{
  "test_id": "ORCL.SEC.SOD",
  "scenario_name": "Segregation of Duties",
  "application": "Oracle Fusion Cloud",
  "product": "Security",
  "module": "Security",
  "process": "Segregation of Duties",
  "business_flow": "Ruleset-Design-to-Conflict-Mitigation",
  "scenario_type": "Positive / Negative / Security",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/security/segregation-of-duties/",
  "objective": {
    "intro": "This test validates conflicting-duty combinations — for example Create Supplier plus Pay Supplier, or Create AP Invoice plus Approve Invoice — against Oracle Fusion Cloud's security configuration, confirms mitigating controls behave as designed where the customer uses them, and confirms conflict status correctly re-evaluates after a role change, using masked/synthetic test data. Potential conflict patterns depend on customer control design and SoD policy — this catalog treats no duty combination as a fixed, one-size-fits-all restriction imposed by Oracle or by a generic industry standard.",
    "confirms": [
      "a user holding a conflicting-duty combination that the customer's SoD ruleset defines as a conflict is correctly flagged, blocked, or routed to a mitigating control, according to that customer's own configuration",
      "a user holding a combination the customer's SoD ruleset does not define as a conflict is correctly permitted to perform both duties, without an assumed universal restriction being applied",
      "where a mitigating control is configured for an approved conflict, the control's evidence (for example a compensating review or secondary approval) is correctly required and recorded rather than silently bypassed",
      "conflict status correctly changes when a new role is granted, when a conflicting role is removed, or when a user is transferred between organizations, business units or positions",
      "a user cannot approve, post or self-authorize their own transaction where the customer's configuration requires an independent approver",
      "Segregation of Duties behavior remains consistent after an Oracle quarterly update, and that any apparent new or removed conflict is correctly attributable to the update rather than an unrelated data or configuration change",
      "an apparent conflict flagged by automated analysis can be reviewed and, where the customer's own analysis determines it is not an actual conflict for their process, correctly treated as a false positive rather than an application defect",
      "SoD evaluation reflects the customer's own configured ruleset, role design and duty definitions rather than a universal Oracle-enforced conflict matrix"
    ],
    "scope_note": "A negative or security Segregation of Duties scenario passes when Oracle correctly enforces the outcome defined by the customer's own configured SoD ruleset — a block, a required mitigating control, or a permitted combination — not when a specific duty pair is denied in every environment. This page catalogs 25 individual Segregation of Duties scenarios as a single comprehensive reference rather than as separate indexable pages. All user, role and transaction values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real access grants or real conflict findings."
  },
  "preconditions": [
    "Oracle Fusion Security Console access is available to a test user with user, role and SoD policy administration privileges.",
    "A representative SoD ruleset with one or more conflicting-duty pairs is defined or can be constructed in the target Oracle Fusion environment, reflecting the customer's own control design.",
    "Test users are available to represent ${USER} personas that hold a single duty, hold both duties in a conflicting pair, and hold an approved conflict with an associated mitigating control.",
    "Representative ${ROLE} definitions exist for each duty under test (for example Create Supplier, Pay Supplier, Create AP Invoice, Approve Invoice).",
    "Where the customer uses mitigating controls, a documented mitigating-control definition and evidence-capture mechanism (for example a compensating review workflow) is available for testing.",
    "A valid ${BUSINESS_UNIT} and ${LEGAL_EMPLOYER} are configured in the target Oracle Fusion environment for scoping conflicting transactions."
