
Access Governance
Oracle Access Governance is a cloud service that delivers policy-driven access provisioning to help you manage access risks across applications, clouds, machines, and databases. Access Governance relies on a prescriptive, analytics-driven process framework to accelerate deployment, simplify integration, and help you decrease overhead by reducing related IT tickets by an average of 70%.
Zero Trust, Maximum Resilience
Traditional perimeter security is no longer sufficient. Learn how a zero trust approach can help protect your systems in the cloud and on-premises from advanced threats, insider risks, and other vulnerabilities.
Why choose Oracle Access Governance?
-
Direct integrations
Tight integrations with Oracle’s market-leading cloud applications greatly streamline the deployment of industry-compliant identity and access.
-
Comprehensive deployment choices
Deploy across commercial and regulated environments in Oracle Cloud Infrastructure’s distributed cloud.
-
Significantly reduced overhead
Increase access governance efficacy and reduce related IT tickets by an average of 70%.
Access Governance cost estimator
Explore Oracle Access Governance
How Oracle Access Governance works
Step 1: Discover
Use AI-driven onboarding to discover and ingest identities, accounts, permissions, and policies from sources such as Oracle Cloud HCM and Active Directory. Provision them to cloud and on-premises targets, including Oracle Cloud Applications, Microsoft Entra ID, and Oracle Health, helping ensure unified governance and precise access.
Step 2: Monitor
Continuously track permissions, entitlements, and attributes across users, machines, roles, and cloud resources. Gain enterprise-wide visibility into access with detailed insights into who has access to what.
Step 3: Learn
Leverage AI and machine learning to analyze patterns, identify anomalies, and provide insights to make informed decisions about access controls and reviews.
Step 4: Automate
Use AI-assisted insights to automate access control, provisioning, and the access review process. Enforce zero trust and least privilege with just-in-time access controls using event-based microcertifications and policy-driven automation.

See how Oracle Access Governance helps you make informed access review decisions.
Featured Access Governance blogs
Unlock the Power of Oracle IGA Integrations
The Oracle IGA Integrations Exchange is a centralized catalog designed to streamline the discovery and integration of disparate systems, applications, and services with Oracle Access Governance or Oracle Identity Governance. The Oracle IGA Integrations Exchange provides a rich library of prebuilt connectors and adapters, enabling organizations to accelerate time to value while reducing the complexity traditionally associated with integration projects.
-
December 5, 2024
Oracle Access Governance Expands with OCI Event Streaming
-
October 22, 2024
Oracle Access Governance: Simplifying Deep Integrations and Enhancing Security
-
July 12, 2024
Parallels and Contrasts of OIG and OAG
-
June 10, 2024
Oracle Access Governance Introduces Next-Gen Access Dashboard and More Integrations
Access Governance customer testimonials
Oracle Access Governance resources
Oracle Cloud Free Tier
Build, test, and deploy applications on Oracle Cloud for free. Sign up and get access to two free offers.
Demo
Join a community of your peers
Cloud Customer Connect is Oracle's premier online cloud community. With more than 200,000 members, it's designed to promote peer-to-peer collaboration and sharing of best practices, product updates, and feedback.
Oracle Access Governance online learning and labs
This free online complete experience workshop is dedicated to showcasing the new features and functionalities of Access Governance. This lab walks you through the steps to get started using Access Governance. Try out the service’s intuitive user experience and prescriptive analytics for access review use cases.
You may also be interested in
-
Security trends
Strengthen your organization’s security posture
-
Oracle partners
Find Oracle partners to support your IAM journey
What’s New?
Oracle Access Governance is continually evolving to enhance identity governance and administration across cloud and on-premises environments. Here’s an overview of the new features we’ve added recently to improve your Oracle Access Governance experience. These advancements underscore our commitment to providing robust and intelligent access governance solutions that help you maintain security and compliance across diverse IT environments.
