Fusion security and OCI identity
Access that passes the audit the first time.
Fusion role design and segregation of duties, Risk Management Cloud, OCI IAM identity domains and federation, Data Safe, Cloud Guard and Security Zones, so security is designed once and provable every quarter.
Overview
Security & Identity, done properly.
Security in Oracle estates usually fails in the seams: a Fusion role copied from a seeded template that grants too much, an integration user with a human's privileges, an OCI policy written as allow-all to get a demo working. AMTEX designs the access model across Fusion and OCI together and leaves you with the evidence auditors ask for.
Technologies
- Fusion Security Console
- Risk Management Cloud
- OCI Vault & IAM
- OCI IAM Identity Domains
- Oracle Data Safe
- Cloud Guard & Security Zones
What we deliver
Capabilities
Everything AMTEX builds, configures and runs across Security & Identity.
Fusion role design
Custom job and data roles built from the segregation-of-duties matrix, not copied from seeded roles.
Segregation of duties
Conflict analysis, mitigating controls and periodic access reviews, with Risk Management Cloud where licensed.
Risk Management Cloud
Advanced Access Controls and Financial Reporting Compliance configuration and rollout.
OCI IAM identity domains
Domain design, groups, policies written for least privilege, dynamic groups for workloads.
Federation & SSO
Entra ID or Okta federation for Fusion and OCI, MFA policy, and provisioning driven from HCM events.
Integration and service identities
Dedicated integration users, OAuth clients, secret rotation in Vault; no shared human accounts anywhere.
Data Safe & database security
Sensitive data discovery, masking for test pods and non-production, activity auditing on ATP.
Cloud Guard & Security Zones
Posture management, detector tuning, responder rules and enforced guardrails per compartment.
Audit evidence
Role catalogues, access review records, policy exports and change logs packaged for SOX and ISO audits.
The hard parts
Where these projects become difficult
The places programmes slip, and what we do about each one.
- 01
Seeded roles in production
The problem
Users hold seeded roles with privileges nobody reviewed.
How AMTEX approaches it
Role redesign from the matrix, a phased cut-over with user acceptance, and access reviews scheduled.
- 02
Allow-all policies
The problem
OCI policies granting manage on the tenancy because it worked in the demo.
How AMTEX approaches it
Policy review against the CIS OCI benchmark, compartment-scoped rewrites, Security Zones to stop regressions.
How we work
From first conversation to steady state
01
Assess
Roles, policies, integration identities, findings from the last audit.
02
Design
SoD matrix, role model, identity domain and policy design.
03
Implement
Roles, federation, Vault, Cloud Guard, Data Safe; cut-over with reviews.
04
Prove
Access reviews, evidence packs and quarterly posture checks.
Related solutions
Oracle Fusion Cloud ERP
Financials, Procurement, Projects and Order Management, implemented and extended with the integrations, reporting and automation a real enterprise needs around them.
Oracle Cloud Infrastructure
OCI architecture for the workloads that live around Fusion: Autonomous Database, Functions, API Gateway, Object Storage, networking, identity and observability, designed for security and high availability.
Logging, Observability & Monitoring
OCI Logging, Logging Analytics, Monitoring, Application Performance Monitoring and Service Connector Hub, applied across OIC, OCI workloads and Fusion so one dashboard tells the truth about the whole estate.
An audit finding on access, or a migration that needs a clean role model?
We will assess the current state and give you a plan the auditors will accept.