Oracle's contract counts a read-only Financials user as a full Hosted Named User at $375 to $475 per month, but Oracle's own privilege-based measurement script does not count them at all
The Hosted Named User definition triggers on authorization, not activity, and contains no read-only carve-out, so on paper every inquiry viewer and approver is a full seat. Oracle's published Metric Descriptions for Fusion Offerings counts only users holding named manage-type privileges, which means a correctly designed inquiry role registers zero. Your entire read-only argument lives in that gap, and it only holds if you did the role surgery before the audit letter arrived.
Prepared by Redress Compliance · August 19, 2026 · Oracle licensing advisory. Fusion Financials renewal and audit engagements, 2024 to 2026.
Executive summary
The contract gives you nothing: a Hosted Named User is any individual authorized to access the service regardless of whether they are actively accessing it, and no read-only exception exists anywhere in the Service Descriptions or the August 6, 2026 Global Price List.
A user provisioned in March who never logged in again is still an authorized user in December, and the count reaches employees, contractors, and third parties equally.
Oracle's own measurement documentation is the buyer's best weapon, because Metric Descriptions for Oracle Fusion Offerings counts HNU by named privilege, and the enumerated privileges are manage-type, not view-type.
Revenue Management counts only users assigned VRM_MANAGE_REVENUE_PROCESSING_PRIV, Grants Management only GMS_MANAGE_AWARD_PRIV, and a user holding several listed privileges is counted once, not several times.
Oracle has published a written admission that provisioning drives the count, in the Advisory Note on Subscription Impact across the 25C, 26A, and 26B releases.
Oracle states that assigning predefined roles as-is may impact subscription usage even for services you have not purchased, that unused assigned privileges still consume subscription, and names Employee, Contingent Worker, and Application Implementation Consultant as the top three offenders.
The money at stake is a 4x to 8x per-seat delta: full Financials sits at $375 to $475 per user per month list while limited self-service access runs $50 to $100, or $60 to $90 in negotiated practice.
Misclassifying 200 approvers and viewers as full seats costs roughly $700,000 to $900,000 a year at list before the 25 to 55 percent discount you should already be taking.
The per-month HNU variant is measured on peak, not average, so a single provisioning spike sets your number for that calendar month.
That makes uncontrolled year-end close access, implementation partner accounts, and temporary audit-season logins the three most expensive housekeeping failures in the estate.
How Oracle defines and how Oracle measures a Hosted Named User
There are two documents in play, they were both written by Oracle, and they do not say the same thing.
The contractual layer is the Hosted Named User definition in the Fusion Cloud Service Descriptions and the Global Price List: an individual authorized by the customer to access the hosted service, regardless of whether that individual is actively accessing it at any given time.
Authorization is the trigger. Activity is irrelevant. There is no read-only carve-out, no inquiry tier, no approver exemption.
The quantity on your ordering document is not an average or a run rate, it is a ceiling, and for the per-month variant the peak number of Hosted Named Users at any point in the calendar month sets compliance.
So a single Friday afternoon of bulk provisioning during month-end can define the whole month.
The operational layer is Metric Descriptions for Oracle Fusion Offerings, Oracle's published per-SKU measurement rules, and it counts something narrower: active users assigned specific enumerated privileges. Revenue Management HNU counts users holding VRM_MANAGE_REVENUE_PROCESSING_PRIV.
Grants Management counts GMS_MANAGE_AWARD_PRIV. Project Financials counts any of a list. All of them are manage-type privileges. A user holding four listed privileges is counted once. A user holding none of them does not register at all.
That is not a loophole a consultant invented, it is Oracle's own script, and it is what the Commercial Measurement Usage Metrics reports (delivered to an OCI Object Storage bucket, readable through the Environment Read-Only User policy) will actually show your renewal team.
| Layer | Source document | What triggers a count | Population reached | Does a view-only role register? |
|---|---|---|---|---|
| Hosted Named User | Service Descriptions / Global Price List | Authorization to access, active or not | Employees, contractors, third parties with credentials | Yes, in full |
| HNU per month | Global Price List | Peak authorized headcount in the calendar month | Same, measured at the worst moment | Yes, and a spike sets the month |
| Hosted Employee | Metric Descriptions for Fusion Offerings | Every Person tracked in the service that month | All Person Types including Agents, Contractors, Consultants; Retiree and Not Managed by HR excluded | Irrelevant, roles do not change the count |
| Privilege-based measurement | Metric Descriptions for Fusion Offerings | Assignment of a named manage-type privilege | Only holders of the enumerated privileges, each counted once | No |
The table shows a mismatch. What it cannot show is that the mismatch is an asset or a liability depending entirely on which document you cited first.
