Governing AI Agents in Oracle Fusion Cloud: A Licensing and Access Control Framework

Updated: 6 days ago
Title: Governing AI Agents in Oracle Fusion Cloud: A Licensing and Access Control Framework
Date: 20 May 2026
Type: Paper
Author: SAASiQ (contact@saasiq.ai)
Word count: 2966 words
Reading time: 11 min
Published: 20-05-2026
Oracle's 26B quarterly update reached production for the first group of Fusion Cloud customers on 15 May, and its readiness notes document several of the 22 Fusion Agentic Applications Oracle announced on 24 March. None of them appears until an administrator switches it on, and once it is on, an agent in Fusion acts through the roles of the user it serves. This paper sets out a framework for governing those agents on access and on licensing, which Fusion ties together through the same role design, using the documents Oracle had published by 20 May.
What 26B switches on, and what it leaves off
Oracle applies each quarterly update in three groups of customers, test environments first and production two weeks later. For 26B the first group's dates were 1 May and 15 May, and the second and third groups take it in June and July.
The agentic applications arrive switched off. The Cost Accounting Close Workspace, for example, stays hidden until an administrator sets the profile option ORA_CST_PERIOD_CLOSE_AGENTIC_APP_ENABLED to Yes at site level, and the 26B What's New for Financials marks the Ledger, Payables and Payments agents as Setup Required. Oracle's questions-and-answers pages for Fusion AI say generative AI features are enabled or disabled in the Setup and Maintenance work area.
Oracle says the agentic applications run entirely inside the existing Fusion security framework, with role-based access, approval frameworks and end-to-end traceability, down to step-by-step actions and full execution paths. Its 24 March announcement gave no price for them. The same day Oracle said AI Agent Studio, the tool customers use to build their own agents, remains available at no additional cost, and SiliconANGLE reported that basic agents running on the built-in models are included while premium language models are charged by usage.
How an agent gets its access
Oracle's documentation describes Fusion security as who can do what on which data. Job roles such as Accounts Payable Manager inherit duty roles, duty roles carry the privileges that open pages and actions, and data access is assigned separately, by business unit, ledger or data access set. Agents get no separate set of permissions. Oracle's AI Agent Studio guide says agents adhere to the native security and role-based access controls of Fusion, and that applies to its business object tools, which let an agent retrieve, create, update or delete records.
Several things have to be in place before a user can talk to an agent. The profile option Enable Security Console External Application Integration (ORA_ASE_SAS_INTEGRATION_ENABLED) must be Yes at site level, so the Security Console can work with permission groups. The user needs a job role containing the Fai Genai Agent Runtime Duty (ORA_DR_FAI_GENERATIVE_AI_AGENT_RUNTIME_DUTY), with permission groups enabled on that role. And the role has to be added on the agent team's Security tab in AI Agent Studio, because a user sees only the agent teams their roles are attached to.
The runtime duty lets a user talk to an agent. What the agent can then do depends on the user's other privileges. Oracle's 26A note for the External Purchase Prices Errors Resolution Assistant in Procurement says the same job role must already hold the Manage External Purchase Prices and View External Purchase Prices privileges. The agent suggests fixes for import errors, creates missing mappings when it has the details, and can resubmit the Import External Purchase Prices scheduled process, all with the privileges its user already has.
Calls from outside the Fusion screens follow the same rule. Agent teams can be invoked through the /invokeAsync REST API, and Oracle's guide says access depends on whether the caller's role can reach the agent team, as set on its Security tab, with authentication through OCI IAM using an OAuth 2.0 bearer token. The Microsoft Teams integration carries the user's identity into Fusion in the same way.
Who can build and change agents
Building agents is a separate set of duties, one per pillar. The guide lists Fai Genai Agent administrator duties for CX, Financials, GRC, HCM, Procurement, Projects, Permitting and Licensing (PSC) and SCM, each paired with a product duty such as the PRC Intelligent Agent Management Duty or Manage Financials Intelligent Agent. Access across all pillars adds a role called Manage All Intelligent Agents (ORA_FAI_MANAGE_ALL_AI_AGENTS). Oracle's Fusion centre of excellence blog set out the same pattern in February, from the 26A documentation, with administrators given the duty for their pillar and end users given the runtime duty only.
Some builder rights reach outside Fusion. Creating an External REST tool, which lets an agent call another application or a public API, needs the Create and Edit Backends for Visual Builder Studio privilege (ORA_FND_TRAP_PRIV). Scheduling a workflow agent team needs the Fai Batch Job Manager Duty, and viewing records in the Monitoring and Evaluation tab needs the read:Generative AI Workflow Execution permission group.
The builder also decides where a person approves. External REST tools have a Require Human Approval setting, so that someone reviews an action before the tool runs, and workflow agents gained a human approval node in 26A that pauses the flow until a person approves, rejects or asks for a change. Oracle builds some of this into its own finance agents: its Payments Agent note says draft recommendations, offers and schedules always need a user to review and confirm them. In a custom agent, an approval exists only where the builder has put one.
