Security & Access Control - People, Ideas & Objects and Oracle Corporation
Date: 2026-08-11
Purpose
Synallagi is based on Oracle Cloud Enterprise Resource Planning and the related capabilities of Oracle Cloud Infrastructure. This provides People, Ideas & Objects with a current, secure and extensible foundation for financial management, procurement, projects, identity, access governance, integration, data protection and cloud operations.
The purpose of this relationship is not to assemble every Oracle security product within Synallagi. It is to use Oracle capabilities where they satisfy the requirements of the application, extend them where Synallagi introduces a distinctive oil & gas operating requirement, and preserve a clear division of responsibility between the Oracle platform and the Synallagi business model.
Oracle provides many of the foundational controls needed to identify users, authenticate them, manage roles, govern access, protect data, monitor activity and maintain cloud services. Synallagi must determine how those controls apply to producers, Joint Operating Committees, service providers, suppliers, temporary working groups, properties, Work Orders, Industrial Command & Control and the other relationships through which the industry conducts its work.
This distinction is essential. Oracle can establish that a person is who they claim to be and provide the mechanisms through which access is granted or denied. Synallagi must establish what authority that person holds, within which organization and Joint Operating Committee, for which property and purpose, during what period, and subject to which business, financial, contractual and operational constraints.
A Capability-Led Architecture
The original People, Ideas & Objects specification is based substantially on the Oracle products available in August 2026. Many of the underlying requirements remain valid, but Oracle's product structure and the delivery of enterprise applications have changed materially.
Synallagi will therefore specify required capabilities before selecting individual Oracle products. A product or service will be included only where its function is required by the target architecture and is not already provided appropriately by Oracle Fusion Cloud Applications or Oracle Cloud Infrastructure.
The architecture will apply the following order of preference:
- Use the security and business controls delivered with Oracle Fusion Cloud Applications.
- Use Oracle Cloud Infrastructure identity, governance, integration and security services for Synallagi extensions and connected services.
- Use Oracle database security and recovery capabilities for databases controlled by People, Ideas & Objects.
- Introduce Oracle Fusion Middleware identity products only where an on-premises, hybrid or legacy integration requirement makes them necessary.
- Implement a Synallagi capability where the requirement is specific to the oil & gas operating model and is not the responsibility of the Oracle platform.
This approach reduces duplication, avoids unnecessary product dependencies and allows Synallagi to benefit from Oracle's continuing cloud development without binding its business design to a historical product catalogue.
Identity Across Organizational Boundaries
Synallagi operates across organizational boundaries. Its users include employees and representatives of producers, members of Joint Operating Committees, service providers, suppliers, contractors, professional advisers and participants in temporary research or operating groups. A person may represent more than one organization or exercise different responsibilities in different circumstances.
Oracle Cloud Infrastructure Identity and Access Management identity domains provide the current foundation for authentication, identity lifecycle management, federation, single sign-on and secure application access across Oracle and non-Oracle services. Oracle Fusion Cloud Applications environments are provisioned with an identity domain that is integrated with Fusion Applications and can support authorized extensions and integrations. Oracle identifies a custom partner application connected to Fusion Applications as an appropriate extension use case.
Synallagi will use identity federation so that participating organizations can authenticate their people through trusted organizational identity providers where appropriate. Federation reduces duplicate credentials and allows an organization to remain responsible for the primary employment or affiliation status of its people. It does not, however, automatically grant access to Synallagi or membership in a Joint Operating Committee.
Admission to Synallagi requires a governed relationship among:
- the person;
- the organization represented by the person;
- the trusted source of the person's identity;
- the person's approved Synallagi participation;
- any Joint Operating Committee or service-provider relationship;
- the effective period of that relationship; and
- the sponsor, approver or agreement under which participation is established.
Separate identity domains may be appropriate for distinct user populations, particularly non-employees and industry participants requiring separate administration, terms of use, profile management or consent. The final identity-domain design will be based on population, trust, administration, privacy, scale, subscription and operational requirements and will be confirmed with Oracle during implementation.
