{
  "test_id": "ORCL.SEC.USER.ACCESS",
  "scenario_name": "User Access",
  "application": "Oracle Fusion Cloud",
  "product": "Security",
  "module": "Security",
  "process": "User Access",
  "business_flow": "Provision-to-Access",
  "scenario_type": "Positive / Negative / Security",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/security/user-access/",
  "objective": {
    "intro": "This test validates sign-in, module, Business Unit, legal employer, inventory organization and worker record access, and access changes following provisioning, deprovisioning, role update and organizational events, using masked/synthetic test data and without assuming a universal access model.",
    "confirms": [
      "an authorized, active ${USER} with an assigned ${ROLE} can sign in to Oracle Fusion Cloud and reach the modules, organizations and worker records the customer's security configuration grants",
      "an inactive user, a user without an application role, or a user outside the intended ${BUSINESS_UNIT}, ${LEGAL_EMPLOYER} or ${INVENTORY_ORG} is correctly denied access to the corresponding module, organization or data",
      "worker-record visibility correctly follows manager hierarchy and workforce population scoping — a worker can view their own record and a manager can view direct reports, while unrelated workers and non-reporting workers are correctly blocked",
      "functional-area access (AP invoices, purchasing, compensation, restricted payroll areas) correctly reflects the assigned role rather than a universal permission set",
      "access correctly changes after approved provisioning, deprovisioning, role update, organization reassignment or manager change, rather than remaining tied to a user's prior state",
      "read-only users and users without a specific action privilege are correctly blocked from update actions and restricted actions, and deep-link navigation cannot bypass the configured access model",
      "access behavior reflects the customer's own configured security model rather than assuming a universal Oracle role or permission structure"
    ],
    "scope_note": "A negative or security User Access scenario passes when Oracle correctly enforces the expected access-control rule; this test does not attempt to certify a specific Oracle application defect. This page catalogs 30 individual User Access scenarios as a single comprehensive reference rather than as separate indexable pages. All user, role and organization values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real access grants."
  },
  "preconditions": [
    "Oracle Fusion Security Console access is available to a test user with user and role administration privileges.",
    "Representative ${ROLE} definitions with and without the functional permission under test are available or can be constructed in the target Oracle Fusion environment.",
    "Test users are available to represent ${USER} personas that are active, inactive, and with and without an assigned application role.",
    "A valid ${BUSINESS_UNIT}, ${LEGAL_EMPLOYER} and ${INVENTORY_ORG} are configured in the target Oracle Fusion environment.",
    "${WORKFORCE_POPULATION} and ${MANAGER_HIERARCHY} scoping options are documented where used by the customer's security configuration.",
    "A user without the relevant role, Business Unit, legal employer, inventory organization or functional permission is available for unauthorized-access security testing."
  ],
  "test_data": [
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Role",
      "example": "${ROLE}"
    },
    {
      "field": "Business Unit",
      "example": "${BUSINESS_UNIT}"
    },
    {
      "field": "Legal Employer",
      "example": "${LEGAL_EMPLOYER}"
    },
    {
      "field": "Inventory Organization",
      "example": "${INVENTORY_ORG}"
    },
    {
      "field": "Workforce Population",
      "example": "${WORKFORCE_POPULATION}"
    },
    {
      "field": "Manager Hierarchy",
      "example": "${MANAGER_HIERARCHY}"
    },
    {
      "field": "Module",
      "example": "${MODULE}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as Security Administrator",
      "action": "Sign in to Oracle Fusion Cloud with a user account that has Security Console access.",
      "test_data": "",
      "expected_result": "The Oracle Fusion Cloud home page loads successfully for the authenticated security administrator.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Provision Test User with Role",
      "action": "Provision ${USER} with ${ROLE} and confirm the user account is active via the Security Console.",
      "test_data": "${USER} / ${ROLE}",
      "expected_result": "The user account and role assignment are created successfully and the user shows as active.",
      "validation_type": "action"
    },
    {
      "step_number": 3,
      "step_name": "Sign In as Test User",
      "action": "Sign in to Oracle Fusion Cloud as ${USER}.",
      "test_data": "${USER}",
      "expected_result": "An active, authorized ${USER} signs in successfully; an inactive user or a user without ${ROLE} is correctly denied sign-in or landing access.",
      "validation_type": "business_assertion",
      "note": "Correctly gating sign-in on active status and role assignment is a core business assertion across the authentication scenarios in this catalog."