Oracle's field organization will quote the HNU definition in a renewal conversation and the privilege list in a technical usage review, and both citations are honest, because Oracle wrote both.
In 25 years of these negotiations, the pattern is consistent: whichever reading produces the larger invoice is the one that arrives in writing.
The reconciliation you want is not philosophical, it is documentary.
Oracle's own Advisory Note on Subscription Impact, published in the Financials and Procurement Security Reference for 25C, 26A and 26B, states that assigning predefined roles as-is may impact subscription usage even for services you have not purchased.
And that privileges assigned but never used still account for subscription consumption.
That is Oracle conceding, in Oracle's documentation, that provisioning drives the number and that the remedy is role design. Use that.
It converts a contract argument you will probably lose into a configuration argument you can win, but only if the configuration was already correct on the measurement date.
Compare the exposure before you argue: the Hosted Employee versus Hosted Named User comparison often matters more than any read-only claim, because Hosted Employee ignores role design entirely.
What actually counts: approvers, inquiry viewers, and BI consumers
Take the three disputed populations in order of how hard they are to defend, because they are not equally defensible and pretending otherwise wastes your credibility on the one you might have won. Approvers are the loss.
An approval task in Financials Cloud writes to a transaction, and the seeded roles that permit it carry manage-type privileges, which is exactly what Oracle's measurement script looks for.
A cost center manager who approves twelve invoices a month registers identically to a full-time AP clerk under both the contract and the privilege count. Concede this population early, in writing, and price it at the $375 to $475 per user per month list band for core Financials before discount.
Arguing it makes every subsequent claim look opportunistic.
Pure inquiry viewers are winnable, conditionally. If someone copied the predefined role, stripped the manage privileges, and assigned only the custom result, the user holds none of the enumerated privileges and does not appear in Oracle's own count.
If they were handed the seeded role as-is, they do appear, and the fact that the person only ever ran a trial balance is legally irrelevant under an authorization-based definition.
Note which roles Oracle itself names as the worst offenders: Employee (ORA_PER_EMPLOYEE_ABSTRACT), Contingent Worker, and Application Implementation Consultant, the last being the classic post-go-live leak where implementation-era access was never unassigned.
Also check the low-cost path: self-service tiers list at roughly $50 to $100 per user per month against $375 to $475 for a core Financials seat, a four to eight times delta that makes the subledger and user-counting trap analysis worth reading before you accept a full-seat quote for a viewer.
BI and dashboard consumers are the population nobody budgeted.
Users who never sign into Fusion but consume Fusion-sourced data in Power BI, Tableau, or Oracle Analytics Server count under most Cloud Services Agreement interpretations of indirect access.
And in our experience this group is routinely two to five times larger than the named Financials population because distribution lists grow without governance.
The privilege-based script will not find them, since they hold no Fusion privileges, which is precisely why Oracle raises them contractually rather than technically.
Inventory every extract, integration, and published report against its recipient list now, decide whether each consumer needs Fusion-sourced detail or an aggregated derivative, and get the treatment of the aggregated case written into your ordering document.
Silence here is not safety, it is a deferred invoice.
The Oracle Core Factor Table: Counting Processors Right
Oracle licenses cores times a core factor, not raw cores. The 0.5 x86 factor, the worked counting, the virtualization trap, and where the factor does not apply.
Get the white paper →The privilege gap is the whole argument, and Oracle wrote both sides of it
Oracle has published two positions on read-only Financials access that cannot both be operationally true, and it published them from different buildings for different reasons.
The Fusion Cloud Service Descriptions and the August 6, 2026 Global Price List define a Hosted Named User as an individual authorized to access the hosted service, regardless of whether that individual is actively accessing it at any given time.
There is no view-only exception, no inquiry tier, no approver carve-out.
Meanwhile the Metric Descriptions for Oracle Fusion Offerings, refreshed June 12, 2026 on docs.oracle.com, counts Hosted Named Users per SKU by enumerated privilege: Revenue Management counts active users assigned VRM_MANAGE_REVENUE_PROCESSING_PRIV, Grants Management counts GMS_MANAGE_AWARD_PRIV.
