Starting today, Oracle API Access Control is available for Autonomous AI Database on Dedicated Exadata Infrastructure and Autonomous AI Database on Cloud@Customer. This new capability extends approval-based governance to sensitive Autonomous Database management operations, helping organizations strengthen security and compliance without slowing day-to-day administration.
With this release, customers can designate selected Autonomous Database management operations as privileged, requiring authorized approval before they can be executed. The result is stronger governance, improved separation of duties, and greater confidence that high-impact administrative actions are performed only with the appropriate authorization.
Organizations running business-critical databases need to balance two requirements that can seem at odds: enabling administrators to respond quickly when needed while maintaining strong governance over operations that could affect availability, data protection, or security.
Autonomous AI Database on Dedicated Exadata Infrastructure and Autonomous AI Database on Cloud@Customer automate much of the operational work required to run enterprise databases. However, some lifecycle and configuration changes still require careful planning and execution. Actions such as restoring a database, terminating a resource, changing capacity, rotating an encryption key, updating administrator credentials, or modifying infrastructure settings can affect application availability, security, performance, and capacity.
Oracle API Access Control provides an additional governance layer for these operations. It enables organizations to require approval before selected privileged management operations are executed, whether those operations are initiated through the OCI Console or directly through OCI REST APIs. This helps security and operations teams reduce risk while preserving the agility needed to manage Autonomous AI Database environments.
Governance Beyond Traditional IAM
OCI Identity and Access Management (IAM) determines who is permitted to manage cloud resources. Oracle API Access Control complements IAM by introducing an additional authorization step for operations an organization considers especially sensitive.
Unlike solutions that temporarily elevate administrator privileges, Oracle API Access Control governs individual management operations on protected resources. Even users who already have the necessary IAM permissions cannot invoke selected privileged APIs until an authorized approver grants time-bound approval.
A security administrator identifies the operations that should require approval and associates them with specific Autonomous AI Database resources. When a database administrator needs to perform one of those operations, they submit an access request that includes:
- The target resource
- The operation to be performed
- The requested execution window
- The business justification
An authorized approver reviews the request. The operation can proceed only after approval, and only during the approved time window.

This model creates a clear separation between requesting a sensitive operation and authorizing it. It is particularly valuable for organizations that want stronger governance around production changes without introducing unnecessary overhead for routine administration.
Apply Governance Where It Matters Most
Not every administrative operation carries the same level of risk. API Access Control allows organizations to focus approval workflows on the operations that deserve additional oversight.
For Autonomous AI Database deployments, customers can govern operations involving:
- Autonomous AI Databases, including restore, delete, start and stop, administrator password changes, encryption key rotation, scaling, and configuration updates
- Autonomous Container Databases, including restart, Data Guard operations, standby management, termination, and key rotation
- Autonomous Exadata VM Clusters and Autonomous Exadata Cloud VM Clusters, including lifecycle management, capacity changes, certificate rotation, Oracle REST Data Services (ORDS) management, maintenance settings, and networking configuration
Consider a production database restore. A database administrator may already have IAM permission to perform the restore, but the organization may require another engineer or security administrator to verify the target database, restore point, and maintenance window before the operation proceeds.
API Access Control supports exactly that workflow without requiring administrators to permanently surrender the permissions they need for day-to-day operations.
Strengthen Separation of Duties
Separation of duties is a familiar compliance requirement, but it is equally valuable as an operational safeguard.
With API Access Control, security administrators designate one or more approval groups that are separate from the users requesting privileged operations. Approvers evaluate requests based on:
- Who is requesting access
- Which resource will be affected
- The specific operation being requested
- The business justification
- The requested duration
Organizations can also require multiple approvals for particularly sensitive operations, such as deleting production databases or making infrastructure-wide configuration changes.
Most importantly, the approval workflow is enforced by the service itself. Sensitive operations cannot bypass the approval process simply because a user already possesses broad administrative permissions.
The result is a workflow that is both deliberate and efficient. Teams can respond quickly when business needs demand action while ensuring that high-impact changes receive appropriate oversight.
Centralized Governance Across Autonomous AI Database Deployments
API Access Control extends the enterprise operational model of Autonomous AI Database by providing centralized, policy-driven governance for sensitive management operations.
Security administrators create privileged API controls in the OCI Console and associate them with Autonomous Exadata VM Clusters, Autonomous Container Databases, and Autonomous AI Databases.

Database administrators request approval when necessary, and authorized approvers can review, approve, reject, extend, or revoke requests through a consistent workflow.
Every request, approval, rejection, extension, and revocation becomes part of an auditable workflow. This provides security teams with greater visibility into sensitive administrative operations and helps organizations demonstrate compliance with internal governance policies and regulatory requirements.
This approach is particularly valuable for organizations operating multiple production environments, supporting different business units, or implementing formal change management processes across cloud infrastructure.
Start with Your Highest-Risk Operations
Most organizations do not need to protect every administrative operation on day one.
A practical starting point is to identify the operations that would have the greatest business impact if performed incorrectly or without appropriate review. Examples include:
- Restoring a production database
- Deleting a database
- Changing the ADMIN password
- Rotating encryption keys
- Changing VM Cluster certificates
As teams become comfortable with the workflow, they can gradually expand protection to additional operations based on their security policies and compliance requirements.
Oracle API Access Control does not replace IAM. Instead, it complements IAM by adding a targeted approval workflow for the moments when permissions alone are not sufficient. By combining identity-based authorization with time-bound approvals and separation of duties, organizations can improve governance while preserving the operational agility expected from cloud services.
Bringing Security and Agility Together
Autonomous AI Database simplifies database operations, but some operations will always warrant additional oversight because of their potential business impact.
Oracle API Access Control provides organizations with a practical way to introduce that oversight without sacrificing productivity. Rather than broadly restricting administrative access, it enables customers to apply approval workflows only where they matter most, protecting sensitive operations while allowing routine administration to continue uninterrupted.
For organizations running mission-critical workloads on Autonomous AI Database, Oracle API Access Control brings together least-privilege governance, separation of duties, time-bound approvals, and comprehensive auditability in a single approval-driven workflow. The result is greater confidence that critical operations are performed by the right people, for the right reasons, and at the right time.
Oracle API Access Control is available for Autonomous AI Database on Dedicated deployments on OCI Public Cloud, Exadata Cloud@Customer, Oracle Database@AWS, and Oracle Database@Azure.