    },
    {
      "step_number": 4,
      "step_name": "Navigate to Assigned Module and Organization Scope",
      "action": "As ${USER}, navigate to ${MODULE} and attempt to access data scoped to ${BUSINESS_UNIT}, ${LEGAL_EMPLOYER} and ${INVENTORY_ORG}.",
      "test_data": "${MODULE} / ${BUSINESS_UNIT} / ${LEGAL_EMPLOYER} / ${INVENTORY_ORG}",
      "expected_result": "${USER} reaches the assigned module and organization scope successfully, and is correctly blocked from unauthorized modules or organizations.",
      "validation_type": "business_assertion",
      "note": "This is the main module and organization-scoping assertion tested across the catalog's positive and negative scenarios."
    },
    {
      "step_number": 5,
      "step_name": "Verify Worker Record and Functional-Area Access",
      "action": "As ${USER}, attempt to view a worker record within ${WORKFORCE_POPULATION} and perform a functional action gated by the assigned ${ROLE}.",
      "test_data": "${WORKFORCE_POPULATION}",
      "expected_result": "${USER} can view worker records and perform actions within the granted scope, and is correctly blocked outside that scope.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 6,
      "step_name": "Verify Unauthorized Access Is Blocked",
      "action": "As a user without ${ROLE} or the required functional permission, attempt the same module, organization or worker-record access, including a direct deep-link URL to the restricted page.",
      "test_data": "${MODULE}",
      "expected_result": "The unauthorized access attempt, including deep-link navigation, is correctly blocked.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 7,
      "step_name": "Apply Provisioning or Organizational Change",
      "action": "Apply a provisioning, deprovisioning, role update, organization reassignment or manager change affecting ${USER} or a worker within ${USER}'s population.",
      "test_data": "${USER} / ${MANAGER_HIERARCHY}",
      "expected_result": "The provisioning or organizational change is applied successfully.",
      "validation_type": "action"
    },
    {
      "step_number": 8,
      "step_name": "Verify Access Re-Scopes Correctly",
      "action": "Confirm that ${USER}'s access correctly reflects the provisioning or organizational change applied in the previous step.",
      "test_data": "${WORKFORCE_POPULATION}",
      "expected_result": "Access correctly re-scopes to reflect the change, according to the customer's configured security rules.",
      "validation_type": "business_assertion",
      "note": "Access regression after provisioning or organizational change is the main business assertion for the propagation scenarios in this catalog."
    }
  ],
  "expected_results": [
    "Authorized, active users can sign in and reach the assigned module, Business Unit, legal employer and inventory organization scope.",
    "Inactive users, users without an application role, and users outside the assigned organization scope are correctly denied access.",
    "Worker-record visibility correctly follows manager hierarchy and workforce population scoping.",
    "Functional-area access (AP invoices, purchasing, compensation, restricted payroll areas) correctly reflects the assigned role.",
    "Access correctly changes after approved provisioning, deprovisioning, role update, organization reassignment or manager change.",
    "Read-only users, unauthorized actions and deep-link navigation attempts are correctly blocked."
  ],
  "validation_checkpoints": [
    "Sign-in correctly gated on active status and application role assignment.",
    "Module, Business Unit, legal employer and inventory organization access correctly scoped.",
    "Worker record visibility correctly follows population and manager-hierarchy scoping.",
    "Functional-area access correctly reflects assigned role and cross-module combinations.",
    "Access correctly updates after provisioning, deprovisioning, role update or organizational change.",
    "Unauthorized actions and deep-link navigation correctly blocked."
  ]
}
