{
  "test_id": "ORCL.SEC.ROLE.ASSIGN",
  "scenario_name": "Role Assignment",
  "application": "Oracle Fusion Cloud",
  "product": "Security",
  "module": "Security",
  "process": "Role Assignment",
  "business_flow": "Provision-to-Revoke",
  "scenario_type": "Positive / Negative / Security / Integration",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/security/role-assignment/",
  "objective": {
    "intro": "This test validates the assignment, removal and replacement of Oracle Fusion application roles, using masked/synthetic test data and without assuming a universal role model across customer configurations.",
    "confirms": [
      "${ROLE} assignments to ${USER} — single, multiple, duplicate and effective-dated where supported — are correctly applied by Oracle Fusion",
      "role assignment correctly enables the intended ${MODULE} menu items and ${FUNCTION} actions, and role removal correctly disables them",
      "role assignment never grants access to ${MODULE} areas or ${FUNCTION} actions outside the scope of the assigned role",
      "module-specific roles — AP, Procurement, GL, HCM, Recruiting, Payroll and SCM — correctly grant only the functions expected for that module",
      "role changes correctly propagate to an active or refreshed ${USER} session within the expected timeframe",
      "role assignment activity is correctly recorded in audit history, and only authorized administrators can assign or remove roles",
      "role removal after a worker transfer or termination correctly revokes access, and role assignment behavior is unaffected by a quarterly Oracle update",
      "role assignment behavior reflects the customer's own configured security model rather than assuming a universal Oracle role structure"
    ],
    "scope_note": "A negative or security Role Assignment scenario passes when Oracle correctly enforces the expected access-control rule; this test does not attempt to certify a specific Oracle application defect. This page catalogs 25 individual Role Assignment scenarios as a single comprehensive reference rather than as separate indexable pages. All user, role and function values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real access grants."
  },
  "preconditions": [
    "Oracle Fusion Security Console access is available to a test user with role administration privileges.",
    "Representative ${ROLE} definitions are available or can be constructed in the target Oracle Fusion environment, spanning AP, Procurement, GL, HCM, Recruiting, Payroll and SCM modules.",
    "Test users are available to represent ${USER} personas with and without the roles under test.",
    "A valid ${MODULE} and set of ${FUNCTION} actions are documented for each role under test.",
    "A user without role administration privileges is available for unauthorized role-administration security testing.",
    "Audit history / role assignment history is available or reviewable for the target Oracle Fusion environment.",
    "A test window around a scheduled Oracle quarterly update is available where quarterly-update regression is in scope."
  ],
  "test_data": [
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Role",
      "example": "${ROLE}"
    },
    {
      "field": "Module",
      "example": "${MODULE}"
    },
    {
      "field": "Function",
      "example": "${FUNCTION}"
    },
    {
      "field": "Data Role",
      "example": "${DATA_ROLE}"
    },
    {
      "field": "Effective Date",
      "example": "${EFFECTIVE_DATE}"
    },
    {
      "field": "Prior Role",
      "example": "${PRIOR_ROLE}"
    },
    {
      "field": "Administrator",
      "example": "${ADMIN_USER}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as Security Administrator",
      "action": "Sign in to Oracle Fusion Cloud with a user account that has Security Console role administration access.",
      "test_data": "",
      "expected_result": "The Oracle Fusion Cloud home page loads successfully for the authenticated security administrator.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Assign Role to Test User",
      "action": "Assign ${ROLE} to ${USER} via the Security Console, including multiple-role and duplicate-assignment variants where relevant.",
      "test_data": "${USER} / ${ROLE}",
      "expected_result": "The role is assigned to the test user successfully, and a duplicate assignment attempt is handled without creating a conflicting grant.",
      "validation_type": "action"
    },
    {
      "step_number": 3,
      "step_name": "Verify Menu and Function Access Granted",
      "action": "As ${USER}, confirm the expected ${MODULE} menu items and ${FUNCTION} actions defined by ${ROLE} are now visible and usable.",
      "test_data": "${MODULE} / ${FUNCTION}",
      "expected_result": "The intended menu items and functions are correctly enabled for ${USER}.",
      "validation_type": "business_assertion",
      "note": "Confirming that role assignment enables exactly the intended functions is a core business assertion across this catalog."
