Applications Environment Management IAM Policy Reference

Set up advanced access policies.

Applications environment management uses Identity and Access Management (IAM) as its base service for authentication and authorization.

IAM is a policy-based identity service. The tenancy administrator for your organization needs to set up compartments, groups, and policies that control which users can access which resources and how. For an overview of this process, see Learn Best Practices for Setting Up Your Tenancy.

You create policies using the Oracle Cloud Infrastructure Console. For detailed information, see Managing Policies.

This topic contains details about the resource types and permissions used in applications environment management. For a quick start policy, see Managing User Access to Applications Environments.

Resource Types

Resource types are the resources that a policy grants access to. The resource types can be an individual resource, such as environment, or a resource family that grants access to multiple, related resources.

Application or Application Suite Individual Resource-Types Aggregate Resource Type
Commerce Cloud

commercecloud-environment

commercecloud-compliancedocs

commercecloud-environment-family

EPM Planning

epm-planning-environment

epm-planning-compliancedocs

epm-planning-environment-family
Financial Services Accounting Standards for Banking Cloud Service

FSGBUASCS-environment

FSGBUASCS-compliancedocs

FSGBUASCS-environment-family

Financial Services Analytical Applications Cloud Service

FSGBUERF-environment

FSGBUERF-compliancedocs

FSGBUERF-environment-family

Financial Services Climate Change Analytics Cloud Service

FSGBUCCA-environment

FSGBUCCA-compliancedocs

FSGBUCCA-environment-family

Financial Services Crime and Compliance Management Anti Money Laundering Cloud Service FSGBUFCCMAMLCS-environment

FSGBUFCCMAMLCS-compliancedocs

FSGBUCCMAMLCS-environment-family

Financial Services Insurance Cloud FSGBUINS-environment

FSGBUINS-compliancedocs

FSGBUINS-environment-family
Financial Services Profitability and Balance Sheet Management Service

FSGBUPBSM-environment

FSGBUPBSM-compliancedocs

FSGBUPBSM-environment-family

Maxymiser Testing and Optimization

maxymiser-environment

maxymiser-compliancedocs

maxymiser-environment-family

Student Financial Planning Cloud Service

OSFPCS-environment

OSFPCS-compliancedocs

OSFPCS-environment-family
Transportation and Global Trade Management Cloud

OTMGTM-environment

OTMGTM-compliancedocs

OTMGTM-environment-family

Utilities Work and Asset Cloud Service

UGBUWACS-environment

UGBUWACS-compliancedocs

UGBUWACS-environment-family
Warehouse Management Cloud Service

LOOGFIRE-environment

LOGFIRE-compliancedocs

LOGFIRE-environment-family

The <application>-environment-family resource-type is an umbrella for the individual resource types. Use the aggregate resource-type to grant permissions to all the individual resource-types in a single policy statement.

See the table in Details for Verb + Resource-Type Combinations for a detailed breakout of the API operations covered by each verb, for each individual resource-type.

Supported Variables

Applications environment management supports all the general variables, plus the ones listed here. For more information about general variables supported by Oracle Cloud Infrastructure services, see General Variables for All Requests.

Variable Variable Type Comments
target.environment.id Entity (OCID) Use this variable to control whether to allow operations against a specific environment in response to a request to read, update, delete, or move an environment.

Details for Verb + Resource-Type Combinations

The level of access is cumulative as you go from inspect to read to use to manage.

A plus sign (+) in a table cell indicates incremental access when compared to the preceding cell, whereas no extra indicates no incremental access.

For example, the read verb for the <Application>-environment resource-type includes the same permissions and API operations as the inspect verb, but also adds the GetEnvironment API operation. Likewise, the manage verb for the <Application>-environment resource-type allows even more permissions when compared to the use permission.

Commerce Details

EPM Planning Details

Financial Services Accounting Standards for Banking Cloud Service Details

Financial Services Analytical Applications Cloud Service Details

Financial Services Climate Change Analytics Cloud Service Details

Financial Services Crime and Compliance Management Anti Money Laundering Cloud Service Details

Financial Services Insurance Cloud Services Details

Financial Services Profitability and Balance Sheet Management Cloud Service Details

Maxymiser Details

Student Financial Planning Cloud Service Details

Transportation and Global Trade Management Cloud Details

Utilities Work and Asset Cloud Service Details

Warehouse Management Cloud Service Details