{
  "test_id": "ORCL.SEC.PRIVILEGE",
  "scenario_name": "Privilege Validation",
  "application": "Oracle Fusion Cloud",
  "product": "Security",
  "module": "Security",
  "process": "Privilege Validation",
  "business_flow": "Privilege Grant-to-Enforcement",
  "scenario_type": "Positive / Negative / Security / Integration",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/security/privilege-validation/",
  "objective": {
    "intro": "This test validates that create, approve, pay, process and view privileges across Financials, Supply Chain Management and Human Capital Management business functions are correctly granted to users holding the required privilege and correctly denied to users who do not, using masked/synthetic test data and without assuming a universal privilege or business-function model.",
    "confirms": [
      "each privilege correctly gates the specific create, approve, pay, process or view action it is intended to control, across Accounts Payable, Procurement, Order Management, General Ledger, Payroll and Recruiting business functions",
      "a user holding the correct role and privilege can successfully perform the privileged action within their granted business-function scope",
      "a user who does not hold the required privilege is correctly blocked from performing the privileged action, including via direct navigation or a deep link to the restricted page",
      "read access does not imply update access, and update access does not imply approval access — each privilege boundary is independently enforced",
      "removing or changing a privilege takes effect immediately, without residual access remaining after the change or after a role change",
      "privilege behavior reflects the customer's own configured business-function and privilege model rather than assuming a universal Oracle privilege structure"
    ],
    "scope_note": "A negative or security Privilege Validation scenario passes when Oracle correctly enforces the expected privilege boundary; this test does not attempt to certify a specific Oracle application defect. This page catalogs 25 individual Privilege Validation scenarios spanning Financials, Supply Chain Management and Human Capital Management as a single comprehensive reference rather than as separate indexable pages. All user, role, privilege and transactional values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real access grants."
  },
  "preconditions": [
    "Oracle Fusion Security Console access is available to a test user with role and privilege administration rights.",
    "Representative ${ROLE} definitions carrying the ${PRIVILEGE} values under test are available or can be constructed in the target Oracle Fusion environment.",
    "Test ${USER} accounts are available both with and without each ${PRIVILEGE} under test, for positive and negative comparison.",
    "Masked/synthetic transactional data — invoices, requisitions, purchase orders, journals, suppliers, sales orders and worker records — is available through DataVault so no real transactions are used in testing.",
    "${BUSINESS_UNIT}, legal employer and business-function configuration is documented for the privileges under test.",
    "Approval limits or thresholds relevant to approve/pay privileges are documented where the customer's configuration enforces them.",
    "A user without the relevant privilege, and a deep link to the restricted page or action, are available for unauthorized-access and deep-link security testing."
  ],
  "test_data": [
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Role",
      "example": "${ROLE}"
    },
    {
      "field": "Privilege",
      "example": "${PRIVILEGE}"
    },
    {
      "field": "Business Function",
      "example": "${BUSINESS_FUNCTION}"
    },
    {
      "field": "Invoice ID",
      "example": "${INVOICE_ID}"
    },
    {
      "field": "Purchase Order Number",
      "example": "${PO_NUMBER}"
    },
    {
      "field": "Requisition ID",
      "example": "${REQUISITION_ID}"
    },
    {
      "field": "Supplier",
      "example": "${SUPPLIER}"
    },
    {
      "field": "Employee ID",
      "example": "${EMPLOYEE_ID}"
    },
    {
      "field": "Business Unit",
      "example": "${BUSINESS_UNIT}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as the Test User Persona",
      "action": "Sign in to Oracle Fusion Cloud as ${USER}, holding the ${ROLE} configured for this scenario.",
      "test_data": "${USER} / ${ROLE}",
      "expected_result": "The user signs in successfully and lands in the work area appropriate to their role.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Confirm Privilege Is Assigned via Role",
      "action": "Confirm via the Security Console that ${ROLE} carries the ${PRIVILEGE} under test for the assigned ${BUSINESS_FUNCTION}.",
      "test_data": "${ROLE} / ${PRIVILEGE}",
      "expected_result": "The privilege is confirmed present on the assigned role, or its absence is confirmed for a negative scenario.",
      "validation_type": "action"
    },
    {
      "step_number": 3,
      "step_name": "Attempt the Privileged Action",
      "action": "As ${USER}, attempt the business action gated by ${PRIVILEGE} — for example create, approve, pay, process or view — within ${BUSINESS_FUNCTION}.",
      "test_data": "${PRIVILEGE} / ${BUSINESS_FUNCTION}",
      "expected_result": "The action attempt completes and returns either a successful business outcome or an access-denied response.",
      "validation_type": "action"
    },
    {
      "step_number": 4,
      "step_name": "Verify Privileged Action Succeeds When Authorized",
      "action": "Confirm that ${USER} holding ${PRIVILEGE} successfully completes the intended action and the resulting record (invoice, requisition, PO, journal, supplier, sales order or worker record) is created or updated as expected.",
      "test_data": "",
      "expected_result": "The privileged action succeeds and the resulting business object reflects the expected outcome.",
      "validation_type": "business_assertion",
      "note": "This is the core positive business assertion tested across the authorized-privilege scenarios in this catalog."
