Oracle Global HR Cloud · Subject 3 · 16 lessons
Managing HCM Security and Users
How Oracle decides what a user can do and which records they can do it to: role types, security profiles, data roles and the provisioning that ties them to real people.
All 16 lessons, free to read in full. No sign-in required.
What this course covers
- Role-Based Access Control
- Five HCM Role Types
- Role Inheritance
- Function vs Data Security
- HCM Data Roles
- Security Profiles
- Person Security Profiles
- Areas of Responsibility
- Role Mapping & Provisioning
- User Accounts & Lifecycle
- Custom Roles
- Security Console
- Security Processes & Synchronization
- Audit & Troubleshooting
- Securing HCM Reporting
- Role Delegation
Lesson 01
Role-Based Access Control
Fundamentals
TechNova hires Priya as an HR specialist. Her access is not one switch. Oracle combines her roles, inherited privileges, and scoped data access to decide what she can do and whose records she can see.
What does it control?
Important distinction
Function security opens a task or action; data security limits the records on which that action can operate.
Easy exam definition
RBAC grants access through roles that combine function and data security.
Relationships
Where this fits
For Role-Based Access Control, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Function security opens a task or action; data security limits the records on which that action can operate.
Implementation
Consultant sequence
- 1Identify business persona
- 2Select function-bearing role
- 3Define data scope
- 4Provision and validate
Acceptance evidence
- Can the user open the task?
- Can the user see only intended records?
Technical Details
Technical Details
Setup & navigation
Tools → Security Console; My Client Groups → Workforce Structures → Data Access
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Who: the signed-in user · What: functions granted through privileges · Which data: records selected by security policies and profiles
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Can the user open the task? · Can the user see only intended records?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
A visible menu does not prove the user can access every record.
Certification
A visible menu does not prove the user can access every record.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
The governing model: who can do what on which data.
Say it aloud
RBAC grants access through roles that combine function and data security.
Do not confuse
Function security opens a task or action; data security limits the records on which that action can operate.
Lesson 02
Five HCM Role Types
Fundamentals
Priya is an Employee, performs HR Specialist duties, and supports only TechNova India. Oracle represents these needs using different role layers rather than one oversized role.
What does it control?
Important distinction
Users receive abstract and data roles. Duty roles are normally inherited, not assigned directly.
Easy exam definition
A data role combines a job role with one or more security profiles.
Relationships
Where this fits
For Five HCM Role Types, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Users receive abstract and data roles. Duty roles are normally inherited, not assigned directly.
Implementation
Consultant sequence
- 1Classify the requirement
- 2Inspect inherited hierarchy
- 3Avoid direct duty-role assignment
- 4Assign user-facing role
Acceptance evidence
- Correct role type?
- No unnecessary inheritance?
Technical Details
Technical Details
Setup & navigation
Tools → Security Console → Roles
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Abstract role: enterprise identity · Job role: functional job · Data role: job role plus data scope · Duty role: related privileges · Aggregate privilege: indivisible task bundle
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Correct role type? · No unnecessary inheritance?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Job roles provide functions but do not by themselves provide the HCM data scope usually needed.
Certification
Job roles provide functions but do not by themselves provide the HCM data scope usually needed.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Abstract, job, data, duty, and aggregate privilege roles.
Say it aloud
A data role combines a job role with one or more security profiles.
Do not confuse
Users receive abstract and data roles. Duty roles are normally inherited, not assigned directly.
Lesson 03
Role Inheritance
Fundamentals
TechNova’s India HR data role inherits the Human Resource Specialist job role, which inherits Person Management duties and aggregate privileges. Priya receives the resulting access through the top role.
What does it control?
Important distinction
Inheritance is cumulative: every inherited grant can expand effective access.
Easy exam definition
Evaluate the complete hierarchy, not only the role name assigned to the user.
Relationships
Where this fits
For Role Inheritance, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Inheritance is cumulative: every inherited grant can expand effective access.
