Results for “oke_compiled_access_rules”

6 results




AI-generated from documented ETRM metadata — verify critical details on the linked pages.

Overview

OKE_COMPILED_ACCESS_RULES is a table in the OKE schema, owned by the Oracle Project Contracts (OKE) module, and is documented as valid in Oracle E-Business Suite 12.1.1 and 12.2.2. The table stores compiled access rules information. In functional terms, it materializes the effective, pre-resolved combination of security roles, secured project contract objects, and the attribute-level granularity at which access is granted or denied. Rather than evaluating access rules dynamically at runtime, OKE compiles the underlying rule definitions into this table so that security checks against contract objects can be performed efficiently.

Under a heuristic Data Vault classification mined from its foreign key structure, OKE_COMPILED_ACCESS_RULES is best modeled as a link. This characterization reflects its role as an associative structure binding a role, a secured object, and an access rule into a combined access assignment. It is not treated as a pure descriptive satellite of a single parent, because its identity depends on the intersection of multiple referenced entities.

Key Information Stored

The physical schema documents thirteen columns. The columns of greatest functional importance are:

The table has two documented unique indexes. The primary key, OKE_COMPILED_ACCESS_RULES_UK01, is composite over ROLE_ID, SECURED_OBJECT_NAME, ATTRIBUTE_GROUP_TYPE, ATTRIBUTE_GROUP_CODE, and ATTRIBUTE_CODE. A second unique index, OKE_COMPILED_ACCESS_RULES_U1, covers ROLE_ID, SECURED_OBJECT_NAME, ATTRIBUTE_CODE, and ATTRIBUTE_GROUP_CODE and serves as a business-key candidate. The table has no single-column surrogate primary key; identity is derived entirely from the composite business key.

Common Use Cases and Queries

Typical uses center on security reporting and troubleshooting access behavior for project contracts. Administrators may query compiled rules to verify which roles hold which access levels on specific contract objects or attributes, and to reconcile compiled results against source rule definitions in OKE_K_ACCESS_RULES.

  • Listing all compiled rules for a given role:
SELECT role_id, secured_object_name, attribute_code, access_level
FROM   oke.oke_compiled_access_rules
WHERE  role_id = :role_id;
  • Reviewing compiled rules for a specific secured object and attribute:
SELECT role_id, attribute_group_type, attribute_group_code,
       attribute_code, access_level, form_item_flag
FROM   oke.oke_compiled_access_rules
WHERE  secured_object_name = :object_name
AND    attribute_code      = :attribute_code;
  • Tracing a compiled entry to its originating rule:
SELECT c.role_id, c.secured_object_name, c.attribute_code,
       c.access_level, r.access_rule_id
FROM   oke.oke_compiled_access_rules c,
       oke.oke_k_access_rules     r
WHERE  c.access_rule_id = r.access_rule_id;

These patterns support access audits, role-to-object entitlement extracts, and diagnostics when compiled access appears inconsistent with configured rules.

Related Objects

The documented foreign keys identify the principal related objects:

  • PA_PROJECT_ROLE_TYPES — joined via ROLE_ID; supplies the project role definition.
  • OKE_K_ACCESS_RULES — joined via ACCESS_RULE_ID; provides the source rule definition that was compiled.
  • OKE_OBJECT_ATTRIBUTES_B — joined via SECURED_OBJECT_NAME and ATTRIBUTE_CODE; defines the secured object and its attributes.

Because the compiled rows depend on these parents, integrity and reconciliation queries should always include them. Together these objects constitute the access-rule compilation chain within the Oracle Project Contracts module, with OKE_COMPILED_ACCESS_RULES acting as the resolved junction between roles, secured objects, and source rules.