Governing Oracle Fusion Cloud Licences: How Oracle Counts Users, Employees and AI Agents

Updated: 6 days ago
Title: Governing Oracle Fusion Cloud Licences: How Oracle Counts Users, Employees and AI Agents
Date: 22 April 2026
Type: Paper
Author: SAASiQ (contact@saasiq.ai)
Word count: 2865 words
Reading time: 11 min
Published: 22-04-2026
Oracle's Metric Descriptions for Fusion Offerings, revised on 14 April 2026, sets out how Oracle counts usage of each Fusion Cloud service it measures. For most ERP, procurement and project services, a person counts once their user account is active and holds any one privilege from a published list, whether or not they ever sign in. This paper explains how those counting rules, the Cloud Services Agreement and Oracle's terms for AI agents fit together, and sets out a monthly routine for keeping a Fusion estate within what the organisation has ordered.
What the agreement says about quantities
Fusion is bought as a subscription under Oracle's Cloud Services Agreement. The UK version of the online agreement (v062223) gives the customer the right to use the services for the Services Period set out in the order, solely for its internal business operations, and makes an order non-cancellable once it is placed. Clause 2.2 deals with overuse in one sentence: if the customer exceeds the quantity of services ordered, it 'promptly must purchase and pay fees for the excess quantity'.
The online agreement has no audit clause. Oracle measures usage itself. Clause 11.1 says Oracle continuously monitors the services, and that the information its monitoring tools collect, excluding the customer's own content, may be used 'for license management purposes'. So the counting happens inside the service every month, and the customer's task is to know what the count is and why.
The agreement also defines the Service Specifications, which include Oracle's service descriptions and the programme documentation, and clause 1.2 allows Oracle to update them during the Services Period, provided the updates do not materially reduce performance, functionality, security or availability. The documents that describe how usage is measured can therefore change while an order is running, which is one reason the routine later in this paper includes a quarterly reread.
Hosted Named User and Hosted Employee
Most Fusion ERP and supply chain services are sold on one of two metrics, and the Fusion Service Descriptions (the edition effective 9 October 2025) defines both. A Hosted Named User is 'an individual authorized by You to access the hosted service, regardless of whether the individual is actively accessing the hosted service at any given time'. Someone who opens Fusion once a quarter counts the same as someone who works in it all day. A few services use a Pooled Named User instead, where Oracle takes the peak number of provisioned users each month and deducts it from a pool bought for the whole Services Period.
Hosted Employee is a headcount measure. It covers all full-time, part-time and temporary employees, plus agents, contractors and consultants who have access to, use of, or are tracked by the programs, and the service descriptions say the quantity 'is determined by the number of Hosted Employees and not the actual number of users'. Where a business function is outsourced, the outsourcer's staff who provide the service and have access to, or are tracked by, the programs count as well.
The metric document explains how Oracle measures that. Hosted Employee 'counts every Person, regardless of Person Type' tracked in the Fusion service during the month, each once, and workers whose only person type is Retiree or Not Managed by HR are left out. Measuring Hosted Employee services requires at least one Hosted Employee base service from Oracle's HCM pillar, because the count comes from HR records.
The same service can be sold on either metric. The service descriptions list Oracle Fusion Enterprise Resource Planning Cloud Service on a Hosted Named User metric (part B91079) and on a Hosted Employee metric (B91084), and the same goes for Procurement and Risk Management. The first governance task is to know which metric each line of the order uses, because the levers are different: user and role design for one, HR data for the other.
How Oracle counts a Fusion user
For services on the Hosted Named User metric, the metric document names the privileges that make a user count. For the ERP Cloud Service (B91079) it is 'the number of active users with at least one of' 31 privileges, among them AP_MANAGE_PAYABLES_INVOICES_ACTIVITIES_PRIV, GL_MANAGE_PERIOD_CLOSE_ACTIVITIES_PRIV and a run of project, revenue and budgetary control privileges. A user who holds several of them counts once. For Procurement (B91082) the list has seven privileges, covering the purchasing and purchase agreement work areas, sourcing negotiations and supplier qualification. Procurement for Self Service (B91083) counts active users with POR_MANAGE_REQUISITION_PRIV.
In practice the count follows role design. Privileges reach users through job roles, which inherit duty roles and aggregate privileges, so a user who is given a job role for convenience, or a custom role copied from a predefined one, counts against the service if any privilege in that hierarchy is on the list, whether or not they use it. Oracle's Securing ERP guide (26A) notes that when a job or abstract role is copied, its aggregate privileges are never copied; the new role is made a member of the same aggregate privileges automatically, so it still carries them.
