Oracle's Construction and Engineering audits target specific measurement points that generic playbooks miss: named-user dictionaries, Unifier Collaborator classifications, and restricted-use middleware. This page names each record Oracle pulls, where your exposure sits, and what to fix before the scripts run.
Oracle's Construction and Engineering audits target specific measurement points that generic playbooks miss: named-user dictionaries, Unifier Collaborator classifications, and restricted-use middleware. This page names each record Oracle pulls, where your exposure sits, and what to fix before the scripts run.
After 25 years across the negotiating table from this vendor, I can tell you the Primavera and Unifier estate does not audit like the database estate. There are no processor cores to count, no Enterprise Edition options quietly enabled by a DBA. The exposure lives in people: named user dictionaries, Unifier license-type assignments, and shared logins that construction firms treat as harmless. Oracle's Construction and Engineering Global Business Unit (CEGBU) products are licensed per user under the Application User metric, and the audit is built to reconcile every unique human against your entitlement.
That distinction matters for scope control. When an Oracle audit letter arrives, the first 30 days should be spent understanding which measurement points Oracle can legitimately reach in Primavera and Unifier, not generically preparing for USMM. The framing sits inside the broader Oracle Construction and Engineering licensing model, but the audit mechanics deserve their own analysis because the records Oracle requests are product-specific and the traps are not obvious from the ordering document.
In a CEGBU audit the exposure is not in the cores. It is in the user dictionary, and Oracle knows exactly where to look.
Primavera on-premise products are licensed under Oracle's Application User metric, which is practically identical to Named User Plus: every individual who accesses the software must hold a license (Atonement Licensing, May 2025). There is no concurrent-user or device-based metric. Oracle formally abandoned concurrent licensing for these products; each license now pertains to a unique user identity (P6 Consulting, December 2024). This is the single most expensive misunderstanding in the construction sector, because so many buyers bought under legacy concurrent assumptions and never re-read the metric.
A worked example from the field makes the risk concrete. A construction company assumed its 20 Primavera P6 licenses were concurrent, when roughly 30 individuals used the system and some shared logins. In audit, Oracle's user lists revealed 30 named accounts, cited the named-individual policy, and forced the purchase of 10 additional licenses plus back support fees, with an immediate order to stop account sharing (Atonement Licensing, May 2025). Shared logins do not reduce your count. They increase your risk, because Oracle treats a shared account as evidence of undercounted named users. Our Primavera P6 compliance guidance walks through mapping the named-user gap before the scripts ever run.
One bundling rule works in the buyer's favor and should be defended: a P6 EPPM license grants the named user the right to use both the P6 Professional client and the P6 Web interface (and related components). Oracle does not license P6 Professional separately from P6 EPPM for the same user (Atonement Licensing, May 2025). If an auditor tries to count Professional and Web access as two consumption events for one person, that is a claim to reject on the entitlement text.
Unifier is where the audit gets granular, and where most self-inflicted exposure hides. Unifier distinguishes license-bearing user types, and its own audit facility records every classification change. If you make a user a Contractor by assigning the Contractor User Type in Primavera Administration, that user consumes a Collaborator license. Any other classification (Employee, Intern, Temp, External, Service, Generic) consumes a Standard license (Oracle Unifier Admin Guide). Oracle's auditors know the mapping and will reconcile your Standard versus Collaborator claims against the actual user table.
The Contractor user type is reserved. Oracle's General Administration Guide (Version 24, October 2025) states plainly that the Contractor type is reserved for the Collaborator user type of Unifier, and must not be used for any user that would otherwise count toward a Standard license. That instruction cuts both ways in audit: misclassifying a full-function user as a Contractor to dodge a Standard license is precisely the pattern Oracle looks for, and the misuse is discoverable because Collaborator license changes are captured in the Audit Log tab, whether the change came through the Partner User screen, a CSV import, or a REST API call (Oracle Unifier General Administration Guide, Version 24).
