Automatic or bulk account creation · Enterprise account options · Username and notification rules · Suspension and termination behavior · User and role synchronization

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Account active at correct time? · Roles reflect current assignments?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Do not create a second user merely because an existing worker cannot sign in.

Certification

Certification trap

Do not create a second user merely because an existing worker cannot sign in.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Employment events can affect account status and roles according to configured enterprise options and processes.

Revision

60-second revision

Create, maintain, suspend, and synchronize HCM-linked users.

PERSON ≠ USER ≠ ROLE

Say it aloud

Employment events can affect account status and roles according to configured enterprise options and processes.

Do not confuse

A person record, user account, and provisioned roles are connected but distinct objects.

Lesson 11

Custom Roles

Fundamentals

TECHNOVA STORY

TechNova needs an HR auditor who can view but not update worker data. The consultant copies the closest predefined role and removes unnecessary capabilities in the custom copy.

What does it control?

Copy top roleCopy top and inherited rolesEdit inherited roles or policiesRegenerate data role grants

Important distinction

Predefined roles should not be modified; custom copies provide a supported place for changes.

Easy exam definition

Copying only the top role keeps inherited predefined roles shared; copying the full hierarchy creates more custom components to maintain.

Memory line COPY CLOSEST → MINIMIZE CHANGE

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Custom Roles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Predefined roles should not be modified; custom copies provide a supported place for changes.

Implementation

Consultant sequence

  1. 1Evaluate delivered role
  2. 2Choose copy strategy
  3. 3Use custom code/name
  4. 4Adjust least privilege
  5. 5Regenerate and test

Acceptance evidence

  • Only required functions remain?
  • Upgrade resilience understood?

Technical Details

Technical Details

01

Setup & navigation

Tools → Security Console → Roles → Copy Role

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Copy top role · Copy top and inherited roles · Edit inherited roles or policies · Regenerate data role grants

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Only required functions remain? · Upgrade resilience understood?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Copying an entire hierarchy without need increases maintenance and reduces resilience.

Certification

Certification trap

Copying an entire hierarchy without need increases maintenance and reduces resilience.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Copying only the top role keeps inherited predefined roles shared; copying the full hierarchy creates more custom components to maintain.

Revision

60-second revision

Copy or create roles while preserving maintainability.

COPY CLOSEST → MINIMIZE CHANGE

Say it aloud

Copying only the top role keeps inherited predefined roles shared; copying the full hierarchy creates more custom components to maintain.

Do not confuse

Predefined roles should not be modified; custom copies provide a supported place for changes.

Lesson 12

Security Console

Fundamentals

TECHNOVA STORY

Priya has different access from another India HR specialist. The security administrator compares users and roles, visualizes inheritance, and identifies the extra data role.

What does it control?

Role and user searchHierarchy visualizationRole and user comparisonRole copyingAdministration options and analytics

Important distinction

Security Console manages roles and users; HCM security profile and role-mapping tasks remain in HCM setup areas.

Easy exam definition

Use comparison and visualization to diagnose effective access before changing roles.

Memory line SEARCH → VISUALIZE → COMPARE → FIX

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Security Console, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Security Console manages roles and users; HCM security profile and role-mapping tasks remain in HCM setup areas.

Implementation

Consultant sequence

  1. 1Reproduce issue
  2. 2Compare known-good user
  3. 3Inspect hierarchy
  4. 4Trace role assignment source
  5. 5Make minimal correction

Acceptance evidence

  • Difference isolated?
  • Effective access retested?

Technical Details

Technical Details

01

Setup & navigation

Navigator → Tools → Security Console

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Role and user search · Hierarchy visualization · Role and user comparison · Role copying · Administration options and analytics

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Difference isolated? · Effective access retested?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Security Console is not the place to define HCM person security-profile criteria.

Certification

Certification trap

Security Console is not the place to define HCM person security-profile criteria.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Use comparison and visualization to diagnose effective access before changing roles.

Revision

60-second revision

Search, visualize, compare, copy, analyze, and administer security.

SEARCH → VISUALIZE → COMPARE → FIX

Say it aloud

Use comparison and visualization to diagnose effective access before changing roles.

