OCI Permissions

Introduction

OCI Permissions are the least-privilege policies CoreStack requires to onboard and manage an Oracle Cloud Infrastructure tenancy. CoreStack uses these permissions to ingest cost, inventory, configuration, and security data from your tenancy, and — where read-write access is granted — to execute policy-based remediation. This page is relevant before onboarding any OCI tenancy, or when adding a new product to an existing one. It applies to Account Admin and Provider Admin users who manage cloud account onboarding.

How It Works

Once OCI permissions are granted, cost and usage data syncs daily to twice daily via the cost/usage reports API export. Inventory, configuration, policy evaluation, and access-posture data sync every 24 hours (configurable). Utilization metrics sync on a 4, 8, or 24-hour user-selectable interval via OCI Monitoring. Activity and audit events ingest near real-time via a Service Connector routed to Notifications, configured per region. Threat findings ingest periodically. Each ingestion path runs as an independently observable process with its own run history and on-demand re-run, visible in Governance > Cloud Accounts > Account Status & Configurations.


Refer to the following user guides to get a summary of which least privilege policies are required to setup in your OCI cloud portal for different products and access levels:


Did this page help you?