For additional information about Oracle Access Governance, please review the service documentation. For information on pricing, please review the pricing documentation.
New features
Access guardrails: Strengthening segregation of duties (SoD) with metadata-driven rules
To help facilitate compliance and mitigate risks, Oracle Access Governance has introduced access guardrails. This feature enforces segregation of duties (SoD) by implementing metadata-driven rules to define eligibility criteria for granting access bundle permissions. Examples include training requirements, toxic combinations of permissions, and identity attributes such as organization and location. Administrators can define and manage these rules to automatically detect and remediate potential SoD violations, thereby maintaining a secure and compliant access framework.
AI Agents: Automating Access Bundles with AI-powered Mining and Generative AI
Leveraging AI, Oracle Access Governance now includes embedded AI agents that streamline application onboarding. These AI agents mine existing permissions and automatically generate access bundle recommendations for managed applications, complete with Generative AI-generated naming conventions. Additionally, the prescriptive analytics-powered AI agent provides insights into outlier access patterns, enabling swift remediation actions to uphold security standards.
Enhanced Event Data Publisher: Integrating with OCI for Advanced Monitoring
The Event Data Publisher has been enhanced to export audit histories into Oracle Cloud Infrastructure (OCI) Buckets or OCI Streams. This enhancement allows for the inclusion of Access Governance operational data, enabling customers to monitor their Access Governance operations and audit data effectively. With Oracle’s reference implementation, this data can be seamlessly integrated into Business Intelligence (BI) dashboards for comprehensive analysis.
Deep Integration with Oracle Ecosystem: Automating identity lifecycle across the ecosystem
Oracle Access Governance offers automated user provisioning, access controls, audit capabilities, and compliance reporting across the entire digital ecosystem. When integrated natively with Oracle Cloud Applications, it ensures that the right individuals have access to the appropriate resources at the right times. This integration maximizes operational efficiency through easy integrations with non-Oracle business technologies.
Simplified Audit Reporting: Streamlining audit reporting process with ease
Audit processes are now more straightforward with Oracle Access Governance's support for compliance reports. The platform provides easy access to who have access to what audit logs, which can be readily downloaded to facilitate compliance reporting and auditing procedures such as SOC1, SOC2, and ISO27001.
Identity orchestration
Access Governance seamlessly integrates with business-critical systems—including Oracle Cloud Infrastructure and industry-leading Oracle applications, such as Oracle Fusion Cloud Applications, Oracle Health EHR, Oracle E-Business Suite, PeopleSoft, and more. The identity orchestration feature accelerates onboarding by seamlessly integrating with cloud and on-premises systems for fast, cordless application setup. It extracts, correlates, and transforms data across multiple sources, providing a unified view of user access.
Lifecycle management
Access Governance simplifies identity lifecycle management across diverse environments by centralizing user access control. It empowers users with self-service capabilities, enabling them to manage identity details, request access, delegate tasks, and review permissions. With automated identity lifecycle management, the system supports secure onboarding, transfers, and offboarding, covering joiner, mover, and leaver scenarios. Additionally, it synchronizes and reconciles accounts across systems, allowing for accurate access assignments and reducing manual workloads.
Access control
Access Governance offers a comprehensive access control framework to help you manage on-premises and cloud permissions with precision and automation. It supports multiple permission models, including role-based access control for assigning permissions based on job roles such as finance analyst or HR manager, attribute-based access control for access tied to identity attributes such as location or job code, and policy-based access control for defining access policies, such as a policy that allows a healthcare provider to access patient records within their area of specialty. This flexible, automated approach gives you granular, customizable control over access across diverse environments.
Access certification
Access certification helps prevent excessive or unauthorized access by allowing you to use certification campaigns to monitor and validate user permissions. Certification campaigns assign review tasks to relevant users, such as managers or entitlement owners, to periodically evaluate access or trigger reviews based on events such as role or location changes. Reviewers can approve or revoke access, and all decisions are recorded to support regulatory compliance, ensuring that access aligns with organizational security policies and compliance requirements.
