This article is part of a series on Overview of Enabling Area of Responsibility (AOR) based Security in Oracle Fusion HCM Analytics. It gives a detailed walkthrough on AOR security flow from Oracle Fusion Cloud HCM to Oracle Fusion HCM Analytics.
The AOR Security Configuration Flow: From Fusion Applications to FDI
The AOR security implementation follows a multi-step process:
- Oracle Fusion Cloud HCM Prerequisites
- Enable Security configuration data
- Auto-Provisioning roles in FDI
- Map auto provisioned roles to Oracle Fusion Cloud HCM group
- Seamless Security Enforced in FDI analytics
Let’s examine each step-in detail.
Step 1: Oracle Fusion Cloud HCM Prerequisites
Before implementing AOR security in FDI, ensure that the following prerequisites are met in Oracle Fusion Cloud HCM:
- Person security profiles are associated with the data roles.
- Users associated with these data roles have the relevant Area of Responsibility (AOR) assignments configured in Fusion Applications.
Person Security Profiles in Fusion Applications
Person Security Profiles are the foundation of AOR security in Fusion Applications. These profiles define the scope of organizational data that users with specific security assignments can access. The key factors that guide the security configuration are found in the AOR section, specifically:
- Responsibility Type
- Scope of Responsibility
Key Considerations:
- When creating a Person Security Profile, the Security Profile Name must not contain leading or trailing spaces.
Example Configuration
Let’s configure a profile for HR representatives based on Business Unit:
- Person Security Profile Name: GSE AOR by Business Unit
- Responsibility Type: Human resources representatives
- Scope of Responsibility: Business Unit

Person security profile associated with the data role:

AOR Assignments to Users
Ensure that users associated with these data roles have the relevant Area of Responsibility (AOR) assignments configured in Fusion Applications. The AOR assignments must align with the Responsibility Type and Scope of Responsibility shown in Image 1.

Image 3 illustrates the flexibility of this configuration by enabling security based on a wider range of workforce structures including Job, Position, Grade, and other organizational attributes, beyond the prebuilt FDI options, which are limited to Business Unit, Department, Location, and Country.
Step 2: FDI Security Configuration and Role Provisioning
After configuring Person Security Profiles in Oracle Fusion Cloud HCM, the next step is to enable security data extraction; that is, activating the HCM Security Configurations functional area in FDI and ensuring role provisioning in FDI.
2.1 Enable Security Configuration Data
FDI needs to extract security metadata including Person Security Profiles and assignments from Oracle Fusion Cloud HCM.
Activate the Security Configuration functional area data pipeline, which extracts AOR data from Oracle Fusion Cloud HCM and loads it into the Oracle Autonomous Data Warehouse (ADW) instance associated with Fusion HCM Analytics. The AOR data is accessed via the DW_ASG_RESPONSIBILITY_D synonym available in the OAX_USER schema and is incrementally refreshed based on your pipeline data refresh schedule.
To extract AOR data, navigate from the FDI Console to Data Configuration.
- Click the Human Capital Management application tile.
- Select the HCM Security Configurations offering.
- Select the Security Configuration Functional Area.
- Click Next.
- Review your selections and click Next.
- Select Run Immediately and click Finish.
2.2 Auto-Provisioning Roles in FDI
FDI automatically provisions FDI automatically provisions data roles from Oracle Fusion Cloud HCM Person Security Profiles:
- Person Security Profiles configured with Responsibility Type and Scope of Responsibility
- For any additional criteria defined in a Person Security Profile (custom, exclusion, or assignment type selection changes), create a custom role in FDI to capture these additional criteria, alongside the auto-provisioned role.
Important: Only Person Security Profiles associated with data roles in Oracle Fusion Cloud HCM are considered for auto-provisioning data roles in FDI.
2.3 Map Auto-Provisioned Roles to a Group in Oracle Fusion Cloud HCM
Ensure that job groups and roles are correctly mapped between Oracle Fusion Cloud HCM and FDI:
- Fusion Person Security Profiles are automatically created as application data roles in FDI.
- These roles must be mapped in the Security area of the FDI Console.
Example: Application Role Provisioning
The application role “AOR – GSE AOR by Business Unit” is auto-provisioned in FDI from the Oracle Fusion Cloud HCM Person Security Profile, with “AOR –” prefixed to the profile name.
- Oracle Fusion Cloud HCM Job roles are synchronized with FDI security groups.
- FDI Application Data roles are provisioned and available for assignment.
- Add the group mappings to the application data role in the Application Roles section of FDI.

Step 3: Seamless Security Enforced in FDI
Once configured, users can automatically see filtered results based on their AOR assignments when accessing data in FDI.
How AOR Security Works in FDI
When a user creates a report or dashboard in FDI, the system automatically:
- Identifies the user’s application role assignments.
- Retrieves the allowed values for each secured dimension.
- Applies filters to the query to restrict data to authorized values.
- Returns only the data the user has permission to view based on AOR assignments.
The following subject areas aren’t secured by the AOR-based data roles:
- HCM – Talent Acquisition
- HCM – Succession Management
- HCM – Diversity Analysis

session log to demonstrate how this configuration is applied as a filter:

Call to Action
Now that you’ve read this article, try it yourself and let us know your results in the Oracle Analytics Community, where you can also ask questions and post ideas
For more information about Oracle Fusion HCM Analytics, see the Help Center Documentation.
