Oracle HRMS
Oracle HRMS
1-31
Security Profiles
Security Profiles The security profile determines which applicant, employee,
contingent worker and other person type records are available to holders of
the responsibility the profile is linked to. If you are using HRMS Standard
security, you link a security profile to one responsibility using the HR:Security
Profile profile option. If you are using Security Groups Enabled security, you
link a security profile to the user's responsibility and business group using the
Assign Security Profile window. You can also link more than one security
profile to a responsibility, as long as the user is different. This saves you
setting up a new responsibility for each security profile you use. Note: If you
are using the Security Groups Enabled security model you must not use the
HR:Security Profile profile option. This is automatically set up when you
assign security profiles using the Assign Security Profile window.
See also Defining a Security Profile, page 1-49
Restricting Access to Records You set up a security profile by identifying
records of employees, applicants, contingent workers, and candidates in the
system which you want users to be able to access. You identify the records by
selecting work structures or other criteria in the application to which
employees, applicants, contingent workers, or candidates are attached. For
example, you could give users access only to the records of employees,
applicants, contingent workers, or candidates in a single organization. You
can also create restrictions on records with a person type of "Other". This
includes contacts for employees or applicants, and any other people with a
person type in the category of "Other". You do this using the "View Contacts"
option. You can combine different types of restriction to create a set of rules
giving exactly the security access permissions you require. When you create
a business group a view-all security profile is automatically created. This has
the same name as the business group. The security profile provides access to
all employee, contingent worker, andapplicant records in the business group.
The system administrator links this view-all profile to users who are setting
up the system. They in turn can set up security for other users. The criteria
you can use to identify records are:
1-32 Oracle Human Resources Management Systems Configuring,
Reporting, and System Administration Guide
Internal organizations and organization hierarchies
Positions and position hierarchies
Payrolls
Supervisors and supervisor hierarchies
Custom restrictions
Assignments
Tip: Oracle recommends that you use either a supervisor or position hierarchy
for Self-Service Human Resources (SSHR). For more information on
hierarchies in SSHR, see: People in Hierarchy, My List, and Search Pages,
Oracle SSHR Deploy Self-Service Capability Guide.
InternalOrganizations and Organization Hierarchies Organizations include
structures like departments, sections, groups and teams. You can restrict
access to a single organization, a list of organizations, or an organization
hierarchy. If you restrict on an organization hierarchy, you can exclude
specific organizations that are in the hierarchy, or add other organizations
that are not in the hierarchy.
Positions and Position Hierarchies Positions are jobs performed within
specified organizations. The position is derived from an organization and a
job, for example, you may have a position of Shipping Clerk associated with
the organization Shipping and the job Clerk.You can define security
restrictions based on a position hierarchy.
Payrolls
You can restrict access to employee records by payroll.For example, you can
give payroll staff who work on the payroll at a particular location access to
records of employees on this payroll only. Controlling security by payroll
assignment limits the employee records users can see and update on
employee-related windows, such as those for employee information, and
element entry. Of course, if an employee assignment does not include a
payroll, payroll security cannot apply to this assignment. Payroll security also
applies to applicants if they are assigned to a payroll.
Security Rules
1-33
Note: Payroll security is not available for contingent workers since they are
not assigned to a payroll.
The windows for compensation definition are unrelated to any particular
employee records or payroll assignments. Therefore limiting access by payroll
does not affect users' access to these windows.
Supervisors and Supervisor Hierarchies The supervisor for an employee,
applicant or contingent worker is the person identified in the Supervisor field