Project Financials counts users assigned any of a listed set.
Every enumerated privilege in that document is a manage-type privilege. A user who holds only view privileges does not appear in Oracle's own measurement output.
This is not sloppiness. The contract exists to protect revenue in an audit, where Oracle wants the broadest possible definition and the burden on you to disprove it.
The documentation exists to protect renewals, support cases, and implementation velocity, where Oracle needs customers to be able to provision people without accidentally lighting up SKUs they never bought. Two audiences, two instruments, one gap between them.
After twenty-five years of negotiating with this vendor, I read that gap as deliberate architecture rather than an editorial slip, and I have never seen Oracle voluntarily reconcile it. The buyer who expects a clean answer from Oracle is asking the wrong party.
The consequence is that the read-only argument is never won by reading the definition differently. Oracle's definition reads exactly the way Oracle says it reads.
The argument is won by changing the facts the definition applies to, and the only way to do that is role surgery performed before anybody sends you a letter.
A buyer who copied the predefined inquiry role, stripped the manage privileges, and can show a privilege inventory dated eighteen months ago is not arguing about interpretation. That buyer is arguing about a measured number, and the measurement rules are Oracle's own.
Timing is the whole difference.
Do the surgery early and you have converted a contractual liability, roughly 400 authorized viewers at the $375 to $475 per user per month list band for core Financials, into a documented measurement position that produces zero for those users under Oracle's published per-SKU rules.
Do the surgery after the audit letter arrives and you have done two damaging things at once: conceded that the prior state was licensable, and created a remediation timeline that Oracle will read as a compliance event. LMS has seen that pattern thousands of times.
Retroactive role cleanup is not a defense, it is an admission with a date on it.
Oracle's own remedy language is the strongest thing in your file, and it is admissible against Oracle's audit theory.
The Advisory Note on Subscription Impact, shipped with the 25C, 26A, and 26B Financials and Procurement security references, states that assigning predefined roles and privileges as-is may impact subscription usage even where you have not purchased the subscription.
And that privileges assigned but unused can still account for consumption.
It then instructs you to copy the predefined role, remove privileges you do not need, and assign only what is required.
It names Employee, Contingent Worker, and Application Implementation Consultant as the top three subscription-impacting roles, and tells you to unassign Application Implementation Consultant once setup completes.
Oracle cannot tell you in product documentation that privilege removal reduces subscription consumption and then tell you in an audit finding that privilege composition is irrelevant because authorization alone governs.
Put both documents side by side in the same email to the same Oracle contact and watch the conversation change register.
So the leverage does not sit in the definition, and it does not sit in fairness. It sits in making the privilege inventory the only measurable fact in the room.
Pull the commercial measurement usage metrics from the OCI Object Storage bucket monthly, using the Fusion Applications Environment Read-Only User policy, so that the per-SKU privilege counts are yours before they are anybody else's.
Then anchor the metric conversation properly, because the choice between Hosted Employee and Hosted Named User determines whether privilege surgery pays at all.
Whoever controls the number controls the negotiation, and privileges are the only version of the number that Oracle has already agreed to in writing.
Role surgery: the four moves that shrink the count without breaking the close
The mechanics are unglamorous and entirely determinative. First, never assign a predefined role as-is to an inquiry population: copy it, then strip the manage privileges, following the instruction Oracle repeats in Role Copying or Editing (25C) and in its U.S.
Federal Financials year-end close guidance, which tells administrators to build their own roles from copies rather than provision predefined ones.
Second, use Oracle's Predefined Roles with Subscription Impact spreadsheet as the working checklist rather than a reference document; it is the only place Oracle enumerates which roles trigger consumption, and it should sit in your change-control process.
Third, unassign Application Implementation Consultant (ORA_ASM_APPLICATION_IMPLEMENTATION_CONSULTANT_JOB) the day setup ends, because Oracle itself concedes as-is assignment is appropriate only during setup and only where you bought every impacted service.
Fourth, consolidate duplicate inquiry roles: the Metric Descriptions rules state that a user holding more than one listed privilege counts once toward the service, so proliferating narrow roles inflates administrative risk without inflating the count, while sprawl makes your inventory unauditable.
Two failure modes destroy this work. Stripping a privilege the close depends on gets you a period-end escalation and a rollback to as-is under pressure, so test every stripped role against a full close cycle in a non-production pod first.
