Skip to main content
Administrator Guide
Last Updated: 2026-03-13
Steps: Set Up Roles for Account Reconciliation

Steps: Set Up Roles for Account Reconciliation

Set up assignable roles for users who will prepare and approve account reconciliations. These roles are linked to account reconciliation definitions, and you assign users to the roles when you create or edit account reconciliation definitions.
You can't use preparer or approver roles that you configured for basic account certification for account reconciliation.
  1. Set Up Assignable Roles.
    1. Add 2 rows to the grid.
    2. From the
      Workday Role
      prompt in each row, select
      Account Reconciliation Preparer
      and
      Account Reconciliation Approver
      .
    3. From the
      Enabled For
      prompts, select
      Account Reconciliation
      .
    4. From the
      Assigned/Reviewed by Security Groups
      prompts, select a security group to approve user assignments for these roles.
      Ensure that users who will set up account reconciliation definitions and assign users to roles on those definitions are members of this security group, and that the group has access to the
      Set Up: Assignable Roles
      domain.
  2. Create a constrained role-based security group for both the preparer and approver roles.
    1. From the
      Type of Tenanted Security Group
      prompt, select
      Role-Based Security Group (Constrained)
      .
    2. From the
      Assignable Role
      prompt, select 1 of your roles.
    3. Click
      OK
      , then
      Done
      .
  3. Edit Domain Security Policies.
    Enable the domain security policy for the
    Process: Account Reconciliation
    domain in the Financial Accounting functional area, and give your account reconciliation roles
    Modify
    access to report and task permissions.
  4. Access each subdomain of the
    Process: Account Reconciliation
    domain:
    • Process: Account Reconciliation - Hub
    • Process: Account Reconciliation - Manage Reconciling Items
    • Process: Account Reconciliation - Manage Supporting Balances
    • Process: Account Reconciliation - Workspace
    • Process: Account Reconciliation - Reporting
    For each subdomain, from the related actions menu of the domain security policy, select
    Domain Security Policy
    Enable
    .
    Click
    Confirm
    , then
    OK
    .
    To preserve internal controls and prevent approvers from changing reconciliations, edit the domain security policies to give your approver role
    View
    access only to reports and tasks on these subdomains:
    • Process: Account Reconciliation - Manage Reconciling Items
    • Process: Account Reconciliation - Manage Supporting Balances
    Security:
    Security Configuration
    domain in the System functional area.
  5. Activate Pending Security Policy Changes.
Create account reconciliation definitions and assign users to the role-based security groups you created.