Implementation is a collaborative effort, with Oracle providing initial templates and cloud service support, while the utility customer is responsible for the overall project management, customization, training, and testing to ensure a successful deployment.
Initial Setup Scope: Oracle provides pre-configured templates and a Utility Reference Model outlining the business processes that form the basis for the application configuration.
Customer Responsibility: The customer or implementing partner retains complete responsibility for overall project management, scope definition, scheduling, budgeting, and all end-user training activities.
Extension Management: Customers are entirely responsible for designing and rigorously testing all configurations and extensions to verify they do not negatively impact the application's performance.
Data Scripting: Oracle will, under exceptional circumstances, execute customer-authored scripts to resolve data issues, but these are subject to a strict security review for compliance.
Script Review Limit: There is a limit of four (4) script reviews per calendar month provided as entitlement, with review requests exceeding this limit potentially being subject to additional fees.
Customisation
Oracle Utilities are built on a highly configurable and extensible framework, allowing utilities to adapt the solution to specific regulatory and operational needs, while adhering to necessary constraints required by the SaaS cloud environment.
Adaptability and Extensibility: The Oracle Utilities Data Model and application framework are designed to be an adaptable and extendable off-the-shelf solution, aligning with utilities industry standards for interoperability.
Design for Scale: The solution is engineered to accommodate a diverse range of utility environments and business types, scaling to handle mass smart meter data volumes and complex operational demands.
Cloud Constraints: As a SaaS product, customers cannot get direct access to the underlying hardware or change server settings; customization is restricted to the application configuration layer to maintain service integrity.
Security Vetting: Any customer-developed customizations that require Oracle intervention (e.g., data correction scripts) must undergo a review for compliance with Oracle's Software Security Assurance standards.
Process Automation: The platform allows for the configuration of security definitions and setups for process automation tools in each provisioned environment to fit unique operational flows.
Additional Costs
The cloud model standardizes maintenance costs into the subscription, but customers should account for initial implementation partner fees, costs associated with extensive customization, and potential over-entitlement fees for certain administrative services.
Implementation Partner Costs: While Oracle may include limited initial Implementation Support Services, the utility must budget for overall project costs, including partner fees for project management, data migration, and comprehensive testing.
Maintenance Included: Oracle handles the costs and effort associated with updates, patching, backups, and disaster recovery as part of the core cloud subscription fee.
Security Cost Reduction: Leveraging the security embedded in Oracle Cloud Infrastructure (OCI) eliminates the extra cost and risk of paying other cloud platforms for storing and protecting vital information.
Over-Entitlement Fees: Exceeding the standard number of customer-script reviews (currently four per month) can trigger additional fees as per the service agreement terms.
Optimized Integration: The system utilizes an internal web services capability rather than external web service managers, which helps reduce implementation costs related to integration security setup.
Training
Oracle provides robust, cloud-based infrastructure support, comprehensive documentation, and system maintenance. However, the onus for end-user training and first-line application troubleshooting rests firmly with the customer's organization or chosen partner.
Customer Training Mandate: End-user training and organizational change management are identified as the complete and exclusive responsibility of the utility customer.
Comprehensive Documentation: Oracle offers extensive resources, including Overview Guides, Security Guides, and Implementation Guides for each specific cloud service.
24x7 Monitoring: The services are built on the secure Oracle Cloud Platform, which provides 24x7 monitoring to ensure continuous data security and rapid alerting for any irregularities.
SaaS Infrastructure Support: Oracle manages all underlying operations, including the infrastructure, patching, backups, and recovery, providing a high level of operational support.
Troubleshooting Access: Documentation implies that the scope of customer access to logs and ability to perform their own troubleshooting is defined in the service guides, determining the boundary of self-service support.
Security Measures
Oracle Utilities is secured by OCI's defense-in-depth strategy, employing security measures across the entire technology stack from the application down to the hardware, with a focus on data encryption and strict access controls.
Defense-in-Depth Strategy: Security is engineered into every layer of the stack (application to hardware) with a comprehensive defense-in-depth strategy and controls protecting all digital assets.
Data Access Restriction: By default, Oracle does not have access to any unencrypted customer data (including via the UI, database, or direct backups) unless permission is explicitly granted by the customer.
Encryption and HTTPS: The application supports encryption for sensitive data configuration and follows a "Secure By Default" policy that encourages and enables the use of HTTPS for application running.
Allowlist Enforcement: The platform supports IP Allowlist configuration to enforce the protection of application resources, requiring customers to log a service request to provide configuration details.
Software Security Assurance: Development follows Oracle Software Security Assurance (SSA) standards, which mandate secure coding, required security training, and the use of automated testing tools.
