PBCS Security and Access Management Guide
PBCS security combines identity controls, roles, groups, permissions, reviews, and governance to protect planning data and activities.
PBCS is an Oracle Cloud service based on Oracle Hyperion Planning 11.1.2.4 on premises’ functionality and core architecture. Businesses moving to various Cloud services like PBCS have voiced many security concerns – how strong is the security on Cloud, how does the
PBCS security relate to the security on premises, how can they control access rights.
PBCS security is built under a shared responsibility model, where Oracle is responsible for the security of the underlying cloud infrastructure and the customers are responsible for securing their data.
Moreover, Oracle has to obtain proper customer authorization to access any of their data. For their part, Oracle has maintained all their on-prem security standards with PBCS infrastructure that includes the on-Cloud data centers, network, hardware, and operational software. They have strong processes in place for disaster recovery (DR), breach detection, auditing, environment control and other service requests.
Customers’ System Administrators can control all on-Cloud applications as well as integrated existing on-prem applications in a single identity domain using the Single Sign-on (SSO) system that uses industry standard SAML 2.0. Access management within an identity domain depends on users and their roles. In the Identity Console, System Administrators need to add users (manually, import .csv file or integrate with on-rem IAM system), add custom roles, and PBCS assign predefined or custom roles to users.
In its Cloud offerings Oracle has emphasized granular and in-depth security that is closer to the data.
Thus, System Administrators can also provision access to groups and users for different levels/features of the applications like dimensions, forms and folders, task lists and business rules. Additionally, Oracle offers security access reports for detection of unauthorized usage and auditing.
MindStream Analytics is a leading consulting and managed services firm focused on providing Business Analytics solutions to organizations. The team at MindStream has years of experience delivering innovative solutions to maximize and provide efficiency to an organizations strategic, operational and financial management processes.
MindStream Analytics has developed a unique approach and methodology to help you rapidly deploy Planning and Budgeting Cloud Services (PBCS) for your core operational planning needs. This offering is known as Planning Xtream ! This methodology combines MindStream’s extensive Planning and Budgeting implementation experience with a unique set of tools and templates that reduce the amount of time and effort needed to deploy Oracle Planning and Budgeting Cloud Service.
How PBCS security supports trusted access
The security model should align user access with job responsibilities and least-privilege principles. Administrators need clear ownership for provisioning, group membership, application roles, data permissions, approval workflows, and periodic certification.
MindStream helps design security models, map users and groups, configure permissions, test representative roles, document controls, train administrators, and establish joiner, mover, and leaver procedures. Testing should confirm both permitted activities and restricted access.
Regular access reviews, audit-log monitoring, documented approvals, and prompt removal of unused accounts keep controls effective as teams and responsibilities change.
Documented ownership keeps access decisions consistent, timely, reviewable, and aligned with changing responsibilities.
