slug: oracle provider: Oracle generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Banking & Capital Markets - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 119 edges: - tag: dataScience spec_file: oracle-datascience-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.92 evidence: '"organize your data science work, access data and computing resources, and build, train, deploy and manage models and model deployments"' reason: Operations manage projects, models, model deployments, pipelines and compute targets for ML — squarely AI/ML model lifecycle and MLOps under Artificial Intelligence Management. - tag: vulnerabilityScanning spec_file: oracle-vulnerability-scanning-api-openapi.yml reanchored_from: oracle-vulnerabilityscanning-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.92 evidence: Use the Vulnerability Scanning Service (VSS) API to manage scan recipes, targets, and reports ... ListContainerScanResults reason: Host and container vulnerability scanning with results and CIS benchmark scores is Vulnerability Management. - tag: blockstorage spec_file: oracle-blockstorage-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: Use the Core Services API to manage resources such as virtual cloud networks (VCNs), compute instances, and block storage volumes reason: Block volume, boot volume and backup lifecycle management — clearly cloud storage infrastructure management. - tag: compute spec_file: oracle-compute-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: '"Use the Core Services API to manage resources such as virtual cloud networks (VCNs), compute instances, and block storage volumes" — AttachBootVolume, Shape, ConsoleHistory' reason: Provisioning and lifecycle of compute instances, images and block volume attachments is cloud compute/storage infrastructure management. - tag: fileStorage spec_file: oracle-file-storage-api-openapi.yml reanchored_from: oracle-filestorage-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: '"Use the File Storage service API to manage file systems, mount targets, and snapshots."' reason: Provisioning and managing cloud storage resources is squarely IT infrastructure management. - tag: identity spec_file: oracle-identity-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: Use the Identity and Access Management Service API to manage users, groups, identity domains, compartments, policies reason: 'Explicit IAM surface: users, groups, policies, auth tokens — identity and access management.' - tag: identityDomains spec_file: oracle-identitydomains-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: Use the Identity Domains API to manage resources within an identity domain, for example, users, dynamic resource groups, groups, and identity providers. reason: User, group, identity provider and credential administration — identity and access management. - tag: sddc spec_file: oracle-sddc-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: '"Creates an SDDC", "ListSupportedHostShapes Lists supported compute shapes", schemas SddcSummary, DatastoreInfo, VsphereLicense' reason: Software-defined data centre (VMware Solution) provisioning — compute, datastore, host shapes. Plainly IT infrastructure management. - tag: virtualNetwork spec_file: oracle-virtualnetwork-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.9 evidence: Use the Core Services API to manage resources such as virtual cloud networks (VCNs), compute instances, and block storage volumes reason: Virtual cloud network, gateway, IP range and circuit management is core cloud network infrastructure management. - tag: AIServiceDocument spec_file: oracle-aiservicedocument-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: POST /actions/analyzeDocument 'Perform document analysis.'; POST /models CreateModel 'Creates a new model .'; POST /processorJobs 'Create a processor job for document analysis.' reason: Custom and pretrained ML model lifecycle (create, update, delete models, projects, inference jobs) for document understanding — AI/ML model lifecycle and MLOps. - tag: AIServiceLanguage spec_file: oracle-aiservicelanguage-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: '''OCI Language Service solutions can help enterprise customers integrate AI into their products ... using our proven, pre-trained and custom models''; POST /actions/batchDetectLanguageSentiments' reason: NLP inference plus model/project/endpoint lifecycle management — squarely AI/ML model lifecycle and delivery, an Information & Data Management capability. - tag: AIServiceVision spec_file: oracle-aiservicevision-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: POST /actions/analyzeImage 'Perform image analysis.'; POST /models CreateModel; 'Pretrained models and custom models are supported.' reason: Computer-vision inference plus custom model/project lifecycle management — AI/ML model lifecycle (MLOps) capability. - tag: ClusterPlacementGroupsCP spec_file: oracle-clusterplacementgroupscp-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: API for managing cluster placement groups. ... CreateClusterPlacementGroup Creates a new cluster placement group. reason: Control-plane lifecycle management of compute cluster placement groups — cloud infrastructure resource management. - tag: DistributedAutonomousDbService spec_file: oracle-distributedautonomousdbservice-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: Create a Globally distributed autonomous database. ... ConfigureDistributedAutonomousDatabaseSharding Configure sharding reason: Provisioning and configuration (sharding, GSM, backup config) of distributed database instances — database/infrastructure platform management. - tag: DistributedDbPrivateEndpointService spec_file: oracle-distributeddbprivateendpointservice-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: CreateDistributedDatabasePrivateEndpoint Creates a DistributedDatabasePrivateEndpoint. reason: Lifecycle management of private network endpoints for distributed databases — cloud network/infrastructure resource management. - tag: GenerativeAi spec_file: oracle-generativeai-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.85 evidence: Use the Generative AI service management API to create and manage dedicated AI clusters, endpoints, custom models ... create a custom model by fine-tuning an out-of-the-box model using your own data reason: Operations manage LLM model lifecycle, fine-tuning, hosting clusters and endpoints — squarely AI/ML model lifecycle management (MLOps). - tag: apmSynthetic spec_file: oracle-apmsynthetic-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.85 evidence: '''Use the APM Availability Monitoring API to query Scripts, Monitors, Dedicated Vantage Points and On-Premise Vantage Points resources''; ''CreateMonitor'', ''GetMonitorResult ... har, screenshot, log, network, diagnostics''' reason: Synthetic availability monitors executed from vantage points are precisely synthetic monitoring under Observability Management. - tag: computeCloudAtCustomer spec_file: oracle-computecloudatcustomer-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"Use the Compute Cloud@Customer API to manage Compute Cloud@Customer infrastructures and upgrade schedules" — CreateCccInfrastructure, CccInfrastructureNetworkConfiguration' reason: Manages on-premises cloud infrastructure resources and their upgrade schedules — infrastructure lifecycle management. - tag: computeManagement spec_file: oracle-computemanagement-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"CreateClusterNetwork", "CreateInstanceConfiguration", schemas InstancePoolSummary, AttachLoadBalancerDetails' reason: Instance configurations, instance pools and cluster networks are compute infrastructure provisioning and scaling constructs. - tag: containerEngine spec_file: oracle-containerengine-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"API for the Kubernetes Engine service ... Use this API to build, deploy, and manage cloud-native applications"; "CreateCluster Create a new cluster.", "CreateNodePoolNodeConfigDetails"' reason: Provisioning and lifecycle management of Kubernetes clusters and node pools is cloud compute infrastructure management (IT Infrastructure Management). - tag: containerInstance spec_file: oracle-containerinstance-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"CreateContainerInstance Creates a new ContainerInstance", "StartContainerInstance Starts an inactive container instance.", "ListContainerInstanceShapes"' reason: Creating, starting, stopping and sizing container compute instances is cloud compute/infrastructure provisioning, i.e. IT Infrastructure Management. - tag: datainfracc spec_file: oracle-datainfracc-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"Use this API to manage Data Infrastructure VM clusters, Application VMs, and related resources"; "Scale storage for the given infrastructure"' reason: Provisioning, activation, validation and scaling of on-premises cloud infrastructure (VM clusters, storage, networks) is IT Infrastructure Management. - tag: dataplane spec_file: oracle-dataplane-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /actions/generateScopedAccessToken GenerateScopedAccessToken Get a scoped-access security token. reason: Operations issue security tokens for authenticated principals — identity and access management (cross-industry IT security). - tag: datastore spec_file: oracle-datastore-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: CreateDatastore Creates a Datastore ... AddBlockVolumeToDatastore Add Block Volume to the provided Datastore reason: VMware solution storage datastore provisioning is cloud/storage infrastructure management, not a business capability of any industry. - tag: datastoreCluster spec_file: oracle-datastorecluster-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: AttachDatastoreClusterToEsxiHost Attach Datastore Cluster to the provided ESXi Hosts reason: Managing VMware datastore clusters and ESXi host attachment is compute/storage infrastructure management. - tag: disasterRecovery spec_file: oracle-disaster-recovery-api-openapi.yml reanchored_from: oracle-disasterrecovery-api-openapi.yml capability_id: BC-160.20 capability_id_l1: BC-160 capability_name: Disaster Recovery Management confidence: 0.85 evidence: '"Use the Full Stack Disaster Recovery (DR) API to manage disaster recovery for business applications" / "CreateDrPlanExecution Execute a DR plan."' reason: DR protection groups, DR plans, plan verification and plan executions across infrastructure, database and application layers are squarely IT/operational disaster recovery management. - tag: esxiHost spec_file: oracle-esxihost-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"ListEsxiHosts Lists the ESXi hosts in the specified SDDC", "IncreaseHostOcpuCount Increase the OCPU count of the specified ESXi host", "ReplaceHost Replace a faulty ESXi host whose underlying bare metal is broken"' reason: Lifecycle of virtualisation hosts / bare-metal compute in a cloud SDDC is IT infrastructure management. - tag: loadBalancer spec_file: oracle-load-balancer-api-openapi.yml reanchored_from: oracle-loadbalancer-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"API for the Load Balancing service. Use this API to manage load balancers, backend sets, and related items"; CreateLoadBalancerDetails, BackendHealth, SSLConfiguration' reason: Provisioning and configuration of network load balancers, listeners, backend sets and certificates is core cloud network infrastructure management. - tag: objectStorage spec_file: oracle-object-storage-api-openapi.yml reanchored_from: oracle-objectstorage-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"CreateBucket Create Bucket"; "BatchDeleteObjects Deletes a batch of objects."; "CreateReplicationPolicyDetails"' reason: Bucket, object, namespace and replication management is cloud storage infrastructure — IT Infrastructure Management. - tag: postgresql spec_file: oracle-postgresql-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"Use the OCI Database with PostgreSQL API to manage resources such as database systems, database nodes, backups, and configurations"; schemas DbSystemDetails, StorageDetails, ShapeOcpuOptions' reason: Provisioning and operating managed database systems, nodes, storage and backups is cloud/database infrastructure management, not a business-domain capability. - tag: roverCluster spec_file: oracle-rovercluster-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"CreateRoverCluster Creates a new RoverCluster"; schemas ShippingAddress, RoverWorkload, RoverNodeSummary' reason: Roving Edge clusters are physical edge compute appliances provisioned, updated and shipped to sites; the surface is compute/edge infrastructure provisioning, i.e. IT Infrastructure Management, not any industry business capability. - tag: roverNode spec_file: oracle-rovernode-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"CreateRoverNode Creates a new RoverNode"; "GetRoverNodeEncryptionKey Get the data encryption key for a rover node"; schema ShippingAddress' reason: Provisioning and lifecycle of Oracle Roving Edge physical compute nodes, including certificates and encryption keys — cloud/edge infrastructure management. - tag: s3ObjectStorage spec_file: oracle-s3objectstorage-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: '"GET Service (List Buckets)", "PUT Bucket (Create Bucket)", "GET Bucket (List Objects)"' reason: S3-compatible object storage bucket and object operations — this is storage infrastructure, squarely IT Infrastructure Management, with no business-domain meaning. - tag: threatintel spec_file: oracle-threat-intel-api-openapi.yml reanchored_from: oracle-threatintel-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.85 evidence: Use the Threat Intelligence API to search for information about known threat indicators, including suspicious IP addresses, domain names ... 