How DNOW (MRC Global) Secures Oracle Cloud ERP with Oracle Fusion Cloud Risk Management At a recent Oracle GO showcase, DNOW (MRC Global) shared their journey to modernize controls and compliance in Oracle Cloud — automating risk and control activities with Oracle Fusion Cloud Risk Management, alongside deployment partner HiQuest and the Oracle Risk Cloud product team. In the Session • Automating controls across access, transactions, and configurations • Strengthening monitoring for SOX and audit requirements • Reducing manual effort for control owners Plus the practical side of the rollout: how DNOW (MRC Global) prioritized use cases, engaged business and IT teams, and built confidence in ongoing compliance — closing with live Q&A. Presenters • Bugesh Veesamsetty — Director IT, ERP Security and Controls, DNOW (MRC Global) • Patrick Palmer — Risk Management and Security, HiQuest • Lakshmi Rajamohan — Product Strategy Manager, Oracle Risk Cloud Watch the full recording: https://lnkd.in/eeKuWu5m Key Takeaway Sustainable compliance in Oracle Cloud comes from automating controls where the ERP data lives — not from more spreadsheets. This session shows what that looks like in practice. #Oracle #OracleCloud #OracleFusion #RiskManagement #GRC #CloudERP #OracleRM #SOX #InternalControls #AccessControl #CloudSecurity #Audit #RiskCompliance #HiQuest
HiQuest Group of IT Companies
IT Services and IT Consulting
San Mateo, California 7,262 followers
About us
Hiquest Group focuses on solving business problems. Having served 250+ customers over the last 15 years, we have learned that business objectives, human capital and technology solutions - in that order - is the right approach to work. We have consistently delivered on time, on budget and exceeding expectations. With Silicone Valley roots, US wide personnel and 24x7 operations in India, we serve customers from the proverbial two guys in a garage to Fortune 500 companies. Our three divisions cover Cyber Security, IT Infrastructure Management, APDM and Data Analytics. We also offer ready-to-deply solutions that can accelerate your initiatives at a lower TCO and faster speed to market.
- Website
-
https://www.hiquestgroup.com
External link for HiQuest Group of IT Companies
- Industry
- IT Services and IT Consulting
- Company size
- 51-200 employees
- Headquarters
- San Mateo, California
- Type
- Privately Held
- Founded
- 2003
Locations
-
Primary
Get directions
3 Waters Park Dr
San Mateo, California 94403, US
Employees at HiQuest Group of IT Companies
Updates
-
HiQuest Group of IT Companies reposted this
Advanced Access Request in Oracle Cloud (Part 2): Putting AAR to Work by Connor Quinton Part 1 covered the "why" and basic flow of Advanced Access Request (AAR). Part 2 covers when to use it and how to roll it out without overcomplicating IT and finance. When AAR Makes the Biggest Impact AAR shines in environments where you already have: - Firefighter scenarios – AP checks that must go out today, urgent AR receipts, GL fixes before close - Email-driven approvals – long threads that are hard to track or reproduce for audit - Manual role removal – admins meaning to remove access later, but getting pulled into other work A typical pattern: - The AP clerk is out unexpectedly - Someone still needs to process payments for a day or two - IT or a manager requests temporary AP Supervisor access for a user who knows the process - After the window expires, the elevated access disappears automatically The Revocation Job: No More “Did We Remove That Role?” An RMC job handles the clean-up piece: Automatic Access Request Revocation. You can: - Schedule it (for example, hourly) - Let it monitor temporary requests that have reached their end date - Have it automatically remove those roles from the Security Console Temporary firefighter access remains truly temporary, without requiring IT to sweep roles at the end of every incident manually. Implementation Game Plan A simple approach to rolling out AAR: 1. Split the seeded AAR role - Take the delivered Advanced Access Request Administrator role and break it into: - Requester - Reviewer - Approver - (Optional) Viewer - Keep requesters mostly in IT; keep approvers closer to business and risk ownership 2. Start with one high-value process - Example: AP check processing when your main clerk is out - Define what “temporary access” means (1–3 days is common) 3. Configure temporary access and the revocation job - Set standard durations for firefighter roles - Schedule the revocation job to run frequently so expired roles are removed quickly 4. Connect permanent access to SoD controls - Make sure your SoD and advanced access controls are deployed and tuned in RMC - Use AAR as the front door for permanent access, so approvers always see violations before approving 5. Use AAR exports for audit and reporting - Approvers can use the Access Request Approvals tile to export: - Who requested - Which role - Temporary vs permanent - Who reviewed/approved and when Why This Matters - Less chaos for IT: fewer one-off emails, fewer manual cleanup tasks - Cleaner risk posture: permanent access runs through SoD; temporary access auto-expires - Better audit story: consistent workflow, exportable approvals, and documented risk decisions Key takeaway: AAR turns firefighter and elevated access from a messy email trail into a controlled, reportable workflow that balances speed, control, and assurance. #Oracle #OracleCloud #RiskManagement #SoD #AccessControl #CloudSecurity #AAR #HiQuest