Identity Is Not the Industry Business Directory
An identity service should contain the information required to authenticate a person, associate that person with trusted identifiers and administer access. It should not become the master repository for every supplier profile, professional capability, calendar, commercial relationship or industry contact.
Synallagi will separate identity information from business-party information.
Oracle Fusion Cloud Procurement and Oracle Supplier Portal provide current capabilities for supplier registration, supplier-maintained profiles, contacts, products and services, user provisioning and controlled supplier access. The Resource Marketplace and other Synallagi capabilities will add the industry-specific descriptions, qualifications, availability, performance evidence and relationships needed by producers and Joint Operating Committees.
This separation allows a supplier or service provider to maintain relevant business information without being permitted to alter the security decisions of a producer or Joint Operating Committee. It supports data minimization: identity systems retain the minimum information needed for trust and access, while authoritative business applications retain the richer information needed for transactions and operating relationships.
One User Experience Without Repeated Authentication
Users should be able to move among authorized Oracle Fusion Cloud Applications, Synallagi extensions and connected services without repeatedly entering credentials. Current identity domains, federation and token-based authentication replace the former dependence on desktop-oriented enterprise single sign-on products.
The experience must remain secure and convenient. Sign-on policies, multi factor authentication, adaptive security, device and network conditions, session controls and stronger verification for sensitive actions will be applied according to risk. A routine inquiry and a material change to financial authority should not necessarily require the same level of assurance.
Authentication establishes confidence in identity. Synallagi must still evaluate authorization for every material request. A successful sign-on must never be treated as authority to view every record or perform every function available through the application.
The Oracle Fusion Cloud Application Security Foundation
Oracle Fusion Cloud Applications provide the first layer of application security. The Security Console supports user and role administration, role analysis, role hierarchies, role assignments, privileges, data security policies and related security management. Oracle Cloud Enterprise Resource Planning applies a relationship among the user, the role and the applicable data context. Oracle summarizes this as who can do what on which data.
Synallagi will use delivered Oracle roles, privileges and data-security mechanisms where they correspond to the required business responsibility. Custom roles will be created only where the delivered design does not meet the requirement, and they will grant the minimum privileges necessary.
Oracle's delivered data contexts include structures such as business units, ledgers, data access sets, asset books, legal entities, intercompany organizations, project organizations and other enterprise structures. These controls will be used wherever they align with Synallagi's financial, procurement, project and organizational requirements.
A Joint Operating Committee and its property context introduce additional relationships that cannot be assumed to exist in every delivered Oracle security structure. Synallagi must therefore supplement Oracle application security with its own governed context. The two layers must operate together:
Oracle security determines whether the user may perform the underlying application function and access the applicable Oracle business data.
Synallagi determines whether the user may perform that function for the selected Joint Operating Committee, property, role, purpose, Work Order, command assignment and effective period.
Neither decision is sufficient by itself when an action crosses both layers.
Joint Operating Committee Context and Authority
The Joint Operating Committee is a central authority boundary within Synallagi. When a user enters a Joint Operating Committee workspace, the system must establish a signed and time-bounded operating context containing the selected property, participating organization, active role, command assignment, governing agreement, ownership version, information classifications and allowed capabilities.
Every material request must be evaluated against that context. The evaluation may include:
- authenticated identity and current identity assurance;
- organization and representation relationship;
Joint Operating Committee membership;
- selected property and applicable agreement;
- active role and command assignment;
- delegated decision authority;
- technical, operational and financial authority;
- Work Order or other authorization;
- record ownership and relationship;
- information classification and Intellectual Property permission;
- purpose of access;
- effective date and time;
- segregation-of-duties restrictions;
- location, device or session risk where applicable; and
- emergency or exceptional authority.
Changes to any of these conditions must be reflected promptly in access. If a person leaves an organization, a producer withdraws from a property, a command assignment ends, a Work Order closes or delegated authority is revoked, the related access must expire without depending on a manual review of every application screen.
