{
  "test_id": "ORCL.SEC.ACCESS.TERMINATION",
  "scenario_name": "Access After Termination",
  "application": "Oracle Fusion Cloud",
  "product": "Security",
  "module": "Security",
  "process": "Access After Termination",
  "business_flow": "Terminate-to-Revoke",
  "scenario_type": "Positive / Negative / Security / Integration",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/security/access-after-termination/",
  "objective": {
    "intro": "This test validates that application login, self-service, manager, payroll, HR admin, procurement, financials, SCM, recruiting and sensitive-data access are correctly removed following worker termination, and that delegated approvals, scheduled jobs, active sessions and rehire access are correctly handled, using masked/synthetic test data and without assuming a universal termination workflow.",
    "confirms": [
      "application login is correctly blocked for a terminated ${WORKER}'s ${USER} account as of ${TERMINATION_DATE}, and not before an effective future-dated termination",
      "employee self-service and manager self-service access are correctly removed for the terminated ${USER}, along with any role tied directly to the worker's employment",
      "payroll, HR admin, procurement, financials, SCM, recruiting and sensitive-data access previously granted by ${ROLE} are correctly removed once employment ends",
      "delegated approvals pending with the terminated ${USER} are correctly reassigned to ${DELEGATE_APPROVER}, and scheduled jobs owned by ${USER} are correctly reviewed, where the customer's workflow configuration requires it",
      "an active session for a user terminated mid-session, and a future-dated termination, are correctly handled according to the customer's configured session and effective-dating rules",
      "rehiring ${WORKER} via ${REHIRE_DATE} correctly restores only the access defined by the new assignment, without retaining unintended prior access",
      "historical HR records for a terminated worker remain visible to an authorized HR user, while the terminated worker cannot access another worker's data",
      "role-removal actions taken during termination are correctly captured as audit evidence",
      "post-termination access-removal behavior reflects the customer's own configured security and termination workflow rather than a universal Oracle behavior"
    ],
    "scope_note": "A negative or security Access After Termination scenario passes when Oracle correctly enforces the expected access-removal rule; this test does not attempt to certify a specific Oracle application defect. This page catalogs 20 individual Access After Termination scenarios as a single comprehensive reference rather than as separate indexable pages. All worker, user, role and date values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real access grants."
  },
  "preconditions": [
    "Oracle Fusion Security Console and HR administration access is available to a test user with role administration and worker-termination privileges.",
    "A representative ${WORKER} with an active ${USER} account and assigned ${ROLE} is available or can be constructed in the target Oracle Fusion environment.",
    "A ${TERMINATION_DATE} and, where applicable, a future-dated termination and a ${REHIRE_DATE} can be applied to the test worker record.",
    "A ${DELEGATE_APPROVER} is available to receive reassigned approvals where the customer's workflow configuration requires reassignment.",
    "Payroll, procurement, financials, SCM, HR admin, recruiting and sensitive-data modules relevant to the test worker's prior ${ROLE} are documented for the environment under test.",
    "A second worker record and an authorized HR user are available to test cross-worker access denial and historical-record visibility."
  ],
  "test_data": [
    {
      "field": "Worker",
      "example": "${WORKER}"
    },
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Role",
      "example": "${ROLE}"
    },
    {
      "field": "Termination Date",
      "example": "${TERMINATION_DATE}"
    },
    {
      "field": "Rehire Date",
      "example": "${REHIRE_DATE}"
    },
    {
      "field": "Delegate Approver",
      "example": "${DELEGATE_APPROVER}"
    },
    {
      "field": "Manager Hierarchy",
      "example": "${MANAGER_HIERARCHY}"
    },
    {
      "field": "Module",
      "example": "${MODULE}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as Security Administrator",
      "action": "Sign in to Oracle Fusion Cloud with a user account that has Security Console and HR administration access.",
      "test_data": "",
      "expected_result": "The Oracle Fusion Cloud home page loads successfully for the authenticated security administrator.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Establish Baseline Access for Active Worker",
      "action": "Confirm ${WORKER}'s ${USER} account is active with ${ROLE} assigned, and that the assigned role grants the module, self-service and functional access expected prior to termination.",
      "test_data": "${WORKER} / ${USER} / ${ROLE}",
      "expected_result": "The baseline active-worker access is confirmed and granted correctly prior to termination.",
      "validation_type": "action"
    },
    {
      "step_number": 3,
      "step_name": "Process Worker Termination Event",
      "action": "Process a termination event for ${WORKER} effective ${TERMINATION_DATE}, including a future-dated termination scenario where applicable.",
      "test_data": "${WORKER} / ${TERMINATION_DATE}",
      "expected_result": "The termination event is recorded successfully against the worker record.",
      "validation_type": "action"
    },
    {
      "step_number": 4,
      "step_name": "Verify Application Login and Self-Service Access Blocked",
      "action": "As ${USER}, attempt to sign in to Oracle Fusion Cloud and access employee self-service and manager self-service functions on or after ${TERMINATION_DATE}.",
      "test_data": "${USER} / ${TERMINATION_DATE}",
      "expected_result": "Application login and self-service access are correctly blocked for the terminated worker as of the termination date, and remain available before a future-dated termination takes effect.",
      "validation_type": "business_assertion",
      "note": "Correctly blocking login and self-service access exactly as of the termination date is the core business assertion across this catalog."