-
HiQuest Group of IT Companies reposted this
Advanced Access Request in Oracle Cloud (Part 1): Fixing Firefighter Access Chaos by Connor Quinton When something breaks in finance or IT, people need elevated access fast. In many organizations, that “firefighter” access still relies on ad hoc emails, one-off approvals, and a vague hope that someone will remember to remove the role later. That creates two familiar problems: - Risk: powerful roles (AP Supervisor, AR Manager, etc.) stick around longer than intended - Friction: IT burns time chasing approvals and manually cleaning up the Security Console The Fix: Advanced Access Request (AAR) Advanced Access Request in Oracle Risk Management Cloud (RMC) pulls that chaos into a single, governed workflow. Instead of “email and a screenshot,” you get a repeatable process with clear ownership and audit trails. Core ideas: - One place to request access: the My Access Requests tile - Separation of responsibilities: - Requester – usually IT, submits access for themselves or a team member - Reviewer – validates that the request is legitimate and appropriate - Approver – makes the final call and accepts any risk - Role + data scope in one flow (business units, orgs, data sets, etc.) - Different paths for temporary vs permanent access Temporary vs Permanent Access When a requester submits an AAR: - If the request is temporary (classic firefighter use case): - The flow stays fast on purpose - The user receives elevated access for a defined number of days - Cleanup is handled by an automated job instead of manual follow-up - If the request is permanent (job-related access): - AAR runs the request against your deployed SoD and access controls in RMC - Approvers see how many violations a role would trigger - They can drill into which controls are hit and decide whether to accept the risk From the end-user side, the experience is simple: select who needs access, choose the role (e.g., Accounts Payable Supervisor), set the duration, add scope if required, and submit. Under the hood, RMC handles the risk logic and routing. #Oracle #OracleCloud #OracleFusion #RiskManagement #SoD #AccessControl #CloudSecurity #AAR #HiQuest
-
Advanced Access Request in Oracle Cloud (Part 2): Putting AAR to Work by Connor Quinton Part 1 covered the "why" and basic flow of Advanced Access Request (AAR). Part 2 covers when to use it and how to roll it out without overcomplicating IT and finance. When AAR Makes the Biggest Impact AAR shines in environments where you already have: - Firefighter scenarios – AP checks that must go out today, urgent AR receipts, GL fixes before close - Email-driven approvals – long threads that are hard to track or reproduce for audit - Manual role removal – admins meaning to remove access later, but getting pulled into other work A typical pattern: - The AP clerk is out unexpectedly - Someone still needs to process payments for a day or two - IT or a manager requests temporary AP Supervisor access for a user who knows the process - After the window expires, the elevated access disappears automatically The Revocation Job: No More “Did We Remove That Role?” An RMC job handles the clean-up piece: Automatic Access Request Revocation. You can: - Schedule it (for example, hourly) - Let it monitor temporary requests that have reached their end date - Have it automatically remove those roles from the Security Console Temporary firefighter access remains truly temporary, without requiring IT to sweep roles at the end of every incident manually. Implementation Game Plan A simple approach to rolling out AAR: 1. Split the seeded AAR role - Take the delivered Advanced Access Request Administrator role and break it into: - Requester - Reviewer - Approver - (Optional) Viewer - Keep requesters mostly in IT; keep approvers closer to business and risk ownership 2. Start with one high-value process - Example: AP check processing when your main clerk is out - Define what “temporary access” means (1–3 days is common) 3. Configure temporary access and the revocation job - Set standard durations for firefighter roles - Schedule the revocation job to run frequently so expired roles are removed quickly 4. Connect permanent access to SoD controls - Make sure your SoD and advanced access controls are deployed and tuned in RMC - Use AAR as the front door for permanent access, so approvers always see violations before approving 5. Use AAR exports for audit and reporting - Approvers can use the Access Request Approvals tile to export: - Who requested - Which role - Temporary vs permanent - Who reviewed/approved and when Why This Matters - Less chaos for IT: fewer one-off emails, fewer manual cleanup tasks - Cleaner risk posture: permanent access runs through SoD; temporary access auto-expires - Better audit story: consistent workflow, exportable approvals, and documented risk decisions Key takeaway: AAR turns firefighter and elevated access from a messy email trail into a controlled, reportable workflow that balances speed, control, and assurance. #Oracle #OracleCloud #RiskManagement #SoD #AccessControl #CloudSecurity #AAR #HiQuest
