{
  "test_id": "ORCL.HCM.SECURITY.ROLE",
  "scenario_name": "Role Security",
  "application": "Oracle Fusion Cloud",
  "product": "HCM",
  "module": "HCM Data & Security",
  "process": "Role Security",
  "business_flow": "Recruit-to-Security",
  "scenario_type": "Positive / Negative / Security / Integration",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/hcm/hcm-data-and-security/role-security/",
  "objective": {
    "intro": "This test validates role assignment, HCM data role and worker population scoping, functional permissions and security regression after organizational changes, using masked/synthetic test data and without assuming a universal role or permission model.",
    "confirms": [
      "${ROLE} and ${DATA_ROLE} assignments correctly grant ${USER} access to the intended ${WORKER_POPULATION} and organization scope, and correctly restrict access outside that scope",
      "functional permissions — hire, change assignment, salary change, payroll access, benefits access, recruiting access, time approval and performance evaluation — correctly gate the corresponding action for the assigned role",
      "unauthorized users are correctly blocked from performing restricted functional actions or accessing restricted data such as national identifiers, candidate records, extracts or HDL loads",
      "role and data role changes never grant unintended excess access beyond what the newly assigned role defines",
      "access correctly re-scopes after organizational changes such as transfer, termination or manager change, rather than remaining tied to a worker's prior organization or reporting line",
      "role and permission behavior reflects the customer's own configured security model rather than assuming a universal Oracle role or permission structure"
    ],
    "scope_note": "A negative or security Role Security scenario passes when Oracle correctly enforces the expected access-control rule; this test does not attempt to certify a specific Oracle application defect. This page catalogs 35 individual Role Security scenarios as a single comprehensive reference rather than as separate indexable pages. All user, role and worker population values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real access grants."
  },
  "preconditions": [
    "Oracle Fusion HCM Security Console access is available to a test user with role and data role administration privileges.",
    "Representative ${ROLE} and ${DATA_ROLE} definitions are available or can be constructed in the target Oracle Fusion environment.",
    "Test users are available to represent ${USER} personas with and without the functional permissions under test.",
    "A valid ${WORKER_POPULATION}, ${ORGANIZATION} and ${LEGAL_EMPLOYER} are configured in the target Oracle Fusion environment.",
    "${BUSINESS_UNIT}, ${DEPARTMENT} and ${MANAGER_HIERARCHY} scoping options are documented where used by the customer's security configuration.",
    "Functional permission mappings for hire, salary change, payroll access, benefits access, recruiting access, time approval and performance evaluation are documented for the roles under test.",
    "A user without the relevant role or functional permission is available for unauthorized-access security testing."
  ],
  "test_data": [
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Role",
      "example": "${ROLE}"
    },
    {
      "field": "Data Role",
      "example": "${DATA_ROLE}"
    },
    {
      "field": "Worker Population",
      "example": "${WORKER_POPULATION}"
    },
    {
      "field": "Organization",
      "example": "${ORGANIZATION}"
    },
    {
      "field": "Legal Employer",
      "example": "${LEGAL_EMPLOYER}"
    },
    {
      "field": "Business Unit",
      "example": "${BUSINESS_UNIT}"
    },
    {
      "field": "Department",
      "example": "${DEPARTMENT}"
    },
    {
      "field": "Manager Hierarchy",
      "example": "${MANAGER_HIERARCHY}"
    },
    {
      "field": "Functional Permission",
      "example": "${FUNCTIONAL_PERMISSION}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as Security Administrator",
      "action": "Sign in to Oracle Fusion Cloud with a user account that has HCM Security Console access.",
      "test_data": "",
      "expected_result": "The Oracle Fusion Cloud home page loads successfully for the authenticated security administrator.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Assign Role and Data Role to Test User",
      "action": "Assign ${ROLE} and ${DATA_ROLE} to ${USER} via the Security Console.",
      "test_data": "${USER} / ${ROLE} / ${DATA_ROLE}",
      "expected_result": "The role and data role are assigned to the test user successfully.",
      "validation_type": "action"
    },
    {
      "step_number": 3,
      "step_name": "Verify Granted Worker Population and Organization Scope",
      "action": "Confirm the ${WORKER_POPULATION}, ${ORGANIZATION} and ${LEGAL_EMPLOYER} scope granted to ${USER} by the assigned data role.",
      "test_data": "${WORKER_POPULATION} / ${ORGANIZATION}",
      "expected_result": "The granted worker population and organization scope match the intended data role definition, or a deliberately mis-scoped assignment is correctly identified.",
      "validation_type": "business_assertion",
      "note": "Correctly scoping access to the intended population is a core business assertion across the data role and population scenarios in this catalog."
    },
    {
      "step_number": 4,
      "step_name": "Attempt Functional Action Within and Outside Granted Scope",
      "action": "As ${USER}, attempt the functional action defined by ${FUNCTIONAL_PERMISSION} (hire, salary change, payroll access, benefits access, recruiting access, time approval or performance evaluation) both within and outside the granted ${WORKER_POPULATION}.",
      "test_data": "${FUNCTIONAL_PERMISSION}",
      "expected_result": "The functional action succeeds within the granted scope and is correctly blocked outside the granted scope.",
      "validation_type": "business_assertion",
      "note": "This is the main functional-permission assertion tested across the catalog's functional permission and negative security scenarios."
    },
    {
      "step_number": 5,
      "step_name": "Verify Unauthorized Actions Are Blocked",
      "action": "As a user without ${ROLE} or the required ${FUNCTIONAL_PERMISSION}, attempt the same restricted functional action or restricted data access (national identifier, candidate data, extract or HDL load).",
      "test_data": "${FUNCTIONAL_PERMISSION}",
      "expected_result": "The unauthorized action or data access is correctly blocked.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 6,
      "step_name": "Change Worker Organization or Manager",
      "action": "Change the ${ORGANIZATION} or ${MANAGER_HIERARCHY} assignment for a worker within ${USER}'s granted population, simulating a transfer, manager change or termination.",
      "test_data": "${ORGANIZATION} / ${MANAGER_HIERARCHY}",
      "expected_result": "The organizational or manager change is applied successfully to the worker record.",
      "validation_type": "action"
    },
    {
      "step_number": 7,
      "step_name": "Verify Role and Population Re-Scope Correctly",
      "action": "Confirm that ${USER}'s access to the affected worker correctly re-scopes to reflect the worker's updated organization, manager hierarchy or termination status.",
      "test_data": "${WORKER_POPULATION}",
      "expected_result": "Access correctly re-scopes to reflect the organizational change, according to the customer's configured security rules.",
      "validation_type": "business_assertion",
      "note": "Security regression after organizational change is the main business assertion for the propagation scenarios in this catalog."
    },
    {
      "step_number": 8,
      "step_name": "Remove Role and Verify Access Revoked",
      "action": "Remove ${ROLE} from ${USER} and confirm that previously granted access is revoked.",
      "test_data": "${USER} / ${ROLE}",
      "expected_result": "Access previously granted by the removed role is correctly and immediately revoked.",
      "validation_type": "business_assertion"
    }
  ],
  "expected_results": [
    "${ROLE} and ${DATA_ROLE} assignments correctly grant access limited to the intended ${WORKER_POPULATION} and organization scope.",
    "Functional permissions correctly gate the intended action across hire, salary, payroll, benefits, recruiting, time and performance modules.",
    "Unauthorized functional actions and restricted data access are correctly blocked.",
    "Role removal correctly and immediately revokes previously granted access.",
    "Role and data role changes never grant unintended excess access.",
    "Access correctly re-scopes after organizational changes such as transfer, termination or manager change."
  ],
  "validation_checkpoints": [
    "Role correctly grants access only to the intended worker population and organization scope.",
    "Functional permissions correctly gate the intended action (hire/salary/payroll/etc.).",
    "Unauthorized actions across all functional areas correctly blocked.",
    "Role removal correctly and immediately revokes access.",
    "Role changes never grant unintended excess access.",
    "Access correctly re-scopes after organizational changes (transfer/termination/manager change)."
  ]
}
