Documentation
Security

Security Guide

Two layers govern access. Captain EPM account roles decide who can administer your organisation's seats; what the add-in can do inside Oracle EPM is decided entirely by the signed-in user's Oracle role — the add-in can never do more than that user already can.

User Roles

Captain EPM accounts carry one of three roles, assigned per user in the admin portal; users cannot self-escalate. A vendor-side super admin exists only for Captain EPM staff. For what each Oracle EPM role unlocks on the ribbon, see the Oracle role guide.

Admin

Full control over your organisation’s Captain EPM account — invite users, assign seats, manage groups and see everyone’s licence status.

  • Invite and manage users
  • Assign and reclaim seats
  • Manage groups
  • View the whole tenant
User

A licensed seat. Signs in to the add-in and uses every ribbon tool the signed-in Oracle EPM account is allowed to.

  • Sign in to EPM Commander
  • Use the full ribbon
  • Manage own saved connections
  • View own activity
Viewer

Read-only in the Captain EPM portal. Cannot invite users or change seats.

  • View the tenant
  • View own profile

Permissions Matrix

FeatureAdminUserViewer
Sign in to the add-in (needs a seat)
Use ribbon tools, within the Oracle EPM role
Invite and manage users
Assign and reclaim seats
Manage groups
View the tenant in the portal

Security Drift & Snapshots

The Security Agent and the Security Report together show who gained or lost access to your Oracle EPM environment, and why — essential for SOX, GDPR and internal audits.

Keep the snapshot current

Run Sync Metadata so the local snapshot holds the application’s current security model — dimension security, member ACLs and role assignments.

Open the Security Agent

System & Security > Security Agent reads the security model from the snapshot and explains what changed in permissions over time, and whether it matters.

See who changed what

The Security Report’s Security Changes tab lists who changed which permission and when, read from the audit export. Object Access and Effective Access show the resulting state.

Export for compliance

Every Security Report tab exports to Excel for SOX, GDPR or internal audit evidence.

Security Best Practices
  • Re-run Sync Metadata after every provisioning event so the snapshot reflects it.
  • Review the Security Agent and the Security Changes tab weekly during active project phases.
  • Assign the minimum required role — avoid granting Tenant Admin unnecessarily.
  • Export audit logs monthly and store them in a secure archive.