Configure Risk Management Cloud (RMC) for Segregation of Duties (SoD) Check

You can evaluate permissions or roles of users within Oracle Fusion Cloud Applications to ensure that permission assignment is valid and doesn't violate SoD checks.

Complete the prerequisites and run mandatory jobs periodically.

Mandatory Role: Risk Administrator Role. With this role, Oracle Access Governance can run Global User Synchronization job periodically before Preventive SoD analysis request. For more information, see Configure Global Users.

Associate Worker Information with User

A user account must have associated worker information. On the Security ConsoleUsers page, verify that a linked account shows Associated Worker Information.
Note

If you receive an error such as "Applying List binding LOV_PersonNumber" while linking PersonNumber to the user account, run the following HCM jobs: Compute Users ACL by Events, Compute Users ACL, Compute Users With Large ACL. For steps, see Schedule ACL Processes .

Run Mandatory Background Jobs

In Oracle Fusion Cloud Applications, after creating or updating the user account, run the following jobs in the order:

Verify User Visibility in Risk Management

After running the jobs, verify the results:

  1. Navigate to Risk Management → Setup and Administration → Global User Configuration.
  2. Search for the user for whom you want to run the SoD violations check.

Workflow Configuration

You must attach an approval workflow with an access bundle to process violation checks. If an access bundle has no approval workflow assigned, Oracle Access Governance triggers the SoD violations check but the provisioning proceeds immediately even if potential violations exist. When an approval workflow is attached, Oracle Access Governance pauses the request until the SoD analysis completes.

For more information, see Preventive Segregation of Duties.