{
  "test_id": "ORCL.SEC.SENSITIVE_DATA",
  "scenario_name": "Sensitive Data Access",
  "application": "Oracle Fusion Cloud",
  "product": "Security",
  "module": "Security",
  "process": "Sensitive Data Access",
  "business_flow": "Access-to-Masked-Evidence",
  "scenario_type": "Positive / Negative / Security / Integration",
  "priority": "High",
  "automation_status": "SyntraFlow Ready",
  "library": "Syntra Standard",
  "canonical_url": "https://www.syntraflow.cloud/oracle-erp-testing-tool/test-library/security/sensitive-data-access/",
  "objective": {
    "intro": "This test validates that sensitive fields — salary, payroll results, national identifiers, bank account details, addresses, dependent and beneficiary data, candidate PII and performance documents in HCM, and supplier/customer/payment banking data in Financials/SCM — are correctly restricted to authorized users, and that any sensitive value captured in test evidence, screenshots, extracts or downstream systems is correctly masked, using masked/synthetic test data throughout.",
    "confirms": [
      "authorized users with the required ${ROLE} and ${FUNCTIONAL_PERMISSION} can correctly view the intended ${SENSITIVE_FIELD} within their granted ${WORKER_POPULATION} or scope",
      "unauthorized users are correctly blocked from viewing salary, payroll results, national identifiers, bank details, address, dependent, beneficiary, candidate and performance data in HCM",
      "unauthorized users are correctly blocked from viewing supplier bank accounts, payment bank accounts, customer sensitive data and payment output in Financials/SCM",
      "extracts, reports and downloads correctly include permitted sensitive fields for authorized users and correctly exclude restricted sensitive fields for unauthorized users",
      "any ${SENSITIVE_FIELD} value captured in SyntraFlow test evidence, screenshots or extracts is correctly masked according to the customer's configured Syntra DataVault masking rules",
      "masked sensitive values remain consistent between Oracle Fusion evidence and downstream masked systems, and an auditable record of sensitive-field access is available for review",
      "sensitive data access behavior reflects the customer's own configured security and masking model rather than assuming a universal Oracle restriction or masking scheme"
    ],
    "scope_note": "A negative or security Sensitive Data Access scenario passes when Oracle correctly restricts unauthorized access to a sensitive field, or when SyntraFlow correctly masks a sensitive value in captured evidence; this test does not attempt to certify a specific Oracle application defect. This page catalogs 25 individual Sensitive Data Access scenarios as a single comprehensive reference rather than as separate indexable pages. All salary, national identifier, bank account and other sensitive values referenced throughout are ${PLACEHOLDER} tokens or explicitly masked test data, never real records."
  },
  "preconditions": [
    "Oracle Fusion Security Console access is available to a test user with role, data role and privilege administration rights.",
    "Representative ${ROLE}, ${DATA_ROLE} and ${FUNCTIONAL_PERMISSION} definitions covering sensitive HCM and Financials/SCM fields are available or can be constructed in the target Oracle Fusion environment.",
    "Test users are available to represent personas with and without access to each ${SENSITIVE_FIELD} under test.",
    "A valid ${WORKER_POPULATION}, ${BUSINESS_UNIT} and representative extract/report definitions are configured in the target Oracle Fusion environment.",
    "Syntra DataVault masking rules are configured for the sensitive fields under test, covering test evidence, screenshot and downstream masking — see /datavault/data-masking/.",
    "A downstream system, extract or masked copy is available for comparing masked values — see /datavault/downstream-masking/.",
    "A user without the relevant role, data role or functional permission is available for unauthorized-access security testing."
  ],
  "test_data": [
    {
      "field": "User",
      "example": "${USER}"
    },
    {
      "field": "Role",
      "example": "${ROLE}"
    },
    {
      "field": "Data Role",
      "example": "${DATA_ROLE}"
    },
    {
      "field": "Functional Permission",
      "example": "${FUNCTIONAL_PERMISSION}"
    },
    {
      "field": "Worker Population",
      "example": "${WORKER_POPULATION}"
    },
    {
      "field": "Sensitive Field",
      "example": "${SENSITIVE_FIELD}"
    },
    {
      "field": "Salary",
      "example": "${SALARY}"
    },
    {
      "field": "National Identifier",
      "example": "${NATIONAL_ID}"
    },
    {
      "field": "Bank Account",
      "example": "${BANK_ACCOUNT}"
    },
    {
      "field": "Supplier Bank Account",
      "example": "${SUPPLIER_BANK_ACCOUNT}"
    },
    {
      "field": "Extract / Report",
      "example": "${EXTRACT_FILE}"
    },
    {
      "field": "Business Unit",
      "example": "${BUSINESS_UNIT}"
    }
  ],
  "business_steps": [
    {
      "step_number": 1,
      "step_name": "Sign In as Test User",
      "action": "Sign in to Oracle Fusion Cloud with a test user account under evaluation for sensitive-data access.",
      "test_data": "",
      "expected_result": "The Oracle Fusion Cloud home page loads successfully for the authenticated test user.",
      "validation_type": "action"
    },
    {
      "step_number": 2,
      "step_name": "Attempt Authorized Sensitive Field Access",
      "action": "As ${USER} holding ${ROLE} and the required ${FUNCTIONAL_PERMISSION}, attempt to view ${SENSITIVE_FIELD} (for example ${SALARY}, ${NATIONAL_ID} or ${BANK_ACCOUNT}) within the granted ${WORKER_POPULATION} or scope.",
      "test_data": "${USER} / ${ROLE} / ${SENSITIVE_FIELD}",
      "expected_result": "The sensitive field is correctly displayed for the authorized user.",
      "validation_type": "business_assertion",
      "note": "Confirming correctly authorized visibility is the counterpart assertion to the restriction scenarios in this catalog."
