Roles and groups

Roles enable you to enforce and maintain individual accountability. Enterprise Security provides system roles, such as PortalSecOfficer and PortalGuest, and user-defined roles, which are created by the PSO. The PortalSecOfficer role is initially granted to the “pso” user, and permits unlimited access to the security system. The PortalGuest role allows Enterprise Portal users to self-register.

Roles provide individual accountability for users performing operational and administrative tasks. Their actions can be audited and attributed to them.

The PSO can define role hierarchies such that if a user is granted one role, the user is also granted roles that it inherits from. For example, the “chief_financial_officer” role might contain both the “financial_analyst” and the “salary_administrator” roles. The Chief Financial Officer can perform all tasks and see all data that can be viewed by Salary Administrators and Financial Analysts.

Enterprise Security associates access control with roles (role-based access control policy). Roles can be granted to a single user or a group of users.

When you create new roles, keep in mind the following functionality:

For information about how to create roles and groups, see “Setting up the security system”.