-
Advanced Access Request in Oracle Cloud (Part 1): Fixing Firefighter Access Chaos by Connor Quinton When something breaks in finance or IT, people need elevated access fast. In many organizations, that “firefighter” access still relies on ad hoc emails, one-off approvals, and a vague hope that someone will remember to remove the role later. That creates two familiar problems: - Risk: powerful roles (AP Supervisor, AR Manager, etc.) stick around longer than intended - Friction: IT burns time chasing approvals and manually cleaning up the Security Console The Fix: Advanced Access Request (AAR) Advanced Access Request in Oracle Risk Management Cloud (RMC) pulls that chaos into a single, governed workflow. Instead of “email and a screenshot,” you get a repeatable process with clear ownership and audit trails. Core ideas: - One place to request access: the My Access Requests tile - Separation of responsibilities: - Requester – usually IT, submits access for themselves or a team member - Reviewer – validates that the request is legitimate and appropriate - Approver – makes the final call and accepts any risk - Role + data scope in one flow (business units, orgs, data sets, etc.) - Different paths for temporary vs permanent access Temporary vs Permanent Access When a requester submits an AAR: - If the request is temporary (classic firefighter use case): - The flow stays fast on purpose - The user receives elevated access for a defined number of days - Cleanup is handled by an automated job instead of manual follow-up - If the request is permanent (job-related access): - AAR runs the request against your deployed SoD and access controls in RMC - Approvers see how many violations a role would trigger - They can drill into which controls are hit and decide whether to accept the risk From the end-user side, the experience is simple: select who needs access, choose the role (e.g., Accounts Payable Supervisor), set the duration, add scope if required, and submit. Under the hood, RMC handles the risk logic and routing. #Oracle #OracleCloud #OracleFusion #RiskManagement #SoD #AccessControl #CloudSecurity #AAR #HiQuest
-
Embedded AI in Risk & Compliance: Smarter Access Decisions Inside Oracle Cloud by Connor Quinton AI in Oracle Risk Management Cloud (RMC) is no longer just a concept slide; it now lives inside access request and certification workflows. The goal: give humans better context and recommendations so they can make faster, more informed decisions. Where AI Shows Up - Access Request Assistant Helps users create access requests for ERP roles and the right data (BU, ledger, etc.) without remembering role names. Launches the Advanced Access Request workflow to run SoD analysis after submission - GenAI Role Briefing Report Gives admins and approvers a plain-language summary of what a requested role does, where it might be sensitive, and why access is being requested - Access Certification Advisor During certifications, suggests keep/remove/investigate for user–role assignments based on privileges, incidents, and peer usage How it Changes Access Requests Instead of “I think I need AP Inquiry…or was it AP Supervisor?” users describe what they are trying to do. Access Request Assistant turns that into a structured request, attaches roles and data scope, and sends it into a workflow with SoD analysis built in. For reviewers, AI Role Briefing cuts out guessing. Rather than approving a cryptic role name, they see a concise role profile: capabilities, sensitive actions, and risk signals. How It Changes Certifications Access Certification Advisor tackles the volume problem: too many assignments, not enough time. It highlights where to focus first (unusual access, low usage, higher-risk privileges) and backs that up with evidence. Certifiers still decide—but they start with a prioritized list, not a flat export. Simple decision guide: Keep → typical access, aligned to usage and peers Remove → stale, unused, or clearly excessive Investigate → risky or unusual Guardrails That Keep AI Helpful - Treat AI outputs as a starting point, not the final answer - Require a short justification when decisions go against a recommendation - Start with lower-risk roles before expanding to privileged access - Make sure control owners understand why a recommendation was made, not just what to click Quick Start 1. Pick 1–2 business areas (AP, GL) for a pilot 2. Turn on Access Request Assistant for common roles in scope 3. Use Role Briefing and Access Certification Advisor for one cycle 4. Compare to prior cycles, tune, and scale Why This Matters - Speed: Less time spent hunting for role details or explaining context - Quality: Approvals and certifications are driven by data and narratives, not guesswork - Assurance: Clearer story for audit and leadership on how risk is being managed Key takeaway: Embedded AI in RMC is not about replacing people. It is about giving risk, security, and business owners the context they need to make better access decisions, faster. #Oracle #OracleCloud #OracleFusion #RiskManagement #SoD #AI #GenAI #CloudSecurity #ICFR #HiQuest