Collaborator users carry functional constraints Oracle can test against your entitlement claims. A Collaborator can be granted view-only permission to existing user-defined and custom reports, and permission to create UDRs, with all license constraints in place (Oracle Unifier Admin Guide). If an auditor finds a Collaborator-classed user performing Standard-level functions, expect a reclassification claim and a demand for Standard licenses. The counting of external contractors is complex enough that we treat it separately in counting external contractors in Primavera and Aconex, and the records trap is examined further in the Primavera Unifier named-user and records analysis.
Legacy on-premise Unifier carries an AutoVue trap worth flagging. The number of unique Unifier application users must match the number of AutoVue 2D Professional application user licenses, and the Unifier minimum quantity applies to AutoVue as well (Unifier Licensing Information User Manual, Version 21, December 2021). If your Unifier user count grew and AutoVue did not, that is a one-to-one shortfall Oracle can quantify instantly.
P6 EPPM exposes measurement points that are, in effect, purpose-built for a compliance claim. The most important is the historic count of unique users who have ever logged into the system. Oracle's documentation confirms this count records one entry per unique user who has logged in, and will never exceed the total in the user dictionary (Oracle Primavera Administration, P6 EPPM Metrics, December 2025). This is the figure that most often exceeds a buyer's license count, because departed employees, one-time reviewers, and test accounts all leave a footprint.
P6 also tracks live session counts based on module access permissions (Oracle Primavera Administration, P6 EPPM Metrics). That live figure can help a buyer demonstrate actual concurrent use, but it does not override the named-user metric. Do not let an auditor use the historic login count as the sole basis of a claim without reconciling it against your dictionary, because the two numbers answer different questions. The historic count includes users who no longer have accounts; the dictionary is the population Oracle is entitled to license.
| Measurement point | Product | What it proves | Buyer action |
|---|---|---|---|
| User dictionary count | P6 EPPM / Unifier | Population of named accounts | Purge stale accounts before collection |
| Historic unique-login count | P6 EPPM | Every user who ever logged in | Reconcile against dictionary; challenge departed users |
| Live session count by module | P6 EPPM | Actual concurrent access | Use to evidence real use, not entitlement |
| Collaborator vs Standard classification | Unifier | License-type consumption | Verify Contractor type used only for Collaborators |
| Unifier Audit Log tab | Unifier | History of license-type changes | Review for reclassification patterns |
| AutoVue 2D user count | Unifier (legacy) | 1:1 match to Unifier users | Confirm parity or expect a shortfall claim |
The historic login count is the number that ends careers. Reconcile it against the dictionary before Oracle does it for you.
P6 EPPM ships with restricted-use middleware, and that restriction is where a scheduling deployment quietly becomes a full-use liability. The Unified Business Process Management Suite and its prerequisites (SOA Suite for Oracle Middleware and WebLogic Suite) are restricted to licensed Primavera users who consume or participate in Primavera workflows. Any user who needs to change or create new workflows requires a full-use license of the BPM Suite and its prerequisites (P6 EPPM Licensing Information User Manual, Version 25). There is no minimum named-user requirement for full use, which means a single user modifying a workflow triggers full-use exposure across the stack.
Two adjacent traps sit in the same manual. Attempts to modify Primavera portals likewise trigger a full-use license (P6 EPPM LIUM, Version 25). And Oracle Analytics Publisher (formerly BI Publisher) is valid only for scheduling, processing, and running reports; any user who customizes or creates new reports needs a full-use license, again with no minimum named-user requirement (P6 EPPM LIUM, Version 25). These are the kinds of restricted-use boundaries Oracle enforces routinely, and the mechanics of defending them are the same as any embedded scope fight. The pattern is examined in our Oracle ESL audit defense and, on the database side, in the restricted-use database hiding under P6 EPPM.
Do not confuse having the middleware installed with using it in a full-use manner. Restricted use is a permitted state. The claim only crystallizes when a user creates or modifies a workflow, portal, or report. In audit, the burden is on Oracle to show the triggering activity, not merely the presence of SOA Suite or WebLogic in the deployment.
