FDI does not currently document a supported role configuration that satisfies all three requirements at the same time:
- DV consumption only
- DV workbook export
- No visibility or access to Classic
In our newly provisioned FDI environment, users with the FAW HCM Licensed Consumer role can access DV content and export data, which is required for our business users. However, the same users also see the Open Classic option in the DV three-dot menu, and clicking it opens Classic Home.
This creates a security concern because Classic exposes catalog capabilities such as copy/paste of catalog objects. Our Consumer users should only consume authorized DV content and export data; they should not have access to Classic Home or Classic catalog actions.
We also tested assigning the Viewer application role. This restricts Classic access, but it removes the required DV export functionality. As a result, there is currently no clearly supported out-of-the-box role configuration that meets our least-privilege requirement.
Current Limitation
The current security model appears to combine capabilities that should be independently configurable:
- DV content consumption
- DV workbook/data export
- Classic Home access
- Classic catalog object actions such as copy/paste
Because these privileges are not separated cleanly, customers must choose between:
- Granting FAW HCM Licensed Consumer, which allows export but exposes Classic access, or
- Granting Viewer, which restricts Classic but removes export functionality.
Requested Enhancement
Please provide a supported, documented security configuration in Oracle FDI/OAC that allows administrators to grant Consumer users the following access:
- Access only authorized DV subject areas and DV workbooks based on content duty roles and data roles.
- Export DV data/workbooks in approved formats.
- Hide or remove the Open Classic option from DV.
- Block access to Classic Home, including direct URL access.
- Prevent Classic catalog copy/paste and other catalog management actions.
Business Justification
Many organizations need Consumer users to export DV data for operational reporting, audit support, reconciliation, and downstream business processes. At the same time, these users should not have Classic catalog access because it introduces capabilities beyond their intended read-only/report-consumer function.
This is a least-privilege security requirement. Exporting DV data and accessing Classic catalog management features are separate business capabilities and should be controlled separately.
Proposed Solution
Oracle should introduce one of the following:
- A separate privilege for DV Export that can be granted independently of Classic access.
- A separate privilege for Classic Home Access / Open Classic Visibility that can be removed from Consumer users.
- A documented application role combination that supports DV consumption plus export while blocking Classic.
- An administrative setting to hide or disable Open Classic for selected roles.
- More granular catalog privileges that prevent copy/paste and object management actions for Consumer users.
Expected Outcome
Consumer users should be able to use DV as intended, including exporting data, while being fully restricted from Classic Home and Classic catalog capabilities.
This would allow customers to implement a secure, least-privilege FDI/OAC access model without creating unsupported custom roles or compromising required export functionality.