Skip to main content
Administrator Guide
Last Updated: 2026-06-12
Example: Set Up Segmented Security for Time Off

Example: Set Up Segmented Security for Time Off

This example illustrates how to configure access to specific time offs for specific groups of users.
You're the security administrator at Global Modern Services (GMS). You want to configure access to a set of time offs for managers so that they can request and correct time off on behalf of other workers.
Create the time offs that you want to secure. Example: Time offs for sick days, vacation, and holidays.
Opt in to Segment Security for Time Off.
Security:
  • Security Configuration
    domain in the System functional area.
  • Set Up: Time Off
    domain in the Time Off and Leave functional area.
  1. Access the
    All Time Off Security Segments
    report.
  2. View the time off security segments in your tenant. If your tenant contains an existing
    Segment-Based Security Group for All Time Off Segment
    segment that's mainly for administrators, you can remove several security groups from the segment-based group. Otherwise, skip steps a-d.
    1. From the related actions menu of the
      Segment-Based Security Group for All Time Off Segment
      security group, select
      Segment-Based Security Group
      Edit
      .
    2. From the
      Security Groups
      prompt, remove these groups:
      • Manager
      • Management Chain
    3. Click
      OK
      .
    4. Click
      Done
      .
  3. Create a time off security segment for managers.
    1. Access the
      Create Time Off Security Segment
      task.
    2. Specify these values:
      Field
      Value
      Name
      Manager Time Offs Segment
      Time Offs
      Select all of the time offs that managers should be able to enter for their direct reports. Example: Vacation time off and holiday time off.
    3. Click
      OK
      .
    4. Click
      Done
      .
  4. Create a time off security segment for all employees.
    1. Access the
      Create Time Off Security Segment
      task.
    2. Specify these values:
      Field
      Value
      Name
      Employee Self Service Time Offs Segment
      Time Offs
      Select a smaller set of time offs that workers should be able to request and correct. Example: Vacation time off and holiday time off.
    3. Click
      OK
      .
    4. Click
      Done
      .
  5. Create a segment-based security group for managers.
    1. Access the
      Create Security Group
      task.
    2. Specify these values:
      Field
      Value
      Type of Tenanted Security Group
      Segment-Based Security Group
      Name
      Manager Time Offs
    3. Click
      OK
      .
    4. Specify these values:
      Field
      Value
      Security Groups
      • Manager
      • Management Chain
      Access to Segments
      Manager Time Offs Segment
    5. Click
      OK
      .
    6. Click
      Done
      .
  6. Create a segment-based security group for all employees.
    1. Access the
      Create Security Group
      task.
    2. Specify these values:
      Field
      Value
      Type of Tenanted Security Group
      Segment-Based Security Group
      Name
      Time Offs - Employee Self Service
    3. Click
      OK
      .
    4. Specify these values:
      Field
      Value
      Security Groups
      Employee as Self
      Access to Segments
      Employee Self Service Time Offs Segment
    5. Click
      OK
      .
    6. Click
      Done
      .
  7. Edit the domain security policy.
    1. Access the
      View Domain
      report.
    2. Select
      Time Off Segmented Setu
      from the
      Domain
      report.
    3. From the related actions menu, select
      Domain
      Edit Security Policy Permissions
      .
    4. In the
      Report/Task Permissions
      section, add these groups with View access:
      • Manager Time Offs
      • Time Offs - Employee Self Service
    5. If the
      Access Time Off (Segmented)
      domain security policy contains the
      All Users
      security group, remove it.
    6. Click
      OK
      .
    7. Click
      Done
      .
  8. Activate the security policy changes.
    1. Access the
      Activate Pending Security Policy Changes
      task.
    2. In the
      Comment
      field, enter:
      Created time off security segments to enable manager and employee self-service access to sets of time offs.
    3. Click
      OK
      .
    4. Select the
      Confirm
      check box.
    5. Click
      OK
      .
    6. Click
      Done
      .
Managers can view all time offs in the
Manager Time Offs
security segment when they enter or correct time off on behalf of workers using either the
Request Absence
task or
Manage Absence
report.
Employees can request or correct time off for the time offs in the
Employee Self Service Time Offs Segment
segment.
Compare access for different groups of users. Example: Sign in to Workday as a worker such as Ben Adams and access the
Request Absence
task or
Manage Absence
report to view the set of time offs.
Create additional time off security segments and segment-based security groups to create a more fine-grained segment-based time off security model, depending on your requirements.