Process automation
Easily create lightweight no-code workflows for access control and governance. Visualize and design linear or parallel workflows and seamlessly integrate user management, management chains, and identity collection into the workflow process.
Automate access control with AI-assisted capabilities, including access bundle onboarding, provisioning, and access reviews. By leveraging peer group analysis, outlier detection, and risk evaluation, Access Governance provides actionable insights and prescriptive recommendations to improve risk awareness and reduce manual efforts.
Compliance
Access Governance helps you maintain governance and compliance by providing a centralized view of all identity and access data in addition to tools for managing access policies, conducting risk assessments, and auditing compliance. It provides out-of-the-box reports with graphical insights and audits for various compliance activities related to HIPAA, GDPR, SOX, and more. Access Governance provides instant auditability of access trends and entitlement risk so you can avoid costly and time-consuming manual access reviews.
Service functionality
What is Oracle Access Governance?
Oracle Access Governance is a cloud native identity governance and administration (IGA) solution that provides user provisioning, access reviews, and identity analytics to define and govern access privileges. It provides visibility into compliance and actionable artificial intelligence/machine learning–driven identity intelligence to reduce risks.
Please refer to the Oracle Access Governance web page for more details about the service.
What are some key features of Oracle Access Governance?
Oracle Access Governance provides the following key features and functionalities:
- Specialized identity orchestration for Oracle and non-Oracle workloads and generic integrations through REST and flat files
- Continuous discovery of users, groups, roles, applications, permissions, and policies
- Visibility into user access privileges for any resource across the organization
- Cross-cloud and cross-enterprise access correlation
- Access requests and role-based, attribute-based, and policy-based access control
- Ad hoc, periodic, and event-based access review campaigns to govern the access privileges assigned to users (including employees, contractors, and partners)
- Prescriptive analytics and recommendations, enabling access reviewers to efficiently review and limit user access
- An easy-to-comprehend view and simplified access reviews of access policies and group memberships
- Automated fulfillment of access decisions
How can I start using Access Governance?
To start using Access Governance, follow these steps:
- Create an Oracle Access Governance instance in Oracle Cloud.
- Set up identity orchestration to fetch identity and access data.
- Set up users and groups in OCI Identity and Access Management (OCI IAM) and assign them to application roles.
Which identity management systems can be integrated with Access Governance?
Access Governance provides out-of-the-box integrations with Oracle and non-Oracle workloads. We will continue to add more systems and services.
Please refer to the following product documentation for more details: Access Governance Integrations.
How does Access Governance connect with Oracle and non-Oracle workloads?
Access Governance connects with cloud applications and cloud service providers, such as Oracle Cloud Infrastructure, through cloud application programming interfaces (APIs).
Access Governance offers a containerized agent for other integrations. This agent is customized and configured to work with a specific instance of Access Governance over a secure channel. The agent’s purpose is to facilitate the secure transfer of data between Access Governance and the customer’s on-premises source of identity and access data.
Can Access Governance be used with Oracle Identity Governance in hybrid mode to perform identity governance and administration?
Yes, Access Governance can be seamlessly integrated with Oracle Identity Governance to perform hybrid identity governance and administration.
Can the Access Governance service be integrated with multiple Oracle Cloud Infrastructure (OCI) tenancies?
Yes, Access Governance can be integrated with multiple OCI tenancies, thus providing cross-cloud access correlation of identities' access privileges. We will eventually continue to add other cloud service providers, such as AWS, Azure, and Google Cloud Platform.
How can users who are synchronized in Access Governance access its service console?
Users who are synchronized in Access Governance should be onboarded in Oracle Cloud Infrastructure Identity and Access Management (OCI IAM) so they can access the Access Governance console. These users can be onboarded in OCI IAM using one of the following approaches:
- Configure Oracle Identity Governance provisioning with OCI IAM using the Oracle Identity Cloud Service connector.
- Set up federation with an external identity provider and enable Security Assertion Markup Language (SAML) just-in-time provisioning.
- Build a self-registration profile.
Please refer to the following product documentation and tutorials for more details:
- Set Up Users for Access Governance by Performing Provisioning Operations in Oracle Identity Governance Using the Identity Cloud Service Connector
- Set Up Identity Orchestration Between Oracle Access Governance and OCI IAM
How can I select a subset of identities in my enterprise to govern their access privileges in Oracle Access Governance?
If you want to govern access privileges assigned to a subset of identities belonging to a defined location, department, organization, or any other user attribute, you can mark those users as Active in Oracle Access Governance.
- Access review tasks will be generated for the identities marked as Active.
- Access control will be provided for the identities marked as Active.
Please refer to this documentation for more details: Activate/Inactivate Identities for License Management.
How do access reviews work in Oracle Access Governance?
Oracle Access Governance is used to execute intelligent access review campaigns with prescriptive analytics–based identity insights to help access reviewers make informed decisions quickly. It supports event-driven, periodic, and on-demand access review campaigns. The access reviewers can review user permissions, role memberships, identity collection memberships, and OCI policies in a single dashboard view, ensuring that users only have the access privileges they need to complete their tasks.
How do event-based access reviews work in Access Governance?
An event-based access review is triggered for a user when their attributes, such as organization, manager, location, employment status, and so on, get updated in Access Governance.
Access Governance also offers timeline-based microcertifications, which help facilitate timely access reviews based on important milestones.
Does Access Governance provide identity intelligence (analytics, artificial intelligence/machine learning–based insights, and so on)?
Access Governance provides AI/ML-driven insights, such as peer group analysis, outlier detection, and recommendations, enabling reviewers to take suggested actions to complete access review tasks.
How does Access Governance help maintain the identity security posture in Oracle Cloud Infrastructure (OCI)?
Access Governance helps an organization maintain the security posture for their OCI workloads by providing
- Visibility into who has access to what for any cloud resource
- An easy-to-comprehend view and simplified access reviews of OCI policies and OCI group memberships
- Identity orchestration and automated fulfillment based on OCI best practices
Can a user’s core and custom attributes be used in Access Governance?
Custom attributes of a user’s schema defined in Oracle Identity Governance can be used in Access Governance to
- View an identity profile
- Mark identities as Workforce users or Consumer users
- Define user selection criteria in access review campaigns
- Define event-based access reviews
Please refer to the following product documentation for more details: View and Configure Custom Identity Attributes.
Can an access reviewer reassign an access review task in Oracle Access Governance?
Yes, you can reassign an access review task to an individual by selecting the reassign option for the selected review task. You can also reassign access review tasks in bulk.
Are access review decisions recorded for auditing and compliance purposes?
Yes, for each decision made in an access review campaign, the following information is stored for auditing or compliance purposes:
- What is decided
- Who decided it
- Why (justification)
- When it was decided
What reporting and analytics functionality does the product provide?
Access Governance provides intelligent reporting for access reviews using graphs and charts that are easy to use and interpret. It also provides a detailed report of the access review campaign in CSV format.
Does Access Governance offer functionality to manage orphaned or unmatched accounts?
Access Governance detects unmatched accounts across all integrated applications and systems and notifies business owners about those that could be orphaned, rogue, or service accounts. Business owners can clean up these unmatched accounts manually or by assigning orphaned accounts to identities and reviewing these assigned accounts periodically. Event-based reviews can also be configured to review unmatched accounts when they are detected for an integrated application or system.
Does the solution provide access request functionality?
Access Governance provides an intuitive self-service user experience to request access privileges for oneself and others and to keep track of the access request’s progress.
What type of access control does Access Governance provide?
