Security Guide
Two layers govern access. Captain EPM account roles decide who can administer your organisation's seats; what the add-in can do inside Oracle EPM is decided entirely by the signed-in user's Oracle role — the add-in can never do more than that user already can.
User Roles
Captain EPM accounts carry one of three roles, assigned per user in the admin portal; users cannot self-escalate. A vendor-side super admin exists only for Captain EPM staff. For what each Oracle EPM role unlocks on the ribbon, see the Oracle role guide.
Full control over your organisation’s Captain EPM account — invite users, assign seats, manage groups and see everyone’s licence status.
- Invite and manage users
- Assign and reclaim seats
- Manage groups
- View the whole tenant
A licensed seat. Signs in to the add-in and uses every ribbon tool the signed-in Oracle EPM account is allowed to.
- Sign in to EPM Commander
- Use the full ribbon
- Manage own saved connections
- View own activity
Read-only in the Captain EPM portal. Cannot invite users or change seats.
- View the tenant
- View own profile
Permissions Matrix
| Feature | Admin | User | Viewer |
|---|---|---|---|
| Sign in to the add-in (needs a seat) | ✅ | ✅ | ❌ |
| Use ribbon tools, within the Oracle EPM role | ✅ | ✅ | ❌ |
| Invite and manage users | ✅ | ❌ | ❌ |
| Assign and reclaim seats | ✅ | ❌ | ❌ |
| Manage groups | ✅ | ❌ | ❌ |
| View the tenant in the portal | ✅ | ✅ | ✅ |
Security Drift & Snapshots
The Security Agent and the Security Report together show who gained or lost access to your Oracle EPM environment, and why — essential for SOX, GDPR and internal audits.
Keep the snapshot current
Run Sync Metadata so the local snapshot holds the application’s current security model — dimension security, member ACLs and role assignments.
Open the Security Agent
System & Security > Security Agent reads the security model from the snapshot and explains what changed in permissions over time, and whether it matters.
See who changed what
The Security Report’s Security Changes tab lists who changed which permission and when, read from the audit export. Object Access and Effective Access show the resulting state.
Export for compliance
Every Security Report tab exports to Excel for SOX, GDPR or internal audit evidence.
- Re-run Sync Metadata after every provisioning event so the snapshot reflects it.
- Review the Security Agent and the Security Changes tab weekly during active project phases.
- Assign the minimum required role — avoid granting Tenant Admin unnecessarily.
- Export audit logs monthly and store them in a secure archive.