Implementation
Consultant sequence
- 1Search top role
- 2Visualize hierarchy
- 3Inspect privileges and policies
- 4Compare effective access
Acceptance evidence
- Expected privilege inherited?
- Unexpected path present?
Technical Details
Technical Details
Setup & navigation
Security Console → Roles → Search → Role Hierarchy
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Top role granted to user · Inherited job or abstract role · Inherited duty roles · Inherited aggregate privileges and privileges
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Expected privilege inherited? · Unexpected path present?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Removing one direct grant may not remove access if another inherited path remains.
Certification
Removing one direct grant may not remove access if another inherited path remains.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
How access flows down the role hierarchy.
Say it aloud
Evaluate the complete hierarchy, not only the role name assigned to the user.
Do not confuse
Inheritance is cumulative: every inherited grant can expand effective access.
Lesson 04
Function vs Data Security
Fundamentals
Priya can open Person Management and update a worker, but she should update only India workers. Function security gives the action; data security provides the India boundary.
What does it control?
Important distinction
Function security answers ‘can perform’; data security answers ‘on which instances.’
Easy exam definition
Both layers must succeed for a user to perform a secured action on a record.
Relationships
Where this fits
For Function vs Data Security, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Function security answers ‘can perform’; data security answers ‘on which instances.’
Implementation
Consultant sequence
- 1Test page/action access
- 2Test record population
- 3Trace privilege
- 4Trace security profile
Acceptance evidence
- Task available?
- Correct population returned?
Technical Details
Technical Details
Setup & navigation
Security Console → Roles; Setup and Maintenance → Manage Data Roles and Security Profiles
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Function privilege: action permitted · Data security policy: privilege on a resource under a condition · Security profile: HCM-friendly definition of the data set
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Task available? · Correct population returned?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
If a page opens but records are missing, investigate data access before adding more function privileges.
Certification
If a page opens but records are missing, investigate data access before adding more function privileges.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Separate the action from the records.
Say it aloud
Both layers must succeed for a user to perform a secured action on a record.
Do not confuse
Function security answers ‘can perform’; data security answers ‘on which instances.’
Lesson 05
HCM Data Roles
Fundamentals
TechNova needs two HR specialists with identical tasks but separate India and UK access. The same job role is reused inside two differently scoped data roles.
What does it control?
Important distinction
Two data roles may inherit the same job role yet expose completely different populations.
Easy exam definition
HCM data roles are customer-defined; select the job role and assign relevant security profiles.
Relationships
Where this fits
For HCM Data Roles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Two data roles may inherit the same job role yet expose completely different populations.
Implementation
Consultant sequence
- 1Name the business scope
- 2Select job role
- 3Assign each required profile
- 4Save and provision
Acceptance evidence
- Every secured object has a profile
- Scope matches requirement
Technical Details
Technical Details
Setup & navigation
My Client Groups → Workforce Structures → Manage Data Roles and Security Profiles
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Job role supplies functions · Security profiles supply scopes · Data role is provisioned to users
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Every secured object has a profile · Scope matches requirement
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Creating a data role is not enough; it must be provisioned and the security changes must finish processing.
Certification
Creating a data role is not enough; it must be provisioned and the security changes must finish processing.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
A job role bound to security profiles.
Say it aloud
HCM data roles are customer-defined; select the job role and assign relevant security profiles.
Do not confuse
Two data roles may inherit the same job role yet expose completely different populations.
Lesson 06
Security Profiles
Fundamentals
Priya needs India organizations, positions, people, documents, and an LDG. TechNova uses the matching security profile type for each secured object.
What does it control?
Important distinction
A profile identifies data; a data role associates profiles with a functional job role.
Easy exam definition
Use the profile type that matches the secured object and preview access when supported.
Relationships
Where this fits
For Security Profiles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
A profile identifies data; a data role associates profiles with a functional job role.
Implementation
Consultant sequence
- 1Identify secured object
- 2Choose delivered or custom profile
- 3Define criteria
- 4Preview, assign, regenerate if required
Acceptance evidence
- Preview population correct?
