Oracle made API Access Control available for Autonomous AI Database on Dedicated Exadata Infrastructure and Cloud@Customer on July 30, 2026. The feature adds a mandatory approval step for sensitive database management operations-restores, deletions, encryption key rotations, and infrastructure changes-so operations teams can enforce governance without slowing down routine administration.
Organizations running business-critical databases face a persistent tension: administrators need to respond quickly, but certain actions carry enough risk to warrant a second set of eyes. Autonomous AI Database automates much of the operational work, but lifecycle and configuration changes still require careful planning. A restore pointed at the wrong target, a premature termination, or an unverified encryption key rotation can affect availability, security, and capacity. Oracle API Access Control inserts an approval workflow directly into that gap.
How the approval workflow operates
The feature complements OCI Identity and Access Management rather than replacing it. IAM determines who can manage cloud resources. API Access Control adds a second authorization step for operations an organization considers especially sensitive. Even users with the necessary IAM permissions cannot invoke selected privileged APIs until an authorized approver grants time-bound approval.
A security administrator designates which operations require approval and associates them with specific Autonomous AI Database resources. When a database administrator needs to perform one of those operations, they submit an access request that includes the target resource, the operation, the requested execution window, and a business justification. An approver reviews the request. The operation proceeds only after approval and only within the approved time window.
This creates a clear separation between requesting a sensitive action and authorizing it. For AI for Operations workflows, that separation is particularly valuable in production environments where change control matters but speed still counts.
Which operations can be governed
Not every administrative action carries the same risk. API Access Control lets organizations focus approval workflows on the operations that deserve additional oversight. For Autonomous AI Database deployments, customers can govern operations involving database restores, deletions, start and stop, administrator password changes, encryption key rotation, scaling, and configuration updates. At the container level, governed operations include restarts, Data Guard operations, standby management, termination, and key rotation. Infrastructure changes-lifecycle management, capacity adjustments, certificate rotation, ORDS management, maintenance settings, and networking configuration-can also require approval.
Consider a production database restore. A database administrator may already hold IAM permission to perform it, but the organization might want another engineer or security administrator to verify the target database, restore point, and maintenance window before the operation proceeds. API Access Control supports that workflow without forcing administrators to surrender permissions they need for day-to-day work.
Separation of duties and auditability
Security administrators designate approval groups separate from the users requesting privileged operations. Approvers evaluate requests based on who is requesting access, which resource will be affected, the specific operation, the business justification, and the requested duration. Organizations can require multiple approvals for high-impact actions such as deleting production databases or making infrastructure-wide configuration changes.
The approval workflow is enforced by the service itself. Sensitive operations cannot bypass the process simply because a user holds broad administrative permissions. Every request, approval, rejection, extension, and revocation becomes part of an auditable record, giving security teams visibility into who did what and why. For teams managing AI for IT & Development infrastructure, this audit trail helps demonstrate compliance with internal governance policies and regulatory requirements.
The feature is available for Autonomous AI Database on Dedicated deployments across OCI Public Cloud, Exadata Cloud@Customer, Oracle Database@AWS, and Oracle Database@Azure.
Why this matters for Operations
Operations teams get a practical tool that enforces least-privilege governance without introducing friction for routine administration. You can start by protecting the handful of operations that would cause the greatest business impact if performed incorrectly-production restores, database deletions, admin password changes, encryption key rotations-and expand coverage as your team adapts to the workflow. The result is a governance model where critical actions are performed by the right people, for verified reasons, within approved time windows, with a complete audit record attached.
Your membership also unlocks: