Oracle Fusion HCM Analytics

Welcome to the Oracle Analytics Community: Please complete your User Profile and upload your Profile Picture

FDI Security Conundrum

203
Views
6
Comments
Rank 1 - Community Starter
edited Jul 11, 2024 7:34PM in Oracle Fusion HCM Analytics

We are working to rollout dashboards and reporting to a pilot group. We have quickly discovered a roadblock.

There are members of our organization that need to see data for the enterprise (example: project labor cost) and they are limited by their ERP roles such as Line Manager or Project Manager.

We have other users that need only to see data limited to their Line Manager or Project Manager roles (working fine as is and don't want to break).

Has anyone faced this requirement and found a way to solve? Forgive me if this is an amateur question, we are just getting warmed up over here!

Tagged:

Welcome!

It looks like you're new here. Sign in or register to get started.

Comments

  • Rank 6 - Analytics Lead

    Hi @Greg "G" Bushman

    This is not an amateur question at all.

    The Line Manager and Project Manager roles (Groups in FDI) do limit data so for those very few that should not be limited, you can goto the FDI Console > Security > Groups and remove one or both as required.

    Details on managing users, groups and roles can be found here:

    https://docs.oracle.com/en/cloud/saas/analytics/24r2/fawag/managing-users-groups-application-roles-and-data-access.html

    If you find this reply to your question useful, others might as well. By clicking the “Yes” button for “Did this answer the question?” below, you’ll be able to help the community members who might have a similar concern find the answer easier.

    Regards,

    John

  • Rank 1 - Community Starter

    @JohnW-Oracle - thank you for the response. That is precisely what we were doing. It was holding as well. It seems the latest update to FDI is not allowing the same behavior. We are seeing the roles sourced from ERP and IDCS into FDI and there is no clear path to eliminating groups/roles from certain users in FDI itself. As of now (and my understanding), any role assigned in ERP will flow to FDI and the option to remove the role in FDI exclusively is gone. We are also exploring 'shell roles' in ERP and mapping those in FDI but the Line Manager will overrule it seems.

  • Rank 1 - Community Starter

    @JohnW-Oracle I see your document is 24.R2 so will review to see what we may be missing.

  • Rank 6 - Analytics Lead

    Hi @Greg "G" Bushman ,

    Sounds good. One other thought. These users you have that are syncing may also be used for Data Validation. You may want to keep them in sync with your FA source and create new User(s) with a very limited number of Admin level Groups/Roles assigned.

    Regards,

    John

  • Rank 4 - Community Specialist

    Hey @Greg "G" Bushman

    My team and I are experiencing a similar issue, any luck with what was provided above or any resolution found?

    Thank you,

    Sean

  • @Greg "G" Bushman - can you please state your exact requirement ? You ideally should not remove users from any group that are synced via IDCS - as next IDCS sync will load it back. If you can provide more clarification of your exact requirement than we can guide you further.

    Regards,

    Nupur

Welcome!

It looks like you're new here. Sign in or register to get started.