This dynamic evaluation is the modern expression of the objective originally assigned to Oracle Entitlements Server. Oracle roles and Oracle Access Governance provide important parts of the solution. The complete decision remains a combination of Oracle controls and Synallagi's business context.
Industrial Command & Control
Industrial Command & Control establishes operational roles, reporting relationships, delegation, escalation and effective assignments among the people and organizations participating in work. Security & Access Control ensures that those assignments are reflected in access to information, decisions and application functions.
- The two capabilities are related but must not be confused.
- Identity confirms the person.
- Industrial Command & Control establishes operational position and direction.
- Joint Operating Committee governance establishes decision rights.
- A Work Order authorizes participation, scope, funding and charging.
- Security & Access Control permits the information and system actions required to exercise valid authority.
Availability of a person or capability does not grant operational authority. Operational authority does not automatically grant authority to spend. Permission to view a record does not grant authority to approve it. One person may hold several roles, but Synallagi evaluates the role being exercised for the particular action.
Oracle's identity and governance services reduce the technical effort required to administer users and access. They do not replace the research, user-community design and application development required to model effective command and collaboration across independent organizations.
Temporary Working Groups and Work Orders
For innovation to be dispersed broadly throughout the industry and become a major focus of scientific development, substantially more collaborative research is required. Producers must be able to contribute to working groups formed through ad hoc relationships that are temporary and have a defined short-term purpose.
These working groups are not Joint Operating Committees. They are not organized around the governance and operation of a jointly owned property, and an Authorization for Expenditure is generally inappropriate. Participants may instead contribute assets, facilities, data, Intellectual Property, specialist talent, services or cash. Those contributions may need to be valued to establish each participant's entitlement to the resulting research, knowledge, Intellectual Property or other output.
Synallagi must therefore recognize the working group as a distinct organizational construct. It must establish its purpose, participants, contributions, decision rights, confidentiality, authority, duration, output ownership, permitted use, accounting treatment and completion conditions without forcing the relationship into a Joint Operating Committee or conventional capital-project model.
In the assessment of People, Ideas & Objects, these working groups have largely ceased to exist. A principal cause is the accounting burden placed upon contributors and originators. Their unusual and temporary relationships produce repeated questions about how contributions are authorized, valued, recorded, shared, recovered and reported. The administrative burden can become so great that the initiative is no longer worth pursuing.
One of the two principal purposes of the Synallagi Work Order is intended to resolve this problem. The Work Order may govern a temporary research or innovation collaboration, or authorize work undertaken for a property or Joint Operating Committee. For a working group, it establishes the common record through which participation, contributions, valuation methods, budgets, cost sourcing, charging, rights to output, approvals and closure are defined.
Federated identities and supplier or capability profiles provide trusted information about prospective participants. The Work Order establishes the business basis for their participation, including scope, funding, contribution, cost sourcing, charging and effective period. Industrial Command & Control assigns the operational structure. Security & Access Control grants the minimum access required for each participant's work.
Temporary access must therefore be:
- sponsored and approved;
- linked to a specific purpose and organizational relationship;
- limited to any relevant project, working group, Joint Operating Committee, property, records or functions;
- effective for a defined period;
- reviewed when the assignment changes;
- automatically removed when the assignment or Work Order ends; and
- retained in the audit evidence after the access itself expires.
Emergency access may be permitted where delay would create unacceptable operational, safety, environmental or financial risk. It must be time-limited, conspicuous, fully recorded and subject to prompt review and confirmation by the appropriate authority.
Identity Lifecycle and Delegated Administration
Access must follow the lifecycle of the person and the business relationship. Synallagi requires controlled processes for registration, sponsorship, verification, approval, provisioning, modification, suspension, recertification and removal.
Oracle Access Governance provides a current cloud-native foundation for identity orchestration, access requests, policy-based access, access reviews, access certification and remediation across cloud and on-premises systems. It integrates with Oracle Fusion Cloud Applications and can manage application accounts and role assignments.
