Administering Cloud EPM: The Platform Beneath the Business Processes · Module 6 · Users, Groups and the Role Model
The access object model
Lesson 64 of 201 · 2 min
Six objects, and three of them get confused with each other constantly. User — an identity in the identity domain. Exists once per domain. Group — a collection of users in the identity domain. Application role — a permission set within a specific environment's business process. Role assignment — the link between a user or group and an application role on an environment. Policy — a rule governing what a group can do with CLOUD RESOURCES, as distinct from what they can do inside a business process. Domain-level administrator role — administration of the identity domain itself. Now the distinction to labour, because learners merge these three. An application role governs what you can do INSIDE A BUSINESS PROCESS. A policy governs what you can do WITH CLOUD RESOURCES. A domain administrator role governs IDENTITY ITSELF. Three different things. And one person traced through: a user, in a group, with…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 6 · Users, Groups and the Role Model
- 1What we are building
- 2The decision that does not feel like oneFree preview
- 3The access object model
- 4Predefined application roles
- 5Roles by business process
- 6Domain-level administrator roles
- 7Designing the group model
- 8Creating users
- 9Creating groups
- 10Policies for users and groups
- 11Assigning roles to groups
- 12Unassigning and offboarding
- 13Proving the model works
- 14What breaks
- 15Lab briefing: a role model for eight environments
- 16Lab solution walkthrough
