How can I give users access to AI agents?

You can provide users access to explore and interact with AI agents.

Here you can find instructions for these products:

  • Oracle Fusion Cloud Human Capital Management
  • Oracle Fusion Cloud Procurement
  • Oracle Fusion Cloud Sales
  • Oracle Fusion Cloud Service
  • Oracle Fusion Cloud Supply Chain & Manufacturing
  • Oracle Permitting and Licensing

Provide Access to Agents in HCM, Procurement, Sales, Service, and SCM (for Users without the SCM Job Roles)

  1. Set the profile options to enable external application integration for Security Console and the VBCS Progressive Web Application user interface.
    1. In the Setup and Maintenance work area, search for the Manage Administrator Profile Values task using the search link in the Search Panel Icon panel.
    2. Search for the Enable Security Console External Application Integration (ORA_ASE_SAS_INTEGRATION_ENABLED) profile option and set the value for the Site profile level to Yes.
    3. Search for the Enable VBCS Progressive Web Application User Interface (ORA_HCM_VBCS_PWA_ENABLED) profile option and set the value for the Site profile level to Y.

  2. Create a custom role.
    1. Go to Navigator > Tools > Security Console, and create a new custom job role.
      Note: Make sure to enable permission groups.
    2. On the Function Security Policies page, select Add Function Security Policy and add the Access Intelligent Agent Chat (HRC_ACCESS_AI_AGENT_CHAT_PRIV) privilege.
    3. On the Role Hierarchy page, open the Roles and Permission Groups tab and add the Fai Genai Agent Runtime Duty (ORA_DR_FAI_GENERATIVE_AI_AGENT_RUNTIME_DUTY) duty role.
    4. Save the custom role.
  3. Assign the custom role to users.
    1. In the Security Console work area, open the Users tab and select the user you want to assign the custom role to.
    2. On the User Account Details page, edit the user account and add the role.
  4. Associate the custom role with a workflow.
    1. Go to AI Agent Studio and select the Workflows tab.
    2. Edit the workflow that you want to give users access to.

    3. Select Settings and open the Security tab.
    4. Add the custom role and publish your workflow.

Users with the custom role can now access the workflows associated with that role.

Provide Access to the SCM Agents for Users with SCM Job Roles

  1. Set the Enable VBCS Progressive Web Application User Interface (ORA_HCM_VBCS_PWA_ENABLED) profile option.
    1. In the Setup and Maintenance work area, search for the Manage Administrator Profile Values task using the search link in the Search Panel Icon panel.
    2. Search for the profile option and set the value for the Site profile level to Y.

  2. In the Security Console work area, search for any of these roles to edit:
    • ORA_CJM_CHANNEL_CLAIMS_MANAGER_JOB
    • ORA_CJM_CUSTOMER_CHANNEL_PROGRAM_MANAGER_JOB
    • ORA_CMF_FISCAL_DOCUMENT_SPECIALIST_JOB
    • ORA_CMF_RECEIVING_SPECIALIST_JOB
    • ORA_CMK_B2B_ADMINISTRATOR_ABSTRACT
    • ORA_CMK_TRADING_PARTNER_B2B_ADMINISTRATOR_ABSTRACT
    • ORA_CSE_ASSET_ADMINISTRATOR_JOB
    • ORA_CST_COST_ACCOUNTANT_JOB
    • ORA_DOO_ORDER_ADMINISTRATOR_JOB
    • ORA_DOO_ORDER_MANAGER_JOB
    • ORA_DOS_SUPPLY_CHAIN_OPERATIONS_MANAGER_JOB
    • ORA_EGI_PRODUCT_DATA_STEWARD_JOB
    • ORA_EGP_PRODUCT_MANAGER_JOB
    • ORA_ENQ_PRODUCT_RECALL_MANAGER_JOB
    • ORA_ENQ_QUALITY_ENGINEER_JOB
    • ORA_FOM_ORDER_ENTRY_SPECIALIST_JOB
    • ORA_FOS_SUPPLY_CHAIN_CONTROLLER_JOB
    • ORA_INV_HEALTHCARE_INVENTORY_SPECIALIST_JOB
    • ORA_INV_INVENTORY_MANAGER_JOB
    • ORA_INV_WAREHOUSE_MANAGER_JOB
    • ORA_INV_WAREHOUSE_OPERATOR_JOB
    • ORA_MNT_MAINTENANCE_MANAGER_JOB
    • ORA_MNT_MAINTENANCE_TECHNICIAN_JOB
    • ORA_MSC_BACKLOG_MANAGER
    • ORA_MSC_DEMAND_PLANNER
    • ORA_MSC_DEMAND_AND_SUPPLY_PLANNER
    • ORA_MSC_MATERIALS_PLANNER
    • ORA_MSC_ORDER_PROMISING_MANAGER
    • ORA_MSC_PRODUCTION_SCHEDULER
    • ORA_MSC_REPLENISHMENT_PLANNER
    • ORA_MSC_SALES_AND_OPERATIONS_PLANNER
    • ORA_MSC_SUPPLY_CHAIN_PLANNER
    • ORA_MSC_SUPPLY_CHAIN_PLANNING_APPLICATION_ADMINISTRATOR
    • ORA_QP_PRICING_ADMINISTRATOR_JOB
    • ORA_QP_PRICING_ANALYST_JOB
    • ORA_QP_PRICING_MANAGER_JOB
    • ORA_RCL_DEPOT_REPAIR_MANAGER_JOB
    • ORA_RCL_FIELD_SERVICE_ADMINISTRATOR_JOB
    • ORA_RCS_SUPPLY_CHAIN_APPLICATION_ADMINISTRATOR_JOB
    • ORA_RCV_RECEIVING_AGENT_JOB
    • ORA_SCH_PURCHASE_PRICING_MANAGER_JOB
    • ORA_VCS_SUPPLY_CHAIN_COLLABORATION_PLANNER_JOB
    • ORA_WIE_PRODUCTION_OPERATOR_JOB
    • ORA_WIE_PRODUCTION_SUPERVISOR_JOB
    • ORA_WIS_MANUFACTURING_ENGINEER_JOB
    • ORA_WSH_SHIPPING_AGENT_JOB
    • ORA_WSH_SHIPPING_MANAGER_JOB
    1. Enable permission groups.
  3. Associate the edited job roles with the workflows.
    1. Go to AI Agent Studio and select the Workflows tab.
    2. Edit the workflow that you want to give users access to.

