Securing AI Agents and Agentic Apps
Set up security before administrators configure AI agents or users work with AI output in Oracle Permitting and Licensing. Security requirements depend on the AI experience, the offering, and the users who need access.
Let's take a look at the types of access to review for Public Sector AI agents and agentic apps. For detailed role and permission group setup steps in Security Console, see Provide Access to Configure AI Agents in Oracle Permitting and Licensing. That Fusion AI topic provides the configuration steps for users with and without the PSC Application Administrator job role.
Security Overview
AI security includes configuration access and runtime access.
-
Configuration access is for implementers and administrators who use AI Agent Studio to copy templates, configure agents, publish agents, configure documents, or schedule workflows.
-
Runtime access is for agency staff, inspectors, registered public users, and other users who interact with AI output from application pages, drawers, landing page tiles, Business Rules Framework actions, scheduled workflows, or agentic app workspaces.
Users also need access to the underlying Permitting and Licensing records and pages. For example, inspectors need access to the Inspector Application and related inspections, and Code Enforcement users need access to the incidents they review.
Reviewing Roles by AI Experience
Here's information about the AI-related access to review for each delivered AI experience. Use the linked setup topics and the Fusion AI security documentation for detailed configuration steps.
|
AI Experience |
Users |
AI-Related Access to Review |
|---|---|---|
|
AI Agent Studio configuration |
Implementers and administrators |
AI Agent Studio configuration access. See Provide Access to Configure AI Agents in Oracle Permitting and Licensing. |
|
AI Summary of Inspection Comments |
Inspectors for permits, business licenses, or both |
PSC Access Inspection AI Agents duty role:
|
|
Inspection History Summary |
Inspectors for permits, business licenses, or both |
PSC Access Inspection AI Agents duty role:
|
|
Plan Review Prescreen Advisor |
Registered public users; administrators who configure the agent |
Registered public users need PSC AI Agent End User Custom Role and PSC Custom Registered Public User to access the agent from the public user landing page. Administrators also need AI Agent Studio access to copy and publish the template. |
|
Permit Health Monitor |
Administrators; email recipients who review permit health output |
Administrators need AI Agent Studio access. Email recipients should have access to the Permit Health Metrics dashboard in OTBI because the email links to the dashboard. |
|
Code Enforcement Reported Incident Review Assistant |
Code Enforcement agency users who review incidents |
PSC Access Code Enforcement Incident AI agent duty role:
|
|
Code Enforcement Incident Workspace |
Code technicians and agency users who manage reported incidents |
General AI runtime access and Code Enforcement incident AI
access. The internal runnable-agent security reference maps the
Code Enforcement incident dashboard and incident review agents
to
|
Running Security Sync
Run Security Sync after changing AI-related roles, permission groups, or custom role assignments. Run it after assigning runtime access, adding product-specific AI duty roles, or updating registered public user access for AI experiences. Runnable-agent setup guidance includes Security Sync after runtime role assignment.