    },
    {
      "step_number": 3,
      "step_name": "Attempt Unauthorized Sensitive Field Access",
      "action": "As a user without ${ROLE} or the required ${FUNCTIONAL_PERMISSION}, attempt to view the same ${SENSITIVE_FIELD}.",
      "test_data": "${SENSITIVE_FIELD}",
      "expected_result": "Access to the sensitive field is correctly restricted or hidden.",
      "validation_type": "business_assertion",
      "note": "This is the main assertion tested across the HCM and Financials/SCM sensitive-field scenarios in this catalog."
    },
    {
      "step_number": 4,
      "step_name": "Run Extract or Report Containing Sensitive Fields",
      "action": "Run ${EXTRACT_FILE} both as an authorized and as an unauthorized user, where the extract or report would include ${SENSITIVE_FIELD}.",
      "test_data": "${EXTRACT_FILE}",
      "expected_result": "The extract or report correctly includes permitted fields for the authorized user and correctly excludes restricted fields for the unauthorized user.",
      "validation_type": "business_assertion"
    },
    {
      "step_number": 5,
      "step_name": "Capture Test Evidence for the Access Attempts",
      "action": "Capture screenshots and step-level evidence for the authorized and unauthorized access attempts using SyntraFlow's evidence capture.",
      "test_data": "",
      "expected_result": "Evidence is captured for each step.",
      "validation_type": "action"
    },
    {
      "step_number": 6,
      "step_name": "Verify Sensitive Field Masked in Evidence",
      "action": "Inspect the captured evidence for any ${SENSITIVE_FIELD} value; confirm Syntra DataVault masking rules are applied to the value shown in the evidence.",
      "test_data": "${SENSITIVE_FIELD}",
      "expected_result": "Sensitive field values are correctly masked in the captured test evidence, according to the customer's configured masking rules.",
      "validation_type": "business_assertion",
      "note": "See /datavault/data-masking/ for how Syntra DataVault masking rules are configured and applied to captured evidence."
    },
    {
      "step_number": 7,
      "step_name": "Compare Masked Value with Downstream System",
      "action": "Compare the masked ${SENSITIVE_FIELD} value captured during testing with the corresponding masked value in a downstream system or extract, per Syntra DataVault downstream masking.",
      "test_data": "${SENSITIVE_FIELD}",
      "expected_result": "The masked value is consistent between the Oracle Fusion evidence and the downstream masked representation.",
      "validation_type": "business_assertion",
      "note": "See /datavault/downstream-masking/ for how masked values are propagated consistently to downstream systems."
    },
    {
      "step_number": 8,
      "step_name": "Review Access Audit Trail",
      "action": "Review the audit log entry recorded for the ${SENSITIVE_FIELD} access attempt.",
      "test_data": "${SENSITIVE_FIELD}",
      "expected_result": "An auditable record of the access attempt, including user, role and outcome, is correctly available for review.",
      "validation_type": "business_assertion"
    }
  ],
  "expected_results": [
    "Authorized users correctly view ${SENSITIVE_FIELD} within their granted scope.",
    "Unauthorized users are correctly blocked from viewing salary, payroll, national identifier, bank, address, dependent, beneficiary, candidate and performance data.",
    "Unauthorized users are correctly blocked from viewing supplier bank accounts, payment bank accounts, customer sensitive data and payment output.",
    "Extracts and reports correctly include permitted sensitive fields and exclude restricted sensitive fields based on the requesting user's access.",
    "Sensitive field values are correctly masked in captured test evidence, screenshots and extracts.",
    "Masked values remain consistent between Oracle Fusion evidence and downstream masked systems.",
    "An auditable record of sensitive-field access is correctly available for review."
  ],
  "validation_checkpoints": [
    "Authorized access to sensitive fields correctly granted within scope.",
    "Unauthorized access to HCM sensitive fields correctly blocked.",
    "Unauthorized access to Financials/SCM sensitive fields correctly blocked.",
    "Extracts and downloads correctly include/exclude sensitive fields per access.",
    "Sensitive fields correctly masked in test evidence and screenshots.",
    "Masked values correctly consistent between evidence and downstream systems.",
    "Sensitive data access correctly recorded for audit.",
    "No real PII, salary figures, national identifiers or bank numbers ever used in testing."
  ]
}