    },
    {
      "step_number": 5,
      "step_name": "Verify Module and Functional Access Removed",
      "action": "Confirm that payroll, HR admin, procurement, financials, SCM, recruiting and sensitive-data access previously granted to ${USER} by ${ROLE} is removed.",
      "test_data": "${ROLE} / ${MODULE}",
      "expected_result": "Module and functional-area access tied to the terminated worker's employment is correctly removed.",
      "validation_type": "business_assertion",
      "note": "This is the main access-removal assertion tested across the catalog's module-specific scenarios."
    },
    {
      "step_number": 6,
      "step_name": "Verify Delegated Approvals and Scheduled Jobs Reassigned",
      "action": "Confirm that approvals pending with ${USER} are reassigned to ${DELEGATE_APPROVER} and that scheduled jobs owned by ${USER} are reviewed, where the customer's workflow configuration requires it.",
      "test_data": "${USER} / ${DELEGATE_APPROVER}",
      "expected_result": "Delegated approvals and owned scheduled jobs are correctly reassigned or reviewed according to the customer's configured workflow.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 7,
      "step_name": "Verify Active Session, Historical Records and Cross-Worker Access",
      "action": "Confirm the behavior of an active session for ${USER} terminated mid-session, that historical HR records for ${WORKER} remain visible to an authorized HR user, and that the terminated worker cannot access another worker's data.",
      "test_data": "${WORKER} / ${USER}",
      "expected_result": "Active sessions are handled according to the customer's configured session policy, historical records remain available to authorized HR, and the terminated worker is correctly blocked from another worker's data.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 8,
      "step_name": "Verify Rehire Restores Required Access Only",
      "action": "Rehire ${WORKER} effective ${REHIRE_DATE} with a new ${ROLE} assignment and confirm the resulting access.",
      "test_data": "${WORKER} / ${REHIRE_DATE} / ${ROLE}",
      "expected_result": "Rehire correctly restores only the access required by the new assignment, without retaining unintended prior access.",
      "validation_type": "business_assertion",
      "note": "Access regression after rehire is the final business assertion validating full-cycle termination and rehire behavior in this catalog."
    }
  ],
  "expected_results": [
    "Application login and self-service access are correctly blocked for a terminated worker as of the termination date.",
    "Payroll, HR admin, procurement, financials, SCM, recruiting and sensitive-data access tied to employment are correctly removed.",
    "Delegated approvals and scheduled jobs owned by the terminated user are correctly reassigned or reviewed.",
    "Active sessions and future-dated terminations are correctly handled according to configured policy.",
    "Historical HR records remain visible to authorized HR, and a terminated worker cannot access another worker's data.",
    "Rehire correctly restores only the access required by the new assignment, without unintended residual access."
  ],
  "validation_checkpoints": [
    "Application login and self-service access correctly blocked as of the termination date.",
    "Payroll, HR admin, procurement, financials, SCM, recruiting and sensitive-data access correctly removed.",
    "Delegated approvals and scheduled jobs correctly reassigned or reviewed where configured.",
    "Active-session and future-dated termination behavior correctly enforced.",
    "Historical records remain visible to authorized HR; cross-worker access correctly blocked.",
    "Rehire correctly restores only required access without residual prior access."
  ]
}