What Oracle charges for
Oracle divided its Fusion AI offer in two in April 2025. Miranda Nash, group vice president for applications development and strategy, wrote on 29 April 2025 that embedded AI is included with a Fusion subscription at no extra cost, and that custom AI would be a separately priced offering using seat-based and employee-based pricing, like the rest of Fusion. On Oracle's third-quarter call on 10 March this year, co-chief executive Mike Sicilia said Oracle had delivered well over 1,000 agents inside its applications at no additional cost.
The 26B AI Agent Studio guide, as published in May, says where the line falls. Customers can use the ready-to-use templates and make minor changes, such as uploading documents, adjusting display fields or editing prompts, without a Custom AI Agent subscription. A subscription is needed to create new agents, to modify templates significantly (adding integrations or actions, or changing the agent's purpose), to use third-party or marketplace agents, or to select a language model Oracle does not provide. The guide adds that fees may apply if premium model usage goes past the default token allocation.
Oracle's Fusion service descriptions dated 9 October 2025 define a Custom AI Agent in the same terms: any agent created in AI Agent Studio or modified from an Oracle-delivered one, for example by adding a tool, reaching an external service or MCP server, bringing the customer's own model, or adding image, voice or video. They define two metrics. AI Agent per Authorized User counts each person given access to each custom agent, so ten users with access to five custom agents is a quantity of 50, measured at the month's highest point, and the charge continues for as long as the agent stays published for that user. AI Agent per Employee applies the Hosted Employee count to each custom agent.
Oracle's price list of the same date puts Custom AI Agents for ERP, SCM, HCM and CX at $50 a month per agent per authorised user, with a minimum of 10, and the ERP, SCM and HCM versions at $2.50 a month per agent per employee, with a minimum of 500. Each per-user unit adds 1 million tokens a month to a pooled allowance and each per-employee unit up to 50,000, on top of 100 million a month granted with the initial base Fusion subscription in an environment, and more tokens cost $500 per billion. Tokens left at the end of the subscription period are forfeited. In the October table, tokens used by OpenAI's GPT-4.1 mini were deducted from the pool and those used by the Cohere and Llama 3.3 models were not, and a customer bringing its own model deals with that provider under its own contract. Negotiated orders can differ, so the terms that apply are the ones on the customer's order.
How named users are counted
Oracle's Metric Descriptions for Fusion Offerings, in the version dated 14 April 2026, explain how Fusion subscriptions are measured, and user counts are measured by privilege. Fusion Financials counts active users assigned any of 11 privileges, among them AP_MANAGE_PAYABLES_INVOICES_ACTIVITIES_PRIV and GL_MANAGE_PERIOD_CLOSE_ACTIVITIES_PRIV, and Purchasing counts users holding either of two work area privileges. The document lists no metric for AI agents, and none of the AI Agent Studio duties or privileges is among those it counts.
So the named-user effect of an agent turns on the business privileges its users hold. Adding the runtime duty to a role adds nobody to the Financials count. Adding a Payables or General Ledger privilege to a role so that its users' agent can act on invoices or journals may, because the count follows the privilege whether or not anyone uses it. Oracle's 26A advisory note on subscription impact says that privileges assigned but unused can still account for subscription consumption, even for a service the customer has not bought, and recommends copying a predefined role, removing the privileges not needed and assigning the copy. The AI Agent Studio guide repeats the caution for the predefined roles used to configure agents.
Hosted Employee works differently. Oracle counts every person tracked in the service during the month, of any person type, including employees, agents, contractors and consultants, each once. The agents in that list are people acting for the customer: the same wording appears in Oracle's Hosted Employee definition in its service descriptions of December 2022.
Step one: list what is switched on
The framework starts with a register of agents. For each agent team it records whether the team is an Oracle template used as delivered, a template with minor changes or a custom agent, which model it runs on (Oracle-provided, premium or the customer's own), which roles are on its Security tab, which business objects and tools it uses, where its approval steps sit and who owns it.
The register also needs the settings that turn agents on: the profile options for agentic applications such as the Cost Accounting Close Workspace, the Setup Required agents that have been configured, and the generative AI features enabled in Setup and Maintenance. Some of these arrive with each quarterly update, so the register is refreshed in the two weeks between test and production.
Step two: build runtime roles on purpose
Agents should run under custom job roles built for the purpose, holding the runtime duty and the privileges the agent's actions need, with data access set by business unit or ledger as for any other role. Following Oracle's advisory note, these are copies of predefined roles with the unneeded privileges removed, and each one is checked against the metric descriptions before it goes on a Security tab, so that the named-user count moves only where the organisation means it to.
The same roles go through separation of duties analysis before agents are switched on. Oracle's Risk and Security Snapshot Report, part of Fusion Cloud Risk Management, runs access analysis (for example, users who hold the privileges both to create a payables invoice and to approve payment on it) and transaction analysis (occasions when one user has done both), and it flags roles that grant sensitive access on their own. Because the agent acts with its user's roles, a conflict inside a role is also a conflict for the agent.
