Suite components were deployed beyond the licensed bundle in roughly half the estates, creating compliance gaps on the directory and federation pieces
The interesting boundary is contractual rather than technical. The access tier is clearly licensed; the directory and the governance tooling usually are not.
Prepared by Redress Compliance · August 19, 2026 · Oracle identity reviews. 15 to 25 reviews covering Access Manager, 2024 to 2025.
Executive summary
Suite components ran beyond the licensed bundle in roughly half the estates, opening compliance gaps on the directory and federation pieces specifically.
Processor counts were overstated by 20 to 45 percent where virtualization was not documented to policy. The count is the bill, and the documentation is the count.
User metrics breached the stated per processor minimums as the population grew past the crossover. Every user based technology metric carries a floor.
Nobody could produce the ordering document. Teams argued about the current price list while the entitlement sat in a contract from 2013.
What is actually running, and what is licensed?
Five things run. Only some of them attach to this license, and the difference is where the exposure lives. Oracle documents the product on its identity management pages.
The parts you will find running
- The access server tier, where the license attaches.
- Agent modules on web servers and proxies that call the access server.
- A policy and session store holding policies, sessions and configuration.
- A user directory, frequently a separately licensed product.
- Federation and token services for inbound and outbound trust.
Where the product ends and the bill begins
The access tier is clearly covered. The directory, the governance tooling and the risk based authentication service usually are not.
Component detail sits in the Access Manager documentation, and neither page tells you what you bought. Only the ordering document does.
Which metric fits which deployment?
Processor for populations you cannot count, user based for populations you can. Getting that backwards is what turns a manageable estate into an argument.
| Deployment | Population | Metric that usually wins | What decides it |
|---|---|---|---|
| Employee single sign on | Known, bounded, internal | User metric | Headcount against the per processor minimum |
| Customer or citizen portal | Large, external, growing | Processor | You cannot count or cap the users |
| Partner federation hub | Third party, uncontrolled | Processor | The population is not yours to enumerate |
| Mixed internal and external | Both | Processor on the shared tier | One tier serving both cannot be split by metric |
The floor under every user based count
Every user based technology metric carries a stated minimum expressed per processor, which puts a floor under the count no matter how few people you have. The principle is set out in the Software Investment Guide.
Never buy a user metric for a shared tier
A single access tier serving both an internal and an external audience is counted once, and the uncountable half sets the answer. That is the cheapest mistake to avoid and the most expensive one to discover.
The Oracle middleware licensing guide
How the middleware metrics behave, where the bundle boundaries sit, and the buyer side moves across the estate.
Get the brief →What 15 to 25 Oracle identity reviews showed
Across roughly 15 to 25 Oracle Identity and Access Management reviews that included Access Manager, Fredrik Filipsson found bundle scope and component usage drove most of the exposure. Four patterns recur.
- Suite components were deployed beyond the licensed bundle in roughly half the estates, creating compliance gaps on directory and federation pieces.
- Processor counts on access tiers were overstated by 20 to 45 percent where virtualization was not documented to policy.
- Identity programs licensed on user metrics breached the stated per processor minimums as the population grew past the crossover point.
- Nobody could produce the ordering document, while the entitlement sat in a contract from 2013 that nobody had read.
Teams argued about the current price list while their actual rights were defined by paper more than a decade old. The price list is not the entitlement.
- Your agreements decoded into plain English before the auditor interprets them for you
- Entitlements, caps and protections verified across your whole contract portfolio
- A defensible position paper generated in minutes rather than weeks
Why do processor counts run 20 to 45 percent high?
Because virtualization that is not documented to policy is counted as if it does not exist. The cores you can prove are partitioned are the cores you pay for.
The count is the bill, and the paper is the count
Processor licensing counts cores on the servers running the licensed program, adjusted by the core factor table. The partitioning position is set out separately in the partitioning policy.