'ListIndicators Get a list of threat indicator summaries based on the search criteria.' reason: Curated threat indicator and threat-type lookup is cybersecurity threat intelligence feeding detection and response operations. - tag: database spec_file: oracle-database-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: '"The API for the Database Service. Use this API to manage resources such as databases and DB Systems"; operations like CreateAutonomousContainerDatabase, ListApplicationVips' reason: Provisioning and lifecycle of database systems, VM clusters and VIPs is cloud/compute/storage infrastructure management, i.e. IT Infrastructure Management, not a data-governance or industry capability. - tag: privilegedApiControl spec_file: oracle-privilegedapicontrol-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: '"PrivilegedApiControl: This is created by the customer which defines which service apis are controlled and who can access it"' reason: Defining which privileged control-plane APIs are restricted and who may access them is privileged access / IAM policy management. - tag: privilegedApiRequests spec_file: oracle-privilegedapirequests-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: '"ApprovePrivilegedApiRequest Approves privilegedApi request"; "RevokePrivilegedApiRequest Revokes an already approved privilegedApi request"' reason: Request/approve/reject/revoke workflow for elevated access to privileged APIs is privileged access management within IAM. - tag: redisCluster spec_file: oracle-rediscluster-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: '"CreateRedisCluster Creates a new RedisCluster"; "ListRedisClusterNodes Gets a list of nodes in a cluster"; "A cluster is a memory-based storage solution"' reason: Provisioning and management of a managed in-memory cache cluster and its nodes is plainly cloud compute/storage infrastructure management. - tag: AIServiceSpeech spec_file: oracle-aiservicespeech-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: POST /actions/synthesizeSpeech 'Creates an audio for the given input text.'; POST /transcriptionJobs 'Creates a new Transcription Job'; CreateCustomization reason: Speech-to-text and text-to-speech inference with model customisation lifecycle — AI/ML service and model management rather than any contact-centre or business process capability. - tag: accessRequest spec_file: oracle-access-request-api-openapi.yml reanchored_from: oracle-accessrequest-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"Use the Managed Access API to approve access requests, create and manage templates, and manage resource approval settings."; HandleAccessRequest, RemindAccessRequest — "resend notifications to pending approvers"' reason: Request-and-approval workflow governing who may access cloud resources, i.e. access request/approval within identity and access management. Some ambiguity only in whether this is IAM or a broader governance sub-capability. - tag: accessRequests spec_file: oracle-access-requests-api-openapi.yml reanchored_from: oracle-accessrequests-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"Operator Access Control enables you to control the time duration and the actions an Oracle operator can perform on your Exadata Cloud@Customer infrastructure"; ApproveAccessRequest, RejectAccessRequest, RevokeAccessRequest, GetAuditLogReport' reason: Privileged-access approval, revocation and audit of operator access to infrastructure — classic PAM within identity and access management. Alternative reading as production-change/human-access authorisation keeps confidence at 0.8. - tag: cloudGuard spec_file: oracle-cloudguard-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.8 evidence: '"Use the Cloud Guard and Security Zones API to automate processes..." — schemas ResponderExecution, SightingImpactedResourceSummary, MitreDetails, RiskScoreAggregation' reason: Detector recipes, sightings, problems, responders and MITRE mappings are cloud security threat detection and automated response — SOC-style detection & response, not enterprise/financial risk. - tag: cluster spec_file: oracle-cluster-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Use the Oracle Cloud VMware API to create SDDCs and manage ESXi hosts and software" — CreateCluster, VsphereLicense, DatastoreDetails' reason: CRUD over VMware clusters/ESXi hosts within an SDDC is compute/storage infrastructure provisioning. - tag: dataSafe spec_file: oracle-datasafe-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"APIs for using Oracle Data Safe."; operations "ListAlertPolicies", "GetAlert", schemas "SqlFirewallViolationsCollection", "UpdateUnifiedAuditPolicyDetails", "AuditProfile"' reason: Database security service covering security policies, audit trails, alerts and SQL firewall violations — clearly Cybersecurity Management, but it spans governance, monitoring and data protection so no single L2 is named. - tag: dbManagement spec_file: oracle-dbmanagement-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.8 evidence: Use the Database Management API to monitor and manage resources such as Oracle Databases, MySQL Databases, and External Database Systems reason: Monitoring and administration of database estates is IT operations management. - tag: devops spec_file: oracle-dev-ops-api-openapi.yml reanchored_from: oracle-devops-api-openapi.yml capability_id: BC-4210 capability_id_l1: BC-4210 capability_name: Software Release & Deployment Management confidence: 0.8 evidence: '"configure code repositories, add artifacts to deploy, build and test software applications, configure target deployment environments, and deploy software applications" / "CreateBuildRun Start a code build run"' reason: Build pipelines, build runs, deploy stages and deploy environments are CI/CD and release/deployment tooling. L2 left null because the surface spans continuous integration, environment management and deployment orchestration simultaneously. - tag: dns spec_file: oracle-dns-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"API for the DNS service. Use this API to manage DNS zones, records, and other DNS resources." / "CreateResolverEndpoint"' reason: Zones, records, resolvers, resolver endpoints and steering policies are network infrastructure services — IT Infrastructure Management (network). - tag: dynamicSet spec_file: oracle-dynamicset-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.8 evidence: '"InstallPackagesOnDynamicSet Install packages on a dynamic set", "RebootDynamicSet", "UpdatePackagesOnDynamicSet" within "OS Management Hub API ... manage and monitor updates and patches for instances"' reason: Grouping of managed OS instances for package install/update/reboot is day-to-day IT operations and patch automation. - tag: fleetAppsManagement spec_file: oracle-fleetappsmanagement-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.8 evidence: '"Fleet Application Management provides a centralized platform to help you automate resource management tasks, validate patch compliance", "GenerateComplianceReport Request to generate Compliance Report for a Fleet"' reason: Fleet-level resource management, target discovery and patch-compliance reporting across IT estate is IT operations management. - tag: fleetAppsManagementOperations spec_file: oracle-fleetappsmanagementoperations-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.8 evidence: '"ListInstalledPatches Gets a list of installed patches.", "CreatePatch Creates a new Patch", "ExportComplianceReport Generate Compliance Report"' reason: Patch inventory, patch lifecycle and scheduled job execution across managed resources is core IT operations management. - tag: generativeAiAgent spec_file: oracle-generativeaiagent-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.8 evidence: '"Use the Generative AI Agents API to create and manage agents, knowledge bases, data sources, endpoints, data ingestion jobs"' reason: Lifecycle management of LLM agents, knowledge bases and ingestion — AI/ML model and application lifecycle management. - tag: healthChecks spec_file: oracle-healthchecks-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.8 evidence: Use the Health Checks API to manage endpoint probes and monitors. reason: Endpoint probes and HTTP/ping monitors are IT operations monitoring. - tag: lustreFileStorage spec_file: oracle-lustrefilestorage-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Use the File Storage with Lustre API to manage Lustre file systems and related resources"; CreateLustreFileSystem, ObjectStorageLink' reason: Provisioning and lifecycle of file-system storage resources is IT infrastructure (compute, storage, network, cloud) management. - tag: networkLoadBalancer spec_file: oracle-network-load-balancer-api-openapi.yml reanchored_from: oracle-networkloadbalancer-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"CreateNetworkLoadBalancer Creates a network load balancer."; "ListNetworkLoadBalancerHealths"; schema "BackendSet"' reason: Managing load balancers, listeners, backend sets and health checkers is network infrastructure provisioning — IT Infrastructure Management. - tag: omhubNetworkAnchor spec_file: oracle-omhubnetworkanchor-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: schemas "OciVcn", "OciNetworkSubnet", "OciDns"; "Gets a list of NetworkAnchors." reason: Network anchors expose VCN/subnet/DNS metadata for multicloud connectivity — clearly network/cloud infrastructure management. - tag: opensearchCluster spec_file: oracle-opensearchcluster-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"CreateOpensearchCluster Creates a new OpensearchCluster"; "ResizeOpensearchClusterHorizontal"' reason: Provisioning, resizing, backup and remote configuration of managed search clusters — cloud compute/storage infrastructure management. - tag: operatorControl spec_file: oracle-operatorcontrol-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"CreateOperatorControl Creates a new Operator Control" — "control the time duration and the actions an Oracle operator can perform on your Exadata Cloud@Customer infrastructure"' reason: CRUD over controls that govern which privileged actions an Oracle operator may perform and for how long — clearly privileged/identity access management, with audit logging of operator actions. - tag: operatorControlAssignment spec_file: oracle-operatorcontrolassignment-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"Creates an Operator Control Assignment resource. In effect, this brings the target resource under the governance of the Operator Control for specified time dura..."' reason: Binds privileged-access controls to target infrastructure resources for a time window — access entitlement assignment, i.e. identity and privileged access management. - tag: privateServiceAccess spec_file: oracle-privateserviceaccess-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"PSA endpoints are used to create private access between resources in a VCN or on-premises and services in Oracle services network"' reason: Managing private network endpoints between VCNs and cloud services is network infrastructure configuration. - tag: usagePlans spec_file: oracle-usage-plans-api-openapi.yml reanchored_from: oracle-usageplans-api-openapi.yml capability_id: BC-4270.50 capability_id_l1: BC-4270 capability_name: API Consumption Governance confidence: 0.8 evidence: 'API Gateway service ... schemas: Quota, RateLimit, UsagePlanSummary, EntitlementSummary — ''CreateUsagePlan''' reason: Usage plans with quotas, rate limits and entitlements on an API Gateway are API consumption governance — quotas/rate limits mapped to consumer tiers. This is the API ecosystem governance capability, not billing. - tag: vaults spec_file: oracle-vaults-api-openapi.yml capability_id: BC-4210.60 capability_id_l1: BC-4210 capability_name: Configuration & Secrets Management confidence: 0.8 evidence: Use the Secret Management API to manage secrets and secret versions ... RotateSecret Rotates an existing secret. reason: Secret storage, versioning and rotation is squarely Configuration & Secrets Management; alternatively security governance, but secrets lifecycle is the precise fit. - tag: GenerativeAiInference spec_file: oracle-generativeaiinference-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.78 evidence: POST /actions/chat Chat; POST /actions/embedText; POST /actions/applyGuardrails Applies guardrails to the input content reason: Runtime LLM inference plus guardrail application is the serving/responsible-AI side of AI model management; closest supported capability is Artificial Intelligence Management. - tag: costAd spec_file: oracle-costad-api-openapi.yml capability_id: BC-600.80 capability_id_l1: BC-600 capability_name: IT Financial Management confidence: 0.78 evidence: '"CreateCostAlertSubscription Creates a new Cost Alert Subscription", "ListCostAnomalyEvents Returns a list of Cost Anomaly Event", "CreateCostAnomalyMonitor"' reason: Budget/cost alerting and cloud cost anomaly monitoring is IT spend monitoring and cost optimisation — IT Financial Management rather than general financial accounting. - tag: delegateAccessControl spec_file: oracle-delegateaccesscontrol-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: '"ApproveDelegatedResourceAccessRequest Approves a Delegated Resource Access Request." / "Customers maintain control over who has access to the delegated resources in their tenancy and what actions can be taken."' reason: Approve/reject/revoke of third-party operator access to tenancy resources with audit log reports is access governance over privileged/delegated access — Identity & Access Management. Not corporate delegation of signing authority despite the word 'delegation'. - tag: query spec_file: oracle-query-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.78 evidence: '"Use the Application Performance Monitoring Trace Explorer API to query traces and associated spans in Trace Explorer"' reason: Querying distributed traces and spans for APM is observability of a running service (logs, metrics, traces). - tag: replicas spec_file: oracle-replicas-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"CreateReplica Creates a DB System Read Replica."; "The API for the MySQL Database Service"' reason: Managing read replicas of a managed database service is database/cloud infrastructure provisioning — IT infrastructure management, no business-process meaning. - tag: DataIntegration spec_file: oracle-dataintegration-api-openapi.yml capability_id: BC-610 capability_id_l1: BC-610 capability_name: Information & Data Management confidence: 0.75 evidence: create data flows, pipelines and tasks, and then publish, schedule, and run tasks that extract, transform, and load data reason: ETL/data pipeline design and orchestration — clearly Information & Data Management; no single L2 fits ETL pipelines precisely (closest would be data architecture), so L1 only. - tag: MultiCloudResourceDiscovery spec_file: oracle-multicloudresourcediscovery-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Discovers Multicloud Resource and their associated resources based on the information provided." / "removes its associated metadata from Oracle Cloud Infrastructure"' reason: Discovery and lifecycle of cloud infrastructure resources across Azure/OCI — cloud infrastructure management, not a business-domain capability. - tag: OracleDBAzureBlobContainer spec_file: oracle-oracledbazureblobcontainer-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"The Oracle Azure Blob Container Resource is used to capture the details of an Azure Blob Container. This resource can then be reused across multiple Exadata VM clusters"' reason: Manages cloud storage container resources used by database VM clusters — cloud/storage infrastructure management. - tag: OracleDBAzureBlobMount spec_file: oracle-oracledbazureblobmount-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Unmounts Oracle DB Azure Blob Mount resource from an Exadata VM cluster in Oracle Exadata Database Service on Dedicated Infrastructure (ExaDB-D)"' reason: Mounting cloud object storage onto database compute clusters is storage/compute infrastructure provisioning. - tag: applicationDependencyManagement spec_file: oracle-applicationdependencymanagement-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.75 evidence: '''Use the Application Dependency Management API to create knowledge bases and vulnerability audits''; schemas ''ApplicationDependencyVulnerabilitySummary'', ''RemediationRecipe'', ''RemediationRun''' reason: Scans application dependencies for known vulnerabilities and drives remediation runs — vulnerability scanning and remediation. An open-source supply-chain reading (BC-4200.60) is possible, hence not higher. - tag: bastion spec_file: oracle-bastion-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: Bastions let authorized users connect from specific IP addresses to target resources using Secure Shell (SSH) sessions reason: Bastion provides restricted, time-limited privileged access to infrastructure resources — privileged access/session management, which sits under Identity & Access Management. Some case for IT Infrastructure Management, but access control is the explicit purpose. - tag: budget spec_file: oracle-budget-api-openapi.yml capability_id: BC-600.80 capability_id_l1: BC-600 capability_name: IT Financial Management confidence: 0.75 evidence: Use the Budgets API to manage budgets and budget alerts ... [Budgets Overview](/iaas/Content/Billing/Concepts/budgetsoverview.htm) reason: Cloud spend budgets and threshold alert rules — IT financial management / cloud cost control rather than enterprise FP&A budgeting. - tag: dataCatalog spec_file: oracle-data-catalog-api-openapi.yml reanchored_from: oracle-datacatalog-api-openapi.yml capability_id: BC-610.10 capability_id_l1: BC-610 capability_name: Data Governance Management confidence: 0.75 evidence: '"Use the Data Catalog APIs to collect, organize, find, access, understand, enrich, and activate technical, business, and operational metadata"; schemas "UpdateGlossaryDetails", "TermRelationshipCollection"' reason: Metadata cataloguing with glossaries, terms and lineage is the tooling layer of data governance and stewardship. - tag: kafkaCluster spec_file: oracle-kafkacluster-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Use Oracle Streaming with Apache Kafka Control Plane API to create/update/delete managed Kafka clusters"; CreateKafkaClusterDetails, BrokerShape, NodeShapeCollection' reason: Provisioning and configuring managed Kafka clusters (broker shapes, node shapes, cluster configs) is cloud platform infrastructure provisioning, i.e. IT Infrastructure Management. - tag: monitoring spec_file: oracle-monitoring-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.75 evidence: '"Use the Monitoring API to manage metric queries and alarms for assessing the health, capacity, and performance of your cloud resources"' reason: Metrics and alarms for cloud resource health is IT operations monitoring. Note this is infrastructure observability, not financial-crime alerting despite the Alarm/Suppression schemas. - tag: networkFirewall spec_file: oracle-networkfirewall-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"CreateNetworkFirewallPolicy Creates a new Network Firewall Policy"; schemas "SecurityRule", "DecryptionRule_2", "CreateMappedSecretDetails"' reason: Operations create and manage network firewalls, security rules, NAT and decryption rules — network security control enforcement, i.e. Cybersecurity Management. No single L2 is clearly named (it spans security architecture and operations), so L2 left null. - tag: ociCacheConfigSet spec_file: oracle-ocicacheconfigset-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Create a new OCI Cache Config Set for the given OCI cache engine version"; "A cluster is a memory-based storage solution"' reason: Operations manage configuration sets for OCI Cache clusters — provisioned cloud compute/storage resources. This is cloud infrastructure administration, not a business capability of any industry domain. - tag: scheduledJob spec_file: oracle-scheduled-job-api-openapi.yml reanchored_from: oracle-scheduledjob-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.75 evidence: '"Use the OS Management Hub API to manage and monitor updates and patches for instances"; "CreateScheduledJob", "RunScheduledJobNow"' reason: Scheduled jobs for OS patching/update automation across managed instances — IT operations automation. Could arguably be Vulnerability Management (patching) but the surface is generic job scheduling. - tag: waf spec_file: oracle-waf-api-openapi.yml capability_id: BC-620.50 capability_id_l1: BC-620 capability_name: Security Architecture Management confidence: 0.75 evidence: API for the Web Application Firewall service. Use this API to manage regional Web App Firewalls and corresponding policies for protecting HTTP services. reason: WAF policy management is a security control configuration surface — security architecture/controls under Cybersecurity Management. Sub-capability choice between security architecture and threat detection is somewhat ambiguous, hence moderate confidence. - tag: weblogicManagementService spec_file: oracle-weblogicmanagementservice-api-openapi.yml capability_id: BC-600.60 capability_id_l1: BC-600 capability_name: IT Application Management confidence: 0.75 evidence: on-demand patching of WebLogic domains, rollback of the last applied patch, discovery and management of WebLogic instances on a compute host reason: Managing application server (WebLogic) domains, servers and installed patches is IT application lifecycle/middleware management. - tag: DistributedDbService spec_file: oracle-distributeddbservice-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: POST /distributedDatabases CreateDistributedDatabase Create a Globally distributed database; ConfigureDistributedDatabaseSharding reason: Provisioning and configuring managed cloud database resources (shards, GSMs, backup config) is IT infrastructure/platform management, not a business-domain capability. - tag: macDevice spec_file: oracle-macdevice-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"dedicated, partially-managed Mac servers hosted in an OCI Data Center"; "TerminateMacDevice Terminates a MacDevice"' reason: Listing and terminating dedicated server devices is infrastructure resource management, not device/HR or asset accounting. - tag: managementAppliance spec_file: oracle-managementappliance-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Use the Oracle Cloud VMware API to create SDDCs and manage ESXi hosts and software"; CreateManagementAppliance' reason: Provisioning and managing VMware SDDC management appliances is compute/virtualisation infrastructure management. - tag: ociCacheDefaultConfigSet spec_file: oracle-ocicachedefaultconfigset-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Return a list of OCI Cache Default Config Set."; "Use the OCI Cache API to create and manage clusters"' reason: Read-only listing of default configuration templates for cache clusters — cloud infrastructure resource configuration. - tag: omhubResourceAnchor spec_file: oracle-omhubresourceanchor-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Use the Oracle Multicloud API to retrieve resource anchors ... related a Cloud Service Provider"' reason: Read-only inventory of cloud resource anchors and provider metadata — cloud infrastructure resource management. - tag: organization spec_file: oracle-organization-api-openapi.yml capability_id: BC-4230.10 capability_id_l1: BC-4230 capability_name: Tenant Provisioning & Lifecycle confidence: 0.72 evidence: '"CreateChildTenancy Creates a child tenancy asynchronously.", "DeleteOrganizationTenancy Initiate tenancy termination.", "RestoreOrganizationTenancy Restore tenancy."' reason: Creates, terminates, restores and transfers child tenancies within an organization — provisioning and lifecycle of tenants in a multi-tenant cloud estate. The subscription-assignment operation adds slight ambiguity. - tag: AiDataPlatform spec_file: oracle-aidataplatform-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Use the AiDataPlatform Control Plane API to manage Data Lakes. ... CreateAiDataPlatform Creates a AiDataPlatform. reason: Cloud control-plane provisioning of data lake platform resources (create/update/delete, compartments, work requests). This is IT infrastructure/platform provisioning rather than data governance itself; BC-600.50 IT Infrastructure Management fits best, with BC-610 data-platform overtones causing some ambiguity. - tag: DbMulticloudAwsProvider spec_file: oracle-dbmulticloudawsprovider-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: CreateOracleDbAwsIdentityConnector Creates Oracle DB AWS Identity Connector resource. ... Create DB AWS Key resource. reason: Provisioning of cross-cloud connector and encryption-key resources for Exadata database clusters — infrastructure/multicloud integration plumbing. Key/identity connector aspects touch BC-620.20 but the operations are resource lifecycle management of infrastructure. - tag: DbMulticloudGCPProvider spec_file: oracle-dbmulticloudgcpprovider-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: CreateOracleDbGcpIdentityConnector Creates Oracle DB GCP Identity Connector resource. ... Creates DB GCP Key Rings based on the provided information reason: 'Same pattern as the AWS provider: lifecycle management of GCP connector and key-ring resources for Oracle database clusters — cloud infrastructure integration.' - tag: Logging spec_file: oracle-logging-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: Use the Logging Ingestion API to ingest your application logs; PutLogs Ingests logs for a logId reason: Application log ingestion is observability instrumentation for running services; Observability Management is the closest supported capability (IT Operations Management is an alternative reading). - tag: MarketplacePublisher spec_file: oracle-marketplacepublisher-api-openapi.yml capability_id: BC-4270.70 capability_id_l1: BC-4270 capability_name: Software Marketplace Listing Management confidence: 0.7 evidence: '"Use the Marketplace Publisher API to manage the publishing of applications in Oracle Cloud Infrastructure Marketplace." with operations "ValidateAndPublishArtifact", "SubmitListingRevisionForReviewDetails", "ListDisbursementReportRecords"' reason: Operations manage listings, listing revisions, terms and disbursement reporting for publishing software offerings on a cloud marketplace — i.e. software marketplace listing stewardship. Some overlap with partner app programme management keeps confidence moderate. - tag: OracleDBAzureConnector spec_file: oracle-oracledbazureconnector-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Patch Azure Arc Agent on Oracle Cloud VM Cluster with new version." / "install the Azure Arc Server on an Exadata VM cluster"' reason: Installs, patches and refreshes an agent on database VM clusters to integrate two clouds — infrastructure management/agent lifecycle rather than a business capability. - tag: ResourceManager spec_file: oracle-resource-manager-api-openapi.yml reanchored_from: oracle-resourcemanager-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Use the Resource Manager API to automate deployment and operations for all Oracle Cloud Infrastructure resources. Using the infrastructure-as-code (IaC) model, the service is based on Terraform"' reason: Operations create/run Terraform stacks and jobs to provision and drift-detect cloud infrastructure (Stack, Job, DetectStackDriftDetails, CustomTerraformProvider). That is management of compute/storage/network cloud infrastructure. An alternative reading as deployment orchestration (BC-4210.40) exists, but the object of the API is infrastructure resources, not product releases, so IT Infrastructure Management is the honest fit; confidence held at 0.7 for that ambiguity. - tag: attributes spec_file: oracle-attributes-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: '''Use the Application Performance Monitoring Trace Explorer API to query traces and associated spans in Trace Explorer''; ''BulkActivateAttribute Activate a set of attributes for the given APM Domain''' reason: Governs which trace/span attributes are collected and surfaced in the tracing explorer — configuration of trace observability data. - tag: batchComputing spec_file: oracle-batchcomputing-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: Use the Batch Control Plane API to encapsulate and manage all aspects of computationally intensive jobs reason: Cloud compute job/pool orchestration — provisioning compute for batch jobs. Maps to IT Infrastructure Management (compute). Not a business capability of its own. - tag: capacityManagement spec_file: oracle-capacitymanagement-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: OCI Control Center (OCC) Capacity Management enables you to manage capacity requests ... CreateOccCapacityRequest A post call to create capacity request reason: Requesting and tracking cloud infrastructure capacity availability — infrastructure capacity provisioning/management for the customer's cloud estate. - tag: certificatesManagement spec_file: oracle-certificatesmanagement-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"API for managing certificates." — CreateCertificateAuthority, ListCaBundles, RevokeCertificateAuthorityVersionDetails' reason: Operations manage TLS/PKI certificates, certificate authorities and CA bundles — a security control capability (cryptographic/certificate management). Sits under Cybersecurity Management; no L2 cleanly covers PKI, so L1 only. - tag: computeInstanceAgent spec_file: oracle-computeinstanceagent-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"Oracle Cloud Agent is a lightweight process that monitors and manages compute instances" — CreateInstanceAgentCommand, GetInstanceAgentCommandExecution' reason: Dispatching and tracking execution of agent commands on running instances is day-to-day IT operations/automation rather than provisioning. - tag: dataLabeling spec_file: oracle-data-labeling-api-openapi.yml reanchored_from: oracle-datalabeling-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: '"Use Data Labeling API to create Annotations on Images, Texts & Documents, and generate snapshots."' reason: Annotation of training records and datasets is ML training-data preparation, part of the AI/ML model lifecycle. - tag: dataLabelingManagement spec_file: oracle-datalabelingmanagement-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: '"Use Data Labeling Management API to create, list, edit & delete datasets"; "AddDatasetLabels Add Labels to the Dataset LabelSet"' reason: Dataset and label-set management for a data labeling (ML training data) service supports the AI/ML model lifecycle. - tag: databaseMigration spec_file: oracle-databasemigration-api-openapi.yml capability_id: BC-600 capability_id_l1: BC-600 capability_name: Information Technology Management confidence: 0.7 evidence: '"Use the Oracle Cloud Infrastructure Database Migration APIs to perform database migration operations"; CloneMigrationDetails, TargetAssessmentConnection' reason: Assessment and execution of database migrations is IT technology work (infrastructure/application migration). L1 IT Management is defensible; the evidence does not clearly pick between infrastructure and application management, so L2 is left null. - tag: dbBackups spec_file: oracle-dbbackups-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST /backups CreateBackup Create DB System Backup reason: MySQL DB system backup lifecycle — IT infrastructure/data platform operations. Could also read as disaster recovery, but the surface is plain database backup administration. - tag: dbSystem spec_file: oracle-dbsystem-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"CreateDbSystem Create and launch a DB System." / "The API for the MySQL Database Service"' reason: Operations provision, start, stop and update managed MySQL database systems in the cloud — provisioning and stewardship of compute/storage infrastructure, i.e. IT Infrastructure Management. No banking or SaaS-commercial reading fits. - tag: events spec_file: oracle-events-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"API for the Events Service. Use this API to manage rules and actions that create automation in your tenancy.", "CreateRule Creates a new rule"' reason: Rules-and-actions automation over cloud infrastructure events is IT operations automation, not business event processing. - tag: fleetAppsManagementAdmin spec_file: oracle-fleetappsmanagementadmin-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"ListCompliancePolicies Gets a list of compliancePolicies.", "CreateOnboarding Onboard a tenant to Fleet Application Management.", schema "PlatformConfiguration"' reason: Administration of patch/compliance policies and platform configuration for the fleet management tooling; IT operations rather than enterprise compliance management. - tag: fleetAppsManagementMaintenanceWindow spec_file: oracle-fleetappsmanagementmaintenancewindow-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"CreateMaintenanceWindow Creates a new MaintenanceWindow", within "Fleet Application Management ... automate resource management tasks, validate patch compliance"' reason: Scheduling maintenance windows for fleet patching activity is IT operations scheduling. - tag: fleetAppsManagementRunbooks spec_file: oracle-fleetappsmanagementrunbooks-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"Fleet Application Management provides a centralized platform to help you automate resource management tasks, validate patch compliance, and enhance operational efficiency"; "Creates a Runbook"' reason: Runbooks define automated operational task workflows for fleets of resources — IT operations automation. Mapped to IT Operations Management; could arguably be process automation but the context is clearly infrastructure ops. - tag: generativeAiAgentRuntime spec_file: oracle-generativeaiagentruntime-api-openapi.yml capability_id: BC-610.60 capability_id_l1: BC-610 capability_name: Artificial Intelligence Management confidence: 0.7 evidence: '"Chat with endpoint", "Creates an agent Session", "Retrieve Metadata of knowledge base"' reason: Runtime inference/chat surface for generative AI agents; AI service consumption. Could also be seen as pure runtime plumbing, hence 0.7. - tag: kmsCrypto spec_file: oracle-kmscrypto-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"POST /20180608/encrypt Encrypt"; "Signs data by using the given SignDataDetails resource"; "GenerateDataEncryptionKey"' reason: Cryptographic operations against managed keys — a security control capability. Mapped at L1 Cybersecurity Management only, as no listed L2 (IAM, threat detection, vulnerability) squarely covers cryptographic key operations. - tag: kmsHsmCluster spec_file: oracle-kmshsmcluster-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"CreateHsmCluster Creates a new HSM cluster resource"; "UploadPartitionCertificates Upload partition certificate and partition owner certificate for the HSM cluster"' reason: Management of hardware security module clusters and their certificates is a cybersecurity infrastructure control. L1 only — no candidate L2 specifically covers HSM/key custody. - tag: kmsManagement spec_file: oracle-kmsmanagement-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"ListKeys Lists keys in the specified vault and compartment"; "DisableKey Disables a key so it cannot be used for cryptographic operations"' reason: Encryption key lifecycle (create, import, rotate, backup, disable, schedule deletion) is a cybersecurity control capability; mapped at L1 since no L2 covers key management explicitly. - tag: lockbox spec_file: oracle-lockbox-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Use the Managed Access API to approve access requests, create and manage templates, and manage resource approval settings"; CreateLockbox / UpdateLockbox with AccessContextAttribute schemas' reason: Lockboxes govern and approve access to cloud resources, i.e. access control/approval workflows — Identity & Access Management. Not a business-domain capability; the operations are pure access governance over OCI resources. - tag: managementAgent spec_file: oracle-managementagent-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"Use the Management Agent API to manage your infrastructure''s management agents, including their plugins and install keys"; POST /managementAgents/actions/deployPlugins DeployPlugins' reason: Lifecycle management of monitoring/management agents deployed across infrastructure is day-to-day IT operations tooling, not a business-domain capability. - tag: schedule spec_file: oracle-schedule-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"Use the Resource scheduler API to manage schedules, to perform actions on a collection of resources"' reason: OCI Resource Scheduler automates start/stop actions on cloud resources — day-to-day IT operations automation. Cross-industry IT Operations Management is the honest mapping; not a business scheduling capability. - tag: secrets spec_file: oracle-secrets-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Use the Secret Retrieval API to retrieve secrets and secret versions from vaults"' reason: Vault secret retrieval is credential/secrets management, a security control. Could also map to BC-4210.60 Configuration & Secrets Management, but this is a cloud security service rather than a SaaS product release pipeline; IAM is the safer L2. - tag: usageapi spec_file: oracle-usageapi-api-openapi.yml capability_id: BC-600.80 capability_id_l1: BC-600 capability_name: IT Financial Management confidence: 0.7 evidence: Use the Usage API to view your Oracle Cloud usage and costs ... used by Cost Analysis, Scheduled Reports, and Carbon Emissions Analysis reason: Queries and custom tables for analysing cloud usage and cost — IT spend/cost analysis (IT Financial Management). Carbon emission endpoints are a secondary aspect; primary surface is cost/usage reporting. - tag: vnMonitoring spec_file: oracle-vnmonitoring-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: Use the Network Monitoring API to troubleshoot routing and security issues ... POST /pathAnalysis GetPathAnalysis A path analysis query. reason: Network path analysis/troubleshooting tooling for cloud resources — IT operations monitoring and diagnostics. - tag: zpr spec_file: oracle-zpr-api-openapi.yml capability_id: BC-620.50 capability_id_l1: BC-620 capability_name: Security Architecture Management confidence: 0.7 evidence: Use the Zero Trust Packet Routing Control Plane API to manage ZPR configuration and policy reason: Zero Trust network segmentation policy management maps to security architecture (zero trust patterns) under Cybersecurity Management; some ambiguity vs. general infrastructure networking.