Oracle's audit is run by License Management Services, now branded Global Licensing and Advisory Services (GLAS). The primary tooling is the Universal Script for Measuring and Monitoring (USMM), supplemented by the Oracle LMS diagnostic scripts and the Review Lite tool (Oracle Licensing Experts, March 2026). For the CEGBU estate, LMS SQL collection scripts extract user counts and feature usage history from the P6 EPPM and Unifier databases (Redress Compliance, August 2025). That output is the raw material of the compliance claim.
The critical discipline: raw script output overstates exposure. LMS scripts report installed programs, enabled options, and feature usage history, and they do not separate entitled use from accidental or default-enabled use (Redress Compliance, March 2026). In a Primavera context that means the historic login count, dormant accounts, and restricted-use middleware presence all appear as apparent liability until reconciled. Never submit raw script output. Reconcile it first, remove departed users, and separate restricted from full use, exactly as we counsel in the 22 Oracle license audit secrets.
Understand also what the data does after the audit. LMS collection captures more than compliance data: hardware topology, deployment patterns, application architecture, and usage trends flow to Oracle's sales team and inform the next renewal, the ULA proposal, and the cloud migration pitch (Oracle Licensing Experts, March 2026). In construction accounts this frequently becomes a push toward Primavera Cloud. Judge that move on economics, not audit pressure, using our comparison of Primavera Cloud versus P6 EPPM at scale.
Preparation is not passive. Based on repeated CEGBU engagements, the buyer-side sequence that holds up is the following.
Where the leverage sits: the buyer controls the reconciliation, and Oracle's raw scripts overstate. The compliance gap on a CEGBU audit is almost always smaller than the first draft findings suggest, provided you purge stale users, defend the P6 bundling rule, and refuse to concede restricted-use middleware without evidence of a triggering action. If the compliance position is weak and the estate is stable, the settlement math may also point toward independent maintenance, which we assess in Primavera and Unifier third-party support. The goal is not to win the audit on principle. It is to convert an inflated draft finding into a defensible, quantified position before it becomes a renewal or a cloud subscription you did not choose.
Named. Oracle licenses Primavera on-premise products under the Application User metric, which functions like Named User Plus: every unique individual who accesses the software needs a license. Oracle formally abandoned concurrent licensing for these products, so shared logins increase risk rather than reducing count.
Oracle reviews the user table and license-type classifications (Standard versus Collaborator), the Unifier Audit Log tab that records every license-type change, and whether the reserved Contractor user type is used only for genuine Collaborators. Misclassifying a full-function user as a Contractor to avoid a Standard license is a pattern auditors specifically look for.
No. Each module is licensed separately. A P6 license does not cover Unifier and a Unifier license does not cover P6. If you deploy both, you must license the users of each product independently, and cross-usage without proper entitlement is a common audit finding.
P6 EPPM records the total historic count of unique users who have ever logged in, with one entry per unique user. It matters because departed employees, one-time reviewers, and test accounts all leave a footprint, so this count often exceeds your licensed population. Reconcile it against the current user dictionary before Oracle uses it as the basis of a claim.
Installation alone does not. The middleware ships as restricted use for Primavera workflow participation. The full-use liability crystallizes only when a user creates or modifies a workflow, modifies a Primavera portal, or creates or customizes reports in Analytics Publisher. In audit, Oracle must show the triggering activity, not merely the presence of the software.
Submitting raw LMS script output without reconciliation. The scripts overstate exposure because they do not separate entitled use from accidental or default-enabled use. Purge stale users, eliminate shared logins, verify Unifier classifications, and separate restricted from full use before any data leaves your environment.
The strategic framework for Oracle audit defense across LMS, license verification, and contractual response. Beyond the tactical playbook.
Gated with a work email on the download page. No sales follow up you did not ask for.
Get the White Paper →500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.