-
Oracle AI World 2025: A first-timer’s take on AI, Risk, and real hands-on wins - Part 1 by Connor Quinton First off—wow. AI really is changing everything, and it’s arriving faster than ever. After a full week at Oracle AI World, I’m convinced you won’t want to miss what’s coming next. Across keynotes, workshops, and demos, my team saw AI move from “assistive” to embedded—directly inside the Oracle products we use every day. Where AI showed up in a big way - In Risk Management Cloud (RMC), the new Access Request Assistant (25D) lets us request access via chat and run preventive SoD checks before anything is provisioned. It turned what used to be back-and-forth emails into a guided, explainable flow. - During certifications, Access Certification Advisor (26A) generated “keep/remove/investigate” recommendations with clear rationale (privileges, incidents, peer usage). It didn’t replace judgment—it sped it up without lowering the bar. - The Risk & Security Snapshot – Assurance Advisor summarized process risks (P2P, R2R, etc.) in plain English so control owners could focus on action instead of hunting through spreadsheets. - On the identity side, Oracle Access Governance streamlined Workday/Entra/Fusion provisioning and enforced preventive SoD inside the access request path—cleaner audits, fewer blind spots. - And for observability, AI-powered audit insights in Log Analytics condensed noisy logs into readable narratives that we could actually use. Case studies > hype: CTB’s playbook Some of the most valuable time was spent with customers who demonstrated what works and what doesn’t during real-world implementations. A highlight was our client CTB, Inc. walking through their RMC journey: DOs: Design custom roles (don’t stay on seeded) and bake preventive SoD into access requests. Run daily data-driven controls: transaction-level SoD, IT superuser monitoring, and configuration drift. Make certifications and reviews operational, not annual; involve line-1 owners, not just audit. Use RMC dashboards to route incidents to owners and track remediation. DON’Ts: Don’t run ICFR/SoD with quarterly scripts and spreadsheet chases. Don’t assume seeded roles are “good enough.” They’re flexible by design and often mask risk. Don’t stop at access setup—link access → actions → transactions to see actual misuse. #OracleAIWorld #OracleAIWorld2025 #Oracle #OracleCloud #OracleFusion #RiskManagement #GRC #SoD #AccessGovernance
-
Oracle AI World 2025: A first-timer’s take on AI, Risk, and real hands-on wins - Part 2 by Connor Quinton Impact: CTB transitioned from over 6,500 initial incidents to minimal incidents by tightening roles, enabling preventive SoD, and adopting continuous monitoring. That’s the kind of before/after that sticks with you. Hands-on, not just hands waving: solving a procurement problem We also got rare hands-on keyboard time. In a “Cloud Adventure” session, we used Oracle Analytics to diagnose a procurement issue end-to-end: 1. Explore spending with augmented analytics and AI narratives to spot concentration risk and category trends. 2. Investigate cycle time from requisition approval to PO fulfillment. A single supplier, Lee Supplies, was taking over 24 hours, significantly slower than its peers. 3. Test a hypothesis: Are long cycle times tied to no blanket purchase agreements (BPAs)? Jump to Agreements, filter properly (no IT ticket required), and confirm that Lee has no active agreements. 4. Evaluate performance: Supplier Performance showed Lee’s quality at 77% and a 16.5% rejection rate—proper leverage before creating any agreements. 5. Decide and act: Open Supplier Scorecard (Lee’s delivery/quality score = 42) and launch a corrective Action Plan in Fusion Procurement—assign owners, due dates, and track remediation in the same workflow. That’s the theme of the week: analytics → insights → operational action—without leaving the product. We didn’t just identify the issue; we kicked off the fix in the same session. Security kept pace On the security front, Oracle’s message was consistent: AI raises both power and peril. The roadmap emphasized zero-trust and layered defenses—input/output guardrails for AI, least-privilege scopes, runtime anomaly monitoring, stronger transport (TLS 1.3), and retiring legacy basic authentication with WAF, OAuth, and passwordless authentication. It’s the right pairing to ship AI features responsibly across Fusion and RMC. Final thoughts Overall, the experience, knowledge gained, and the roadmap ahead were well worth it. If you’re evaluating Oracle Fusion or tightening ICFR/SOX in the cloud, this is the moment to pilot the AI-assisted flows—Access Request Assistant, Certification Advisor, Snapshot Assurance Advisor, and Access Governance with preventive SoD. The value isn’t just automation; it’s faster, better decisions with stronger controls baked into everyday work. #OracleAIWorld #Oracle #OracleCloud #OracleFusion #RiskManagementCloud #SoD #ProcurementAnalytics #AI #GenerativeAI #AIinSecurity #CloudSecurity #HiQuest