Applications Environment Management IAM Policy
Reference
Set up advanced access policies.
Applications environment management uses Identity and Access Management (IAM) as its base service
for authentication and authorization.
IAM is a policy-based identity service. The tenancy administrator for your organization needs to set up compartments, groups, and policies that control which users can access which resources and how. For an overview of this process, see Learn Best Practices for Setting Up Your Tenancy.
You create policies using the Oracle Cloud Infrastructure
Console. For detailed information, see Managing Policies.
Resource types are the resources that a policy grants access to. The resource types can
be an individual resource, such as environment, or a resource family that grants access
to multiple, related resources.
Application or Application Suite
Individual Resource-Types
Aggregate Resource Type
Commerce Cloud
commercecloud-environment
commercecloud-compliancedocs
commercecloud-environment-family
EPM Planning
epm-planning-environment
epm-planning-compliancedocs
epm-planning-environment-family
Financial Services Accounting Standards for Banking Cloud
Service
FSGBUASCS-environment
FSGBUASCS-compliancedocs
FSGBUASCS-environment-family
Financial Services Analytical Applications Cloud Service
FSGBUERF-environment
FSGBUERF-compliancedocs
FSGBUERF-environment-family
Financial Services Climate Change Analytics Cloud Service
FSGBUCCA-environment
FSGBUCCA-compliancedocs
FSGBUCCA-environment-family
Financial Services Crime and Compliance Management Anti Money Laundering Cloud Service
FSGBUFCCMAMLCS-environment
FSGBUFCCMAMLCS-compliancedocs
FSGBUCCMAMLCS-environment-family
Financial Services Insurance Cloud
FSGBUINS-environment
FSGBUINS-compliancedocs
FSGBUINS-environment-family
Financial Services Profitability and Balance Sheet Management
Service
FSGBUPBSM-environment
FSGBUPBSM-compliancedocs
FSGBUPBSM-environment-family
Maxymiser Testing and Optimization
maxymiser-environment
maxymiser-compliancedocs
maxymiser-environment-family
Student Financial Planning Cloud Service
OSFPCS-environment
OSFPCS-compliancedocs
OSFPCS-environment-family
Transportation and Global Trade Management Cloud
OTMGTM-environment
OTMGTM-compliancedocs
OTMGTM-environment-family
Utilities Work and Asset Cloud Service
UGBUWACS-environment
UGBUWACS-compliancedocs
UGBUWACS-environment-family
Warehouse Management Cloud Service
LOOGFIRE-environment
LOGFIRE-compliancedocs
LOGFIRE-environment-family
The <application>-environment-family resource-type
is an umbrella for the individual resource types. Use the aggregate resource-type to
grant permissions to all the individual resource-types in a single policy statement.
Applications environment management supports all the general variables, plus the ones
listed here. For more information about general variables supported by Oracle Cloud Infrastructure services, see General Variables for All Requests.
Variable
Variable Type
Comments
target.environment.id
Entity (OCID)
Use this variable to control whether to allow operations against a
specific environment in response to a request to read, update, delete,
or move an environment.
Details for Verb + Resource-Type Combinations 🔗
The level of access is cumulative as you go from inspect to
read to use to manage.
A plus sign (+) in a table cell indicates incremental access when
compared to the preceding cell, whereas no extra indicates no
incremental access.
For example, the read verb for the
<Application>-environment resource-type
includes the same permissions and API operations as the inspect verb,
but also adds the GetEnvironment API operation. Likewise, the
manage verb for the
<Application>-environment resource-type
allows even more permissions when compared to the use permission.