Steps: Maintain Access to Customer Information
- Understand segment-based security groups and segmented security.
- Determine whether you need to restrict segments of data to groups of workers.
You can control worker access to your customer data through configurable customer security segments. Customer segmented security restricts access to designated customers and visibility to customer information so that workers can't:
- Select customers that they don't have access to when creating, editing, or searching for transactions.
- See customer information in search results. Workday masks the customer name with asterisks and doesn't display other important information.
- Print or view customer documents, such as invoices, statements, and refunds.
- See the printed versions of these documents.
- See the customer’s name in transaction reporting. Workday masks the customer name with asterisks when you view customer transaction details in a report.
- Access theCreate Customer Security Segmenttask.
- To restrict access to the customers in this security segment to just the workers in specific companies, selectCompanyandCompany Hierarchyvalues in theCompanyfield.Leave theCompanyfield blank to enable workers in any company to access the customers you select.
- Select theCustomeror customers that are part of the segment.
Create enough segments to cover each unique security access requirement. Included values can span across multiple segments, or be mutually exclusive. Workday recommends that you build from least to most restrictive.Security:Customer Segmented Setupdomain in the System functional area. - Access theCreate Security Grouptask.Create the security groups to associate with the security segments, if existing groups don't meet your business requirements. You can create groups based on criteria such as location, role, job, or organization. Or, you can assign specific users to a user-based security group.
- SelectSegment-Based Security Groupin theType of Tenanted Security Groupfield.
- Select the customer security segment that you created in theAccess to Segmentsfield.
- Edit Domain Security Policies.
- Select theCustomersFunctional Area.
- Select theAccess Customer (Segmented)security policy. This policy controls the access to customer information.
- Remove theAll Userssecurity group.
- Add the desired security groups. You can include your customer segment-based security groups to restrict their members to the values included in their security segments.
- Activate Pending Security Policy Changes.
- Test the security policy changes.Sign in as a different user for each segment and verify that you can access only the customers associated with your segment-based security group. Example: View the customers in theCustomerfield to validate which ones display.
Workers can view or select from only the customers that they have access to based on their segment-based security groups.
- To access EMEA customers, enable only members of your EMEA sales team.
- To access only the customers that are their responsibility, enable your collectors.