Setup Considerations: Access Rules
You can use this topic to help make decisions when planning your configuration and use of access rules. It explains:
- Why to set it up.
- How it fits into the rest of Workday.
- Downstream impacts and cross-product interactions.
- Security requirements and business process configurations.
- Questions and limitations to consider before implementation.
Refer to detailed task instructions for full configuration details.
What It Is
Access rules define specific intersections of data that users or groups can edit or view. Workday provides default access rules that mimic your current level-based security. You can view these default rules from the
Access Rules
page under Administration
. Based on your requirements, you can:
- Change the default access rules.
- Configure additional access rules.
Business Benefits
- Prevents users from seeing contributing splits and details. You can also hide accounts, levels, and custom dimension values, so users never see them.
- Enable users to view an entire department data and edit another department data.
- Free up your levels so they can accurately reflect your organizational structure.
- Control user access to rows, columns, and cells in sheets.
- Reduce overhead by eliminating user-assigned sheets and using access rules instead.
Use Cases
- Enable users to access some accounts or dimensions in some areas of your model. Then, restrict or even hide them in other areas.
- Build 1 report and share it with many users. The report filters out the data that each user can't see.
- Introduce new dimensions and make them available to a limited group of users. Example: You want to test a new product dimension or an acquisition level and plan it out with a few stakeholders before implementing it.
Questions to Consider
Questions | Considerations |
|---|---|
Are you planning to secure only your levels and accounts or also your custom dimensions? | Consider securing your custom dimensions only if you want to configure complex security with detailed granular rules. To understand the full downstream impact, see Reference: Access Rules and Your Model
In either case, understand the effects of securing your custom dimensions and use these guidelines for smooth planning:
When you secure custom dimensions:
|
How many custom dimensions and dimension values do you currently have? | You can secure a maximum of:
If you have additional custom dimensions and values that you want to secure, contact Workday Customer Care to request a review of your use case. |
Based on the tasks that your users must accomplish, what levels of access do they need? | The access rules that you assign to the user groups enable the group members to complete their jobs. Ensure that your user groups accurately reflect the job groupings for your organization. Example: If your planners are signing in and just running reports, then you can create a Planners user group. Then, create and assign an access rule that grants the Planners group permissions for generating reports. You can assign different degrees of permissions to users based on their varying needs. Example: On level-assigned standard and cube sheets, to let users:
|
How do you want to mass manage access for users? | You can create user groups and assign access rules to groups with common goals.
Example: If you're restricting access by departments, then you can create user groups by departments such as Sales or Engineering. Then, create and assign access rules to these user groups to provide access to the departments.
It's easier for you to add more users to the user groups than to create more access rules. If you don't have a lot of users, you can assign the access rules to the individual users directly. However, we still do recommend that you use user groups for easier maintenance. |
What are some other ways besides access rules that you can secure data? |
Consider these supplemental options in addition to access rules:
|
Do your admins or modelers need access rules to manage the model? | Modeling and administration permissions enable users to see the entire hierarchies of levels, accounts, and custom dimensions. Permissions alone are sufficient to enable modelers to manage the structure of the model. You don't need to give them view or edit access to data, unless you want them to test data changes in the model. |
Do you publish plans from Adaptive Planning to Human Capital Management (HCM) or Financial Management? | To let users publish the entire plan to another platform, give Edit access to all secured dimension values in the model. |
Do you have users or groups with the Import Capabilities and Import to All Locations permissions? | To let users with these permissions validate their data or metadata imports, give them at least Full View access to all secured dimension values in the model. Otherwise, they can't see all that they imported in the sheets and reports and might think that the import failed. |
Recommendations
- Keep your access rules as simple as possible. Initially, just secure all your levels. Grant users either view or edit access to specific levels in the hierarchy. Next, secure your accounts. This way you can expect some subtle changes in your model.
- Depending on how you plan to use access rules, you can take a slightly different approach for configuration.
