Types of Oracle BPM Administrative Users

There are two types of administrative users described in the following sections.

Oracle BPM System Administrator

A system administrator is responsible for configuring and maintaining Oracle BPM Enterprise. A system administrator has access to the entire project and can:
  • Create, configure, and control process execution engines
  • Configure audit record generation
  • Create and modify participants
    Note: When using a hybrid directory service, all participant information is maintained by the LDAP administrator.
  • Monitor processes
  • Publish and deploy projects
There are two types of Oracle BPM administrators:
Oracle BPM Administrator Type Description
Oracle BPM administrator defined when configuring a directory service. There is one Oracle BPM administrator for each directory service configuration.
Oracle BPM Administrator (participant) defined by granting Oracle BPM administrator access to a participant within the organization. This user has the same administrative privileges as the main Oracle BPM Administrator.

User Administrator

A user administrator is responsible for managing participants within an organizational unit, including creating and modifying participants and assigning and removing roles.

An Oracle BPM Administrator can grant user administrator privileges to any participant. The scope of a user administrator's access to manage participants is determined by the organizational unit they are assigned to. This assignment can be at the participant or group level.

Authentication of Administrators

Both Oracle BPM system administrators and user administrators must enter a username and password to access Process Administrator. Where Oracle BPM stores the passwords and permission information depend on the type of administrative user and directory service configuration.
Administrator Type Location of password
Oracle BPM System Administrator Is stored as part of the directory service configuration.

If you are using a database-only directory service this password can be changed using the Admin Center. If you are using a hybrid directory service, this password must be changed for the Oracle BPM Administrator user on your LDAP server.

Oracle BPM System Administrator (participant) Is stored as part of the participant information.

If you are using a database-only directory service, this password can be changed using Process Administrator. If you are using a hybrid directory service, this password must be changed for this participant on your LDAP server.

User Administrator Permissions and password are are stored as part of the participant information.

If you are using a database-only directory service, this password can be changed using Process Administrator. If you are using a hybrid directory service, this password must be changed for this participant on your LDAP server.