Updates
Updates are managed entirely by Oracle as part of the Cloud Service model, ensuring the utility always runs on the most current and secure version of the software with minimal operational disruption to the customer.
Vendor Managed Updates: Oracle handles all updates and patching for the cloud services automatically, removing the burden of system maintenance from the utility's IT team.
Regular Cadence: The services follow a regular, frequent release schedule typical of Oracle Cloud services (e.g., quarterly or biannually), ensuring continuous feature improvement and security updates.
Secure Deployment: Updates incorporate security enhancements, such as secure cookie attributes, following the Oracle Secure By Default policy to continuously maintain a high-security posture.
Infrastructure Management: Patching is managed alongside Oracle's responsibilities for backups and disaster recovery to ensure system stability during and after deployment.
Automated Deployment: Application updates, patches, and security fixes are generally automatically deployed to the application environments by Oracle's cloud operations team.
Data Ownership and Portability
The utility retains ownership of its data. While the underlying software is licensed, the customer's operational and customer data can be accessed and ported through defined data models, APIs, and governed data exchange methods.
Customer Data Ownership: The utility customer retains ownership of their business and customer data; Oracle's access is limited and controlled by the customer.
Intellectual Property (IP): The Oracle software, documentation, and related technology are protected by IP laws and are provided under a restrictive license that prohibits reverse engineering or decompilation.
Data Portability Solutions: Oracle supports partnerships and integration points that enable standardized, secure data exchange through APIs, facilitating data portability for end-users and third parties.
Analytics Access: The architecture, leveraging the Oracle Utilities Data Model, provides a structured foundation for data access, business intelligence, and analytics across the enterprise.
Data Export/Extract: Mechanisms exist for moving files in and out of the services, which is crucial for data loading, integration, and bulk data export/portability.
Scaling Up / Down
The Cloud Service model provides inherent, enterprise-grade scalability, allowing utilities to adjust resources and capacity to handle variable workloads, especially those driven by mass smart meter data.
Mass Volume Scalability: The system is specifically engineered to scale with mass smart meter volumes, handling complex data and processing requirements across multiple jurisdictions.
Resource Adjustment: Customers have the ability to scale the resources provided by default within the cloud services (e.g., Data Intelligence) based on changes in their operational workload.
OCI Backbone: Leveraging the Oracle Cloud Infrastructure (OCI) ensures underlying architectural support for high-availability, cost-effective scalability, and reliability.
Architectural Efficiency: Scaling is optimized using Oracle Database features like partitioning and compression to maintain performance and reliability during periods of growth.
Evolutionary Capacity: The system's application components are designed to accommodate many types of environments and evolve with the utility's business needs and advanced digital requirements.
The terms & conditions for contract renewal and cancellation
Contractual terms for renewal and cancellation are highly specific to the signed Master Agreement and Cloud Service descriptions, adhering to standard enterprise software licensing principles and intellectual property rights.
License Agreement Foundation: The use of the software is governed by a detailed license agreement that outlines restrictions, permitted use, and intellectual property rights.
Subscription Model: The service is provided via an activated subscription, meaning renewal is tied to the continuation of the cloud subscription term outlined in the contract.
Prohibited Activities: The contract strictly prohibits activities such as reverse engineering, copying, or decompilation of the core software and documentation.
Commercial Standards: Terms are written to align with commercial computer software standards and regulations, particularly regarding the rights and responsibilities of both Oracle and the customer.
Governing Documents: Specific details regarding notice periods, early termination penalties, and renewal pricing structures are contained within the Cloud Service Description and the larger Oracle Master Cloud Services Agreement.
Compliance
Oracle Utilities leverages the global compliance framework of the Oracle Cloud Infrastructure (OCI), undergoing regular audits and assessments to meet stringent standards required by global and regional utility regulations.
Internal Auditing: Oracle follows the Business Assessment & Audit (BA&A) process to perform global process and regional reviews, ensuring operational and compliance standards are consistently met.
Security Standard Adherence: The software development adheres to Oracle Software Security Assurance (SSA), which reduces security weaknesses and fosters security innovations compliant with industry standards.
Third-Party Vetting: Through partnerships (e.g., for data portability), the platform aligns with requirements for using SOC 2 certified systems, which provides assurance over security, availability, and confidentiality.
Data Governance: The data handling and management practices are designed to help customers configure the system to adhere to various regional and international data privacy and regulatory mandates.
Industry Alignment: The architecture is built on a framework that adheres to utilities industry standards, assisting utilities in meeting their regulatory and reporting obligations.