Delegated administration is necessary because People, Ideas & Objects cannot maintain every participant's information centrally. Producers, suppliers and service providers should be able to maintain approved portions of their organizational and contact information and request access for their people. The receiving producer, Joint Operating Committee or People, Ideas & Objects authority retains control over what access is granted.
Delegation itself must be governed. A supplier administrator may manage eligible people from that supplier but must not assign internal producer roles, expand access beyond the supplier's permitted scope or approve the supplier's own exceptional privileges without independent control.
Access Requests, Reviews and Segregation of Duties
Oracle Access Governance and Oracle Fusion Cloud Risk Management provide current capabilities for access requests, access certification, sensitive-access analysis and segregation-of-duties controls. Preventive analysis can identify conflicting access before a requested role is provisioned. Periodic, event-based and targeted reviews can determine whether existing access remains necessary.
Synallagi will apply these capabilities to both conventional corporate responsibilities and the smaller, cross-company organizations formed through Joint Operating Committees.
Small organizations create a particular challenge because a limited number of people may perform several functions. Synallagi must identify material conflicts, prevent combinations that cannot be accepted and document compensating controls where complete separation is impractical. Compensating controls may include an independent approval, lower transaction limit, additional evidence, retrospective review, restricted duration or participation by another producer.
Oracle products can support internal control and provide compliance evidence, but their use does not make an organization compliant by itself. Compliance depends upon the complete design and operation of policies, responsibilities, controls, evidence, review and remediation.
Understanding Who, What, Why and How
The Security & Access Control strategy must explain more than whether access is technically allowed. Synallagi must preserve enough evidence to determine:
- who performed or attempted the action;
- which organization the person represented;
- which role and authority were exercised;
- which Joint Operating Committee and property were active;
- what information, function or transaction is involved;
- when and from what session the activity occurred;
- why access is required;
- which agreement, assignment, Work Order, decision or approval supported it;
- what policy decision is made;
- what result or change followed; and
- whether an exception, conflict or override occurred.
Raw technical logs cannot establish all of this meaning. Oracle services can record authentication, role, application and database activity. Synallagi must connect those records to its business context, authority records and transaction history.
Audit evidence must be protected from inappropriate alteration and retained according to legal, regulatory, contractual and business requirements. Amendments correct or supersede prior information without erasing the record that was effective when the original action occurred.
Access analytics should identify excessive privileges, unusual activity, dormant accounts, repeated denials, conflicting roles, inappropriate administrator activity and access that no longer corresponds to a valid business relationship. Analytics and artificial intelligence may assist reviewers, but material access and remediation decisions remain governed, explainable and reviewable.
Information Classification and Confidentiality
Synallagi will protect information according to its ownership, business relationship, sensitivity and permitted purpose. Relevant classes include producer-private information, Joint Operating Committee information, service-provider working information, market-disclosure information, confidential technical and reserve information, financial information, personal information, strategy and Intellectual Property.
Classification must apply consistently to transaction processing, search, reporting, analytics, notifications, documents, exports, caches, training data and generated content. Moving information into a report, analytical model or artificial intelligence process must not weaken its original restrictions.
Oracle Fusion Cloud application security and data contexts will protect information held in delivered applications. Synallagi-controlled databases may additionally use Oracle Database security capabilities. Transparent Data Encryption protects information stored in database files and backups. Oracle Database Vault can restrict inappropriate privileged-administrator access. Data Redaction or application controls may be used where particular displayed values require protection.
Encryption at rest and in transit is a baseline requirement, but encryption alone does not determine who may see information after it is legitimately decrypted. Identity, authorization, context, classification, auditing and key management remain necessary.
Database Security, Monitoring and Configuration
Oracle Data Safe provides a current cloud service for database security assessment, user assessment, sensitive-data discovery, masking, activity auditing, alerts, security policies and centralized management of Oracle Database firewall controls for structured query language activity. It will be evaluated as the principal security-management service for Synallagi-controlled Oracle databases.
