Generate and Download Access Governance Reports
Use Reports to export data across Oracle Access Governance entities for offline review, auditing, and analysis. Oracle Access Governance generates reports asynchronously. The report includes data ingested in Oracle Access Governance and are downloaded as ZIP files containing report data in CSV format.
Role: Administrator (AG_Administrator), Auditor (AG_Auditor)
You can request the following reports:
- Identities: Provides identity information, such as username, email, status, manager, and other identity attributes. You can select the identity attributes that you want to include.
globalIdentityId,personNumber,primaryEmail,userName,managerUserName,firstName,lastName,status,agStatus,startDate,terminationDate globalId.example.001,10001,user001@example.com,user001,manager01,John,Smith,ACTIVE,ACTIVE,2026-01-01T00:00:00Z, - Access Bundle Assignments: Lists provisioned access bundle assignments for identities, including assignment status and validity dates.
identityId,userName,primaryEmail,accessBundleName,status,validTo,validFrom globalId.example.001,user001,user001@example.com,PRODUCTION~ERP~Finance Analyst~N/A,PROVISIONED,2026-12-31T23:59:59Z,2026-05-06T14:00:41Z globalId.example.002,user002,user002@example.com,PRODUCTION~HCM~Absence Partner~N/A,PROVISIONED,,2026-06-09T13:35:54Z - Accounts: Lists global identities and their accounts across orchestrated systems. Oracle Access Governance generates one report download as a ZIP file, with a separate CSV file for each orchestrated system
Identity ID,Employee user name,Email,Account ID,Account globalId.example.001,user001,user001@example.com,targetId.account.example.001,user001 globalId.example.002,user002,user002@example.com,targetId.account.example.002,user002 - Access Bundles: Lists access bundle, role and permission relationship. The report includes access bundles associated with roles and doesn't include access bundles that have no associated role. If an access bundle contains several permissions, the report represents the access bundle-to-role-to-permission relationships as separate records. Role names in this report can be system-generated.
Role ID,Role name,Access Bundle ID,Permission,System ID,System name,Permission name role-001,PRODUCTION~ERP~Finance Admin,PRODUCTION~ERP~Finance Administrator~N/A,ERP Production,Finance Administrator role-002,PRODUCTION~HCM~Absence Partner,PRODUCTION~HCM~Absence Transactions - Region~N/A,HCM Production,Absence Transactions - Region
CSV exports from the Identities and Enterprise-wide Browser pages export the current view or filtered results and have limits on the number of records you can export. Reports include all records returned by the report query across Oracle Access Governance entities.
Report Retention and Limits
You can access a generated report for 30 days from the date you create it. You can request to seven reports of each report type in a service instance. This limit includes reports created by all users and failed reports.
In case a report fails, you can retry a failed report without creating a new report. A retry doesn't add another report in the seven-report limit.
Check Report Status
Use the Reports page to check the status of the requested reports.
A report can have one of the following statuses:
- Requested: The report request is received.
- In Progress: The report generation is in progress.
- Available: The report is ready to download.
- Failed: The report generation failed. If report generation fails because of internal processing error, you can retry the failed report.
Request a Report
Request a downloadable report that contains the Oracle Access Governance data you want to review or analyze.
AG_Administrator), Auditor (AG_Auditor) roles. You can have only one report of the same type generating at a time in a service instance. Wait for the current report to finish before requesting another report of that type. See Report Retention and Limits- Sign in to Oracle Access Governance.
-
From the
navigation menu , select Reports.
- Select report type that you want to request.
- Select Request report.
- Select the attributes to include, if available.
- Select Request.
Oracle Access Governance generates the report in the background and notifies you when it's ready to download. For an Identities report, you can select supported identity attributes to include. Some attributes, such as email address, employee username, identity ID are always included.
Download a Report
Download an available report to review its data offline.
- Go to the Reports page.
-
For a report that you want to download:
-
From the
action menu for a report, select Download.
-
Select the
Download link to download the report.
-
From the
Delete a Report
Delete a report when you no longer need it or to accommodate other reports. The report is automatically deleted after the retention period.
- Go to the Reports page.
-
From the
action menu for a report, select Delete.
- Confirm the deletion.
Report Notification
You receive an email when the report is ready to download, fails to generate, or is scheduled for deletion.
When the report is ready, the email includes a link to the report and how long the report is available. If the report fails, the email includes a link to view the report status and failure details. If the report is scheduled for deletion, the email includes the deletion date and a link to download the report before it's permanently deleted.
Report Detail Reference
Use this reference to understand the data included in each report and how report columns relate to information in Oracle Access Governance.
Identities
The Identities report lists global identities and their identity attributes. You can select supported identity attributes when you request this report.
| CSV column | Display name | Description |
|---|---|---|
identityId |
Identity ID | Unique identifier of the global identity. |
userName |
Employee username | Username associated with the identity. |
primaryEmail |
Primary email address of the identity. | |
displayName |
Name | Display name of the user. |
Access Bundle Assignments
The Access Bundle Assignments report lists provisioned access bundle assignments for identities.
| CSV column | Display name | Description |
|---|---|---|
identityID |
Identity ID | Unique identifier of the global identity. |
userName |
Employee username | Username associated with the identity. |
primaryEmail |
Primary email address of the identity. | |
accessBundleName |
Permission | Name of the assigned access bundle |
status |
Status | Provisioning status of the assignment. |
validTo |
Valid to | Date until which the assignment is valid, when available. |
validFrom |
Valid from | Date from which the assignment is valid, when available. |
Accounts
The Accounts report lists global identities and their accounts across orchestrated systems.
| CSV column | Display name | Description |
|---|---|---|
identityId |
Identity ID | Global identity associated with the account. |
userName |
Employee username | Username associated with the identity. |
primaryEmail |
Primary email address of the identity. | |
AccountId |
Account ID | Unique identifier of the account. |
AccountName |
Account name | Account name |
Access Bundles
The Access Bundles report lists role-to-access-bundle-to-permission configuration.
| CSV column | Display name | Description |
|---|---|---|
roleId |
Role ID | Identifier of the role associated with the access bundle. |
roleName |
Role name | Name of the role associated with the access bundle. The report can be system-generated role name. |
accessBundleId |
Access Bundle ID | Identifier of the access bundle. |
accessBundleName |
Permission | Name of the access bundle. |
targetId |
System ID | Identifier of the associated orchestrated system. |
targetName |
System name | Name of the associated orchestrated system. |
permissionName |
Permission name | Name of the permission in the access bundle. |