Assigning Specialized Workflow Monitoring Privileges

You can designate certain users as administrators only for particular types of workflows by assigning those users specialized workflow monitoring privileges with restricted access to workflow data. You can base the restrictions on a defined set of item types or on criteria specific to a particular functional area.

Ensure that users who act as specialized workflow administrators have access to the administrator version of the Status Monitor, either through an Oracle Workflow responsibility or from another application. See: Oracle Workflow Administrator Navigation Paths and Providing Access to the Status Monitor from Applications.

You must also grant permissions to specialized workflow administrators to enable them to perform administrative actions within the Status Monitor for workflows to which they have access. However, note that users cannot perform any actions on workflows that they own themselves, irrespective of any permissions granted to them. Only users with full workflow administrator privileges assigned in the Workflow Configuration page can perform administrative actions on workflows that they own themselves.

Note: If a user has full workflow administrator privileges assigned in the Workflow Configuration page, then those privileges override any specialized workflow monitoring privileges assigned to that user. That is, a user with full workflow administrator privileges can access all workflows, irrespective of any restrictions defined for any specialized privileges. See: Setting Global User Preferences.

arrow icon   To Grant Restricted Access to Workflow Monitoring Data:

You can restrict access to workflow monitoring data based only on item types, only on functional criteria, or on both item types and functional criteria. However, because grants based on functional criteria depend on item attribute values, these grants are most effective when combined with grants for item types that share the same item attributes.

For more information about creating instance sets and grants, see: Defining Data Security Policies and Assigning Permissions to Roles.

  1. If you want to restrict access based on item types, perform the following steps.

  2. If you want to restrict access based on criteria specific to a particular functional area using item attributes, perform the following steps.

arrow icon   To Grant Permissions for Administrative Actions within the Status Monitor:

If you want to assign a user privileges for all administrative actions within the Status Monitor, assign that user the role WF_ADMIN_ROLE. This role by default is granted the seeded permission set "Business workflow item permission set" (WF_ADMIN_PSET), which includes the permissions for all the administrative actions.

If you want to assign a user privileges only for specific administrative actions, create a custom permission set with the permissions you want to assign, and grant that permission set to the user. The following table lists the permission names and codes that correspond to the administrative actions.

Permissions for Administrative Actions in the Status Monitor

Action Permission Name Permission Code
Skip Skip Workflow Activity WF_SKIP
Retry Retry Activity WF_RETRY
Rewind Rewind Workflow WF_REWIND
Suspend Suspend Workflow WF_SUSPEND
Cancel Cancel Workflow WF_CANCEL
Update Update Workflow Item Attributes WF_UPDATE_ATTR
Monitor Monitor Data WF_MON_DATA

See: Assigning Permissions to Roles.