- To secure only levels:
- Consider training.
- Contact professional services.
- (Optional) Test in sandbox.
- To secure accounts:
- Complete training.
- Consider contacting professional services.
- Consider testing in sandbox.
- To secure custom dimensions:
- Complete training.
- Contact professional services.
- Since maintaining the rules for all the custom dimensions and dimension values can become a huge effort with heavy downstream impact, consider:
- Removing any existing, unused custom dimensions and dimension values that you no longer need before securing them.
- Carefully selecting the custom dimensions that you want to secure and understanding how the rules affect the model for your users.
- Testing the access rules in your sandbox and checking reports, dashboards, and sheets.
- After you assign rules to user groups, don't update the group using theAvailable Levelslist on theGlobal User Groupspage inAdministration. Users added this way to groups don't automatically get included in the access rules.
- Adopt a piece-meal approach. Try adding complexity to your access rules for levels and accounts before you secure the custom dimensions.
- To control access to levels, accounts, and custom dimensions, use attributes as they might be easier to maintain. See Create Dynamic Access Rules.Example: The attribute West Coast Regions groups 100 different levels in your model. In access rules, rather than list all the levels, you can just list the attribute that groups these levels. Attributes are also helpful when you add or remove levels, as you don't need to update the access rules to reflect these changes.
- Use association codes to create access rules. You can then update the associations instead of the access rules to update user access. If you use a Workday report to import roles into Adaptive Planning, you can maintain the associations automatically and use them to create role-based rules. See Create Dynamic Access Rules.Example: Level ownership is a prebuilt association that connects users to levels. To add access for new levels, you don't need to update the existing rules. You can just update level ownership.
- To grant most privileges except a few to users or groups, use theGrant All (Except)rule. Conversely, to take away more privileges and grant only a few, use theGrant Allrule.
Requirements
- You must complete your model structure, including the levels, accounts, and custom dimensions before you create access rules.
Limitations
- After you enable access rules for an instance, you can't disable it.
- User-assigned sheets override access rules. You have edit access to all the data intersections on user-assigned sheets.
- Despite securing and using attributes as access rules, you have access to all attributes.
- In modeled sheets, if you have Full View access to all secured parent dimension combinations, then you can view all the split rows including the ones with dimensions with restricted access.
- You can't secure custom dimensions that have these settings active:
- Use on Levels
- Data import automatically creates dimension values
- Edit dimension valuewhen added to modeled or cube sheets
- System dimensions including time, subsidiary, versions, and currency dimensions aren't eligible for access rules.
- You can't restrict the consolidation percentage sheet using access rules. To let users open and edit the consolidation percentage sheet, assign them a permission set with theModel Management Access > Consolidationpermission.
- Using access rules alone doesn't secure your data completely. Consider using these other security features along with access rules. See Concept: Access Rules.
- Permissions
- Level ownership (formerly level access)
- Versions access controls
- Salary detail settings
- Sheet settings and restrictions
- These permissions circumvent access rules by exposing the secured elements and sometimes the data. See Concept: Access Rules.
- Import CapabilitiesandImport to All Locations.
- System Audit Access.
- Integration> Data DesignerandIntegration> Integration Developer.
- Refresh Linked Levels.
- Access Consolidation.
Tenant Setup
For new customers, Access Rules are enabled for all Adaptive Planning instances. Existing customers can create a case in the Workday Customer Center to enable Access Rules for their instances.
Security
To create access rules, you need the
Admin Access > Users
permission.Business Processes
No impact.
Reporting
No impact.
Integrations
You can use the updateAccessRules API to update or replace a set of existing access rules from a spreadsheet file. See updateAccessRules.
Connections and Touchpoints
Workday offers a Touchpoints Kit with resources to help you understand configuration relationships in your tenant. Learn more about the Workday Touchpoints Kit on Workday Community.
Other Impacts
For information about how access rules impact all areas of your model, see Reference: Access Rules and Your Model.