Oracle Audit Vault and Database Firewall may be appropriate where Synallagi requires centralized audit collection and database activity monitoring across on-premises, hybrid, Oracle and non-Oracle databases. It is not automatically required for Oracle Fusion Cloud Applications, where the underlying database is operated as part of Oracle's cloud service.
Database firewall controls operate through configured or learned policies. They should not be described as automatically knowing every statement that is valid for every user and application. Their effectiveness depends upon deployment architecture, policy quality, monitoring, exception handling and continued maintenance.
Configuration security will be based on approved baselines, controlled changes, environment separation, automated deployment where appropriate, security assessment, drift detection, remediation and evidence. A configuration-management service should not be assumed to reverse every incorrect change automatically. Oracle Data Safe, Oracle Cloud Infrastructure services and Oracle Enterprise Manager may each contribute depending upon which party operates the database or platform.
Backup, Recovery and Historical Information
Backup and recovery are business-continuity capabilities, not simply storage functions. The Synallagi recovery architecture must establish:
- which information and services must be recoverable;
- acceptable data loss and restoration time;
- backup frequency and retention;
- encryption and key availability;
- administrative separation;
- protection against deletion, compromise and ransomware;
- regional and service-failure scenarios;
- long-term retention requirements;
- restoration testing; and
- evidence that recovery objectives are being met.
For Oracle Cloud databases, Oracle Database Autonomous Recovery Service provides a current managed backup and recovery capability with enforced backup encryption and isolation of backup infrastructure. The final service selection will reflect the databases used by Synallagi and the applicable subscription and recovery requirements.
Historical query is separate from backup. Oracle Flashback Data Archive can preserve database changes for authorized historical access where it is appropriate to the data model. It does not replace backup, an application transaction history, immutable audit evidence or formal records management.
Extending Oracle Fusion Cloud Applications
The Synallagi requirements that are not delivered directly by Oracle Fusion Cloud Applications will be implemented through supported cloud configuration, extension and integration methods.
Oracle Visual Builder Studio supports application extensions and additional application interfaces within the Fusion Applications ecosystem. Oracle Integration and secured application programming interfaces support controlled information exchange and process coordination. These capabilities provide the technical means to develop Joint Operating Committee workspaces, Industrial Command & Control, Resource Marketplace interactions, Work Order relationships and other Synallagi functions while continuing to use Oracle applications as authoritative sources for the business information they own.
Extensions must not duplicate or bypass Oracle controls. They must preserve:
- the authenticated user and active identity domain;
- Oracle application roles and data access;
- the selected Joint Operating Committee and property context;
- source-system ownership of records;
- transaction and approval controls;
- information classification;
- traceability across interfaces; and
- the security effects of changes in either Oracle or Synallagi authority.
Configuration and extension designs must accommodate Oracle's cloud update lifecycle. Security-critical workflows and integrations will be tested against scheduled Oracle updates before production adoption.
Conditional Use of Oracle Fusion Middleware
Oracle continues to provide Oracle Identity and Access Management products for on-premises and hybrid environments. These products remain relevant where Synallagi must integrate legacy applications, locally operated directories or customer-controlled infrastructure. They are not the default foundation for a cloud-first Synallagi implementation.
Where such requirements exist:
- Oracle Access Management may protect on-premises web applications.
- Oracle Identity Governance may support provisioning and governance across locally operated systems.
- Oracle Internet Directory or Oracle Unified Directory may provide directory services.
- Oracle Unified Directory virtualization may present controlled views across existing directories.
- Oracle Advanced Authentication and Oracle Adaptive Risk Management replace the former Oracle Adaptive Access Manager direction.
- identity federation is provided as an integrated capability rather than requiring the former standalone Oracle Identity Federation architecture.
The former Oracle Enterprise Single Sign-On Suite, Oracle Identity Analytics and Oracle Total Recall names should not be used as target-architecture products. Their required capabilities are now met through current identity domains, Oracle Access Governance, Oracle Fusion Cloud Risk Management, current database services and Oracle Flashback technology.
Every middleware addition creates licensing, operation, patching, availability, integration and specialist-support obligations. Its inclusion must therefore be justified by an explicit requirement and confirmed with Oracle.