Undocumented is not the same as unlicensed
A defensible position is a documented one, produced before the conversation rather than during it. The audit sequence sits in the audit practice, and the wider middleware picture in the middleware licensing reference.
Watch the briefing · 4:17How to Negotiate Your Oracle SaaS Renewal: The Five Moves at the TableScope before price, killing the escalator, trading term for protections, and closing on their clock rather than yours.
Is it sold standalone, or only inside a suite?
In practice it is bought inside a suite, and has been for well over a decade. Older estates still hold narrower legacy entitlements, which is exactly where the arguments start.
Legacy entitlements permit less than people assume
If the contract names an older access product rather than a current suite, the rights are defined by the licensing documentation in force for that release, not by what the equivalent suite includes today.
Four answers to get in writing before a suite migration
- What quantity and metric do you end up holding, against what you hold now?
- What happens to the support base, and does the annual fee move up?
- Are the original licenses terminated, and is that irreversible?
- Which components does the new entitlement add that you actually intend to deploy?
Teams read the current suite description, see federation and adaptive access listed, and deploy both against a license that never covered either. That is the single most common misunderstanding on this product.
The neighbouring metric questions sit in the identity licensing reference, with the same processor and user question worked through for the analytics server and the process suite.
Where the common advice on this product is wrong
The common advice is to read the current price list and size against it. We disagree.
The price list is a catalog, not a grant
In roughly half the estates reviewed, components ran outside the licensed bundle while the team was benchmarking against a document that described a product they had never bought.
The buyer side move is to find the ordering document first, establish which release documentation governs it, and only then look at the count. The support policy that governs the annual line sits in the support policies.
What the reviews measured, 2024 to 2025
Two cuts of the review file, one on scope and one on count.
With components deployed beyond what the entitlement covered, concentrated on the directory and federation pieces.
Where virtualization was not documented to policy, so cores that were in fact partitioned were counted as if they were not.
The first is a compliance exposure and the second is an overpayment. Both are settled by paper rather than by negotiation.
Your first five moves
- Find the ordering document before anything else, because in the reviewed estates nobody could produce it and the rights sat in a contract from 2013.
- Establish which release documentation governs that entitlement, since legacy paper grants less than the current suite description implies.
- Map deployed components against the bundle boundary, which is where half the estates were running outside their license on directory and federation.
- Document the virtualization position to policy, because undocumented partitioning is what pushed processor counts 20 to 45 percent high.
- Check the user metric against its per processor minimum. The Oracle practice runs the entitlement reconstruction before the count conversation, which is the only order that helps.
Frequently asked questions
What does the license actually attach to?
The access server tier. The agents call it, but the directory, the governance tooling and the risk based authentication service are usually separate products.
How often do estates run outside the bundle?
In roughly half of those reviewed, with the gaps concentrated on the directory and federation pieces rather than on the access tier itself.
Why are processor counts so high?
They ran 20 to 45 percent above the defensible figure where virtualization was not documented to policy. Cores you cannot prove are partitioned are counted as if they are not.
Which metric should a portal use?
Processor. A large, external or growing population cannot be counted or capped, so a user based metric on that tier is a number nobody can defend.
What is the per processor minimum?
A stated floor that every user based technology metric carries, expressed per processor. It applies no matter how few people actually use the program.
Can a shared tier split metrics?
No. One access tier serving both internal and external audiences is counted once, and the uncountable half sets the answer for the whole tier.
Do legacy entitlements cover the current suite?
No. Rights are defined by the licensing documentation in force for the release the contract names, not by what the equivalent suite includes today.
What should a suite migration offer answer?
The resulting quantity and metric, what happens to the support base, whether the original licenses are terminated irreversibly, and which added components you intend to deploy.
Why does the ordering document matter so much?
Because it is the only record of what was actually granted. The price list describes a catalog, and in the reviewed estates the two had drifted a decade apart.
Where should the work start?
By reconstructing the entitlement from the ordering document. Counting before that is counting against a number nobody has established you owe.