Skip to content

Predefined Permission Sets

Predefined Permission Sets are created upon installation of IFS Cloud. These are tagged as 'IFS_MANAGED' or 'IFS_MANAGED_BASE' and should not be modified.

IFS Managed Base Permission Sets

The Permission Sets required for login and performing basic functionalities in IFS Cloud.

Permission SetDescriptionType
FND_WEBRUNTIMEThe Functional Role needed for a user to logon to IFS Cloud.Functional Role
FND_WEBENDUSER_MAINRole that contains framework functionality for IFS Cloud Web for a user. FND_WEBRUNTIME is granted this role. This role is a basic end user role for all IFS Cloud Web main users.End User Role
FND_WEBENDUSER_B2BRole that contains framework functionality for IFS Cloud Web for a Business to Business (B2B) user. FND_WEBRUNTIME is granted this role. This role is a basic end user role for all IFS Cloud Web B2B users.End User Role
MOBILE_APP_RUNTIMERole needed for a mobile user to logon and run a IFS Cloud Mobile app. FND_RUNTIME is granted to this role.Functional Role
FND_WEBENDUSER_MAIN_FNDWFBasic role for end users of IFS Cloud. Contains Business Process Automation Workflow functionality for usersFunctional Role
FND_WEBENDUSER_B2B_FNDWFBasic role for B2B users of IFS Cloud. Contains Business Process Automation Workflow functionality for B2B usersFunctional Role
FND_WEBENDUSER_MAIN_BISERVBusiness Reporter- FND Web end-user.Functional Role
FND_CONTACT_WIDGET_USER_ENTERPRole needed for Contact Widget to display customer and supplier information.End User Role

Administration

Permission SetDescriptionType
FND_ADMINRole needed for a user to be an administrator of IFS Platform. FND_WEBENDUSER_MAIN, FND_WEBENDUSER_B2B and FND_CUSTOMIZE are granted to this role.End User Role
FND_SCIM_ADMINRole used for handling SCIM container requestsEnd User Role

Development & Translations

Permission SetDescriptionType
FND_DEVELOPERThis role is for users that are developing IFS Applications. It gives rights to for instance debugging and analyzing functionality. Developers using IFS Developer Studio also need this role.End User Role
FND_DEVELOPER_FNDDEVRole for Developers which needs for Translation Management.Functional Role
FND_DEVELOPER_FNDMOBThis role is for users that are developing IFS Applications. It gives rights to for instance debugging and analyzing functionality. Developers using IFS Developer Studio also need this role.Functional Role
FND_TRANS_MANRole contains grants related to Translations Management in central scanning environments.End User Role
FND_TRANS_MAN_FNDDEVRole contains grants related to Translations Management in central scanning environments.Functional Role
FND_CUSTOMIZERole needed for customizing clients.End User Role

IFS Connect

Permission SetDescriptionType
FND_CONNECTRole needed for a user to run IFS Connect framework.End User Role
FND_CONNECT_APPSRVRole needed for IFS Connect framework user.Functional Role
FND_CONNECT_BISERVRole needed for IFS Connect framework user.Functional Role
FND_CONNECT_TABMFWRole needed to handle Tabular Models background jobs with IFS Connect framework user.Functional Role

Data Migration, Excel Addin, Data synchronization and Data catalog

Permission SetDescriptionType
FNDMIG_EXCEL_ADMINGrants the user access to use the IFS Data Migration Excel Addin.End User Role
FND_ADMIN_FNDRREGrants to Fndrre Administration forms not requiring App owner privileges.Functional Role
IFS_SSRSORINTIFS SSRSOR Integration.End User Role
FND_DCAT_ADMINRequired grants for Data Catalog admin userEnd User Role
FND_DCAT_USERRequired grants for Data Catalog userEnd User Role
FND_SYNCRequired grants for Data Synchronization service userEnd User Role
FND_SYNCADMINRequired grants for Data Synchronization admin userEnd User Role
FND_CLOUD_DMMRole needed for data migration manager admin actions.End User Role

