Oracle Fusion Security Console
The Oracle Fusion Security Console is the security administration tool of Oracle Fusion Applications, the suite of enterprise business applications Oracle delivers as cloud services. It is one of the components of the Fusion security implementation, and it is the interface that "allows for research and customization of the Fusion Applications security environment."[^c1] Security administrators use the console to create and maintain roles, to assign users to those roles — for example by navigating to the console and selecting Create Role to build an abstract role[^c2] — and to configure access controls such as location-based access.
Access in Fusion Applications rests on role-based access control (RBAC), "a security model that restricts system access based on the roles assigned to individual users."[^c9] The suite couples function security, which governs what tasks a user can perform, with data security, so that users reach only the records relevant to their responsibilities. Oracle describes Fusion Applications security as offering "consistent and transparent function and data security, native identity management and access provisioning, enforcement across tools (all the tools use the same policies) and across the information lifecycle," together with integration with Oracle Fusion Governance, Risk, and Compliance.[^c3]
Users and roles are not kept in the applications themselves: "Oracle Fusion Applications externalizes both the users and the roles to reside in a Lightweight Directory Access Protocol (LDAP) system."[^c4] In current deployments the directory layer is an Oracle Cloud Infrastructure IAM identity domain, and "the Fusion Security Console remains the authoritative place to manage Fusion users and their roles."[^c10] Changes made in the console are therefore propagated through a scheduled process — "whenever we make changes in Security Console, we need to run a process to propagate those changes throughout the rest of the application."[^c5] Cloud instances are updated quarterly, with each update carrying security alerts and data fixes[^c8] and sometimes changing seeded roles; auditing and performance monitoring have run by default since Release 13 19A.[^c6] Governance tooling such as Oracle Access Governance extends the ecosystem, integrating with Fusion Applications and Oracle Cloud Infrastructure to add automated identity lifecycle management, segregation-of-duties guardrails, and access certification.[^c7]