The seeded Common Content folder under: /Shared/Common Content is visible to BI users, including users assigned the seeded BI Consumer Role.
We would like to restrict the visibility and access to this seeded folder for end users based on our organization's reporting security requirements.
Currently, the BI Consumer role has the following privileges on the Common Content folder:
Read Traverse Run Publisher Report Schedule Publisher Report View Publisher Output
Unlike other seeded folders the permissions associated with the seeded Common Content folder cannot be modified or restricted by customers through the Security Console.
As a result, administrators are unable to prevent end users from seeing or accessing this seeded folder even when the folder is not required for their business reporting activities.
Requested Enhancement:
Please provide an administrator-controlled mechanism to:
Hide the seeded /Shared/Common Content folder from selected users or roles.Allow administrators to modify or restrict the folder permissions through standard OTBI/Oracle security mechanisms.Provide the ability to control access using custom BI roles, similar to other seeded folders.Ensure that administrators can manage the visibility of the folder without modifying Oracle-seeded objects.Ideally, provide a supported option to disable unnecessary access to Publisher-related privileges such as:Run Publisher ReportSchedule Publisher ReportView Publisher Output
Business Impact:
The inability to control access to this seeded folder creates challenges in maintaining a clean and role-based environment. It can also expose functionality and content that may not be relevant to certain end users.
The current workaround is to copy the required content to a custom folder and manage security on the custom folder. However, this approach introduces additional administration and maintenance overhead and may require customers to maintain duplicate content whenever Oracle updates the seeded content.
A supported mechanism to control visibility and permissions for the seeded Common Content folder would provide greater flexibility, improve security administration, and allow organizations to follow the principle of least privilege.
Expected Outcome
Provide customers with a supported configuration/security option to control the visibility and permissions of the seeded /Shared/Common Content folder without requiring modification of seeded Oracle objects.