    },
    {
      "step_number": 4,
      "step_name": "Verify No Unrelated Access Granted",
      "action": "As ${USER}, attempt to access ${MODULE} areas and ${FUNCTION} actions outside the scope of the assigned ${ROLE}.",
      "test_data": "${MODULE} / ${FUNCTION}",
      "expected_result": "Access outside the scope of the assigned role is correctly blocked, confirming no unintended access was granted.",
      "validation_type": "business_assertion",
      "note": "This is the main negative-scope assertion tested across the module-specific and boundary scenarios in this catalog."
    },
    {
      "step_number": 5,
      "step_name": "Verify Unauthorized Role Administration Blocked",
      "action": "As a user without role administration privileges, attempt to assign or remove a role for another user.",
      "test_data": "${USER} / ${ROLE}",
      "expected_result": "The unauthorized role administration attempt is correctly blocked.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 6,
      "step_name": "Simulate Session Refresh and Organizational Change",
      "action": "Refresh or re-establish ${USER}'s session after a role change, and simulate a transfer or termination event affecting ${USER} or a worker within scope.",
      "test_data": "${USER} / ${ROLE}",
      "expected_result": "The role change is correctly reflected after session refresh, and the organizational change is applied successfully.",
      "validation_type": "action"
    },
    {
      "step_number": 7,
      "step_name": "Verify Role Assignment Regression and Audit History",
      "action": "Confirm ${USER}'s role assignment behaves correctly after the organizational change and, where in scope, after a quarterly Oracle update, and review the audit history entry recorded for the role assignment.",
      "test_data": "${ROLE}",
      "expected_result": "Role assignment and functional access behave correctly after the change, and the assignment is correctly recorded in audit history.",
      "validation_type": "business_assertion",
      "note": "Security regression after organizational change and quarterly update is the main business assertion for the propagation scenarios in this catalog."
    },
    {
      "step_number": 8,
      "step_name": "Remove Role and Verify Access Revoked",
      "action": "Remove ${ROLE} from ${USER}, or replace it with a different role, and confirm previously granted access is revoked or updated accordingly.",
      "test_data": "${USER} / ${ROLE} / ${PRIOR_ROLE}",
      "expected_result": "Access previously granted by the removed or replaced role is correctly and immediately revoked or updated.",
      "validation_type": "business_assertion"
    }
  ],
  "expected_results": [
    "${ROLE} assignment, removal and replacement are correctly applied by Oracle Fusion, including multiple-role and duplicate-assignment handling.",
    "Role assignment correctly enables the intended ${MODULE} menu items and ${FUNCTION} actions, and role removal correctly disables them.",
    "Role assignment never grants access to ${MODULE} areas or ${FUNCTION} actions outside the scope of the assigned role.",
    "Unauthorized role administration attempts are correctly blocked.",
    "Role changes correctly propagate to an active or refreshed session within the expected timeframe.",
    "Role assignment behaves correctly after transfer, termination or a quarterly Oracle update, and is correctly recorded in audit history."
  ],
  "validation_checkpoints": [
    "Role correctly grants only the intended menu items and functions.",
    "Role assignment never grants unrelated or excess access.",
    "Duplicate role assignment handled without a conflicting grant.",
    "Unauthorized role administration correctly blocked.",
    "Role changes propagate correctly after session refresh.",
    "Role removal correctly and immediately revokes access.",
    "Role assignment correctly recorded in audit history.",
    "Role assignment behaves correctly after transfer, termination and quarterly update."
  ]
}