Access Governance provides access requests and role-based access control (RBAC), attribute-based access control (ABAC) and policy-based access control (PBAC).
Does Access Governance provide functionality to build custom workflows?
Access Governance provides functionality to build custom workflows for access approvals and access reviews. Multistage and parallel workflows can be defined effortlessly, without coding.
Does Access Governance offer integration with a disconnected resource or application?
Access Governance supports CSV (flat) file-based integration for a disconnected resource. It can be integrated as a source of identities and/or as a managed system.
Does Access Governance offer integration through REST endpoints?
Access Governance supports generic REST-based integration with sources of identities and/or downstream applications.
Does Access Governance provide rules to transform attributes?
Access Governance offers transformation rules to generate or construct identity attributes when identity data is reconciled from the source of identities. It also provides rules to transform account attributes during account reconciliation.
Does Access Governance provide rules to correlate identities and match accounts?
Access Governance provides matching rules to map identities reconciled from sources of identities and to match accounts reconciled from downstream applications with the identities.
Does Access Governance provide a web-based and mobile-friendly administration and self-service console?
Access Governance is a smart device–optimized, web-based console designed to perform seamlessly from any device—computer, tablet, or smartphone.
Which identity providers does Access Governance support for user login?
Access Governance supports Oracle Cloud Infrastructure Identity and Access Management as its identity provider for user login and authorization. To log in using an external identity provider, configure OCI IAM to use that external identity provider for federated authentication.
Please refer to the following product documentation for instructions on how to set up federation with an external identity provider: Manage Identity Providers.
Service management
How can I get Access Governance in Oracle Cloud?
Access Governance is available as part of Oracle Universal Credits. When you order Oracle Access Governance through Universal Credits, you automatically get access to Oracle Cloud Infrastructure and other required services. For details, please refer to the following product documentation: Before You Begin.
How do I create an Access Governance instance?
You create an Access Governance instance in the Oracle Cloud Infrastructure Console. For details, please refer to the following product documentation: Set Up Service Instance.
How do I manage an Access Governance instance?
You can manage an Access Governance instance in the Oracle Cloud Infrastructure Console. For details, please refer to the following product documentation: Manage Service Instance.
How can I launch an Access Governance instance once it's created?
It’s accessible from the Oracle Cloud Infrastructure Console. You can navigate to the Access Governance page, select the service instance you want to access, and then click the Access Governance URL.
How can I get support for Access Governance?
Go to My Oracle Support and create a service request.
Is there a charge for Oracle Support in addition to my subscription fee?
No. Support is included in the subscription fee.
How can I patch or upgrade my service?
Access Governance is a cloud native service. Oracle takes care of patching and upgrading the service.
Where can I get more information about the service level agreement?
Please refer to the SLA documentation (PDF).
Licensing and pricing
What are the various license types and SKUs available in Oracle Access Governance?
Oracle Access Governance offers three license types and five SKUs. These are
- Oracle Access Governance for Oracle Cloud Infrastructure
- Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User
- Oracle Access Governance for Oracle Workloads
- Oracle Access Governance for Oracle Workloads—Workforce User
- Oracle Access Governance for Oracle Workloads—Consumer User
- Oracle Access Governance Premium
- Oracle Access Governance Premium—Workforce User
- Oracle Access Governance Premium—Consumer User
For more details, please refer to the Oracle Access Governance pricing web page.
What are the various tiers within the SKUs for Oracle Access Governance?
Oracle Access Governance provides multiple tiers within the SKUs. These are
- Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User
- First 100,000 workforce users
- More than 100,000 workforce users
- Oracle Access Governance for Oracle Workloads—Workforce User
- First 10,000 workforce users
- More than 10,000 workforce users and up to 30,000 workforce users
- More than 30,000 workforce users
- Oracle Access Governance for Oracle Workloads—Consumer User
- No tiers
- Oracle Access Governance Premium—Workforce User
- First 10,000 workforce users
- More than 10,000 and up to 30,000 workforce users
- More than 30,000 workforce users
- Oracle Access Governance Premium—Consumer User
- No tiers
Which integrations are supported under each license type?
