Oracle Fusion HCM Analytics

Welcome to the Oracle Analytics Community: Please complete your User Profile and upload your Profile Picture

need to know what is the significance of functional group while defining security filters for custom

Received Response
62
Views
3
Comments

We are defining custom security for employees who have both all data access and are Line Managers. We are following this blog and defining security configuration for custom roles. As per blog, if security filters for 2 roles have same functional group associated, it will create an OR condition while applying filters.

need to know what is the significance of functional group while defining security filters for custom role. Which functional group do we need to select

BLOG -

https://blogs.oracle.com/analytics/post/setting-up-custom-hr-analyst-and-line-manager

Welcome!

It looks like you're new here. Sign in or register to get started.

Answers

  • Hi Gayatri, Functional Group is Custom or Prebuilt Group where you can map multiple application roles to the Group in FAW so you can select a Prebuilt Group or Custom Group based on your business requirement

    For more details on FAW Group please review following documentation:

    thank you,

    -Rajesh

  • Rank 1 - Community Starter

    Hi gayatri, we also have a similar requirement of view all role should superseed line manger role, did you get the understanding of the functional group , whats the functional group should we select while implementing the same, any leads will br highly sppreciated

  • edited Mar 10, 2025 7:54AM

    @user11382739 @Phalke, Gayatri - Yes , Today in FDI HCM - OOTB data roles grant most restrictive access as each OOTB data role has a different Functional Group associated.

    • Grant Least Restrictive access across multiple data role 
      • Each data role should have same functional group
    • Grant most restrictive access across multiple data roles
      • Each data role should have a unique functional group
    • Combination of OOTB Data Role + Custom Data role
      • To grant most restrictive - use Unique Functional Group in Custom data role , as one cannot change anything in the OOTB data role configurations.
      • To grant least restrictive data access -Combination of OOTB and custom data role always grants most restrictive access by default. To override this behavior - you need to create all data roles as custom data role and use same functional group in each data role to grant least restrictive data access.

    No Functional group in different data roles - also gets treated as same functional group. Hence multiple data roles without any functional group associated also grants least restrictive data access.

    For your requirement -

    Option-1 - You can create one data role for View All Data Role and use HCM_FACT_LM as the functional group in that.

    Option-2 - You can also create 2 data roles ( one for Line Manager and one for View All data role ) and use the same functional group - however , this creates additional data role which can be avoided in the 1st option. We have documented this use case in https://blogs.oracle.com/analytics/post/setting-up-custom-hr-analyst-and-line-manager , kindly note that this blog was published couple of years ago and some of the Semantic model UI may have changed , hence navigations may not match exact with the UI.

    In upcoming FDI HCM release , we are also coming up with a feature where you will be able to change this behaviour by a toggle of a button. Please look for What's new section in documentation in upcoming FDI HCM releases.

Welcome!

It looks like you're new here. Sign in or register to get started.