Configurations

Permission SetDescriptionType
CUSTOM_OBJECTS_ADMINRequired grants for administration of Configuration ItemsFunctional Role
FND_LOBBY_ADMINEnd user role administrating IFS LobbyEnd User Role
FND_LOBBY_SQLDS_ADMINEnd user role administrating IFS Lobby and manipulating SQL data sourcesEnd User Role
QUERY_DESIGNER_ADMINRequired grants for administration of Query ObjectsFunctional Role

Mobile Framework and Services

Permission SetDescriptionType
MOBILE_APP_ADMINRole needed for a user to be an administrator of IFS Cloud Mobile. FND_WEBRUNTIME is granted to this role.End User Role
MOBILE_APP_RUNTIMERole needed for a mobile user to logon and run a IFS Cloud Mobile app. FND_RUNTIME is granted to this role.Functional Role
FND_MOBILE_APP_SYSTEMRole needed for IFS Cloud System UserEnd User Role
FND_MOBILE_APP_SYNC_TRACERole needed for IFS Cloud Mobile end user to enable synchronization traces.End User Role
VIRTUAL_MAP_USERRole needed to grant for objects in Virtual Map solution.End User Role

Analysis Model

Permission SetDescriptionType
AAAS_ADMINISTRATORRole needed for Analysis Models - Power BI admin user.End User Role
AAAS_DL_USERRole needed for Analysis Models - Power BI Data Lake user.End User Role
AAAS_UPLOAD_USERRole needed for Analysis Models - Power BI upload models.End User Role
TABM_SETUP_ADMINAnalysis Models Self Hosted administrator role for environment setup.End User Role
TABM_ADMINAnalysis Models Self Hosted administrator role for general actions.End User Role

Aviation Maintenance

Permission SetDescriptionType
FLOPS_FLIGHT_CONTROLLERRequired grants for the Flight Controller user in the Forward Flight Operations solution.End User Role
MM_ADMINISTRATORRequired grants for the Administrator user configuring Mobile Maintenance for Aviation for end users.End User Role
MM_FLIGHT_APIRequired grants for third-party flight following systems to update flights in Mobile Maintenance for Aviation using the IFS Cloud Open API.End User Role
MM_LINE_PLANNERRequired grants for the Line Planner user in the Mobile Maintenance for Aviation solution.End User Role
MM_MAINT_OPERATIONS_CONTROLLERRequired grants for the Maintenance Operations Controller user in the Mobile Maintenance for Aviation solution.End User Role
MM_OVERRIDE_HARD_STOPRequired grants to release an aircraft, overriding a release restriction due to missing mandatory components or overdue maintenance.End User Role
MM_SUPERVISORRequired grants for the Supervisor user in the Mobile Maintenance for Aviation solution.End User Role
MM_TECHNICIANRequired grants for the Line Technician user in the Mobile Maintenance for Aviation solution.End User Role
AC_CONFIG_CON_BOARDRequired permissions for the Allowable Configuration Board in the Aviation Technical Content Manager solution.End User Role
AC_CONFIG_SPECIALISTRequired permissions for the Allowable Configuration Specialist in the Aviation Technical Content Manager solution.End User Role
AC_ENG_SERVICE_PARTNERRequired permissions for the Allowable Configuration Engineering Service Partner in the Aviation Technical Content Manager solution.End User Role

Remote Assistance

Permission SetDescriptionType
FND_REM_ASST_ADMINRequired grants of all the RA admin projections and ActionsEnd User Role
FND_REM_ASST_ENDUSERRequired grants of all the enduser related Projections and ActionsEnd User Role
FND_REM_ASST_SERVICERequired grants of RA service userEnd User Role

IFS Signature Service

Permission SetDescriptionType
FND_DSS_ASST_ADMINRequired grants of all the Digital Signature admin ActionsEnd User Role
FND_DSS_ASST_ENDUSERRequired grants of all the enduser related Actions for Digital SignatureEnd User Role
FND_DSS_ASST_SERVICERequired grants of Digital Signature service userEnd User Role

