Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Steps: Maintain Access to Customer Information

Steps: Maintain Access to Customer Information

  • Understand segment-based security groups and segmented security.
  • Determine whether you need to restrict segments of data to groups of workers.
You can control worker access to your customer data through configurable customer security segments. Customer segmented security restricts access to designated customers and visibility to customer information so that workers can't:
  • Select customers that they don't have access to when creating, editing, or searching for transactions.
  • See customer information in search results. Workday masks the customer name with asterisks and doesn't display other important information.
  • Print or view customer documents, such as invoices, statements, and refunds.
  • See the printed versions of these documents.
  • See the customer’s name in transaction reporting. Workday masks the customer name with asterisks when you view customer transaction details in a report.
  1. Access the
    Create Customer Security Segment
    task.
    • To restrict access to the customers in this security segment to just the workers in specific companies, select
      Company
      and
      Company Hierarchy
      values in the
      Company
      field.
      Leave the
      Company
      field blank to enable workers in any company to access the customers you select.
    • Select the
      Customer
      or customers that are part of the segment.
    Create enough segments to cover each unique security access requirement. Included values can span across multiple segments, or be mutually exclusive. Workday recommends that you build from least to most restrictive.
    Security:
    Customer Segmented Setup
    domain in the System functional area.
  2. Access the
    Create Security Group
    task.
    Create the security groups to associate with the security segments, if existing groups don't meet your business requirements. You can create groups based on criteria such as location, role, job, or organization. Or, you can assign specific users to a user-based security group.
    • Select
      Segment-Based Security Group
      in the
      Type of Tenanted Security Group
      field.
    • Select the customer security segment that you created in the
      Access to Segments
      field.
  3. Edit Domain Security Policies.
    • Select the
      Customers
      Functional Area
      .
    • Select the
      Access Customer (Segmented)
      security policy. This policy controls the access to customer information.
    • Remove the
      All Users
      security group.
    • Add the desired security groups. You can include your customer segment-based security groups to restrict their members to the values included in their security segments.
  4. Activate Pending Security Policy Changes.
  5. Test the security policy changes.
    Sign in as a different user for each segment and verify that you can access only the customers associated with your segment-based security group. Example: View the customers in the
    Customer
    field to validate which ones display.
Workers can view or select from only the customers that they have access to based on their segment-based security groups.
  • To access EMEA customers, enable only members of your EMEA sales team.
  • To access only the customers that are their responsibility, enable your collectors.