    Venkatesh Chella
    In Advanced Access Control under Enforcement Type, How does...
    Topic posted January 9, 2019 by Venkatesh Chella, tagged GRC, Risk Management, Separation of Duties 
    In Advanced Access Control under Enforcement Type, How does Prevent and Approval Required work.
    Usage of Enforcement Type in Controls

    Would like to know the different functionalities of Enforcement Type ( Monitor, Prevent , Approval Required ). How does it work ?

    We are in 18C and would like to know how to make use of Enforcement Type in Controls.




      Hi Venkatesh,

      Today, the enforcement type field is only used for reporting purposes. Hope this helps.

      Hi Lakshmi,

      Thanks for your response.  It would be a great option if they can implement or introduce the functionality of " Approval Required " / " Prevent " . Because the business actually would like to validate such SoD conflicts during the time of assigning itself, either by Preventing or by getting approval as defined by the SoD Control. I was hoping that it would be delivered in 18C, but not. Hope this option is rolled out at the earliest in the next future releases.

      Hi Venkatesh!

      Thank you for your feedback. 

      Here's Oracle's guidance on your question: If you use HCM to provision users (UI or Data Loader), use Role Mappings to enforce access policies; if you use another application to provision users (e.g., Oracle Identity Cloud), use that app's equivalent functionality. In either case, use AAC to support the design of the access policies. 

      Hope this helps.

      Hi Lakshmi,

      Thanks for your Guidance. We are using HCM to provision users. Can you direct me to the documentation where I can understand about " Role Mappings to enforce access policies ". Basically would like to prevent the SoD conflicts at the time of assigning them to users.

      Appreciate your assistance.

