Use these pages to create a grant. Grants are used to manage user access to product functionality. In these pages you give access to functions to specified users.
In this page you specify basic information for the grant.
To define a grant:
Enter a name and description for your grant.
Enter effective dates for your grant.
Enter the security context information.
The security context defines the circumstances in which the grant is active.
For Grantee, you can select a single user, a role, or global (all users and roles).
For Operating Unit, specify an operating unit if you want your grant to apply to a specific one.
For Responsibility, specify a responsibility if you want your grant to apply to a specific one.
Enter the Data Security information if you are creating a data security policy for an object. The grant applies to the object you specify.
If you are not creating a data security policy, you will skip the next step.
Note: You cannot change a data security policy once it has been saved. You can delete it or provide an end date to a data security policy.
If you specified that your grant applies to a single object, you add context for that object in this page.
Choose one of the following:
Global (All Rows) - Indicates that the set of functions is being granted for all rows of the object (for a function security grant).
Instance - Indicates that the set of functions are being granted for a single row, specified by value(s) for the primary key.
Instance Set - Indicates that the set of functions are being granted for a set of rows which is specified by an instance set predicate.
If you selected either an object instance or an instance set earlier, you can further customize the resulting set by additional information for the data context.
Additionally, you can select either a permission set or a navigation menu that can additionally specify how the grant will be applied in the security context.
For an instance set:
In the Predicate region, the predicate that defines the instance set is shown. In the Instance Set Details region, specify the values for the parameters to be used in the predicate above.
Select the permission set or navigation menu set that defines the grantee's access.
For an instance:
In the Instance Details region, specify information identifying the instance.
Select the permission set or navigation menu set that defines the grantee's access.
Use this page to review the definition of your grant. Click Finish to save your work.
Use this page to update the definition of your grant.