Configuring User Access
EPM Assistants use separate security layers to control authentication, authorization, and AI Agent Studio access. Understanding these layers helps prevent configuration and access issues during deployment.
Table 7-7 Security Layers for EPM Assistants
| Layer | What It Controls | What It Does Not Control |
|---|---|---|
| AI Agent Studio | Who can configure, import, test, debug, and publish AI agents. | It does not grant Cloud EPM or Cloud EDM authorization. |
| SSO or federation | Whether users authenticated through Oracle Fusion Applications can access Cloud EPM or Cloud EDM without signing in again. | It does not assign Cloud EPM or Cloud EDM application roles or business process security. |
| Cloud EPM or Cloud EDM authorization | Whether users can access the Cloud EPM or Cloud EDM environment and perform business process actions. | It does not grant AI Agent Studio design-time access. |
Configuring user access is an integration prerequisite for EPM Assistants. Before you configure authentication and data source connections, configure the user access required for AI Agent Studio and Oracle Fusion Cloud Enterprise Performance Management or Oracle Fusion Cloud Enterprise Data Management.
Complete the following tasks:
- Assign AI Agent Studio roles and privileges to users who create, import, test, debug, and publish AI agents. See Access Requirements for AI Agent Studio.
- Assign the required application and granular roles to users who access Cloud EPM or Cloud EDM through EPM Assistants. See Managing Users and Groups in OCI IAM.
- Configure single sign-on (SSO) between AI Agent Studio and the Cloud EPM or Cloud EDM environment. See Configuring SSO Between Services Across Identity Domains within an Oracle Cloud Account.
SSO authenticates users, but Cloud EPM or Cloud EDM authorizes access to data and business process operations. Users must have the required Cloud EPM or Cloud EDM roles and security assignments before they can access Cloud EPM or Cloud EDM resources through EPM Assistants.
After you configure access, configure authentication for the integration between AI Agent Studio and Cloud EPM or Cloud EDM.