Payments Agent Security Setup

Payments Agent uses Oracle Fusion Cloud Financials security roles, permission groups, profile options, and business unit data access controls to manage administration and user access.

Enable Required Profile Options at Site Level

Enable the required profile options before configuring Payments Agent security and runtime access.

  1. Go to Navigator > My Enterprise > Setup and Maintenance > Manage Administrator Profile Values.
  2. Search for the profile option code ORA_HCM_VBCS_PWA_ENABLED.
  3. Select the Site level row. From the Profile Value drop-down list, select Y.
  4. Select Save.
  5. Search for the profile option code ORA_ASE_SAS_INTEGRATION_ENABLED.
  6. Select the Site level row. From the Profile Value drop-down list, select Yes.
  7. Select Save and Close.

Create Custom Role for AI Agent Administration

Create a custom role for users who will configure Payments Agent in AI Agent Studio, such as implementation team and designated admin users. This role grants administrative access to the Financials Intelligent Agent framework.

Create a custom role for users who will configure Payments Agent in AI Agent Studio, such as implementation team and designated admin users. This role grants administrative access to the Financials Intelligent Agent framework.

  1. Go to Navigator > Tools > Security Console > Roles.
  2. Select Create Role.
  3. On the Basic Information page, enter these values:
    • Role Name: Enter a name for the role. For example, Financials Intelligent Agent Administrator.
    • Role Code: Enter a unique role code according to your organization's naming standards.
    • Role Category: Financials - Discretionary Roles
  4. Select Enable Permission Groups and then select Next.
  5. On the Roles and Privileges tab, select Add Role.
  6. Search for ORA_FUN_MANAGE_FIN_AI_AGENT.
  7. Select Manage Financials Intelligent Agent and add it to the role.
  8. Select Add Role again, search for ORA_FUN_MANAGE_FIN_AI_AGENT_HCM.
  9. Select Manage Financials Intelligent Agent (HCM Variant) and add it to the role.
  10. Verify that both roles appear in the role hierarchy and then select Next.
  11. On the Roles and Permission Groups tab, select Add Role.
  12. Search for ORA_DR_FAI_GENERATIVE_AI_AGENT_FIN_ADMINISTRATOR_DUTY.
  13. Select Fai GenAI Agent FIN Administrator Duty.
  14. Add the permission group to the role.
  15. Verify that the permission group appears in the list and then select Next.
  16. On the Users page, go to Roles and Privileges tab and select Add User.
  17. Search for and select the users who administer Payments Agent.
  18. Add each selected user to the role and select Next.
  19. Review the role configuration on the Summary page.
  20. Verify the role hierarchy entries, the permission group, and the assigned users.
  21. Select Save and Close.

Enable Permission Groups for Payment Specialist Job Role

Enable permission groups for the Payment Specialist job role to allow users to access Payments Agent capabilities.

  1. Go to Navigator > Tools > Security Console.
  2. Search for the Payment Specialist role.
  3. Select the Payment Specialist role (ORA_AP_PAYMENT_SPECIALIST_JOB).
  4. Select Enable Permission Groups.
  5. Select Save and Close.

Assign Payment Specialist Job Role to Users

Assign the Payment Specialist job role to users who access Payments Agent.

  1. Go to Navigator > Tools > Security Console.
  2. Select Users.
  3. Search for the user who requires access to Payments Agent.
  4. Select the user.
  5. Select Edit.
  6. Select Add Role.
  7. Search for the Payment Specialist role (ORA_AP_PAYMENT_SPECIALIST_JOB).
  8. Select the role and add it to the user.
  9. Select Add Role Membership.
  10. Verify that the role is assigned to the user.
  11. Select Save and Close.

Repeat these steps for each user who requires access to Payments Agent.

Create Runtime Role for Payments Agent Chat Access

Create a custom job role that grants access to the Financials Intelligent Agent chat interface. Users assigned this role must also be assigned the Payment Specialist job role.

  1. Go to Navigator > Tools > Security Console > Roles.
  2. Select Create Role.
  3. On the Basic Information page, enter these details:
    • Role Name: Enter a name for the role. For example, Financials Intelligent Agent Administrator.
    • Role Code: Enter a unique role code according to your organization's naming standards.
    • Role Category: Financials - Discretionary Roles
  4. Select Enable Permission Groups.
  5. Select Next.
  6. On the Roles and Privileges tab, select Add Role.
  7. Search for ORA_FUN_FIN_AI_AGENT_RUNTIME_DUTY.
  8. Select Financials Intelligent Agent Runtime Duty and add it to the role.
  9. Select Add Role again, search for ORA_FUN_FIN_AI_AGENT_RUNTIME_DUTY_HCM.
  10. Select Financials Intelligent Agent Runtime Duty (HCM Variant) and add it to the role.
  11. Verify that both roles appear in the role hierarchy and then select Next.
  12. On the Users page, go to the Roles and Privileges tab.
  13. Select Add User.
  14. Search for and select users who are assigned the Payment Specialist job role.
  15. Select Next.
  16. Review the role configuration on the Summary page.
  17. Verify the role hierarchy entries and assigned users.
  18. Select Save and Close.

Run Security Import ESS Jobs

Run the required security import processes to synchronize role assignments and application security data.

  1. Go to Navigator > Tools > Scheduled Processes.
  2. Select Schedule New Process and search for Import Resource Application Security Data.
  3. Select Submit.
  4. Wait for the process to complete successfully before proceeding.
  5. Select Schedule New Process.
  6. Search for and select Import User and Role Application Security Data.
  7. Select Submit.
  8. Wait for the process to complete successfully before proceeding.
  9. Select Schedule New Process.
  10. Search for and select Retrieve Latest LDAP Changes.
  11. Select Submit.
  12. Wait for the process to complete successfully.

Assign Business Unit Data Access

Assign business unit data access to users who access Payments Agent. Payments Agent enforces business unit security. Users can access only the data associated with their assigned business units.

  1. Go to Navigator > My Enterprise > Setup and Maintenance >Manage Data Access for Users.
  2. Select Users with Data Access.
  3. Enter the username and click Search.
  4. In the search results, locate the Payment Specialist role (ORA_AP_PAYMENT_SPECIALIST_JOB).
  5. If a business unit assignment doesn't exist, select Add.
  6. Enter the following fields:
    • Username: Select the user requiring access.
    • Role: Payment Specialist (ORA_AP_PAYMENT_SPECIALIST_JOB)
    • Security Context: Business Unit
    • Security Context Value: Select the appropriate business unit.
  7. Select Save.
  8. Repeat these steps for each user and business unit combination that requires access.

Synchronize Business Unit Data Access

After assigning business unit data access, synchronize the Payments Agent data access policies to ensure that users can access the appropriate business unit data.

  1. Go to Navigator > My Enterprise > Setup and Maintenance >Manage Data Access for Users.
  2. Verify that all required business unit assignments are complete.
  3. Select Process Permission Group Policies.
  4. Select Submit.
  5. Wait for the process to complete successfully before proceeding.

If Process Permission Group Policies isn't enabled, the controlling profile option isn't enabled for your environment. Complete the following setup and then return to this page.

  1. Go to Navigator > My Enterprise > Setup and Maintenance > Manage Standard Lookups.
  2. Search for the lookup type ORA_ERP_CONTROLLED%.
  3. Select Add Lookup Code.
  4. Enter these values:
    • Look Code: MDA_36604437
    • Meaning: Show Button for Process Permission Group Policies
  5. Select Save and Close.