Oracle attaches two caveats. The metric document is 'for general guidance and reference purposes only' and does not amend the service descriptions, and for Hosted Named User services the privileges it lists 'may be representative of, rather than exhaustive of' those needed to use the whole service. It also changes with the quarterly releases. The February revision showed PO_VIEW_PURCHASE_AGREEMENT_WORKAREA_PRIV counting towards Purchasing and Supplier Portal from release 25D, and the 14 April revision says that from release 26B, 42 more service privileges will count towards Fusion Suite Professional (B108674), a user type that covers ERP, supply chain, EPM and CX services, while nine will stop counting.
The service descriptions also show what each user type buys. The ERP Hosted Named User covers Financials, Advanced Collections, Revenue Management, Grants Management, the project financials services, Joint Venture Management and Lease Accounting, with two environments, one for production and one for staging, and further environments at extra cost. A separate ERP for Self Service user (B91080) covers viewing reports, approvals, expense entry and approval, invoice viewing and payment, and project time entry. Oracle's security guide says that common functions such as creating expense reports and time cards are granted through the Enterprise Resource Planning Self Service User abstract role, separately from job roles.
The report Oracle already sends
Oracle publishes its own count. Its guide to finding SaaS service usage (June 2025 edition) says the SaaS Service Usage Metrics Report is generated and delivered daily to the customer's Cloud Console. It shows each service in the subscription with its subscribed quantity, usage for the current month and the last three months, and services being used that are not in the subscription, which Oracle labels unexpected usage. A negative Remaining Quantity means more users are authorised than the contract allows.
Most metrics are reported as the peak for the month. Oracle's example: 20 Hosted Named Users authorised on 5 June, 32 on 22 June and 18 from 25 June to the month end gives a June figure of 32. A reduction made late in a month shows only in the next month's figure.
Access to the report needs a tenancy administrator, or membership of a group with the right policies, and Oracle keeps each report in the console for a minimum of one month. After that it is deleted and cannot be recovered, and Oracle recommends keeping a local copy to track history.
AI agents and the licence
Oracle's position is that the agents it delivers inside Fusion are included. On its third-quarter call on 10 March, co-chief executive Mike Sicilia said Oracle had delivered well over 1,000 agents inside its applications at no additional cost, and Oracle said on 24 March that AI Agent Studio, the tool customers use to build agents, remains available at no additional cost. SiliconANGLE reported the same day that 'basic agents using built-in models are included with existing applications at no additional charge' and that capabilities using premium large language models 'will incur usage-based charges'. On 9 April Oracle announced 12 agentic applications for finance and supply chain and eight for HR, which it says inherit the role-based access and data permissions already set up in Fusion.
Custom agents are priced separately. Oracle said in April 2025 that custom AI would be a separately priced offering with seat-based and employee-based pricing, and the service descriptions effective 9 October 2025 define a Custom AI Agent as any agent 'either created with, or resulting from modification of Oracle delivered agents'. The modifications they list include adding a tool, accessing an external service, reaching external tools through Model Context Protocol (MCP) servers, bringing your own model, and adding multimodal capabilities such as image generation, voice or video.
The same edition sells Custom AI Agents for ERP, SCM, HCM and CX per 'Authorized User', and for ERP, SCM and HCM per employee. On the per-user metric Oracle counts each authorised user once for every custom agent they can use in production, taking the highest figure in the month: ten users with access to five custom agents is 50, and so is five users with ten. An agent is charged for each user 'as long as the custom AI Agent remains published for that Authorized User'.
Model usage is metered through an AI Token Pool, made up of an allowance with the base Fusion subscription plus 1,000,000 tokens a month for each custom agent seat in that edition. Tokens are deducted monthly, the customer tops up with part B111575 if the pool runs out, and unused tokens are forfeited at the end of the Services Period. Whether a model draws on the pool is set in a table: in the October 2025 edition OpenAI's GPT-4.1 mini did, Cohere's Command R and Meta's Llama 3.3 did not, and a model the customer brings runs under its own contract with that provider. Oracle reserves the right to change which models draw on the pool 'with prompt notice'.
For governance, the line between included and chargeable is drawn by how an agent is changed. A builder who adds an MCP server or an outside model to a delivered agent in AI Agent Studio has, on Oracle's definition, made a custom agent. Oracle's 26A notes for the Risk Management assurance agents say an AI Agent Studio administrator must explicitly grant a role access to an agent before its users can see it, and agent access generally follows the roles the customer assigns, so the list of who can use each agent, and therefore the per-user count, sits with the customer.
