Access Requirements for AI Agent Studio

You can give access to AI Agent Studio by assigning predefined duty roles to job roles. Also, make sure to complete these prerequisites:

  • Enable security console to work with permission groups
  • Run scheduled processes to import security data
  • Run scheduled process to use the builder assistant
  • (Optional) Assign privilege to use external REST API tools
  • (Optional) Assign duty role to create Microsoft Teams and Slack client connectors
  • (Optional) Assign role to schedule workflows
  • (Optional) Assign permission group to view monitored agent records
  • Give users access to AI agents

Enable Security Console to Work with Permission Groups

For the Security Console to work with permission groups and related objects, set the Enable Security Console External Application Integration (ORA_ASE_SAS_INTEGRATION_ENABLED) profile option at the site level.
  1. In the Setup and Maintenance work area, search for the Manage Administrator Profile Values task using the search link in the Search Panel Icon panel.
  2. Search for the profile option and set the value for the Site profile level to Yes.

Run Scheduled Processes to Import Security Data

To import resources from LDAP, and transfer the necessary information into the security tables of Fusion Applications, run these two scheduled processes sequentially.

  1. Import Resource Application Security Data
  2. Import User and Role Application Security Data

You must run the processes one after the other.

  1. Go to Navigator > Tools > Scheduled Processes.
  2. Click Schedule New Process.
  3. Leave the type as Job.
  4. Search for and select the process.
  5. Submit the process.

Run Scheduled Process to Use the Builder Assistant

You can get answers to questions about developing agents, workflows and agentic apps from the builder assistant agent integrated into AI Agent Studio. Using this conversational agent, you can get answers to questions about existing agents, search for agents, tools, and topics using natural language, and receive AI powered suggestions for relevant resources.

To use the builder assistant, run the Index AI Agent Studio Assistant Objects and Attributes scheduled process daily.

  1. Go to Scheduled Processes, and select Schedule New Process.
  2. Leave the type as Job.
  3. Search for and select the Index AI Agent Studio Assistant Objects and Attributes process.
  4. Submit the process.

Assign Privilege to Use External REST API Tools

To create External REST API tools in AI Agent Studio, the Create and Edit Backends for Visual Builder Studio (ORA_FND_TRAP_PRIV) privilege must be added to the custom role assigned to the user. You can add this privilege while creating or editing a custom role.

  1. Go to the Security Console.
  2. To use a new custom role, create it. To use an existing custom role, search for the custom role and edit it.
  3. Go to the Function Security Policies page and select Add Function Security Policy.
  4. Add the Create and Edit Backends for Visual Builder Studio (ORA_FND_TRAP_PRIV) privilege to the role and save it.
  5. Save the custom role and assign to the user.

Assign Duty Role to Create Microsoft Teams and Slack Client Connectors

To create Microsoft Teams and Slack client connectors from the Connectors tab in AI Agent Studio, the Collab Tools Duty role (ORA_DR_FAI_GENERATIVE_AI_AGENT_COLLAB_TOOLS_DUTY) must be added to the custom role assigned to the user. You can assign the duty role while creating or editing a custom role.

  1. Go to the Security Console.
  2. To use a new custom job role, create it. To use an existing custom job role, search for the custom job role and edit it.
    Note: Make sure to enable permission groups.
  3. Go to the Role Hierarchy page. From the Roles and Permission Groups tab select Add Role.
  4. Search for and add the Collab Tools Duty role (ORA_DR_FAI_GENERATIVE_AI_AGENT_COLLAB_TOOLS_DUTY) duty role.
  5. Save the custom role and assign to the user.

Assign Role to Schedule Workflows

You can call a workflow using a scheduled trigger. To schedule the workflow, the Fai Batch Job Manager Duty (ORA_DR_FAI_BATCH_JOB_MANAGER_DUTY) role must be added to the custom role assigned to the user.

  1. Go to the Security Console.
  2. To use a new custom role, create it. To use an existing custom role, search for the custom role and edit it.
    Note: Make sure that permission groups are enabled for the custom role.
  3. Go to the Role Hierarchy page and open the Roles and Permission Groups tab.
  4. Add the Fai Batch Job Manager Duty (ORA_DR_FAI_BATCH_JOB_MANAGER_DUTY) role.
  5. Save the custom role and assign to the user.

Assign Permission Group to View Monitored Agent Records

To view records in the Monitoring and Evaluation tab of AI Agent Studio, an additional permission group must be added to the custom role assigned to the user.

  1. Go to the Security Console.
  2. To use a new custom role, create it. To use an existing custom role, search for the custom role and edit it.
    Note: Make sure that permission groups are enabled for the custom role.
  3. Open the Permission Groups page and select Add Permission Groups.
  4. Search for and add the read:Generative AI Workflow Execution permission group.
  5. Add security view for the permission group.
    1. Select the permission group added.
    2. In the Details section, open the Security Views tab.
    3. Select Add Security Views and add the AllRowsRestrictedFields security view.
  6. Save the custom role and assign to the user.

Give Users Access to AI Agents

After your agents are created and ready for use, provide access for users to interact with the AI agents. For information, see How can I give users access to AI agents?

Assign Predefined Duty Roles to Job Roles

Assign predefined product-specific duty roles to the appropriate job roles, and make sure permission groups are enabled. You can give people access to configure AI agents in all or specific products.
Caution: Using predefined roles might account for subscription consumption irrespective of whether you purchased the cloud service or not. See Guidance for Assigning Predefined Roles.