    },
    {
      "step_number": 5,
      "step_name": "Remove or Withhold Privilege from User",
      "action": "Remove ${PRIVILEGE} from ${ROLE}, or use a comparison ${USER} who never held ${PRIVILEGE}.",
      "test_data": "${USER} / ${ROLE} / ${PRIVILEGE}",
      "expected_result": "The privilege removal, or the absence of the privilege for the comparison user, is applied and confirmed.",
      "validation_type": "action"
    },
    {
      "step_number": 6,
      "step_name": "Attempt the Same Action Without the Privilege",
      "action": "As the same or comparison ${USER}, attempt the identical action from Step 3, including by direct navigation or deep link where applicable.",
      "test_data": "${PRIVILEGE} / ${BUSINESS_FUNCTION}",
      "expected_result": "The unauthorized action attempt is submitted for evaluation.",
      "validation_type": "action"
    },
    {
      "step_number": 7,
      "step_name": "Verify Unauthorized Action Is Correctly Blocked",
      "action": "Confirm that the action attempted without ${PRIVILEGE} is denied and that no unauthorized create, approve, pay or process outcome occurs.",
      "test_data": "",
      "expected_result": "The unauthorized action is correctly blocked, including when attempted via a restricted deep link.",
      "validation_type": "business_assertion",
      "note": "This is the main negative/security business assertion for the unauthorized-access and deep-link scenarios in this catalog."
    },
    {
      "step_number": 8,
      "step_name": "Verify Privilege Change Takes Effect Without Residual Access",
      "action": "Confirm that a privilege removal, role change or role-replacement scenario leaves no residual access from the prior privilege configuration.",
      "test_data": "${ROLE} / ${PRIVILEGE}",
      "expected_result": "Privilege changes take effect immediately and completely, with no residual access remaining from the prior configuration.",
      "validation_type": "business_assertion"
    }
  ],
  "expected_results": [
    "Each privilege correctly gates the specific create, approve, pay, process or view action across Financials, SCM and HCM business functions.",
    "Authorized users successfully complete the privileged action within their granted role and business-function scope.",
    "Unauthorized users, including deep-link attempts, are correctly blocked from the privileged action.",
    "Read, update and approval permission boundaries are independently and correctly enforced.",
    "Privilege removal or change takes effect immediately with no residual access.",
    "Privilege behavior reflects the customer's own configured business-function model rather than a universal Oracle privilege structure."
  ],
  "validation_checkpoints": [
    "Privilege correctly gates only the intended create/approve/pay/process/view action.",
    "Authorized users complete the privileged action successfully within scope.",
    "Unauthorized action attempts, including deep-link attempts, correctly blocked.",
    "Read/update/approval permission boundaries independently enforced.",
    "Privilege removal or change takes effect immediately, no residual access.",
    "Privilege regression after role change never grants unintended excess access."
  ]
}