- Future-dated data considered?
Technical Details
Technical Details
Setup & navigation
Setup and Maintenance → Workforce Deployment → security profile task
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Organization · Position · Person · Document type · Legislative data group · Country · Payroll, flow, element, transaction and specialist profiles
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Preview population correct? · Future-dated data considered?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Avoid a view-all profile simply because a targeted profile is harder to design.
Certification
Avoid a view-all profile simply because a targeted profile is harder to design.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Reusable rules that identify accessible data.
Say it aloud
Use the profile type that matches the secured object and preview access when supported.
Do not confuse
A profile identifies data; a data role associates profiles with a functional job role.
Lesson 07
Person Security Profiles
Fundamentals
Priya supports India employees but must not see executives. TechNova creates a person profile driven by her area of responsibility and applies an exclusion rule.
What does it control?
Important distinction
Person-level access exposes all assignments of a person; assignment-level security can restrict access based on individual assignments.
Easy exam definition
Area of Responsibility is the recommended scalable method for person security.
Relationships
Where this fits
For Person Security Profiles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Person-level access exposes all assignments of a person; assignment-level security can restrict access based on individual assignments.
Implementation
Consultant sequence
- 1Choose access method
- 2Set person/assignment level
- 3Add exclusions
- 4Preview access
- 5Attach to data role
Acceptance evidence
- Expected people included?
- Sensitive groups excluded?
Technical Details
Technical Details
Setup & navigation
Setup and Maintenance → Manage Person Security Profile
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Area of Responsibility · Manager hierarchy and person type · Person-level or assignment-level access · View-all with exclusions · Custom criteria as last resort
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Expected people included? · Sensitive groups excluded?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
The person profile and the user’s actual AoR must both be configured.
Certification
The person profile and the user’s actual AoR must both be configured.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Control which person or assignment records a user can access.
Say it aloud
Area of Responsibility is the recommended scalable method for person security.
Do not confuse
Person-level access exposes all assignments of a person; assignment-level security can restrict access based on individual assignments.
Lesson 08
Areas of Responsibility
Fundamentals
Priya supports the India Software BU today and Cloud Services next month. One AoR-based profile adapts from her dated responsibility records instead of requiring a new data role each time.
What does it control?
Important distinction
AoR separates the reusable access rule from each user’s changing operational territory.
Easy exam definition
The accessible set is calculated dynamically from the user’s responsibility records.
Relationships
Where this fits
For Areas of Responsibility, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
AoR separates the reusable access rule from each user’s changing operational territory.
Implementation
Consultant sequence
- 1Define responsibility type
- 2Create AoR-driven profile
- 3Assign AoR to user
- 4Run/allow processing
- 5Validate
Acceptance evidence
- Dates active?
- Scope values correct?
Technical Details
Technical Details
Setup & navigation
My Client Groups → Person Management → Areas of Responsibility
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Responsibility type · Scope attributes · Start and end dates · Person or organization access
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Dates active? · Scope values correct?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
An expired or future AoR can make a correct profile appear broken.
Certification
An expired or future AoR can make a correct profile appear broken.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Dynamic responsibility-based scope for people and organizations.
Say it aloud
The accessible set is calculated dynamically from the user’s responsibility records.
Do not confuse
AoR separates the reusable access rule from each user’s changing operational territory.
Lesson 09
Role Mapping & Provisioning
Fundamentals
When Priya’s assignment becomes HR Specialist in India, Oracle should automatically give the India HR data role. When the qualifying assignment ends, the role should be removed if the mapping is configured for autoprovisioning.
What does it control?
Important distinction
Role mapping decides eligibility and provisioning behavior; it does not define the privileges inside the role.
Easy exam definition
Conditions are evaluated against assignments, and each associated role has its own provisioning options.
Relationships
Where this fits
For Role Mapping & Provisioning, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Role mapping decides eligibility and provisioning behavior; it does not define the privileges inside the role.
Implementation
Consultant sequence
- 1Define conditions
- 2Add associated role
- 3Select provisioning options
- 4Save
- 5Process and validate
Acceptance evidence
- Qualifying assignment found?
