For data security, encryption, and credential storage information that applies across all connectors, see Data & Security - Enterprise Search Connectors.
The connector requests the minimum set of permissions the Oracle HCM REST APIs allow for its functionality, and only read-oriented access.
The connector never writes to or modifies data in Oracle HCM.
Credentials are stored encrypted and are never exposed in logs, search results, or the Simpplr UI after initial entry.
Auth type: Basic authentication (username and password)
The integration account you create in Oracle HCM must be able to read learner learning assignment records via the HCM REST API:
Permission / requirement | Why it's needed |
|---|---|
Read access to | Fetch learner assignment records for indexing |
Oracle role with HCM REST API access (for example, Human Capital Management Integration Specialist) | Allows the integration account to call HCM REST APIs and read records within Oracle data security rules |
An Oracle HCM administrator must provision the integration account and confirm it can read the learner records your organization wants indexed. Oracle data security policies may further limit which records the account can see.
Supported: Oracle Fusion Cloud HCM (SaaS) tenants with HCM REST API access (for example, https://{tenant}.fa.{region}.oraclecloud.com)
Not supported: On-premises Oracle HCM deployments without HCM REST API access, and ingestion paths that require Oracle Integration Cloud as an intermediary
When Enable document level security is turned on in the connector configuration, permissions are enforced at query time based on the assignee's primary work email on each learner assignment record.
Permission sync: Assignee email addresses are captured on each record during incremental and full content sync and used for query-time filtering.
User sync: Oracle HCM users are synced to Simpplr by the ACL sync. When a user is added or removed, the change is reflected in Simpplr after the next ACL sync.
Records without assignee email: Assignment records that do not include an assignee work email are indexed but may not be visible to any user.
Access removal: When a user's email no longer matches an assignment record, that record stops appearing in their search results after the next incremental sync (every 2 hours).
Change in Oracle HCM | Reflected in Simpplr |
|---|---|
User added / removed | After the next ACL sync (within a week) |
Assignee email changed on/removed from a record | After the next incremental sync (within 2 hours) |