How Fusion's abstract/job/duty/data role model, aggregate privileges and Security Console map to D365's role-duty-privilege-entry-point hierarchy and Extensible Data Security, why the naming resemblance is deceptive, and why Fusion's native segregation-of-duties tooling is materially stronger than D365's out of the box.
Most of this course leaves D365 F&O looking, if not better, then at least no worse than the Fusion capability it replaces. Security is different, and it deserves to be said plainly at the top of this unit: Oracle Fusion Cloud ERP's role-based access control is one of the more mature, purpose-built enterprise-security frameworks in SaaS…
D365 security is built bottom-up from securable objects called entry points — menu items, action menu items, output menu items, web content items, and service operations. A permission grants one access level (No Access, View, Edit, Create, Delete, Correct or Invoke) to one entry point.
Fusion's role model has four tiers below the assignment itself, plus two supporting constructs.
Line the two models up and the correspondence looks almost exact: job role and duty role sit next to role and duty; privilege sits next to privilege; both support role hierarchies. That correspondence is real at the naming level and misleading at the behavioural level, in three specific ways.
Fusion's ledger-level data restriction is the Data Access Set: a definition, scoped to a ledger or ledger set, that grants either full access or access restricted to specific primary-balancing-segment values, each marked read-only or read-write.
Fusion's segregation-of-duties story does not stop at the role level. Advanced Access Controls, part of the separately licensed Oracle Risk Management Cloud (the modern name for GRC for Cloud), continuously monitors posted transactions against a seeded rule library, runs certification campaigns where managers periodically re-attest to…
D365 licensing is named-user, and each user's required licence tier is driven by the highest-tier duty or privilege reachable through any role assigned to them — not by how the user actually spends their day.
Fusion's Application Audit Trail is configured through Manage Audit Policies at the business-object and attribute level: an administrator flags which business objects (GL Journals, Payables Invoices, and so on) and which attributes on them should be tracked, and Oracle manages retention and provides a dedicated Audit Report Region for…
Inventory the Fusion job role, its data role, and any directly attached aggregate privileges or data security policies. Decompose the job role to duty-role granularity and match each duty role to the closest existing D365 duty, creating a custom duty only where no reasonable match exists.
Fusion's security model is a coherent, purpose-built RBAC framework, and in several respects — a single administrative console, data scope bundled into the assignable role, a seeded and continuously monitored segregation-of-duties rule library — it is genuinely stronger than what D365 offers out of the box.