Tuesday, 21 July 2026

GenAI - Security - Role User Matrix

A2CF ERP Solutions Pvt Ltd


 GenAI - Security - Role User Matrix


To create a custom role in Oracle Fusion, use the Security Console to define basic

 information, add functional and data security policies, build role hierarchies, and assign users

Navigation and Setup

  • Go to the Navigator, expand the Tools section, and open the Security Console.
  • Select the Roles tab and click Create Role (or choose to copy an existing predefined role to save time).
  • Fill in basic details like Role Name, Role Code, and Role Category (such as Financials Job Role or HCM Job Role)

Configuring Policies and Hierarchy
  • Functional Security Policies: Add specific privileges (actions a user can perform, like viewing or creating a purchase order).
  • Data Security Policies: Define what specific data or business unit instances the user can access.
  • Role Hierarchy: Add relevant duty roles or inherit lower-level privileges into your job role.
  • Users: Assign the finalized custom role directly to the target users, then review and save your changes.
Core Components
  • Privileges: The smallest pieces of security. They let a user do one specific task like create, edit, or view a page.
  • Roles: Groups of privileges. Job roles and duty roles collect these privileges and give them to the right workers.
  • Policy Store: The secure storage area where Oracle keeps these permission rules.

1. Classic Business Examples of SoD Conflicts
An SoD violation occurs when a single user can execute both sides of a high-risk financial or operational transaction lifecycle: [1, 2]
  • Procure-to-Pay Conflict: A user assigned to Create Suppliers should never be allowed to Approve Supplier Invoices or Process Supplier Payments (preventing the generation of phantom vendors and fraudulent payouts). [1, 2]
  • Order-to-Cash Conflict: A user who can Enter Customer Sales Orders should be restricted from Issuing Credit Memos or Approving Write-Offs.
  • General Ledger Conflict: A user who can Create Journal Entries should be structurally blocked from Posting Journal Entries.
3. How to Enforce SoD Within the Security Console
You can evaluate and prevent conflict expansion during the active role design phase: [1, 2]
  1. Enable the Profile Option: Go to the Manage Administrator Profile Values page in the Functional Setup Manager. Search for the code ASE_SEGREGATION_OF_DUTIES_SETTING and change its site-level value to Yes.
  2. Design Custom Roles Responsibly: When creating or customizing a Job Role inside the Security Console, add only mutually compatible Duty Roles.
  3. Run the Separation of Duties Check: With the profile option enabled, a dedicated Separation of Duties page displays during the final stages of role creation. This page flags if your selected role hierarchy combines conflicting privileges before you deploy the changes to your production users

URL: https://fa-euth-dev20-saasfademo1.ds-fa.oraclepdemos.com/
Username::Deepika.KK
Password::Welcome@123

Created Job Role " A2CF_AI_Agent_studio_Access_Job_Role"

Assigned to the User "Deepika.KK"

No comments: