Glossary Oracle EPM & Hyperion services

What Is EPM Cloud Deployment Architecture?

Oracle EPM Cloud deployment architecture defines how Oracle's cloud EPM applications — PBCS, FCCS, ARCS, Narrative Reporting — are provisioned, connected, and governed across an enterprise's IT environment. For IT directors and EPM architects, deployment architecture decisions made at provisioning…

Oracle EPM Cloud deployment architecture is the complete technical design of how Oracle EPM Cloud services are provisioned, connected, and integrated within an enterprise’s broader IT environment — covering the Oracle Cloud Infrastructure (OCI) region selection, the identity and access management configuration, the number and types of environments provisioned, the integration architecture connecting EPM Cloud to on-premise or other cloud systems, the data residency and network routing configuration, and the governance framework for the deployed environment. Deployment architecture decisions are made once at provisioning time and are constrained by Oracle’s SaaS delivery model — changing the OCI region, the identity domain structure, or the tenant configuration after provisioning typically requires provisioning a new environment and migrating the existing configuration, not modifying the existing deployment in place.

Core Deployment Architecture Decisions

Decision Options Implication if Wrong
OCI Region Saudi Arabia (Jeddah, Riyadh); UAE (Abu Dhabi, Dubai); US, EU, AP regions Data residency non-compliance; latency for GCC users if non-GCC region; cannot change without full environment migration
EPM Cloud service type PBCS, EPBCS, FCCS, ARCS, Narrative Reporting — separately subscribed Missing features if wrong service subscribed; cannot add modules to wrong service type
Environment count Production + Test (standard); Dev + Production + Test (enhanced) Insufficient testing environments for complex organisations; additional environments require subscription changes
Application framework (PBCS) Classic vs Next Gen Irreversible without application rebuild; missing features if Classic chosen when Next Gen needed
Identity domain New domain vs existing domain; SAML federation vs native auth SSO not functioning; MFA policy not enforced; loss of admin access if single admin account
EPM Integration Agent Required for on-premise data source connections Cannot connect to on-premise ERP without Agent; file-based workaround required

Multi-Application EPM Cloud Architecture

For GCC enterprises deploying multiple Oracle EPM Cloud applications — EPBCS for planning and FCCS for consolidation being the most common combination — the deployment architecture must address how data flows between the applications and how user provisioning is managed across them. Data flows from EPBCS (where planning data is entered and budget approval workflows run) to FCCS (where statutory consolidation is executed) through a data push or data integration connection — this inter-application connection must be designed and configured as part of the deployment architecture, not discovered as a requirement after each application is provisioned independently. User provisioning spans both applications through the same identity domain — a user provisioned in EPBCS needs separate provisioning in FCCS if they require access to both, through the same IDCS identity domain.

Network Architecture for GCC Deployments

EPM Cloud user access is delivered over HTTPS from Oracle Cloud to the user’s browser — no VPN is required for standard EPM Cloud access, which is one of the operational advantages of the cloud model. However, for EPM Integration Agent connectivity — where the on-premise agent makes outbound HTTPS connections to Oracle Cloud — the enterprise’s proxy server configuration and outbound firewall rules must permit HTTPS traffic to Oracle’s OCI regional endpoints. GCC enterprises with strict outbound proxy configurations — common in financial institutions regulated by SAMA or the UAE Central Bank — must whitelist Oracle’s EPM Cloud URLs for the EPM Integration Agent to function. The whitelist requirements are documented in Oracle’s EPM Agent deployment guide and should be coordinated with the network security team before Agent deployment begins.

What Goes Wrong in Practice

The most consequential EPM Cloud deployment architecture error — with no straightforward remediation — is provisioning the OCI region without verifying the data residency requirement of the organisation’s regulatory environment. A SAMA-regulated Saudi financial institution that provisions its Oracle EPM Cloud tenancy in Oracle’s US East region (because it was the default in the provisioning interface) has a deployed EPM environment that stores financial data outside Saudi Arabia’s territory — a potential NCA and SAMA compliance issue that cannot be resolved by configuration change, only by deprovisioning and reprovisioning in the Saudi Arabia OCI region and migrating all configuration and data.

How Loop Wise Solutions Designs Deployment Architecture

We produce an EPM Cloud deployment architecture document as the first deliverable of every Oracle EPM Cloud implementation engagement — before any environment is provisioned. This document specifies every architecture decision listed above, documents the rationale for each decision, and is reviewed and approved by the client’s IT security, compliance, and finance leadership before provisioning begins. Changes after provisioning are significantly more expensive than getting the architecture right at the outset.

← Back to glossary

Need help implementing EPM Cloud Deployment Architecture?

Our team works with enterprise organizations across Egypt and the GCC. Tell us about your situation.