- Role added/removed as expected?
Technical Details
Technical Details
Setup & navigation
Setup and Maintenance → Manage Role Provisioning Rules
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Assignment-based conditions · Associated roles · Autoprovision · Requestable · Self-requestable
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Qualifying assignment found? · Role added/removed as expected?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Multiple qualifying assignments or mappings may preserve a role after one assignment changes.
Certification
Multiple qualifying assignments or mappings may preserve a role after one assignment changes.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Conditions that automatically or manually provision roles.
Say it aloud
Conditions are evaluated against assignments, and each associated role has its own provisioning options.
Do not confuse
Role mapping decides eligibility and provisioning behavior; it does not define the privileges inside the role.
Lesson 10
User Accounts & Lifecycle
Fundamentals
Priya is hired, transfers, and later terminates. TechNova’s enterprise options determine account creation and maintenance, while employment events and provisioning processes affect role and account status.
What does it control?
Important distinction
A person record, user account, and provisioned roles are connected but distinct objects.
Easy exam definition
Employment events can affect account status and roles according to configured enterprise options and processes.
Relationships
Where this fits
For User Accounts & Lifecycle, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
A person record, user account, and provisioned roles are connected but distinct objects.
Implementation
Consultant sequence
- 1Confirm person-worker linkage
- 2Check account status
- 3Check enterprise options
- 4Check provisioned roles
- 5Run synchronization if appropriate
Acceptance evidence
- Account active at correct time?
- Roles reflect current assignments?
Technical Details
Technical Details
Setup & navigation
Setup and Maintenance → Manage Enterprise HCM Information; Security Console → Users
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Automatic or bulk account creation · Enterprise account options · Username and notification rules · Suspension and termination behavior · User and role synchronization
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Account active at correct time? · Roles reflect current assignments?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Do not create a second user merely because an existing worker cannot sign in.
Certification
Do not create a second user merely because an existing worker cannot sign in.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Create, maintain, suspend, and synchronize HCM-linked users.
Say it aloud
Employment events can affect account status and roles according to configured enterprise options and processes.
Do not confuse
A person record, user account, and provisioned roles are connected but distinct objects.
Lesson 11
Custom Roles
Fundamentals
TechNova needs an HR auditor who can view but not update worker data. The consultant copies the closest predefined role and removes unnecessary capabilities in the custom copy.
What does it control?
Important distinction
Predefined roles should not be modified; custom copies provide a supported place for changes.
Easy exam definition
Copying only the top role keeps inherited predefined roles shared; copying the full hierarchy creates more custom components to maintain.
Relationships
Where this fits
For Custom Roles, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Predefined roles should not be modified; custom copies provide a supported place for changes.
Implementation
Consultant sequence
- 1Evaluate delivered role
- 2Choose copy strategy
- 3Use custom code/name
- 4Adjust least privilege
- 5Regenerate and test
Acceptance evidence
- Only required functions remain?
- Upgrade resilience understood?
Technical Details
Technical Details
Setup & navigation
Tools → Security Console → Roles → Copy Role
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Copy top role · Copy top and inherited roles · Edit inherited roles or policies · Regenerate data role grants
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Only required functions remain? · Upgrade resilience understood?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Copying an entire hierarchy without need increases maintenance and reduces resilience.
Certification
Copying an entire hierarchy without need increases maintenance and reduces resilience.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Copy or create roles while preserving maintainability.
Say it aloud
Copying only the top role keeps inherited predefined roles shared; copying the full hierarchy creates more custom components to maintain.
Do not confuse
Predefined roles should not be modified; custom copies provide a supported place for changes.
Lesson 12
Security Console
Fundamentals
Priya has different access from another India HR specialist. The security administrator compares users and roles, visualizes inheritance, and identifies the extra data role.
What does it control?
Important distinction
Security Console manages roles and users; HCM security profile and role-mapping tasks remain in HCM setup areas.
