top of page

LATEST INSIGHTS

Expert insights across your SaaS environment

Blogs and papers from the SAASiQ team on enterprise SaaS, cloud and AI.

Oracle Makes 22 Agentic Applications Available in Fusion, Running Within Users' Existing Roles

Writer: SAASiQ.ai
SAASiQ.ai
Apr 2
5 min read

Updated: 6 days ago

Title: Oracle Makes 22 Agentic Applications Available in Fusion, Running Within Users' Existing Roles

Date: 2 April 2026

Type: Blog

Author: SAASiQ (contact@saasiq.ai)

Word count: 1317 words

Reading time: 5 min

Published: 02-04-2026


Oracle said on 24 March that 22 Fusion Agentic Applications are now available, each a workspace in which a team of AI agents works towards one business outcome in finance, HR, supply chain or customer experience. Oracle says they run entirely inside the existing Fusion security framework, with role-based access, approval frameworks and end-to-end traceability. Oracle's setup notes show what that means in practice: an agent reaches only what the user's roles already allow, so a customer's existing role design decides what its agents can see and do.


What Oracle announced

The announcement came at Oracle's AI World Tour event in London. Oracle named four of the 22 as examples: a Workforce Operations application for HR scheduling and payroll issues, a Design-to-Source Workspace for supply chain, a Cross-Sell Program Workspace for sales teams and a Collectors Workspace aimed at faster cash collection and lower days sales outstanding. According to the release, the applications move routine actions forward within guardrails and surface only the exceptions, trade-offs and decisions where a person's judgement changes the outcome.


On the same day Oracle updated AI Agent Studio, the tool Fusion customers use to build their own agents. It added an Agentic Applications Builder, orchestration with rules for how work moves between steps and points for human oversight, contextual memory and an Agent ROI dashboard. Oracle said the studio remains available at no additional cost.


Two weeks earlier, on Oracle's third-quarter earnings call on 10 March, Mike Sicilia, who shares the chief executive role with Clay Magouyrk, said the company had delivered well over 1,000 agents inside its applications, and that the embedded agents come at no additional cost.


How Fusion decides what a user can do

Oracle's own documentation sums up the Fusion security model as who can do what on which data. The who is the user. The what comes from job roles, such as Accounts Payable Manager or Buyer, which inherit duty roles, which in turn carry the privileges that open pages and actions. The which is set separately: an administrator assigns data access for each job role through the Manage Data Access for Users task, by business unit, ledger, data access set, asset book or legal entity in Financials.


So a user's reach is the combination of function security and data security. Both are configured by the customer in the Security Console, and the agent setup Oracle describes works through the same roles rather than a separate set of permissions for agents.


How an agent gets its access

Oracle's 26A readiness notes, for the update that customers have been taking since February, show the pattern agent by agent. For the External Purchase Prices Errors Resolution Assistant in Procurement, an administrator first sets the profile option Enable Security Console External Application Integration to Yes. A user who wants to talk to the agent then needs a configured job role containing the Fai Genai Agent Runtime Duty, with permission groups enabled in the Security Console. That is not enough on its own: the same job role must already hold the Manage External Purchase Prices and View External Purchase Prices privileges.


Besides answering questions, the agent suggests fixes for import errors, can create missing mappings when it has the details, and can resubmit the Import External Purchase Prices scheduled process. It does those things with the user's own privileges, which is why the underlying role has to carry them.


Building and publishing agents is a separate permission. In Procurement, AI Agent Studio access comes through the PRC Intelligent Agent Management Duty and a Fai Genai Agent administrator duty, and the Risk Management notes say a role must be explicitly granted access to an agent by an AI Agent Studio administrator before its users can see it. Oracle also revised its 26A note on calling agents through a REST API on 27 March. Access is based on the roles assigned to the agent team in AI Agent Studio, and a user assertion token issued through Oracle's identity service makes sure a caller reaches only the agent teams and data it is allowed.


Where approvals sit

Workflow agents in AI Agent Studio gained a human approval node in 26A, a step that pauses the workflow until a person approves, rejects or asks for a change, then carries on according to that decision. Oracle revised the feature note on 13 March. It is a node the builder adds to a workflow, so an approval happens only where one has been designed in.


For tracing what agents did, Oracle's 24 March release says the agentic applications record step-by-step actions and full execution paths. AI Agent Studio has had a monitoring dashboard since October 2025 showing sessions, latency, error rates and token usage, and 26A added scoring of answers drawn from documents for groundedness and relevance.


Roles that already carry conflicts

Because an agent works through the user's roles, any segregation of duties conflict already built into a role applies to the agent as well. Oracle's Risk Management and Compliance service measures this. Its Risk and Security Snapshot report analyses a business process over a chosen period, and its output includes separate tabs for intrarole access risks, where the conflict sits inside a single role, and user access risks, where it arises from the combination of roles one person holds.


26A added four Assurance Advisor agents, for Source to Settle, Order to Cash, Record to Report and Hire to Retire, that answer questions about that report in plain English, for example which users or which roles have the most violations. The snapshot data is converted to JSON, saved as text files and uploaded to the agents' document tools. The Access Request Assistant, which arrived in 25D last November, lets a user ask for roles in natural language and then starts the Advanced Access Requests workflow, which runs the separation of duties analysis before anything is granted.


Oracle Access Governance, Oracle's cloud identity governance service, uses machine learning in access reviews to flag users whose access differs from their peer group. Since June 2025 it has passed approval decisions on flagged segregation of duties conflicts in Fusion straight to Risk Management, and its March 2026 update added an audit trail of actions taken in the service. SAASiQ's view is that the snapshot is worth running on the roles that will carry the runtime duty before agents are switched on, since any conflict it finds will also be there when an agent acts.


The database side

Oracle's database announcements on 24 March apply the same principle below the application. Deep Data Security puts end-user-specific access rules in the database, so that a user, or an AI agent acting for a user, sees only the data that user is allowed to see. Oracle describes it as declarative, database-native least-privilege access, and says it is meant to protect against threats such as prompt injection. The Private Agent Factory is a no-code agent builder that runs as a container in a public cloud or on the customer's own hardware, with pre-built Database Knowledge, Structured Data Analysis and Deep Data Research agents.


Oracle says these are available on all platforms, from multicloud to on-premises. Oracle AI Database 26ai Enterprise Edition for Linux x86-64 became generally available for on-premises use in the January 2026 release update (version 23.26.1), including the in-database SQL firewall, and since 23 December 2025 each Autonomous AI Database on serverless infrastructure has had a managed MCP server that applies the database's existing roles, auditing and Virtual Private Database policies to external agents.


What comes next

Oracle applies each quarterly update in three groups of customers, with test environments first and production two weeks later. The last group is taking 26A in April. Oracle first published its 26B What's New for Financials on 6 March, and it describes Ledger, Payables, Payments and Expenses agents. 26B reaches test environments for the first group on 1 May and production on 15 May.

SAASiQ - Intelligent Solutions for SaaS ©

Optimise your SaaS licences and software subscriptions with SAASiQ

bottom of page