IFS AI Services

Permission SetDescriptionType
FNDGPT_RUNTIMERole needed to access IFS.ai Copilot ChatEnd User Role
FNDGPT_ADMINRole needed to administer and publish prompts to the organizationFunctional Role

IFS Planning and Scheduling Optimization

Permission SetDescriptionType
FNDSCH_RUNTIMERole needed for IFS Planning and Scheduling Optimization Workbench usersEnd User Role
FNDSCH_ADMINRole needed for IFS Planning and Scheduling Optimization Workbench Administrator usersEnd User Role
FNDSCH_WEBSERVICERole needed for IFS Planning and Scheduling Optimization to broadcast messages to IFS Cloud. FND_WEBRUNTIME is granted to this role.End User Role

IFS Human Capital Management

Permission SetDescriptionType
ABSENCE_INTEGRATION_USERRole needed for Absence Integration usersEnd User Role
PAYROLL_INTEGRATION_USERRole needed for Payroll Integration usersEnd User Role
TIMECLOCK_USERRole needed for Time Clock Integration usersEnd User Role
EMPLOYEE_INTEGRATION_USERRole needed for Employee Integration usersEnd User Role
TRIP_TRACKER_USERRole needed for Trip Tracker Mobile App userEnd User Role

Business Process Automation (BPA) Workflow

Permission SetDescriptionType
FND_BPA_ADMIN_FNDWFRole required for Business Process Automation Workflow functionality for admin userFunctional Role
FND_WEBENDUSER_MAIN_FNDWFBasic role for end users of IFS Cloud. Contains Business Process Automation Workflow functionality for usersFunctional Role
FND_WEBENDUSER_B2B_FNDWFBasic role for B2B users of IFS Cloud. Contains Business Process Automation Workflow functionality for B2B usersFunctional Role
FND_BPA_AUTHOR_FNDWFPermission set needed for managing Business Process Automation Workflows and its configurations in IFS CloudEnd User Role

Manufacturing Execution Controller

Permission SetDescriptionType
MANUF_EXECUTIONPermission set for Manufacturing Execution integration services.End User Role

IFS Relationship Management Panel

Permission SetDescriptionType
EXCHANGE_SYNC_USERPermission set for exchange sync usersEnd User Role
MASTER_SYNC_ROLEPermission set for Master sync userEnd User Role

IFS Business Reporter

Permission SetDescriptionType
BA_REPORT_ADMINEnd user role to be granted to an end user that should manage Configuration and Administration of IFS Business Reporter-related functionality in IFS Cloud Web client. This role also provides the necessary grants to handle report administration in Business Reporter as well as access to all published BR reports.End User Role
BA_REPORT_DESIGNEREnd user role to be granted to an end user that is supposed to work with report design within IFS Business Reporter client. This role has access to all necessary functionality/activities needed for a report designer but has NO default access to published Reports.End User Role
BA_USEREnd user role to be granted to an end user that executes IFS Business Reporter reports either from within IFS Business Reporter or in IFS Cloud. This role has access to all necessary functionality/activities needed for an end user but has NO default access to published Reports.End User Role
IFS_BRESRole needed when using IFS BR Execution Server.End User Role
BA_ADMINISTRATORFunctional role for IFS Business Reporter administrators that gives access to all administrator-related activities.Functional Role
BA_DESIGNERFunctional role that gives access to IFS Business Reporter design activities.Functional Role
BA_ENDUSERFunctional role that gives access to necessary activities for a typical end user in IFS Business Reporter end user mode.Functional Role
BA_PUBLISHERFunctional role that gives access to publish a report in IFS Business Reporter to IFS Cloud.Functional Role
BA_REPORT_USERFunctional role that gives access to IFS Business Reporter report execution within IFS Cloud.Functional Role
BA_SUPER_USERFunctional role with access to all design and end-user related functionality.Functional Role
BA_UNPUBLISHERFunctional role that gives access to un-publish a IFS Business Reporter report from IFS Cloud.Functional Role
BA_WRITEBACK_USERFunctional role with access to write back related functionality from IFS Business Reporter to IFS Cloud.Functional Role
BR_EXAMPLE_REPORT_ACCESSFunctional role with access to all IFS Business Reporter reports.Functional Role
BR_FULL_REPORT_ACCESSFunctional role with access to all IFS Business Reporter example reports.Functional Role
FND_CONNECT_BISERVFunctional role needed for IFS Connect framework user.Functional Role
FND_ADMIN_BISERVBusiness Reporter- FND Administrator.Functional Role
FND_WEBENDUSER_MAIN_BISERVBusiness Reporter- FND Web end-user.Functional Role