Oracle Access Governance provides a large set of integrations. The integrations supported by each of the SKUs are
- Oracle Access Governance for Oracle Cloud Infrastructure
- Supported integrations: Oracle Cloud Infrastructure
- Oracle Access Governance for Oracle Workloads
- Supported integrations: Oracle Cloud Infrastructure and Access Governance integrations with Oracle Cloud services and Oracle enterprise applications, such as Oracle E-Business Suite, Oracle AI Database, Oracle Unified Directory, and others.
- Oracle Access Governance Premium
- Supported integrations: All Access Governance integrations, including ServiceNow, Azure AD, and others.
What is the unit metric in an Oracle Access Governance license?
There are two unit metrics in Oracle Access Governance.
- Workforce user per month: for an identity that is configured to access the service either through a user interface or through programmatic configuration during the billing period, regardless of whether the identity is actively accessing the service at any given time
- Consumer user per month: for an identity that is not configured to access the service through either a user interface or through a programmatic configuration during the billing period, but whose accesses are managed in the Access Governance console by workforce users
Please refer to the following documentation for more details: Oracle PaaS and IaaS Universal Credits Service Descriptions (PDF).
How can I select a subset of identities in my enterprise to be governed in Oracle Access Governance?
If you want to govern access privileges assigned to a subset of identities belonging to a defined location, department, organization, or any other user attribute, you can mark those users as Active in Oracle Access Governance.
You can further flag these Active identities as Workforce or Consumer users.
What does it mean to have “Workforce” or “Consumer” identities in Access Governance?
Active identities in Access Governance can be workforce users or consumer users.
- Workforce users can log in to the Access Governance console. They can contribute to the identity and governance administration program by performing administrative roles in Access Governance and by requesting and reviewing access privileges assigned to themselves or others.
- Consumer users cannot log in to the Access Governance console. They are provisioned with a fixed set of privileges that typically don’t change over time. They can’t request and review access privileges assigned to themselves or others.
For more details about the capabilities of workforce and consumer users, please refer to the following documentation: Manage Identities.
Please provide some examples that demonstrate who should be marked as “Workforce” users and who should be marked as “Consumer” users.
These are some examples illustrating who should be marked as Workforce and Consumer users in Access Governance; they are for illustration purposes only.
| Industry/ sector | Workforce identities | Consumer identities |
|---|---|---|
| Banking and insurance | Employees and contractors: bank accountants and managers, tellers, financial advisors, administrative staff, outsourced IT staff | Customers: bank account owners, bank loan holders, insurance policy holders Contractors: cafeteria, electric, janitorial Partners and vendors: suppliers selling insurance or similar ancillary services |
| Healthcare | Employees and contractors: doctors, clinicians, medical staff, administrative staff | Consumers: patients, beneficiaries Contractors: cafeteria, janitorial Partners and vendors: companies providing canes, bandages, medications, and so on |
| Education | Employees and contractors: faculty, support staff, administrative staff | Consumers: students, alums, parents, guardians Contractors: cafeteria, janitorial Partners and vendors: companies providing textbooks, transportation service providers, and so on |
Will I be charged for all identities synchronized in Access Governance?
Only the identities marked as Active (workforce users or consumer users) in Access Governance will be considered for billing, starting from the hour in which those identities are marked as Active. Even though the metric for Access Governance SKUs is per month, Oracle is passing benefits on to the customer by calculating the number of active identities on an hourly basis and generating the bill for the entire month.
Please refer to the following documentation for more details: Manage Identities.
How can I mark identities as ”Active” and as ”Workforce” and ”Consumer” users in Access Governance?
Access Governance provides identity filtering or marking functionality based on which identities can be marked as Active or Workforce/Consumer users. An administrator may use identity attributes to define such rules.