Do not confuse

Security Console manages roles and users; HCM security profile and role-mapping tasks remain in HCM setup areas.

Lesson 13

Security Processes & Synchronization

Fundamentals

TECHNOVA STORY

TechNova created a mapping correctly, but Priya’s role has not appeared. The consultant checks whether the relevant provisioning or security synchronization process has completed before redesigning the mapping.

What does it control?

Autoprovision Roles for All UsersSend Pending LDAP RequestsImport User and Role Application Security DataRegenerate Data Security Profiles and Grants

Important distinction

Each process solves a different layer: eligibility, identity-store request, security data import, or grant regeneration.

Easy exam definition

Select the process that matches the stale layer; do not run every process blindly.

Memory line MAP → PROVISION → SYNC → VERIFY

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Security Processes & Synchronization, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Each process solves a different layer: eligibility, identity-store request, security data import, or grant regeneration.

Implementation

Consultant sequence

  1. 1Identify stale layer
  2. 2Check process history
  3. 3Run targeted process
  4. 4Review log/output
  5. 5Retest user

Acceptance evidence

  • Process succeeded?
  • Role/profile visible afterward?

Technical Details

Technical Details

01

Setup & navigation

Tools → Scheduled Processes

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Autoprovision Roles for All Users · Send Pending LDAP Requests · Import User and Role Application Security Data · Regenerate Data Security Profiles and Grants

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Process succeeded? · Role/profile visible afterward?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

A successful job does not prove the original role-mapping conditions were satisfied.

Certification

Certification trap

A successful job does not prove the original role-mapping conditions were satisfied.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Select the process that matches the stale layer; do not run every process blindly.

Revision

60-second revision

Processes that reconcile users, roles, profiles, and grants.

MAP → PROVISION → SYNC → VERIFY

Say it aloud

Select the process that matches the stale layer; do not run every process blindly.

Do not confuse

Each process solves a different layer: eligibility, identity-store request, security data import, or grant regeneration.

Lesson 14

Audit & Troubleshooting

Fundamentals

TECHNOVA STORY

Priya can suddenly see UK workers. TechNova compares her access, traces inherited roles and data scopes, then reviews audit history to find the configuration change and its actor.

What does it control?

Function testData population testRole/user comparisonProvisioning sourceAudit reports and logs

Important distinction

Audit explains what changed and by whom; it does not replace effective-access analysis.

Easy exam definition

Troubleshoot in layers: account → assigned role → inheritance → function privilege → data policy/profile → processing.

Memory line ACCOUNT → ROLE → FUNCTION → DATA → PROCESS

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Audit & Troubleshooting, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Audit explains what changed and by whom; it does not replace effective-access analysis.

Implementation

Consultant sequence

  1. 1Capture exact symptom
  2. 2Compare with working user
  3. 3Trace access chain
  4. 4Review recent changes
  5. 5Correct and retest

Acceptance evidence

  • Root cause evidenced?
  • Excess access removed without breaking valid access?

Technical Details

Technical Details

01

Setup & navigation

Security Console; Tools → Audit Reports; Scheduled Processes

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Function test · Data population test · Role/user comparison · Provisioning source · Audit reports and logs

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Root cause evidenced? · Excess access removed without breaking valid access?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Adding a broad role may hide the symptom while creating a larger security risk.

Certification

Certification trap

Adding a broad role may hide the symptom while creating a larger security risk.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Troubleshoot in layers: account → assigned role → inheritance → function privilege → data policy/profile → processing.

Revision

60-second revision

Trace access from symptom to source and interpret security changes.

ACCOUNT → ROLE → FUNCTION → DATA → PROCESS

Say it aloud

Troubleshoot in layers: account → assigned role → inheritance → function privilege → data policy/profile → processing.

Do not confuse

Audit explains what changed and by whom; it does not replace effective-access analysis.

Lesson 15

Securing HCM Reporting

Fundamentals

TECHNOVA STORY

Priya may run the India headcount analysis but must not access UK worker rows. TechNova secures both the catalog/subject-area capability and the underlying data returned by the report.

What does it control?

OTBI subject areas and foldersBI roles and catalog permissionsHCM data securityBI Publisher data modelsSecured list views

Important distinction

Catalog access controls who can open content; data security controls which rows are returned.