Letting a systems integrator reprovision predefined roles as-is during a quarterly update quietly restores the liability, so put role assignment on the change-control gate alongside the subledger and add-on module counting traps.
| Move | Oracle source | Failure mode if skipped |
|---|---|---|
| Copy predefined role, strip manage privileges | Role Copying or Editing, 25C; Federal close guidance, 24C | Every inquiry viewer registers in the per-SKU privilege count |
| Work from Predefined Roles with Subscription Impact | Advisory Note on Subscription Impact, 26A | Unknown roles consume SKUs you never purchased |
| Unassign Application Implementation Consultant post-setup | Advisory Note, 26A | Classic post-go-live leak, admins counted at full Financials rates |
| Consolidate duplicate inquiry roles | Metric Descriptions, June 12, 2026 | Unauditable sprawl, no defensible inventory at audit |
The table lists four moves, but their value is almost entirely sequential rather than additive.
Steps one and three cut the measured count; step two tells you where to aim; step four is what makes your position provable eighteen months later, when the person who did the surgery has left and Oracle asks how you arrived at your number.
Note also what the table cannot show: the difference between a role design that is correct and one that is documented as correct on a date.
Same privilege inventory, same measured zero, but only the dated version survives contact with an audit, because Oracle will otherwise argue the strip happened after notice.
Evidence base: what the documents say and where disputes recur
Six documents carry this argument, and you should have all six in the same folder before you speak to Oracle.
The Oracle Fusion Cloud Service Descriptions and the Global Price List of August 6, 2026 supply the contractual definition: a Hosted Named User is an individual authorized to access the service regardless of whether that individual is actively accessing it.
The ordered quantity is a maximum rather than an average, and for the per-month variant the peak count at any time during the calendar month determines compliance.
The Metric Descriptions for Oracle Fusion Offerings of June 12, 2026 supplies the counter: measurement is privilege-based per SKU, and the enumerated privileges are manage-type (VRM_MANAGE_REVENUE_PROCESSING_PRIV, GMS_MANAGE_AWARD_PRIV.
And the Project Financials privilege list), with a user holding several listed privileges counted only once.
The Advisory Note on Subscription Impact across the 25C, 26A, and 26B releases is Oracle admitting in writing that assigning predefined roles as-is may impact subscription usage even where the subscription was never purchased.
And that unused assigned privileges still consume. Role Copying or Editing (25C) repeats the warning at the point of role creation, and Commercial Measurement Usage Metrics tells you where Oracle's own numbers live.
Across renewal and audit engagements, the same four patterns recur. Predefined roles assigned as-is at go-live, never revisited, is the most common single cause of an inflated count.
Orphaned implementer accounts come second: Application Implementation Consultant is one of Oracle's own top three subscription-impacting roles, and it is supposed to be unassigned once setup completes. Third, provisioning spikes at period close and year-end reset the peak for the whole month.
Fourth, business intelligence consumption of Fusion-sourced data rarely enters anyone's user count until Oracle raises it.
In our experience the commercial measurement reports land in an OCI Object Storage bucket and go unread for years; pull them monthly, and pull twelve months before you open renewal talks. ::pctshold::
Core Financials lists at $375 to $475 per user per month against $50 to $100 for limited self-service users (ERP Research, June 2026).
List prices are the opening position; discount depth tracks deal size and timing, not user classification arguments alone.
The pattern behind all four disputes is identical: the count is set by provisioning decisions made by implementation staff who were never told that a role assignment is a purchase order.
Oracle's advisory note makes that link explicit, which is why it belongs in your evidence pack rather than theirs. Read it alongside our analysis of Hosted Employee versus Hosted Named User economics before you decide which metric you want to defend.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Pull twelve months of commercial measurement usage metrics before any renewal conversation, assigning the task to your Fusion environment administrator using the Environment Read-Only User policy, so you walk in knowing Oracle's own privilege-based number rather than reacting to it.
- Run a privilege inventory against Oracle's Predefined Roles with Subscription Impact spreadsheet, owned by the security administrator with a 30-day deadline, and flag every user whose only claim to a full seat is an as-is predefined role assignment rather than a manage-type privilege.
- Execute the role surgery and unassign Application Implementation Consultant from every account that is not actively performing setup, copying predefined roles and stripping unneeded privileges exactly as Oracle's advisory note instructs, and complete this before the audit letter arrives because retroactive remediation carries no contractual weight.