Oracle has put agents into this process too. The Access Request Assistant, added in 25D, takes a request for ERP roles in plain English and starts the Advanced Access Requests workflow, which runs the separation of duties analysis before anything is granted, and 26B adds a reporting subject area for access requests covering volumes, approval times and policy violations. Oracle Access Governance has passed approval decisions on flagged segregation of duties conflicts in Fusion to Risk Management since June 2025.
Step three: classify every agent for licensing
Each agent in the register gets a licence class. Oracle templates used as delivered, or with minor changes, sit within the Fusion subscription. Anything built new, given new tools or integrations, taken from the marketplace or run on a non-Oracle model is a custom agent and needs the Custom AI Agent subscription before it goes into production.
For custom agents the Security tab sets the count. On the October 2025 definition, every person authorised to access a custom agent counts once for that agent while it stays published for them, so attaching a role that 400 people hold to one custom agent team makes 400 units for that agent. SAASiQ's view is that whoever owns the Oracle licence position should sign off the Security tab of every custom agent team, since on Oracle's definition that tab decides the bill.
Model choice goes in the same record. Premium models draw on the token pool, a customer's own model is paid for under its contract with the provider, and the Monitoring and Evaluation tab shows input and output token counts for each run, which is where consumption against the pool can be checked.
Step four: keep building separate from using
The pillar administrator duties belong with a small, trained group, and the cross-pillar Manage All Intelligent Agents role with fewer people still. Oracle's guide says a user's access to AI Agent Studio is removed by taking the related custom roles off their account in the Security Console, and who holds those roles is part of the quarterly review.
Changes to agents can be reviewed in three tiers. The first covers Oracle templates within one pillar, approved by the application administrator with an entry in the register. The second covers custom agents that stay inside Fusion, reviewed by security and by the licence owner, since they carry the subscription. The third covers agents that reach outside Fusion through External REST tools, MCP servers or the customer's own model, which add a review of the external service's data terms before they are published.
In every tier, any tool that creates or changes records should have a human approval step in front of it, using the Require Human Approval setting or a human approval node. ORA_FND_TRAP_PRIV should be held only by builders in the third tier, since it is the privilege that lets an agent call out of Fusion.
Step five: decide where the data goes
Oracle publishes where the OpenAI endpoints used for AI agents in Fusion are located for each data centre. Its list, as it stood in mid-May, maps London and Newport to endpoints in Europe (EEA and Switzerland), along with Frankfurt, Amsterdam, Zurich, Stockholm and Milan, while Ashburn and Phoenix map to the USA, as do Sydney, Melbourne, Tokyo, Toronto and Sao Paulo. For an organisation with a residency rule, that list is where the choice of agents and models for sensitive data starts.
Location of the Fusion environment matters as well. Oracle's 26B Payables Agent note says generative AI services run in its commercial cloud realm (OC1), and environments hosted elsewhere get them when the services reach their region. Agents in the third tier send data wherever their tools point, under whatever terms the customer has agreed with that service, so each external connection is recorded in the register with its data classification.
Step six: monitor and review each quarter
AI Agent Studio has had a monitoring dashboard since October 2025 showing sessions, latency, error rates and token usage, and its traces show each step of a run with its latency and token counts. 26B adds a Value dashboard that reports time and cost saved per agent team, but the savings are the administrator's own per-run estimates multiplied by the number of runs, so they measure use at an assumed value.
A quarterly review goes through the register agent by agent. It checks that each agent is still used, that its roles and Security tab match the register, that its licence class is still right after any changes, and that the snapshot report shows no new conflicts in its roles. A custom agent nobody uses can be unpublished, which on Oracle's definition also stops the per-user charge.
Quarterly updates are part of the review. Oracle's guidance on predefined roles notes that updates can change those roles, and that the same changes have to be made to custom copies by hand, which applies to every runtime role built in step two. The two weeks between test and production are the time to rerun the agents in the register and repeat the role checks.
Where the framework stops
Agents used in HR can fall under the EU AI Act, whose Annex III covers AI used in recruitment, promotion, task allocation and monitoring of workers. On 7 May Council and Parliament negotiators reached a provisional agreement to move the Annex III obligations from 2 August 2026 to 2 December 2027, pending formal adoption. Deployers of a high-risk system will have to assign human oversight and keep the logs it generates, and the register, the approval steps and the monitoring records described here are the material that work draws on.
The framework covers agents inside Fusion Applications. Agents built on Oracle databases outside Fusion are governed in the database, where Deep Data Security became available in Oracle AI Database 26ai on 1 May, applying per-user row, column and cell policies to queries an agent sends. It also leaves out E-Business Suite and PeopleSoft, the quality of agent answers, and the negotiation of AI terms in an Oracle order.
The second group of Fusion customers takes 26B in June and the third in July, and the first group receives 26C in August.
SAASiQ - Intelligent Solutions for SaaS ©


