This article is part of a series on Overview of Enabling Area of Responsibility (AOR) based Security in Oracle Fusion HCM Analytics. It gives a detailed walkthrough on AOR security flow from Oracle Fusion Cloud HCM to Oracle Fusion HCM Analytics.

The AOR Security Configuration Flow: From Fusion Applications to FDI

The AOR security implementation follows a multi-step process:

  • Oracle Fusion Cloud HCM Prerequisites
  • Enable Security configuration data
  • Auto-Provisioning roles in FDI
  • Map auto provisioned roles to Oracle Fusion Cloud HCM group
  • Seamless Security Enforced in FDI analytics

Let’s examine each step-in detail.

Step 1: Oracle Fusion Cloud HCM Prerequisites

Before implementing AOR security in FDI, ensure that the following prerequisites are met in Oracle Fusion Cloud HCM:

  • Person security profiles are associated with the data roles.
  • Users associated with these data roles have the relevant Area of Responsibility (AOR) assignments configured in Fusion Applications.

Person Security Profiles in Fusion Applications

Person Security Profiles are the foundation of AOR security in Fusion Applications. These profiles define the scope of organizational data that users with specific security assignments can access. The key factors that guide the security configuration are found in the AOR section, specifically:

  • Responsibility Type
  • Scope of Responsibility

Key Considerations:

  • When creating a Person Security Profile, the Security Profile Name must not contain leading or trailing spaces.

Example Configuration

Let’s configure a profile for HR representatives based on Business Unit:

  • Person Security Profile Name: GSE AOR by Business Unit
  • Responsibility Type: Human resources representatives
  • Scope of Responsibility: Business Unit
[Image 1: Fusion HCM Person Security Profile]

Person security profile associated with the data role:

[Image 2: Fusion HCM Person Security Profile associated with a data role]

AOR Assignments to Users

Ensure that users associated with these data roles have the relevant Area of Responsibility (AOR) assignments configured in Fusion Applications. The AOR assignments must align with the Responsibility Type and Scope of Responsibility shown in Image 1.

[Image 3: Fusion HCM user AOR assignment]

Image 3 illustrates the flexibility of this configuration by enabling security based on a wider range of workforce structures including Job, Position, Grade, and other organizational attributes, beyond the prebuilt FDI options, which are limited to Business Unit, Department, Location, and Country.

Step 2: FDI Security Configuration and Role Provisioning

After configuring Person Security Profiles in Oracle Fusion Cloud HCM, the next step is to enable security data extraction; that is, activating the HCM Security Configurations functional area in FDI and ensuring role provisioning in FDI.

2.1 Enable Security Configuration Data

FDI needs to extract security metadata including Person Security Profiles and assignments from Oracle Fusion Cloud HCM.

Activate the Security Configuration functional area data pipeline, which extracts AOR data from Oracle Fusion Cloud HCM and loads it into the Oracle Autonomous Data Warehouse (ADW) instance associated with Fusion HCM Analytics. The AOR data is accessed via the DW_ASG_RESPONSIBILITY_D synonym available in the OAX_USER schema and is incrementally refreshed based on your pipeline data refresh schedule. 

To extract AOR data, navigate from the FDI Console to Data Configuration.

  1. Click the Human Capital Management application tile.
  2. Select the HCM Security Configurations offering.
  3. Select the Security Configuration Functional Area.
  4. Click Next.
  5. Review your selections and click Next.
  6. Select Run Immediately and click Finish.

2.2 Auto-Provisioning Roles in FDI

FDI automatically provisions FDI automatically provisions data roles from Oracle Fusion Cloud HCM Person Security Profiles:

  • Person Security Profiles configured with Responsibility Type and Scope of Responsibility
  • For any additional criteria defined in a Person Security Profile (custom, exclusion, or assignment type selection changes), create a custom role in FDI to capture these additional criteria, alongside the auto-provisioned role.

Important: Only Person Security Profiles associated with data roles in Oracle Fusion Cloud HCM are considered for auto-provisioning data roles in FDI.

2.3 Map Auto-Provisioned Roles to a Group in Oracle Fusion Cloud HCM

Ensure that job groups and roles are correctly mapped between Oracle Fusion Cloud HCM and FDI:

  • Fusion Person Security Profiles are automatically created as application data roles in FDI.
  • These roles must be mapped in the Security area of the FDI Console.

Example: Application Role Provisioning

The application role “AOR – GSE AOR by Business Unit” is auto-provisioned in FDI from the Oracle Fusion Cloud HCM Person Security Profile, with “AOR –” prefixed to the profile name.

  • Oracle Fusion Cloud HCM Job roles are synchronized with FDI security groups.
  • FDI Application Data roles are provisioned and available for assignment.
  • Add the group mappings to the application data role in the Application Roles section of FDI.
[Image 4: Role mapping in the Security area of the FDI Console]

Step 3: Seamless Security Enforced in FDI

Once configured, users can automatically see filtered results based on their AOR assignments when accessing data in FDI.

How AOR Security Works in FDI

When a user creates a report or dashboard in FDI, the system automatically:

  • Identifies the user’s application role assignments.
  • Retrieves the allowed values for each secured dimension.
  • Applies filters to the query to restrict data to authorized values.
  • Returns only the data the user has permission to view based on AOR assignments.

The following subject areas aren’t secured by the AOR-based data roles:

  • HCM – Talent Acquisition
  • HCM – Succession Management
  • HCM – Diversity Analysis

session log to demonstrate how this configuration is applied as a filter:

[Image 6: FDI session log snippet showing applied filters]

Call to Action

Now that you’ve read this article, try it yourself and let us know your results in the Oracle Analytics Community, where you can also ask questions and post ideas

For more information about Oracle Fusion HCM Analytics, see the Help Center Documentation.