Provision Users

To provision end users with access to Expenses Agent, choose the provisioning approach that best aligns with your organization’s security model. The following sections describe each approach and when to use it.

Important:

Whichever approach you choose, permission groups must be enabled for the role that provides access to Expenses Agent.

If the Enable Permission Groups option isn’t available in Security Console, enable the ORA_ASE_SAS_INTEGRATION_ENABLED profile option first:
  1. Navigate to Setup and Maintenance and search for the Manage Administrator Profile Values task.
  2. Search for the profile option code ORA_ASE_SAS_INTEGRATION_ENABLED.
  3. Set the profile value to Yes at the Site level.

This profile option enables permission-group evaluation. Because permission groups are enabled individually for each role, the impact is limited to the roles for which you enable them. See Set Profile Option Values for more information.

Choose a Provisioning Approach

If you want to… Use
Grant access through a dedicated Expenses role Approach 1: Create a new custom role or update an existing one and enable permission groups on it.
Grant access by provisioning the ERP Self Service User abstract role instead of managing a separate custom role Approach 2: Use the ERP Self Service User abstract role (ORA_FUN_ERP_SELF_SERVICE_USER_ABSTRACT) and enable permission groups on it.

Approach 1: Use a Custom Role

Use this approach if you want to provide access to Expenses Agent through a dedicated custom role.

  1. Navigate to the Security Console.
    1. Sign in as the Security Manager.
    2. Go to Tools > Security Console > Roles.
  2. Create or edit your custom role.
    • If you're creating a new custom role:
      1. Select Create Role.
      2. On the Basic Information page, enter the following details (rename as preferred):
        Field Value
        Role Name Expenses Agent Role
        Role Code EXM_TOUCHLESS_EXPENSES_ROLE
        Role Category Financials – Abstract Roles
    • If you're using an existing custom role:
      1. Search for your existing custom role.
      2. Select Edit.
  3. Enable permission groups.
    1. On the Basic Information page, select Enable Permission Groups.

    2. If this option is unavailable, complete the prerequisite listed above as Important, then return here.

  4. Add the Expenses Self Service duty role.
    1. Go to the Role Hierarchy page.
    2. Select the Roles and Permission Groups tab.
    3. Select Add Role.
    4. Search for and add ORA_DR_EXM_SELF_SERVICE_EXPENSES (Expenses Self Service Duty).
  5. Assign users and save.
    1. On the Users page, assign the custom role to the users who need access to Expenses Agent.
    2. Review the Summary page and save your changes.

Approach 2: Use the ERP Self Service User Role

Use this approach if your organization wants to use the ERP Self Service User abstract role (ORA_FUN_ERP_SELF_SERVICE_USER_ABSTRACT) to grant access through your standard employee roles instead of managing a separate custom role.

Tip: Consider auto-provisioning the ERP Self Service User abstract role for existing employees and new hires during onboarding. If needed, modify the role to remove duties that your organization doesn’t require.
  1. Edit the ERP Self Service User abstract role.
    1. Sign in as the Security Manager.
    2. Go to Tools > Security Console > Roles.
    3. Search for and edit ORA_FUN_ERP_SELF_SERVICE_USER_ABSTRACT.
  2. Enable permission groups.
    1. On the Basic Information page, select Enable Permission Groups.

    2. If this option is unavailable, complete the prerequisite listed above as Important, then return here.

  3. Verify the role assignment.
    1. On the Role Hierarchy page, select the Roles and Permission Groups tab.
    2. Confirm that ORA_FUN_ERP_SELF_SERVICE_USER_ABSTRACT is assigned to your employee role.
  4. Assign users and save.
    1. Assign the role to users through your organization’s existing provisioning process, or through your configured auto-provisioning rules.
    2. Review your changes and save them.