Administering Cloud EPM: The Platform Beneath the Business Processes · Module 6 · Users, Groups and the Role Model
Lab solution walkthrough
Lesson 77 of 201 · 18 min
The defensible alternatives, named first. Whether the subsidiary finance team is a separate group or shares one with their domestic equivalents is a genuine call. It depends on whether you expect their access to diverge. Whether internal audit gets a viewer role per environment, or a single cross-estate group, is similarly open. Then the consultants, directly. The immediate action is obvious. The interesting part of the answer is the process: time-bounded access grants for external parties, with an expiry that somebody actually acts on. A submission that removes the access and does not propose the process has answered half the question. Then the model is built on screen — matrix first, groups derived, roles assigned to groups, and the joiner test run live. "If your group model differs from mine and it is derived from access profiles rather than the org chart, you passed. The thing that fails is a…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 6 · Users, Groups and the Role Model
- 1What we are building
- 2The decision that does not feel like oneFree preview
- 3The access object model
- 4Predefined application roles
- 5Roles by business process
- 6Domain-level administrator roles
- 7Designing the group model
- 8Creating users
- 9Creating groups
- 10Policies for users and groups
- 11Assigning roles to groups
- 12Unassigning and offboarding
- 13Proving the model works
- 14What breaks
- 15Lab briefing: a role model for eight environments
- 16Lab solution walkthrough
