Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In Oracle Fusion Cloud Applications, grant users the roles that provide the tasks they need, then configure the data access that limits which records and business contexts those tasks can reach. Start by inspecting the user and role hierarchy in Security Console; in ERP, assign data access separately. The exact administration screens and rules vary across ERP, HCM, SCM, and other product families.

How Oracle Fusion roles and permissions fit together

Effective access has two parts: function security, which controls the tasks, functions, or interfaces a user can use, and data security, which controls the records or enterprise contexts available through those functions. Oracle’s Oracle Fusion Cloud ERP: Securing ERP guide (26A) describes the model this way: “The Oracle Fusion security model requires a three-way link between users, role, and data.” A role that permits a task does not, by itself, establish which business unit, ledger, or inventory organization the user can work with.

Role or security concept What it represents How it is used
Job role A job or responsibility, such as an accounts payable manager. Typically assignable to users; its hierarchy can include duties and privileges.
Abstract role A person’s relationship to the enterprise, independent of a specific job. Generally assignable to users; may include duties and privileges.
Duty role A group of tasks and privileges. Normally inherited through a job- or abstract-role hierarchy, not assigned directly to a user.
Aggregate privilege A predefined grouping of a functional privilege and relevant data security. Can be included in an ERP role hierarchy.
Function security Permission to use a function, task, or UI capability. Provides the functional side of access.
Data security Permission to access particular records, datasets, or enterprise contexts. Provides the data side of access.

Users generally receive job and abstract roles, either through direct assignment or provisioning rules. Duties are typically inherited from the roles above them; they are not a substitute for an assignable job role.

Inspect a user or role before changing access

  1. Open Tools > Security Console.
  2. Search for the user or role you want to investigate.
  3. Open its hierarchy graph or table. For a user, review directly assigned and inherited roles. For a role, follow its hierarchy toward the duties and privileges it includes.
  4. Use the hierarchy to identify whether a missing task is absent from the user’s role set or whether the relevant role is present but lacks the required data access.

The documented ERP workflow requires the IT Security Manager role to use Security Console. In HCM, data roles can be reviewed in Security Console, but they are managed separately through Manage HCM Data Role and Security Profiles, as described in Oracle’s Oracle Fusion Cloud HCM: Securing HCM guide (G34732-10).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose an appropriate role rather than granting broad access

When a user cannot perform a task, inspect the hierarchy and compare the user’s responsibilities with the relevant role definitions before adding access. Oracle’s ERP security guide explains that a position or job and its included duties determine tasks, and that users generally receive roles through provisioning rules. A user may need a suitable job or abstract role; adding a duty role directly to the user is generally not the right assignment pattern.

Provisioning rules can grant roles based on work assignments. Direct assignment and rule-based provisioning are different administration choices: a direct assignment is made to a particular user, while a rule can provision access according to configured conditions. Which method is appropriate depends on the organization’s setup and the application family.

Assign ERP data access separately from the role

In the ERP workflow documented for release 26A, assign at least one appropriate job role, then configure the applicable data access in Functional Setup Manager using Manage Data Access for Users. The guide also describes configuring role and data provisioning rules based on work assignments.

For example, Oracle’s guide associates an Accounts Payable Manager job role with the US Operations business unit. Other ERP data contexts may include a ledger, asset book, inventory organization, or reference data set. The exact context depends on what the user needs to do and the application configuration; the ERP screen path should not be assumed to apply unchanged to HCM, SCM, or every Fusion product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
The Faeries' Oracle
  • The Faeries' Oracle

Create a custom role by copying a delivered role

If a predefined role is too broad or does not fit the organization’s job design, use a copy as the starting point. Oracle’s ERP 26A guide identifies predefined roles by the ORA_ role-code prefix and says their duties cannot be edited to add or remove them. Avoid changing the delivered role itself.

  1. In Security Console, start the role-creation workflow and select the appropriate role category.
  2. Define any needed function-security and data-security policies.
  3. Add the relevant roles or privileges to the hierarchy. A duty role belongs within a job or abstract role and is not assigned directly to the user.
  4. Review the Summary and Impact Report, including affected roles and users, before saving.

Review the complete hierarchy rather than only the new permission: adding a role or privilege can change access for users who inherit it through other roles.

Check segregation-of-duties conflicts where configured

Oracle’s ERP role-creation guide for release 25D describes segregation-of-duties analysis in the role workflow when the organization uses Risk Management Advanced Controls provisioning rules. This check is configuration-dependent; do not assume every tenant has it enabled or available. Where it is configured, review the analysis along with the role’s impact report before saving.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Configure integration accounts with both privilege and data policies

Service accounts used for integrations need privileges scoped to the integration’s tasks as well as applicable data policies. Oracle’s Access Governance integration guidance warns that without data policies, API calls may succeed but return zero records. After configuring access, follow the application-specific procedure to run Refresh Access Control Data and User and Roles Synchronization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify access after configuration

Return to Security Console and inspect the user and role hierarchies to confirm the intended assignment and inheritance. For ERP, verify the relevant data access separately in the applicable setup workflow. If the result does not match the user’s needs, distinguish between a missing functional role or privilege and a missing data context before making another change; those are separate parts of the access model.

The release labels above identify the Oracle documentation workflows cited: ERP 26A, ERP role creation and Risk Management 25D, and HCM guide G34732-10 (copyright through 2026). Oracle Cloud updates quarterly, and screens, requirements, and available features can differ by product family and tenant configuration. Check the documentation and settings for the release and application you administer.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.