BRING YOUR OWN CLI AGENT
Ask Oracle in plain language.
Act through a governed plan.
Codex. Claude Code. Whatever agent is already open in your terminal.
It reads your Oracle data through typed, bounded commands.
Reads run freely, within limits. Every write stops at a plan until you confirm it yourself.
What it replaces
An invoice is on hold. Open it. Find the hold. Check the supplier. Check it’s even releasable. Decide. Click through. Again tomorrow.
The judgement was always yours. The clicking never was.
Ask it anything
- Why is invoice SYN-INV-1007 blocked?
- Who owns approval for expense report SYN-EX-42?
- Why can worker SYN-P-204 not sign in?
- What is the status of purchase order SYN-PO-800?
It picks the workflow, checks your profile and environment, asks Oracle for only the fields it needs, and tells you plainly when there is no match, more than one, or no access.
Ask it to act, and it can’t
It can only draft a plan.
- One target. Bound to your profile, environment, Oracle origin, actor, workflow and payload.
- Ten minutes. Single use. Tamper-evident.
- Your confirmation. Typed into your terminal. No flag, no environment variable, no agent can supply it.
- Verified. State re-read before the write, business result re-read after. An HTTP 200 is not success.
What it can do
| Area | It can prepare |
|---|---|
| Invoices | Release one eligible hold |
| Expense approvals | Reassign one approval |
| Worker and account | Allow-listed field or manager change, link, suspend, reactivate |
| Data security | Add or deactivate one allow-listed grant |
| Employee self-service | Submit one allow-listed definition |
| BI Publisher | One allow-listed catalogue-object change |
| Purchase orders | Read-only |
| SQL diagnosis | Read-only |
What it will never do
- Write anything without your typed confirmation
- Delete or recreate a worker
- Touch bank accounts
- Run on a schedule, or unattended
- Treat Oracle text as an instruction
Your Oracle security still decides
It uses the dedicated Oracle identity in your profile and cannot follow credentials to another host. Roles and data access rule exactly as they did before.
Your model provider sees your prompts and the bounded, redacted results you share. Credentials, plans and audit stay on your machine. See the data flow.
Try it for 30 days
AI Administrator is in every plan. So are the CLI and SQL Studio.
Real SQL. ESS jobs in cron. Swiss QR-bill invoices, cleared.
No card. Nothing renews.
