My organization needs a practical way to generate a comprehensive report listing all members—including both direct and inherited assignments—of every custom application role within the Oracle Analytics Cloud (OAC) Console’s Roles and Permissions area. Today, the only built‑in method is exporting one role at a time through the OAC UI. With hundreds of custom roles in our shared service environment, this process is not scalable and becomes impossible to manage effectively. OAC manages its own application‑role membership internally and IAM only houses the user information, not the roles. Therefore, IAM cannot serve as a reliable source for auditing or reporting on role assignments. The required information exists only inside the OAC Console, and OAC currently provides no bulk export, API endpoint, or automated mechanism to retrieve role membership across all roles at once. This is a significant audit concern without a centralized, reportable way to extract all role‑to‑user mappings, the organization cannot easily identify which users—directly or indirectly—have elevated or superuser‑level access granted through custom roles. In an environment with hundreds of roles, the absence of a bulk-reporting capability creates a risk: privileged access could be assigned without detection, and auditors would lack sufficient evidence to validate that access is appropriate, controlled, and monitored.
This leads to the core need: developing or requesting a centralized, automated role‑membership reporting solution for OAC so the organization can reliably track, verify, and audit all custom role assignments at scale.