Development With Oracle and the User Community
Oracle's current platform substantially reduces the amount of foundational security technology that People, Ideas & Objects must develop. It does not remove the need for sustained design and research.
The most difficult questions concern how independent organizations should work together: how authority originates, how it is delegated, how temporary groups form, how costs and obligations are accepted, how operational direction is exercised, how trust is established and how accountability is preserved. Those questions must be resolved with producers, engineers, geologists, service providers, security specialists, auditors, legal advisers and Oracle Services specialists.
People, Ideas & Objects will use our user community to test these requirements through representative operating scenarios. Development costs can then be amortized across the producer community while each participating producer receives the benefit of the common architecture and accumulated industry learning.
Implementation Principles
The following principles govern the relationship between Synallagi and the Oracle platform:
- Business authority is explicit and cannot be inferred solely from identity or organizational membership.
- Every material action is evaluated in the correct Joint Operating Committee, property, organizational and temporal context.
- Oracle-delivered controls are used before equivalent custom controls are developed.
- Synallagi extensions preserve rather than bypass Oracle application security.
- Identity information is separated from supplier, capability, contact and transaction information.
- Access is limited to the minimum information and functions required for an approved purpose.
- Temporary and delegated access has an owner, reason, effective period and automatic end condition.
- Authority to view, decide, direct, perform, approve and spend remains distinguishable.
- Segregation of duties and compensating controls are evaluated in the complete cross-company process.
- Audit evidence connects technical activity with business purpose, authority and result.
- Encryption, backup, recovery and historical access are designed as separate but coordinated controls.
- Analytics and artificial intelligence do not weaken confidentiality, authority or accountability.
- On-premises middleware is introduced only for a demonstrated hybrid or legacy requirement.
- Commercial availability, licensing and supported configurations are confirmed with Oracle before implementation commitment.
- People, Ideas & Objects Intellectual Property ownership and permitted use are explicit, controlled, auditable and enforceable.
- The architecture is reviewed continuously as Oracle services and Synallagi requirements develop.
Current Oracle Direction
The Oracle product direction in this section is validated against Oracle documentation available in August 2026. At that time, the principal Oracle capabilities applicable to this architecture were:
- Oracle Cloud ERP
- Oracle Fusion Cloud Applications Security Console, application roles and data security;
- Oracle Fusion Cloud Applications identity domains and Oracle Cloud Infrastructure Identity and Access Management;
- Oracle Access Governance;
- Oracle Fusion Cloud Risk Management, including access requests, access certifications and advanced access controls;
- Oracle Fusion Cloud Procurement and Oracle Supplier Portal;
- Oracle Visual Builder Studio and Oracle Integration;
- Oracle Database encryption, Database Vault and Oracle Data Safe;
- Oracle Audit Vault and Database Firewall where hybrid monitoring is required;
- Oracle Database Autonomous Recovery Service; and
- current Oracle Identity and Access Management middleware for justified on-premises or hybrid requirements.
- Oracle's services will continue to change. Synallagi therefore treats these products as the present means of satisfying durable requirements, not as permanent substitutes for those requirements.
- Oracle Reference Material
- Oracle Fusion Cloud Applications Security Console
- Oracle Fusion Cloud Applications data access
- Oracle Fusion Cloud Applications identity domain for extensions
- Oracle Cloud Infrastructure Identity and Access Management identity domains
- Oracle identity-domain types
- Oracle Access Governance
- Oracle Access Governance integration with Fusion Cloud Applications
- Oracle Fusion Cloud Risk Management advanced controls
- Oracle Supplier Portal user provisioning
- Oracle Visual Builder Studio
- Oracle Integration
- Oracle Data Safe
- Oracle Data Safe activity auditing
- Oracle Transparent Data Encryption
- Oracle Data Redaction
- Oracle Database Vault
- Oracle Audit Vault and Database Firewall
- Oracle Database Autonomous Recovery Service
- Oracle Database Flashback technology
