Securing AI Agents and Agentic Apps

Set up security before administrators configure AI agents or users work with AI output in Oracle Permitting and Licensing. Security requirements depend on the AI experience, the offering, and the users who need access.

Let's take a look at the types of access to review for Public Sector AI agents and agentic apps. For detailed role and permission group setup steps in Security Console, see Provide Access to Configure AI Agents in Oracle Permitting and Licensing. That Fusion AI topic provides the configuration steps for users with and without the PSC Application Administrator job role.

Security Overview

AI security includes configuration access and runtime access.

  • Configuration access is for implementers and administrators who use AI Agent Studio to copy templates, configure agents, publish agents, configure documents, or schedule workflows.

  • Runtime access is for agency staff, inspectors, registered public users, and other users who interact with AI output from application pages, drawers, landing page tiles, Business Rules Framework actions, scheduled workflows, or agentic app workspaces.

Users also need access to the underlying Permitting and Licensing records and pages. For example, inspectors need access to the Inspector Application and related inspections, and Code Enforcement users need access to the incidents they review.

Reviewing Roles by AI Experience

Here's information about the AI-related access to review for each delivered AI experience. Use the linked setup topics and the Fusion AI security documentation for detailed configuration steps.

AI Experience

Users

AI-Related Access to Review

AI Agent Studio configuration

Implementers and administrators

AI Agent Studio configuration access.

See Provide Access to Configure AI Agents in Oracle Permitting and Licensing.

AI Summary of Inspection Comments

Inspectors for permits, business licenses, or both

PSC Access Inspection AI Agents duty role: ORA_DR_PSC_INSPECTIONS_AI_ASSISTANT_DUTY. Assign to the applicable custom agency roles for permit and business license inspectors.

Inspection History Summary

Inspectors for permits, business licenses, or both

PSC Access Inspection AI Agents duty role: ORA_DR_PSC_INSPECTIONS_AI_ASSISTANT_DUTY. This access is mapped to CUSTOM_PSC_MANAGE_PERMITS_AGENCY and CUSTOM_PSC_MANAGE_BL_AGENCY.

Plan Review Prescreen Advisor

Registered public users; administrators who configure the agent

Registered public users need PSC AI Agent End User Custom Role and PSC Custom Registered Public User to access the agent from the public user landing page. Administrators also need AI Agent Studio access to copy and publish the template.

Permit Health Monitor

Administrators; email recipients who review permit health output

Administrators need AI Agent Studio access. Email recipients should have access to the Permit Health Metrics dashboard in OTBI because the email links to the dashboard.

Code Enforcement Reported Incident Review Assistant

Code Enforcement agency users who review incidents

PSC Access Code Enforcement Incident AI agent duty role: ORA_DR_PSC_CE_INCIDENTS_AI_ASSISTANT_DUTY. Assign it to the custom Code Enforcement agency user role that manages incidents and cases.

Code Enforcement Incident Workspace

Code technicians and agency users who manage reported incidents

General AI runtime access and Code Enforcement incident AI access. The internal runnable-agent security reference maps the Code Enforcement incident dashboard and incident review agents to ORA_DR_PSC_CE_INCIDENTS_AI_ASSISTANT_DUTY.

Running Security Sync

Run Security Sync after changing AI-related roles, permission groups, or custom role assignments. Run it after assigning runtime access, adding product-specific AI duty roles, or updating registered public user access for AI experiences. Runnable-agent setup guidance includes Security Sync after runtime role assignment.