The Inspiration: Legacy OBI EE "Act As" & Proxy Security Testing
In enterprise analytics, verifying that security rules work as designed is critical. Inspired by legacy OBI EE "Act As" proxy functionality and modern IAM impersonation tools, FDI needs a native User Impersonation Engine. This allows administrators and security authors to view the platform through the exact lens of any given user without needing their login credentials.
Problem Statement
Testing complex Data-Level Security such as row-level filters based on Business Units, Legal Entities, or Cost Centers and Object-Level Security in FDI is currently manual, tedious, and prone to blind spots:
- Cumbersome Testing Workarounds: Admins must either ask business users for screen shares, maintain multiple dummy test accounts with distinct role combinations, or temporarily alter user credentials in lower environments.
- Troubleshooting Friction: When a user reports missing data on a workbook, admins cannot easily reproduce what that specific user sees, leading to back-and-forth email chains and slow ticket resolution.
- Compliance & Security Risk: Testing security by temporarily granting roles to an admin account can lead to accidental privilege creep or invalid test results that don't match the target user's true security profile.
Proposed Solution: The "Act As / Security Preview" Console
Oracle should introduce a native, audited Impersonate User ("Act As") utility within the FDI Console and Workbook Viewer:
- User Impersonation Selector: Administrators or Security Managers with appropriate privileges can select any active user (e.g., yagnesh@obi.guru) from a secure dropdown.
- Context-Aware Rendering: The system immediately evaluates and applies the target user's exact:
- Application & Duty Roles (Object permissions)
- Data Security Assignments (Row-level filters for BU, Legal Entity, Country, etc.)
- Subject Area & Canvas Access
- Visual Proxy Sandbox: Displays a clear, persistent banner ("Currently Viewing as: Yagnesh [Read-Only Mode]") to ensure full operational awareness.
- Strict Audit Logging: Every "Act As" session is logged with the Admin ID, Target User ID, Timestamp, and Session Duration to satisfy enterprise compliance requirements.
Business Value
- Instant Security Validation: Verify complex row-level security across Business Units or Legal Entities in seconds before releasing new canvases.
- Accelerated Support: Resolve user access tickets immediately by seeing the exact dashboard state reported by the user.
- Flawless Compliance: Eliminates the risky practice of sharing credentials or manually editing test user role assignments