Example: Set Up Segmented Security for Time Off
This example illustrates how to configure access to specific time offs for specific groups of users.
You're the security administrator at Global Modern Services (GMS). You want to configure access to a set of time offs for managers so that they can request and correct time off on behalf of other workers.
Create the time offs that you want to secure. Example: Time offs for sick days, vacation, and holidays.
Opt in to Segment Security for Time Off.
Security:
- Security Configurationdomain in the System functional area.
- Set Up: Time Offdomain in the Time Off and Leave functional area.
- Access theAll Time Off Security Segmentsreport.
- View the time off security segments in your tenant. If your tenant contains an existingSegment-Based Security Group for All Time Off Segmentsegment that's mainly for administrators, you can remove several security groups from the segment-based group. Otherwise, skip steps a-d.
- From the related actions menu of theSegment-Based Security Group for All Time Off Segmentsecurity group, select .
- From theSecurity Groupsprompt, remove these groups:
- Manager
- Management Chain
- ClickOK.
- ClickDone.
- Create a time off security segment for managers.
- Access theCreate Time Off Security Segmenttask.
- Specify these values:FieldValueNameManager Time Offs SegmentTime OffsSelect all of the time offs that managers should be able to enter for their direct reports. Example: Vacation time off and holiday time off.
- ClickOK.
- ClickDone.
- Create a time off security segment for all employees.
- Access theCreate Time Off Security Segmenttask.
- Specify these values:FieldValueNameEmployee Self Service Time Offs SegmentTime OffsSelect a smaller set of time offs that workers should be able to request and correct. Example: Vacation time off and holiday time off.
- ClickOK.
- ClickDone.
- Create a segment-based security group for managers.
- Access theCreate Security Grouptask.
- Specify these values:FieldValueType of Tenanted Security GroupSegment-Based Security GroupNameManager Time Offs
- ClickOK.
- Specify these values:FieldValueSecurity Groups
- Manager
- Management Chain
Access to SegmentsManager Time Offs Segment - ClickOK.
- ClickDone.
- Create a segment-based security group for all employees.
- Access theCreate Security Grouptask.
- Specify these values:FieldValueType of Tenanted Security GroupSegment-Based Security GroupNameTime Offs - Employee Self Service
- ClickOK.
- Specify these values:FieldValueSecurity GroupsEmployee as SelfAccess to SegmentsEmployee Self Service Time Offs Segment
- ClickOK.
- ClickDone.
- Edit the domain security policy.
- Access theView Domainreport.
- SelectTime Off Segmented Setufrom theDomainreport.
- From the related actions menu, select .
- In theReport/Task Permissionssection, add these groups with View access:
- Manager Time Offs
- Time Offs - Employee Self Service
- If theAccess Time Off (Segmented)domain security policy contains theAll Userssecurity group, remove it.
- ClickOK.
- ClickDone.
- Activate the security policy changes.
- Access theActivate Pending Security Policy Changestask.
- In theCommentfield, enter:Created time off security segments to enable manager and employee self-service access to sets of time offs.
- ClickOK.
- Select theConfirmcheck box.
- ClickOK.
- ClickDone.
Managers can view all time offs in the
Manager Time Offs
security segment when they enter or correct time off on behalf of workers using either the Request Absence
task or Manage Absence
report.Employees can request or correct time off for the time offs in the
Employee Self Service Time Offs Segment
segment.Compare access for different groups of users. Example: Sign in to Workday as a worker such as Ben Adams and access the
Request Absence
task or Manage Absence
report to view the set of time offs.Create additional time off security segments and segment-based security groups to create a more fine-grained segment-based time off security model, depending on your requirements.