Easy exam definition
Use comparison and visualization to diagnose effective access before changing roles.
Relationships
Where this fits
For Security Console, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Security Console manages roles and users; HCM security profile and role-mapping tasks remain in HCM setup areas.
Implementation
Consultant sequence
- 1Reproduce issue
- 2Compare known-good user
- 3Inspect hierarchy
- 4Trace role assignment source
- 5Make minimal correction
Acceptance evidence
- Difference isolated?
- Effective access retested?
Technical Details
Technical Details
Setup & navigation
Navigator → Tools → Security Console
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Role and user search · Hierarchy visualization · Role and user comparison · Role copying · Administration options and analytics
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Difference isolated? · Effective access retested?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Security Console is not the place to define HCM person security-profile criteria.
Certification
Security Console is not the place to define HCM person security-profile criteria.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Search, visualize, compare, copy, analyze, and administer security.
Say it aloud
Use comparison and visualization to diagnose effective access before changing roles.
Do not confuse
Security Console manages roles and users; HCM security profile and role-mapping tasks remain in HCM setup areas.
Lesson 13
Security Processes & Synchronization
Fundamentals
TechNova created a mapping correctly, but Priya’s role has not appeared. The consultant checks whether the relevant provisioning or security synchronization process has completed before redesigning the mapping.
What does it control?
Important distinction
Each process solves a different layer: eligibility, identity-store request, security data import, or grant regeneration.
Easy exam definition
Select the process that matches the stale layer; do not run every process blindly.
Relationships
Where this fits
For Security Processes & Synchronization, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Each process solves a different layer: eligibility, identity-store request, security data import, or grant regeneration.
Implementation
Consultant sequence
- 1Identify stale layer
- 2Check process history
- 3Run targeted process
- 4Review log/output
- 5Retest user
Acceptance evidence
- Process succeeded?
- Role/profile visible afterward?
Technical Details
Technical Details
Setup & navigation
Tools → Scheduled Processes
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Autoprovision Roles for All Users · Send Pending LDAP Requests · Import User and Role Application Security Data · Regenerate Data Security Profiles and Grants
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Process succeeded? · Role/profile visible afterward?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
A successful job does not prove the original role-mapping conditions were satisfied.
Certification
A successful job does not prove the original role-mapping conditions were satisfied.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Processes that reconcile users, roles, profiles, and grants.
Say it aloud
Select the process that matches the stale layer; do not run every process blindly.
Do not confuse
Each process solves a different layer: eligibility, identity-store request, security data import, or grant regeneration.
Lesson 14
Audit & Troubleshooting
Fundamentals
Priya can suddenly see UK workers. TechNova compares her access, traces inherited roles and data scopes, then reviews audit history to find the configuration change and its actor.
What does it control?
Important distinction
Audit explains what changed and by whom; it does not replace effective-access analysis.
Easy exam definition
Troubleshoot in layers: account → assigned role → inheritance → function privilege → data policy/profile → processing.
Relationships
Where this fits
For Audit & Troubleshooting, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Audit explains what changed and by whom; it does not replace effective-access analysis.
Implementation
Consultant sequence
- 1Capture exact symptom
- 2Compare with working user
- 3Trace access chain
- 4Review recent changes
- 5Correct and retest
Acceptance evidence
- Root cause evidenced?
- Excess access removed without breaking valid access?
Technical Details
Technical Details
Setup & navigation
Security Console; Tools → Audit Reports; Scheduled Processes
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Function test · Data population test · Role/user comparison · Provisioning source · Audit reports and logs
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Root cause evidenced? · Excess access removed without breaking valid access?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Adding a broad role may hide the symptom while creating a larger security risk.
Certification
Adding a broad role may hide the symptom while creating a larger security risk.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Trace access from symptom to source and interpret security changes.
Say it aloud
Troubleshoot in layers: account → assigned role → inheritance → function privilege → data policy/profile → processing.
Do not confuse
Audit explains what changed and by whom; it does not replace effective-access analysis.
