Understanding this concept makes you realize that one individual user can have any number of different roles at the same time. The combination of roles determines the user's level access to a specific cloud service.
For example, an individual user might be assigned the roles:
- Sales Manager
- Sales Analyst
- Employee
In this example, the individual user gets access:
- As an employee, so the user can access employee functions and data.
- As a sales manager, so the user can access sales manager functions and data.
- As a sales analyst, so the user can access sales analysis functions and data.
In case the user signs into the application (and is successfully authenticated), the user session is established, and all the roles assigned to the specific user are loaded into the session repository. The Fusion Cloud application determines the set of privileges to application resources that are provided by the roles, and then grants the user the most permissive level of access.
Example
In order to understand how the individual user with his or her associated roles and privileges creates the license requirements for the different cloud services and their associated cloud subscriptions, the below real-life example has been created.
User and its Roles: User John Doe has the roles of "Manager" and "Employee."
Roles and their Privileges: An individual user can have one or multiple roles.
The role Employee includes (among others) the privileges:
- Access Time Work Area
- Create Performance Document by Worker
- Manage Expense Report
The role Line Manager includes (among others) the privileges:
- Create Performance Document by Manager
- Manage Team Reputation Tasks
- Access Learning Common Components
Privileges and its Cloud Services: A privilege can belong to one or more cloud services. If you start "mapping" the different privileges to cloud services, the following conclusions can be drawn:
The privilege Access Time Work Area relates to
- Time and Labor Cloud Service AND
- Enterprise Resource Planning for Self Service Cloud Service
The privilege Create Performance Document by Worker relates to
- Performance Management Cloud Service
The privilege Manage Expense Reports relates to
- Enterprise Resource Planning for Self Service Cloud Service
The privilege Create Performance Document by Manager relates to
- Performance Management Cloud Service
The privilege Manage Team Reputation Tasks relates to
- Workforce Reputation Management Cloud Service
The privilege Access Learning Common Components relates to
- Oracle Learning Cloud Service
Cloud Services vs Cloud Subscriptions: A functional cloud service can belong to one or more "Cloud Subscriptions" that can be purchased from Oracle. If you start "mapping" the different cloud services to cloud subscriptions, the following conclusions can be drawn:
- The cloud service "Time and Labor Cloud Service" relates to the cloud subscription "Oracle Fusion Time and Labor Cloud Service"
- The cloud service "Enterprise Resource Planning for Self Service Cloud Service" relates to the cloud subscription "Oracle Fusion Enterprise Resource Planning for Self Service Cloud Service"
The cloud service "Performance Management Cloud Service" relates to the cloud subscription "Oracle Fusion Talent Management and Workforce Compensation Cloud Service," or "Oracle Fusion Talent Management for Coexistence Cloud Service"
- The cloud service "Workforce Reputation Management Cloud Service" relates to the cloud subscription "Oracle Human Capital Management Base Cloud Service"
- The cloud service "Oracle Learning Cloud Service" relates to the cloud subscription "Oracle Fusion Learning Cloud Service"
Conclusion: After doing all these “mappings,” the individual user “John Doe” requires (among others) a Hosted Named User subscription for:
- Oracle Fusion Time and Labor Cloud Service Oracle Fusion Enterprise Resource Planning for Self Service
- Oracle Fusion Talent Management and Workforce Compensation Cloud Service, or
- Oracle Fusion Talent Management for Coexistence Cloud Service
- Oracle Human Capital Management Base Cloud Service
- Oracle Fusion Learning Cloud Service