Before starting
The work needs a named licence owner who can say no to a role change, working with the Fusion security administrator (the IT Security Manager role opens the Security Console) and whoever holds the order documents. It also needs access to the Cloud Console for the usage report, and a stage environment for testing any role that is narrowed.
Step one: build the entitlement baseline
List every line on every current order: part number, service name, metric, quantity and Services Period dates. Include additional environments, any custom agent seats and any token top-ups. Then match each part number to its entry in the metric document, so that the counting rule for each line is written down next to the quantity bought.
Download the latest usage report and set it against the list. Three things need an explanation straight away: any line where usage is above the subscribed quantity, any negative Remaining Quantity, and anything in the unexpected usage tables, since those are services in use that the order does not cover.
Step two: map roles to counted privileges
The User and Role Access Audit Report lists the function and data security privileges granted to a user or role, the same information the Security Console shows, and it runs on data loaded by the Import User and Role Application Security Data process. Running it for all roles and matching the output to the metric document's privilege lists shows which job roles, and which custom roles, make their holders count against which services.
That usually turns up roles carrying a counted privilege that most holders never use. Oracle's guide gives the method for narrowing them: its example builds a General Accountant role without access to reporting structures by copying the job role and removing the General Ledger Reporting duty role. The same method can produce a role for people who only view, approve or enter expenses, which the ERP for Self Service user type is meant for. Whether the narrower role still lets someone do their job is a test to run in the stage environment first.
Segregation of duties uses the same role data. Oracle's guide notes that the predefined Accounts Payable Manager role holds both Force Approve Invoices and Create Payments, which some organisations treat as a conflict and remove. The licence review and the segregation of duties review can run from the same report.
Step three: close accounts and roles nobody uses
Because a Hosted Named User counts whether or not it is used, an account that is active and holds a counted privilege is paid for. The Inactive Users Report lists users who have not signed in for a set number of days, 30 by default, and depends on the Import User Login History process being scheduled daily. The User Role Membership Report gives every user's roles as a CSV file, which makes it easy to spot contractors and leavers who still hold job roles.
Fusion does some of this automatically. By default a user's account is suspended when the user is terminated or left with no roles, and role-provisioning rules can remove roles on termination. Oracle's guide adds that roles provisioned directly on the Security Console are not affected by the User Account Role Provisioning option, so roles granted by hand stay until someone takes them away, and those are the grants to check first.
Removals made in the last days of a month still count for that month, because the figure is the monthly peak, so a clean-up aimed at a particular report should finish early in the month before.
Step four: put integrations and agents on a register
The metric document counts active users by privilege and sets out no exception for accounts used by integrations or scheduled jobs. Each such account belongs on a register with its owner, the system it serves, its roles and any counted privileges, and should hold only what the integration needs.
Agents go on the same register. For each one, record whether it is delivered or custom by Oracle's definition, which roles have been granted access, which model it uses and whether that model draws on the token pool. Before a builder adds a tool, an MCP server or an outside model to a delivered agent, the licence owner should confirm that the order includes custom agent seats for the users who will get it. Oracle's AI Agent Studio monitoring dashboard, added in October 2025, shows sessions, error rates and token usage, and Oracle said at the time that the token figures measure consumption of premium models.
Step five: a monthly check and a renewal file
Once a month, download the usage report, save it, compare it with the baseline and record what was found and done. The saved reports become the organisation's own history, since Oracle commits to keeping each one in the console for a minimum of one month.
Once a quarter, reread the metric document and the What's New notes for the next update. Oracle updates Fusion customers in three groups, with test environments updated first and production two weeks later, and a new feature can bring new privileges or change how a service is measured, as the 25D purchasing change and the 26B Suite Professional change show.
Before a renewal, the saved reports show the peak for each month of the Services Period and support the quantities in the new order. SAASiQ's view is that role and account clean-up is best finished well before renewal talks begin, so that the reports already show the lower counts when quantities are set.
What it costs and where it breaks
The routine takes regular time from the security administrator and the licence owner, and narrowing roles means testing in stage before every change goes to production. Every quarterly update can add privileges to predefined roles, so a role that counted correctly in one quarter needs checking again in the next.
Hosted Employee services cannot be managed through roles at all. The count comes from person records in HCM, so data quality in HR, such as leavers and non-workers carrying the right person types, is what decides it. The metric document is also guidance only: where it and the service descriptions differ, the service descriptions govern, and individual orders can carry their own terms.
This paper does not cover pricing or negotiation, the Enterprise Performance Management and NetSuite services, which have their own usage documents and contracts, or the security design of agents beyond their licence position.
Oracle applies its 26B update to the first group of customers' test environments on 1 May and to production on 15 May.
SAASiQ - Intelligent Solutions for SaaS ©