Lesson 15
Securing HCM Reporting
Fundamentals
Priya may run the India headcount analysis but must not access UK worker rows. TechNova secures both the catalog/subject-area capability and the underlying data returned by the report.
What does it control?
Important distinction
Catalog access controls who can open content; data security controls which rows are returned.
Easy exam definition
OTBI generally respects HCM data security; BI Publisher designs must use secured sources appropriately.
Relationships
Where this fits
For Securing HCM Reporting, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Catalog access controls who can open content; data security controls which rows are returned.
Implementation
Consultant sequence
- 1Grant minimum reporting role
- 2Secure catalog object
- 3Use secured data source
- 4Test as user
- 5Validate exported data
Acceptance evidence
- Can open intended report?
- Only permitted rows returned?
Technical Details
Technical Details
Setup & navigation
Reports and Analytics; Security Console; BI catalog administration
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
OTBI subject areas and folders · BI roles and catalog permissions · HCM data security · BI Publisher data models · Secured list views
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Can open intended report? · Only permitted rows returned?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Selecting directly from an unsecured database table can bypass the intended HCM row security.
Certification
Selecting directly from an unsecured database table can bypass the intended HCM row security.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Protect OTBI and BI Publisher content and data.
Say it aloud
OTBI generally respects HCM data security; BI Publisher designs must use secured sources appropriately.
Do not confuse
Catalog access controls who can open content; data security controls which rows are returned.
Lesson 16
Role Delegation
Fundamentals
Priya will be on leave and delegates an eligible HR role to Maya for a fixed period. Approval-task delegation is handled separately from role delegation.
What does it control?
Important distinction
Role delegation transfers eligible role access temporarily; workflow-task delegation routes approval tasks.
Easy exam definition
Abstract roles cannot normally be delegated because they represent the worker’s own identity in the enterprise.
Relationships
Where this fits
For Role Delegation, always trace both the role hierarchy and the data boundary. A change in either can change the user’s final experience.
Nearest concept
Role delegation transfers eligible role access temporarily; workflow-task delegation routes approval tasks.
Implementation
Consultant sequence
- 1Confirm role eligible
- 2Enable delegation
- 3Choose proxy and dates
- 4Validate scope
- 5Expire/revoke
Acceptance evidence
- Proxy receives only intended role?
- End date enforced?
Technical Details
Technical Details
Setup & navigation
Security Console → enable delegation; Me → Roles and Delegations
Prerequisites
Business access requirement, target user/person, role design, data scope, test user and effective date.
Configuration objects
Delegator and proxy · Delegation-enabled role · Start and end dates · Manager hierarchy implications
Security layers
Account status → assigned role → inheritance → function privilege → data security policy/profile.
Provisioning
Confirm direct, requestable, autoprovisioned, or delegated source; review all qualifying assignments.
Processing
Run only the process appropriate to the changed or stale layer; review status and logs.
Validation
Proxy receives only intended role? · End date enforced?
Effective dating
Check start/end dates on worker, assignment, AoR, delegation, and configuration criteria.
Audit evidence
Record requester, approver, configuration change, process result, and before/after access test.
Downstream impact
Review self-service, approvals, reporting, integrations, delegated access, and segregation of duties.
Troubleshooting
Reproduce → compare → trace → process → retest. Avoid broad grants as a shortcut.
Least privilege
Grant only required functions and populations; prefer resilient, reusable profiles and roles.
Consultant challenge
Delegating a role may also expose its inherited functions and data, so review the full hierarchy.
Certification
Delegating a role may also expose its inherited functions and data, so review the full hierarchy.
What the exam may ask
- Identify the correct security layer from a user symptom.
- Review a role, mapping, or profile configuration and predict effective access.
- Select the most maintainable least-privilege design.
Revision
60-second revision
Temporarily allow a proxy to act using an enabled role.
Say it aloud
Abstract roles cannot normally be delegated because they represent the worker’s own identity in the enterprise.
Do not confuse
Role delegation transfers eligible role access temporarily; workflow-task delegation routes approval tasks.