- Price the reclassified population into the $50 to $100 self-service tier and demand a written tier definition inside the ordering document, not a sales email, because the 4x to 8x delta against $375 to $475 Financials seats only survives if the entitlement language names the roles and privileges that qualify.
- Cap the Hosted Named User ceiling with a documented peak-management procedure, owned jointly by finance operations and IT security, so a close-week provisioning spike cannot reset the monthly peak that the price list says determines compliance.
The sequencing here is not optional. Every move after the first depends on knowing what Oracle's script already reports, and every move after the third depends on the role surgery being complete and evidenced by change tickets with dates.
A buyer who reclassifies users in the ordering document while leaving predefined roles assigned as-is has bought a contractual argument they cannot win, because Oracle's measurement will keep returning the higher number and the contract definition will back it.
The written tier definition is where the money actually sits.
Oracle sales will readily agree that inquiry users belong in the cheaper tier during a renewal conversation and then decline to define the tier in the ordering document, which leaves you paying self-service rates against a definition that only Oracle controls.
Insist that the qualifying role names, or the excluded privilege list, appear in the order itself. Our guide to subledger licensing and user counting traps covers the wording that has survived subsequent audits.
Frequently asked questions
Does a user who only views reports in Oracle Financials Cloud need a license?
Under the contractual Hosted Named User definition, yes: any individual authorized to access the service counts regardless of activity, and there is no read-only carve-out.
Under Oracle's own Metric Descriptions for Fusion Offerings, that user only registers if they hold one of the enumerated privileges for the SKU, and those are manage-type privileges.
In practice you are defensible only if the role was copied and stripped of the listed privileges before measurement, and you can evidence it.
Do approvers count as full Financials Cloud users?
Almost always yes. Approval workflows typically require a manage-type privilege on the relevant object, which is exactly what Oracle's measurement scripts count.
Treat approvers as full seats in your baseline and argue them into a cheaper tier only where the approval is genuinely handled through a limited self-service interface such as expenses.
What is the price difference between a full Financials seat and a self-service seat?
List pricing in 2026 runs $375 to $475 per user per month for core Financials and $50 to $100 for limited self-service access, with negotiated self-service typically $60 to $90. That is a 4x to 8x delta.
Most buyers negotiate 25 to 55 percent off list depending on volume and timing, so the absolute gap narrows but the ratio holds.
Is Hosted Named User measured on average or peak?
The ordering document number is a hard ceiling, not an average. For the per-month HNU variant, the August 6, 2026 Global Price List states that the peak number of Hosted Named Users at any time during the calendar month determines compliance.
A single day of over-provisioning during year-end close sets the number for that month.
Does Oracle admit that unused access still consumes subscription?
Yes, in writing.
The Advisory Note on Subscription Impact published in the 25C, 26A, and 26B Financials and Procurement documentation states that assigning predefined roles as-is may impact subscription usage even for services you have not purchased.
And that privileges that are assigned but never used can still account for subscription consumption.
That is Oracle-authored proof that provisioning drives the count.
Which predefined roles cause the most licensing leakage?
Oracle names three: Employee (ORA_PER_EMPLOYEE_ABSTRACT), Application Implementation Consultant (ORA_ASM_APPLICATION_IMPLEMENTATION_CONSULTANT_JOB), and Contingent Worker (ORA_PER_CONTINGENT_WORKER_ABSTRACT).
The implementation consultant role is the classic post-go-live leak because Oracle expects it to be unassigned once setup completes, and almost nobody does it.
Do Power BI or Tableau users pulling Fusion data need Financials licenses?
Under most Cloud Services Agreement interpretations, yes. Access through any interface, including report consumption from Fusion-sourced data delivered into Power BI, Tableau, or Oracle Analytics Server, falls inside the Hosted Named User definition.
Scope this population explicitly before renewal, because it is the most commonly omitted group in a buyer's own count.
How do I get Oracle's own usage numbers before a renewal?
Pull the commercial measurement usage metrics for your production Fusion environments.
Oracle documents per-SKU measurement in Metric Descriptions for Oracle Fusion Offerings and delivers usage reports to an OCI Object Storage bucket, accessible through the Fusion Applications Environment Administrator, Environment Administrator, or Environment Read-Only User policies.
Pull them monthly for at least twelve months before you open renewal talks.