Please refer to the following documentation for more details: Manage Identities.
I want to review the access privileges of disabled identities. How can I do so in Access Governance?
A disabled identity can be marked as an Active workforce user or consumer user in Access Governance so you can review its access privileges.
Will I be charged for disabled identities?
For billing, Access Governance will include only those disabled identities marked as Active.
How can I stop billing and keep the Access Governance instance?
If you don’t mark any identity as Active, there will be no bill for Access Governance.
Can the licensing model of my Access Governance service instance be upgraded if the current license type is Oracle Access Governance for Oracle Workloads?
Yes, the license type of the Oracle Access Governance service instance can be upgraded from Oracle Access Governance for Oracle Workloads to Oracle Access Governance Premium without any service disruption. You can do it manually from the Access Governance page in the Oracle Cloud Infrastructure Console.
Can the licensing model of my Access Governance service instance be upgraded if the current license type is Oracle Access Governance for Oracle Cloud Infrastructure?
Yes, the Access Governance license type can be upgraded without any service disruption. You can upgrade the license type from Oracle Access Governance for Oracle Cloud Infrastructure to Oracle Access Governance for Oracle Workloads or Oracle Access Governance Premium.
Can the licensing model of my Access Governance service instance be downgraded if the current license type is Oracle Access Governance for Oracle Workloads or Oracle Access Governance Premium?
No, these Access Governance license types can’t be downgraded.
If I upgrade from Oracle Access Governance for Oracle Cloud Infrastructure to Oracle Access Governance for Oracle Workloads, how does the metering work for the month when the conversion takes place?
Access Governance is metered hourly. Before the service instance is upgraded, you will be billed for Oracle Access Governance for Oracle Cloud Infrastructure on an hourly basis. After the license upgrade, you will be billed for Oracle Access Governance for Oracle Workloads. In effect, you would see billing for both line items throughout the month, but you will only be charged for the number of hours each license type was active.
I have 22,000 users in Oracle Identity Governance/Oracle Identity Management integrated with Access Governance. I want to set 10,000 users who belong to a specific organization, say Employee, as Workforce users. I also want to set another 8,000 users who belong to another organization, say Contractor, as Consumer users. The license type of my instance is Oracle Access Governance for Oracle Workloads. How can I do so and for how many users will I be billed?
By default, all 22,000 users synchronized from Oracle Identity Management in Access Governance will not be marked as Active. You may mark 18,000 users as Active based on their organization (Employee and Contractor). Then you can mark 8,000 users from the External organization as Consumer users.
You will be billed according to the
- Oracle Access Governance for Oracle Workloads—Workforce User SKU for 10,000 users
- Oracle Access Governance for Oracle Workloads—Consumer User SKU for the other 8,000 users
I have two Identity Access Management domains in my Oracle Cloud Infrastructure tenancy with 1,000 users in each domain, and each OCI user is distinct. For how many users will I be billed?
If you want to review the access privileges of all users in this OCI tenancy, then you may mark all users as Active in Access Governance. You will be billed for 2,000 (2 × 1,000) users in this case.
If you want to review the access privileges of users belonging to only one of the two domains, then you may define a rule to mark only users of that domain as Active in Access Governance. You will be billed for 1,000 (1 × 1,000) users in this case.
How does the billing amount change based on the number of workforce and consumer users during a billing cycle?
You will be metered on an hourly basis and billed monthly for active workforce users and consumer users. The bill amount is calculated based on the metered usage and your rate card. So, if the number of active workforce or active consumer users changes during the billing cycle, your bill is prorated accordingly.
How can I estimate the cost of the service usage?
Please use the cost estimator to estimate the cost of service usage by following these steps:
- Go to www.oracle.com/cloud/costestimator.html.
- Select the “Select Category” drop-down menu.
- Select “Security.”
- Select “Access Governance.”
Access Governance Quick Start Guide
