Policies Required to Integrate OCI Document Understanding with Oracle Analytics
To integrate Oracle Analytics with OCI Document Understanding, make sure that you have the required security policies.
The OCI user that you specify in the connection between Oracle Analytics Cloud and your OCI tenancy must have read, write, and delete permissions on the compartment containing the OCI resources you want to use. Ensure that the OCI user belongs to a user group with the following minimum OCI security policies. When you connect to an OCI tenancy from Oracle Analytics, you can use either an OCI API key or resource principal.
Note:
Oracle Cloud IDs (OCIDs) are resource identifiers used in OCI.Note:
For resource principal, to include all Analytics instances under a compartment, specify{request.principal.type='analyticsinstance', request.principal.compartment.id='<compartmentA_ocid>'}
instead of {request.principal.id='<analytics_instance_ocid>'}
.
API Key Policies | Resource Principal Policies |
---|---|
Allow group |
Allow any-user to manage ai-service-document-family in tenancy where all |
Allow group |
Allow any-user to read buckets in compartment |
Allow group |
Allow any-user to manage objects in compartment |
Allow group |
Allow any-user to read objects in compartment |
Allow group |
Allow any-user to read |