    3. Select Settings and open the Security tab.
    4. Add the job roles and publish your workflow.

Users with any of the edited job roles can now access the workflows associated with that role.

Provide Access to Oracle Permitting and Licensing Agents

Here's what you do:
  1. Set the profile options to enable external application integration for Security Console and the VBCS Progressive Web Application user interface.
    1. In the Setup and Maintenance work area, search for the Manage Administrator Profile Values task using the search link in the Search Panel Icon panel.
    2. Search for the Enable Security Console External Application Integration (ORA_ASE_SAS_INTEGRATION_ENABLED) profile option and set the value for the Site profile level to Yes.
    3. Search for the Enable VBCS Progressive Web Application User Interface (ORA_HCM_VBCS_PWA_ENABLED) profile option and set the value for the Site profile level to Y.

  2. Create a custom role.
    1. Go to Navigator > Tools > Security Console, and create a new custom job role.
      Note: Make sure to enable permission groups.
    2. On the Function Security Policies page, select Add Function Security Policy and add the Access Intelligent Agent Chat (HRC_ACCESS_AI_AGENT_CHAT_PRIV) privilege.
    3. On the Data Security Policies page, select Create Data Security Policy.
      1. Specify the policy name as Grant on AI Agent Workflow.
      2. Specify the data resource as AI Agent Workflow (FAI_WORKFLOWS_B).
      3. Select the value of Data Set as Select by Instance set.
      4. Select the value of Condition Name as Access the ai agent workflow for table FAI_WORKFLOWS_B for ai agent workflows associated to the relevant family.
      5. Specify Parameter as PSC.
      6. From the Actions list, select View AI Agent Workflow.
    4. Create data security policies using the steps in 2.c, for these Data Resource values:
      • AI Agent
      • AI Agent Tool
      • AI Business Object
      • Deep Link
    5. On the Role Hierarchy page, open the Roles and Permission Groups tab and add the Fai Genai Agent Runtime Duty (ORA_DR_FAI_GENERATIVE_AI_AGENT_RUNTIME_DUTY) duty role.
    6. Save the custom role.
  3. If needed, assign the custom role further to users.
    1. In the Security Console work area, open the Users tab and select the user you want to assign the custom role to.
    2. On the User Account Details page, edit the user account and add the role.
  4. Run the scheduled process:
    1. Go to Scheduled Processes.
    2. Select Schedule New Process.
    3. Leave the type as Job.
    4. Search for and select the Security Synchronization scheduled process.
    5. Run the scheduled process.
  5. Associate the custom role with a workflow.
    1. Go to AI Agent Studio and select the Workflows tab.
    2. Edit the workflow that you want to give users access to.

    3. Select Settings and open the Security tab.
    4. Add the custom role and publish your workflow.