  ],
  "test_data": [
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Conflicting Role Pair",
      "example": "${ROLE_A} / ${ROLE_B}"
    },
    {
      "field": "Duty Pair Under Test",
      "example": "${DUTY_PAIR}"
    },
    {
      "field": "SoD Ruleset / Policy",
      "example": "${SOD_RULESET}"
    },
    {
      "field": "Mitigating Control",
      "example": "${MITIGATING_CONTROL}"
    },
    {
      "field": "Business Unit",
      "example": "${BUSINESS_UNIT}"
    },
    {
      "field": "Legal Employer",
      "example": "${LEGAL_EMPLOYER}"
    },
    {
      "field": "Transaction Reference",
      "example": "${TRANSACTION_ID}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as Security Administrator",
      "action": "Sign in to Oracle Fusion Cloud with a user account that has Security Console and SoD policy administration access.",
      "test_data": "",
      "expected_result": "The Oracle Fusion Cloud home page and SoD policy area load successfully for the authenticated security administrator.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Confirm Conflicting Duty Pair and SoD Ruleset",
      "action": "Confirm or configure ${DUTY_PAIR} as a conflict within ${SOD_RULESET}, according to the customer's own control design.",
      "test_data": "${DUTY_PAIR} / ${SOD_RULESET}",
      "expected_result": "The duty pair and its treatment (block, mitigate or permit) are correctly reflected in the configured ruleset.",
      "validation_type": "action"
    },
    {
      "step_number": 3,
      "step_name": "Provision Test User with Conflicting Roles",
      "action": "Provision ${USER} with ${ROLE_A} and ${ROLE_B}, or confirm the existing assignment, via the Security Console.",
      "test_data": "${USER} / ${ROLE_A} / ${ROLE_B}",
      "expected_result": "The role assignments are created or confirmed successfully.",
      "validation_type": "action"
    },
    {
      "step_number": 4,
      "step_name": "Perform the First Conflicting Transaction",
      "action": "As ${USER}, perform the first duty in ${DUTY_PAIR} (for example create a transaction) within ${BUSINESS_UNIT}.",
      "test_data": "${BUSINESS_UNIT} / ${TRANSACTION_ID}",
      "expected_result": "The first transaction step completes and produces a record capable of being approved, paid or posted.",
      "validation_type": "action"
    },
    {
      "step_number": 5,
      "step_name": "Attempt the Second Conflicting Transaction",
      "action": "As the same ${USER}, attempt the second duty in ${DUTY_PAIR} against the same record (for example approve, pay or post it).",
      "test_data": "${TRANSACTION_ID}",
      "expected_result": "Oracle correctly applies the customer's configured outcome for this conflict — blocked, routed to mitigation, or permitted — for the attempted second duty.",
      "validation_type": "business_assertion",
      "note": "Correctly applying the customer's own configured SoD outcome, rather than assuming a universal block, is the core business assertion across this catalog."
    },
    {
      "step_number": 6,
      "step_name": "Verify Mitigating Control Evidence Where Configured",
      "action": "Where ${MITIGATING_CONTROL} applies to this conflict, confirm the required compensating review or secondary approval evidence is captured before the transaction proceeds.",
      "test_data": "${MITIGATING_CONTROL}",
      "expected_result": "The mitigating control evidence is correctly required and recorded; the transaction does not silently bypass the configured control.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 7,
      "step_name": "Apply a Role or Organization Change",
      "action": "Grant a new conflicting role, remove an existing conflicting role, or transfer ${USER} to a different ${BUSINESS_UNIT} or ${LEGAL_EMPLOYER}.",
      "test_data": "${USER} / ${BUSINESS_UNIT}",
      "expected_result": "The role grant, role removal or organizational transfer is applied successfully.",
      "validation_type": "action"
    },
    {
      "step_number": 8,
      "step_name": "Verify Conflict Status Re-Evaluates Correctly",
      "action": "Confirm that ${USER}'s conflict status correctly reflects the role or organization change applied in the previous step.",
      "test_data": "${SOD_RULESET}",
      "expected_result": "The conflict is correctly newly flagged, correctly cleared, or correctly retained, according to the customer's configured SoD ruleset.",
      "validation_type": "business_assertion",
      "note": "Conflict regression after a role or organizational change is the main business assertion for the lifecycle scenarios in this catalog."
    }
  ],
  "expected_results": [
    "Conflicting-duty combinations defined by the customer's SoD ruleset are correctly flagged, blocked or routed to a mitigating control.",
    "Combinations not defined as conflicts by the customer's ruleset are correctly permitted, without an assumed universal restriction.",
    "Mitigating-control evidence is correctly required and recorded where the customer configures a compensating control for an approved conflict.",
    "Self-approval and self-authorization of a user's own transaction are correctly prevented where the customer's configuration requires an independent approver.",
    "Conflict status correctly updates after a role grant, role removal or organizational transfer.",
    "Apparent new or removed conflicts following an Oracle quarterly update are correctly attributable to the update, and reviewed false positives are correctly distinguished from genuine conflicts."
  ],
  "validation_checkpoints": [
    "Conflicting-duty combination correctly evaluated against the customer's own configured SoD ruleset.",
    "Permitted (non-conflicting) combinations correctly allowed without unintended restriction.",
    "Mitigating-control evidence correctly required and recorded, not silently bypassed.",
    "Self-approval of a user's own transaction correctly prevented where configured.",
    "Conflict status correctly re-evaluated after role grant, role removal or transfer.",
    "Quarterly-update regression and false-positive review correctly distinguished from genuine new conflicts."
  ]
}