Easy exam definition

OTBI generally respects HCM data security; BI Publisher designs must use secured sources appropriately.

Memory line CONTENT ACCESS + ROW ACCESS

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Securing HCM Reporting, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Catalog access controls who can open content; data security controls which rows are returned.

Implementation

Consultant sequence

  1. 1Grant minimum reporting role
  2. 2Secure catalog object
  3. 3Use secured data source
  4. 4Test as user
  5. 5Validate exported data

Acceptance evidence

  • Can open intended report?
  • Only permitted rows returned?

Technical Details

Technical Details

01

Setup & navigation

Reports and Analytics; Security Console; BI catalog administration

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

OTBI subject areas and folders · BI roles and catalog permissions · HCM data security · BI Publisher data models · Secured list views

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Can open intended report? · Only permitted rows returned?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Selecting directly from an unsecured database table can bypass the intended HCM row security.

Certification

Certification trap

Selecting directly from an unsecured database table can bypass the intended HCM row security.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor OTBI generally respects HCM data security; BI Publisher designs must use secured sources appropriately.

Revision

60-second revision

Protect OTBI and BI Publisher content and data.

CONTENT ACCESS + ROW ACCESS

Say it aloud

OTBI generally respects HCM data security; BI Publisher designs must use secured sources appropriately.

Do not confuse

Catalog access controls who can open content; data security controls which rows are returned.

Lesson 16

Role Delegation

Fundamentals

TECHNOVA STORY

Priya will be on leave and delegates an eligible HR role to Maya for a fixed period. Approval-task delegation is handled separately from role delegation.

What does it control?

Delegator and proxyDelegation-enabled roleStart and end datesManager hierarchy implications

Important distinction

Role delegation transfers eligible role access temporarily; workflow-task delegation routes approval tasks.

Easy exam definition

Abstract roles cannot normally be delegated because they represent the worker’s own identity in the enterprise.

Memory line ROLE ACCESS ≠ APPROVAL TASKS

Relationships

Where this fits

User
+
Provisioned role
→
Inherited functions
+
Scoped data
→
Effective access

For Role Delegation, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.

Nearest concept

Role delegation transfers eligible role access temporarily; workflow-task delegation routes approval tasks.

Implementation

Consultant sequence

  1. 1Confirm role eligible
  2. 2Enable delegation
  3. 3Choose proxy and dates
  4. 4Validate scope
  5. 5Expire/revoke

Acceptance evidence

  • Proxy receives only intended role?
  • End date enforced?

Technical Details

Technical Details

01

Setup & navigation

Security Console → enable delegation; Me → Roles and Delegations

02

Prerequisites

Business access requirement, target user/person, role design, data scope, test user and effective date.

03

Configuration objects

Delegator and proxy · Delegation-enabled role · Start and end dates · Manager hierarchy implications

04

Security layers

Account status → assigned role → inheritance → function privilege → data security policy/profile.

05

Provisioning

Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.

06

Processing

Run only the process appropriate to the changed or stale layer; review status and logs.

07

Validation

Proxy receives only intended role? · End date enforced?

08

Effective dating

Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.

09

Audit evidence

Record requester, approver, configuration change, process result, and before/after access test.

10

Downstream impact

Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.

11

Troubleshooting

Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.

12

Least privilege

Grant only required functions and populations; prefer resilient, reusable profiles and roles.

13

Consultant challenge

Delegating a role may also expose its inherited functions and data, so review the full hierarchy.

Certification

Certification trap

Delegating a role may also expose its inherited functions and data, so review the full hierarchy.

What the exam may ask

  • Identify the correct security layer from a user symptom.
  • Review a role, mapping, or profile configuration and predict effective access.
  • Select the most maintainable least-privilege design.
Answer anchor Abstract roles cannot normally be delegated because they represent the worker’s own identity in the enterprise.

Revision

60-second revision

Temporarily allow a proxy to act using an enabled role.

ROLE ACCESS ≠ APPROVAL TASKS

Say it aloud

Abstract roles cannot normally be delegated because they represent the worker’s own identity in the enterprise.

Do not confuse

Role delegation transfers eligible role access temporarily; workflow-task delegation routes approval tasks.