IFS Operational Reports and Ad hoc Reports

Permission SetDescriptionType
FND_PRINTSERVERRole needed for a user to run IFS Print Agent.End User Role
FND_QUICK_REPORTSRole needed for creating and publishing Quick Reports.End User Role
FND_ADMIN_CRYSTLGrants to Crystal Administration forms not requiring App owner privileges.Functional Role
FND_DESIGNER_REPORTRole needed for creating and designing Report Studio - Designer type Reports.End User Role

Demand Planner

Permission SetDescriptionType
DEMAND_MLThis permission set has access only to the Demand ML message communication.End User Role
DEMAND_SUPERThis permission set has access to everything related to Demand planning, the only user that can execute manual jobs in the Demand Plan Server from the Dashboard. Only user to create new user and edit access rights for the main Demand Plan Client.End User Role
DEMAND_GENERALThis permission set has access to everything related to Demand planning apart from the basic data set up. The user will be able to add and delete new forecast parts, publish forecast parts to DEMAND_FORECAST users, look at the finished forecasts. The user cannot create/delete/edit base or combined flows or do anything to the Demand Plan Server Setup but can view the Dashboard without being able to execute any jobs on the Demand Plan ServerEnd User Role
DEMAND_FORECASTThis permission set has access only to the Demand Forecast Client. This will only allow to examine, and evaluate the forecast published to the user in the Demand Forecast Client.End User Role
IPR_SUPERThis permission set has access to everything related to IPR. For example IPR Supply Plan, Manage IPR Supply Plan, Analyze Demand Derivation, Refresh Inventory Part Unit Cost Snapshot, IPR Planning Details for Inventory Parts, Planning Hierarchy Basic Data, the IPR Excel Sheet menu on Inventory Part Planning.End User Role

IFS Document Management

Permission SetDescriptionType
DOCUMENT_ATTACHMENT_CLOUD_B2BGrants create and read grants to Attachments / Documents in IFS Cloud B2B.End User Role
DOCMAN_ADMINISTRATORSystem privilege with full administration rights to Document Management functionality.End User Role
DOCUMENT_ATTACHMENT_CLOUDGrants create and read grants to Attachments / Documents in IFS Cloud.End User Role
DOCUMENT_ESIGNGrants permission to send and receive documents for e-signing.End User Role

Application Services

Permission SetDescriptionType
MEDIA_LIBRARYRequired grants to media library methods for Media Attachment use.End User Role

Warehouse Data Collection

Permission SetDescriptionType
WADACO_MOBILE_USERRequired grants for WADACO mobile clientsEnd User Role

Microsoft Project Integration

Permission SetDescriptionType
MSP_INTEGRATIONRequired grants for MS Project Integration users.End User Role

IFS Provider for Oracle Primavera Gateway

Permission SetDescriptionType
OPG_SYNCHRONIZERRequired grants for Oracle Primavera Gateway (OPG) integration, Project & master data synchronization users.End User Role

Export Control Administrator

Permission SetDescriptionType
EXPCTR_ADMINISTRATORGrants right to act as Administrator in component Export ControlEnd User Role

Data Services

Permission SetDescriptionType
DATSVC_ADMINISTRATORRole needed for Data Services Administrator.End User Role
WLJOB_ADMINRole needed for Workload Jobs Administrator.End User Role
WLJOB_END_USERRole needed for Workload Jobs End User.End User Role

Several of the roles above include component specific sub roles with component suffix. Example: FND_ADMIN_FNDMIG. These are included in main Permission Sets structure.

Read more: