Setting Up Groups

Overview

Oracle CPQ is commonly administered by teams of individuals who are responsible for administering different subsets of Oracle CPQ features. Administrator Access Control allows an Access Administrator to secure certain administrative features and prevent other Full Access users from accessing those pages, links and services.

Oracle CPQ has two methods to restrict access to Oracle CPQ administration features:

Administrator Groups

An Enable Administrator Groups setting is available on the General Site Option page. When set to Yes, the Administrator Access Control feature is enabled for the entire Oracle CPQ site.

Using Administrator Access Control with Administrator Groups, companies can delegate and restrict access to certain areas of CPQ’s setup and administration. This prevents unauthorized users from introducing unintentional errors, clarifies areas of responsibility, and protects sensitive or proprietary information.

When Administrator Groups are enabled and setup, Full Access users only have access to the administration pages and data to which they are entitled. To ensure this data is properly secured and the logged in user only sees links to the content they can access, Oracle has added a number of security features.

An Access Administrator has the permissions to set up Access Control Groups. For more information, see User Permissions and Setting Up Groups.

ClosedSecure Pages

The Admin Home page only displays the pages to which the logged in user has access. Members of the “All Access” group can access all pages and navigation menus. In the following example, the user has access to only a few of the administrative segments of the Admin Home page. The links are secured from unauthorized access.

Administration Platform


ClosedSecure Admin Drawer

Full Access users see an Admin Drawer in the upper left-hand corner of the screen under a "hamburger menu”. When the Administrator Access Control feature is turned on, the Admin Drawer only shows the pages to which the logged in user has access.

Secure Admin Drawer


ClosedSecure Navigation Menus

Administrators can customize the Navigation Menus for their users by providing links to internal and customized content. When these links point to administration features, they are removed when the user does not have access to the features. This security applies to headers, sub-headers, and sub-footers when using Top Navigation, Side Navigation, or Alta Navigation.

Secure navigation Menu

Customeize icons

If a custom link points to a restricted administrator page, it is not automatically hidden. An access denied message will display.

Restricted Admin page

Access denied


ClosedSecure SOAP Web Services

All SOAP APIs for administrative features that are public to Full Access users are secured, blocking unauthorized users from accessing data.

When using web services version 1.0 or version 2.0:

  • A SuperUser can access all administrator SOAP APIs (e.g. parts, groups, configuration, price books, data tables, users, exchange rates).
  • Authorized users can access designated administrator SOAP APIs.
  • Users trying to access restricted SOAP APIs will see an error message and the operation will fail.
  • The getGroups operation retrieves information for Sales groups only.
  • The modifyGroups operation can modify Sales groups only.

The following error displays in the response when a SOAP API to access data tables is called by an unauthorized user.

Sample SOAP API Error


ClosedSecure REST Web Services

All REST APIs for administrative features that are public to Full Access users are secured, blocking unauthorized users from accessing data.

  • A SuperUser can access all administrator REST APIs (e.g. parts, groups, configuration, price books, data tables, users, exchange rates).
  • Authorized users can access designated administrator REST APIs.
  • Users trying to access restricted REST APIs will see an error message and the operation will fail.

Sample REST API Error

Consider the following tips when using the Administrator Access Control feature:

  • Newly created Data Table folders and Product Families are only available to “All Access” users upon creation. An Access Administrator must grant access to those newly created items before they are usable by Full Access users who are not “All Access” users.
  • Bulk Data Services can only be globally allowed or restricted. A user with access to Bulk Data Services can access any data available for bulk upload or download, so grant access sparingly.
  • Users can only migrate settings when they have access to the features in both the target and the source site. If the user does not have access to a feature, the migration will fail.
  • Keep in mind that User Administrators can proxy login as any user. These users can bypass Access Controls by logging in as a Full Access user with greater access rights. As a result, grant User Administrator rights sparingly.

Sales Groups

Sales Groups are a collection of users and are useful for determining access rights for Commerce documents. From the Group Administration List page, you can add, edit, or deactivate user groups.

Administration

ClosedEnable Administrator Groups for Your Site

ClosedView Groups Based on Group Type

ClosedCreate and Edit Administrator Groups

ClosedCreate and Edit Sales Groups

Oracle CPQ includes the ability to create a new Group Type called Sales group.

The Group Administration page contains the following:

  • Type field: Use to designate a group type: Sales or Administrator. Once defined, users cannot modify the group type. The Administrator value for the Type field is shown on the Group Administration page only when the Enable Administrator Groups option is turned on.
  • Access Selector: Use to define the administrative features to which member users have access. The Access Selector is only available for Administrator groups and supports bulk selection of administrative features. In the Access Selector, all Admin Home page links are grouped under their respective segment names.

To create and edit Sales groups, perform the following steps:

  1. Open the Admin Home page.
  2. Under Users, select Groups.
    The Group Administration List page opens.
  3. To edit an existing Sales group, click its Group Name to open the Group Administration page.
  4. To create a new Sales group, click Add to open the Group Administration page.
  5. Populate the fields, as desired.
  6. From the Type drop-down, select Sales.

    Group Administration page

  7. Define the users who are members of the Sales group.
    • To add users to the group, move user names from the list of Available Users to the list of Selected Users.
    • To remove users from the group, move user names from the list of Selected Users to the list of Available Users.
  1. Click Save.

• Only Access Administrators can create Administrator groups. All other users can only choose the Sales group type.

• Access Administrators and Full Access users can use the Group Administration page to create and edit Sales groups. When the Enable Administrator Groups option is turned off, only Sales groups can be created.


ClosedAdd Users to Administrator Groups from the User Administration Page

ClosedInactivate a Group

Oracle CPQ 23D and later supports the ability for administrators to deactivate user groups. The Group Administration List page displays active and inactive groups. Once a group is deactivated, it will no longer be allowed access permissions nor will it be selectable for access to Commerce and Configuration properties. Administrators can grant different access to groups of users (using Participant Profiles) and different user-experiences in Commerce. By deactivating groups, administrators can better manage their implementation of user groups. For example, administrators may deactivate a user group to further segment the group or to address changes in business processes.

To deactivate a user group, perform the following steps:

  1. Click Groups in the Users section of the Admin Home page. The Group Administration List page displays showing the active and inactive group lists.

    Groups List Page

  2. To inactivate an existing group, click its Group Name to open the Group Administration page.

  3. Click Inactivate.

    Inactivate

    The selected user group is moved to the Inactive Groups List and the group is no longer allowed access permissions nor is selectable for access to Commerce and Configuration properties.

    Group Administration List Page

• A dependency error message displays while deactivating a group if it has any Administration, Commerce, or Configuration dependency. You must remove all dependencies before a Group can be deactivated.

• If the group variable name is used in BML scripts, a dependency error message does not display. Administrators can manually search BML scripts for the group variable and modify the logic before deactivating the group.

• All Access Administration Group cannot be deactivated.

• Both Host Company and Prtner Organization Groups can be deactivated.

• The Get User Group REST API response result will only provide active groups

Notes

The Users page lists all users. If the logged in user is not a User Administrator they will be able to see other user's detail pages in read-only mode. They can edit their own details by clicking their login in this list or by opening their My Profile page from the navigation bar or header. To restrict access to the Users list create an Admin Group which excludes access to that feature.

Admin Access Control does not impact the user side. A FullAccess user who is restricted from a Product Family on the admin side can still interact with the Product Family on the user side, unless access to the Product Family is restricted for that user through the Home Page. For more information, see the topic Home Page.

Groups can not be deleted once they are added. Oracle CPQ supports the ability for administrators to deactivate user groups. Refer to Inactivate a Group. Prior to Oracle CPQ 23D if you no longer need a group, you can choose to rename the group to indicate that the group is no longer being used.

Related Topics

Related Topics Link IconSee Also