Creating an Implementation Plan

Before you configure EPM Assistants, collect the information required to configure AI Agent Studio and connect to your Cloud EPM or Cloud EDM environment.

Do not record secrets, private keys, or production credentials. Store sensitive information only in your organization's approved credential management system.

Table 7-5 Information Required for Implementing EPM Assistants

Configuration Item Why It Matters
Fusion Applications URL and Fusion identity domain URL Configure administrator access, SAML metadata, and Fusion Applications identity settings.
Cloud EPM environment URL, REST API base URL, and EPM identity domain URL Configure Cloud EPM or Cloud EDM access, REST API connections, and OAuth/JWT authentication.
EPM Assistant ZIP file name and AI Agent Studio data source name The data source name must match the ZIP file name suffix after EPM_AI_Agent_Artifacts-.
Confidential application Client ID and OAuth scope Configure the activated confidential application. Do not publish this information outside your organization.
Certificate owner and private key management process Protect private keys by using your organization's approved credential management system. Do not share private keys in email, tickets, chat messages, screenshots, or documents.
Implementation users and business testers Identify users, Cloud EPM or Cloud EDM Service Administrators and users for validation and testing.

Implementation Best Practices

Consider the following best practices when implementing EPM Assistants.

  • Separate setup administrator access from published-agent runtime access.
  • Use groups and custom least-privilege roles where practical, and avoid broad predefined role assignments unless required.
  • Validate test and production access independently, including authorized and unauthorized access scenarios.
  • Review AI agents that perform high-impact operations, such as calculations, data copy, submissions, write-back, data clearing, deletion, or mass updates, before making them available to users.
  • Configure AI agents to identify the point of view (POV) or source context in responses.
  • Configure AI agents to use retrieved Cloud EPM or Cloud EDM data and return an error when the requested information cannot be retrieved.

Table 7-6 AI Agent Example Action Risk-Levels

Risk Level Example Actions Recommended Policy
Low Retrieve metadata, explain status, summarize reports. Allow after testing and role validation.
Medium Retrieve financial data, compare variances, explain forecast. Allow after Cloud EPM or Cloud EDM role and data security validation.
High Run calculations, copy POV, submit updates. Require confirmation, limited roles, and auditability.
Critical Clear or delete data, mass updates, production structural changes. Avoid in the initial implementation or require a strict approval workflow.