Oracle introduced updates to its cloud-native access governance service on Oracle Cloud Infrastructure (OCI) as an alternative to traditional single-sign-on (SSO) and identity management technologies for large enterprises.

While SSO is successful in the initial phase of identifying users or applications that need access to resources, it lacks the ability to manage those levels of access over time. Oracle's access governance service, however, is able to identify when user roles change and automatically update permissions accordingly.

With thousands of users in a system, manually managing access can be nearly impossible. A medical student at a teaching hospital, for example, will start out with no access to patient data, but they need more access as they become medical residents and eventually practitioners. Oracle Access Governance "greatly streamlines that process," Oracle VP Leo Leung told SDxCentral.

The service also is designed to identify potential risks based on the behavior of users or resources, Leung said. "Then over time, it uses machine learning to further recommend things" like granting a bit more access to a certain resource, or restricting access to data based on suspicious user activity. "It'll save a huge amount of time for administrators, and overall, it improves security posture," he said.

Oracle Access Governance is available on OCI, though the vendor expects to extend the cloud-native service to other public cloud environments in the future.

Oracle targets sensitive industries

In addition to health care, Leung said this service is ideal for highly regulated industries that work with personal data, like financial services and government agencies. The City and County of San Francisco (CCSF), for example, already uses Oracle's service to review access for its users, which include San Francisco's 4.5 million residents, employees, suppliers and other state agencies.

CCSF is also leveraging the service's new no-code workflow formation capabilities and graphical interface to visualize and create access governance processes by tying user management and identity collection services into its workflows.

"As we steer our path towards the adoption of a cloud-native governance architecture, Oracle Access Governance rises as a critical player in this arena. Its strategic design, emphasizing intuitive user access review, prescriptive analytics powered by data insights, and automated remediation, echoes our commitment to fostering a secure IT environment," Director of Identity and Access Management for CCSF Chinna Subramaniam said.