Steps: Set Up Segmented Security for Time Off
- Configure theCorrect Time OffandRequest Time Off, business processes and security policies in the Time Off and Leave functional area.
- Create time offs and absence tables that contain the time off types you want to secure.
- Before configuring new time off security segments or updating existing ones, check that there are no time off entries with an unsubmitted status. This status is only possible when workers enter time off in Time Tracking. If you change time off security, you might prevent those time off events from completing.
You can create time off segments to provide access to specific time offs for different groups of users, including time offs that are part of an absence table. Example: You might create 3 individual segments to provide access for administrators, employees and contingent workers, and managers.
Segmented security for time off removes the need for warning and error validations that control access on time off business processes, streamlining your configurations.
Segmented security for time off is currently an opt-in feature. When you opt in to the feature, Workday:
- Disables and removes the functionality behind theHide from Worker Self Servicecheck box on all time offs in your tenant.
- Applies the segmented security configuration to determine what time offs to display to workers when they request or enter time off.
Workday displays details of the time off segments in your tenant and their associated time offs and security groups on the
All Time Off Security Segments
report.- Access theDomain Security Policies for Functional Areareport.Review the segment-based security groups on theAccess Time Off (Segmented)domain security policy. This domain enables you to configure access to security segments for time offs and absence tables, which control who can request or correct specific time offs.If not already enabled, select from the related actions menu of the security policy for theAccess Time Off (Segmented)domain in the Time Off and Leave functional area.Security: TheSecurity ActivationandSecurity Configurationdomains in the System functional area.
- Access theCreate Time Off Security Segmenttask.Select the time offs that you want to secure to the segment from theTime Offsprompt.For absence tables, we recommend that you either select all of the tier time offs or none of them when providing access for certain security groups. Workday reevaluates all tiers on an absence table after a manager or administrator approves a time off request, including tiers that workers can't access. When providing access to tier time offs, for:
- Managers, select all tiers.
- Employees, select all tiers or none.
Security:Set Up: Time Offdomain in the Time Off and Leave functional area. - Create segment-based security groups that grant specific security groups access to the new time off security segments.
- Edit Domain Security Policies.Edit permissions for theAccess Time Off (Segmented)domain in the Time Off and Leave functional area to grant the segment-based security groups access to the time offs.If you don't have any time offs withHide from Worker Self Servicecheck box selected, Workday adds theAll Userssecurity group to theAccess Time Off (Segmented)security policy. Remove this security group, and replace it with the segment-based security groups you want to use.If you want ISUs and administrators to have access to all time offs, add them to theAccess Time Off (Segmented)domain policy.If theAccess Time Off (Segmented)domain security policy includes security groups that aren't associated with a time off segment, Workday doesn't apply any security segment restrictions to users in the security group, even if they're also in a security group that's associated with another time off segment. Example: Your company has 3 time off types:Annual,PTO, andSick. You configure these segment-based security groups and add them to the domain.Segment-Based Security GroupAccess Time Off (Segmented) Domain AccessAssociated with a SegmentTime Off TypeConsiderationsGroup A - AdministratorsYesNoN/AUsers can access all time off types when correcting or requesting time off. This overrides theGroup B - Employee as Selfsecurity configuration.Group B - Employee as SelfYesYesAnnualandPTOUsers can access only theAnnualandPTOtime off types. They can't access theSicktime off type.
- Before opting in to Segmented Security for Time off, access these reports:ReportConsiderationAll Time OffsCheck these report fields to assess the visibility and security for each time off:
- Hide from Employee Self Service
- Time Off Security Segment
All Time Off Security SegmentsCrosscheck to ensure that all time offs are in the correct segments, secured to the correct segment-based security groups. Make sure that no time offs are missing. - Activate Pending Security Policy Changes.
- If you use authentication policies to restrict access to certain domains, edit access restrictions and update your policies to include the segment-based security groups in an authentication rule.
- (Optional) When an absence partner supports their own supervisory organization, you can change the worker who has theAbsence Partnerrole for that organization. This prevents absence partners seeing the time offs in time off segments secured by theAbsence Partnerrole when requesting time off in an employee self-service context.
- Access theMaintain Feature Opt-Insreport.Opt in to Segmented Security for Time Off.After you opt in, you can't opt out.Security:Set Up: Systemdomain in the System functional area.
- (Optional) Verify the security policy changes. For each new time off security segment:
- Sign in as a user who's a member of a segment-based security group associated with the new time off segment.
- Access 1 of these tasks:
- Manage Absence
- Request Absence
- Verify that the time offs that you secured to the relevant time off segment are available for selection for the user.
- Repeat steps a-c to verify access to the time off segments for each segment-based security group.
Segmented security for time off also applies to certain options on these Time Tracking tasks:- Enter My Time
- Enter Time for Worker
- Enter Time by Type
- Enter Time by Week
- Enter Time
When workers or managers try to use the menu to add more time or time off to an existing time week that includes an absence table time off request, Workday prevents them completing the task. If your company has set up absence tables, we recommend that users request time off using another option on theEnter Timemenu or micro-edit.
As you create new time offs, add them to time off security segments so that users can access the time offs in time off requests or corrections.
To hide an absence table from certain users, remove all of the tier time offs from the time off segment.