A2CF ERP Solutions Pvt Ltd
GenAI - Security - Role User Matrix
To create a custom role in Oracle Fusion, use the Security Console to define basic
information, add functional and data security policies, build role hierarchies, and assign users
Navigation and Setup
- Go to the Navigator, expand the Tools section, and open the Security Console.
- Select the Roles tab and click Create Role (or choose to copy an existing predefined role to save time).
- Fill in basic details like Role Name, Role Code, and Role Category (such as Financials Job Role or HCM Job Role)
Configuring Policies and Hierarchy
- Functional Security Policies: Add specific privileges (actions a user can perform, like viewing or creating a purchase order).
- Data Security Policies: Define what specific data or business unit instances the user can access.
- Role Hierarchy: Add relevant duty roles or inherit lower-level privileges into your job role.
- Users: Assign the finalized custom role directly to the target users, then review and save your changes.
Core Components
- Privileges: The smallest pieces of security. They let a user do one specific task like create, edit, or view a page.
- Roles: Groups of privileges. Job roles and duty roles collect these privileges and give them to the right workers.
- Policy Store: The secure storage area where Oracle keeps these permission rules.
1. Classic Business Examples of SoD Conflicts
An SoD violation occurs when a single user can execute both sides of a high-risk financial or operational transaction lifecycle: [1, 2]
- Procure-to-Pay Conflict: A user assigned to Create Suppliers should never be allowed to Approve Supplier Invoices or Process Supplier Payments (preventing the generation of phantom vendors and fraudulent payouts). [1, 2]
- Order-to-Cash Conflict: A user who can Enter Customer Sales Orders should be restricted from Issuing Credit Memos or Approving Write-Offs.
- General Ledger Conflict: A user who can Create Journal Entries should be structurally blocked from Posting Journal Entries.
3. How to Enforce SoD Within the Security Console
- Enable the Profile Option: Go to the Manage Administrator Profile Values page in the Functional Setup Manager. Search for the code
ASE_SEGREGATION_OF_DUTIES_SETTINGand change its site-level value to Yes. - Design Custom Roles Responsibly: When creating or customizing a Job Role inside the Security Console, add only mutually compatible Duty Roles.
- Run the Separation of Duties Check: With the profile option enabled, a dedicated Separation of Duties page displays during the final stages of role creation. This page flags if your selected role hierarchy combines conflicting privileges before you deploy the changes to your production users
URL: https://fa-euth-dev20-saasfademo1.ds-fa.oraclepdemos.com/
Username::Deepika.KK
Password::Welcome@123
Created Job Role " A2CF_AI_Agent_studio_Access_Job_Role"
Assigned to the User "Deepika.KK"