Skip to main content
Administrator Guide
Last Updated: 2026-06-12
Steps: Set Up Segmented Security for Time Off

Steps: Set Up Segmented Security for Time Off

  • Configure the
    Correct Time Off
    and
    Request Time Off
    , business processes and security policies in the Time Off and Leave functional area.
  • Create time offs and absence tables that contain the time off types you want to secure.
  • Before configuring new time off security segments or updating existing ones, check that there are no time off entries with an unsubmitted status. This status is only possible when workers enter time off in Time Tracking. If you change time off security, you might prevent those time off events from completing.
You can create time off segments to provide access to specific time offs for different groups of users, including time offs that are part of an absence table. Example: You might create 3 individual segments to provide access for administrators, employees and contingent workers, and managers.
Segmented security for time off removes the need for warning and error validations that control access on time off business processes, streamlining your configurations.
Segmented security for time off is currently an opt-in feature. When you opt in to the feature, Workday:
  • Disables and removes the functionality behind the
    Hide from Worker Self Service
    check box on all time offs in your tenant.
  • Applies the segmented security configuration to determine what time offs to display to workers when they request or enter time off.
Workday displays details of the time off segments in your tenant and their associated time offs and security groups on the
All Time Off Security Segments
report.
  1. Access the
    Domain Security Policies for Functional Area
    report.
    Review the segment-based security groups on the
    Access Time Off (Segmented)
    domain security policy. This domain enables you to configure access to security segments for time offs and absence tables, which control who can request or correct specific time offs.
    If not already enabled, select
    Domain Security Policy
    Enable
    from the related actions menu of the security policy for the
    Access Time Off (Segmented)
    domain in the Time Off and Leave functional area.
    Security: The
    Security Activation
    and
    Security Configuration
    domains in the System functional area.
  2. Access the
    Create Time Off Security Segment
    task.
    Select the time offs that you want to secure to the segment from the
    Time Offs
    prompt.
    For absence tables, we recommend that you either select all of the tier time offs or none of them when providing access for certain security groups. Workday reevaluates all tiers on an absence table after a manager or administrator approves a time off request, including tiers that workers can't access. When providing access to tier time offs, for:
    • Managers, select all tiers.
    • Employees, select all tiers or none.
    Security:
    Set Up: Time Off
    domain in the Time Off and Leave functional area.
  3. Create segment-based security groups that grant specific security groups access to the new time off security segments.
  4. Edit Domain Security Policies.
    Edit permissions for the
    Access Time Off (Segmented)
    domain in the Time Off and Leave functional area to grant the segment-based security groups access to the time offs.
    If you don't have any time offs with
    Hide from Worker Self Service
    check box selected, Workday adds the
    All Users
    security group to the
    Access Time Off (Segmented)
    security policy. Remove this security group, and replace it with the segment-based security groups you want to use.
    If you want ISUs and administrators to have access to all time offs, add them to the
    Access Time Off (Segmented)
    domain policy.
    If the
    Access Time Off (Segmented)
    domain security policy includes security groups that aren't associated with a time off segment, Workday doesn't apply any security segment restrictions to users in the security group, even if they're also in a security group that's associated with another time off segment. Example: Your company has 3 time off types:
    Annual
    ,
    PTO
    , and
    Sick
    . You configure these segment-based security groups and add them to the domain.
    Segment-Based Security Group
    Access Time Off (Segmented) Domain Access
    Associated with a Segment
    Time Off Type
    Considerations
    Group A  - Administrators
    Yes
    No
    N/A
    Users can access all time off types when correcting or requesting time off. This overrides the
    Group B - Employee as Self
    security configuration.
    Group B - Employee as Self
    Yes
    Yes
    Annual
    and
    PTO
    Users can access only the
    Annual
    and
    PTO
    time off types. They can't access the
    Sick
    time off type.
  5. Before opting in to Segmented Security for Time off, access these reports:
    Report
    Consideration
    All Time Offs
    Check these report fields to assess the visibility and security for each time off:
    • Hide from Employee Self Service
    • Time Off Security Segment
    All Time Off Security Segments
    Crosscheck to ensure that all time offs are in the correct segments, secured to the correct segment-based security groups. Make sure that no time offs are missing.
  6. Activate Pending Security Policy Changes.
  7. If you use authentication policies to restrict access to certain domains, edit access restrictions and update your policies to include the segment-based security groups in an authentication rule.
  8. (Optional) When an absence partner supports their own supervisory organization, you can change the worker who has the
    Absence Partner
    role for that organization. This prevents absence partners seeing the time offs in time off segments secured by the
    Absence Partner
    role when requesting time off in an employee self-service context.
  9. Access the
    Maintain Feature Opt-Ins
    report.
    Opt in to Segmented Security for Time Off.
    After you opt in, you can't opt out.
    Security:
    Set Up: System
    domain in the System functional area.
  10. (Optional) Verify the security policy changes. For each new time off security segment:
    1. Sign in as a user who's a member of a segment-based security group associated with the new time off segment.
    2. Access 1 of these tasks:
      • Manage Absence
      • Request Absence
    3. Verify that the time offs that you secured to the relevant time off segment are available for selection for the user.
    4. Repeat steps a-c to verify access to the time off segments for each segment-based security group.
    Segmented security for time off also applies to certain options on these Time Tracking tasks:
    • Enter My Time
    • Enter Time for Worker
    When you secure a time off, only members of the segment-based security groups with access to the time off segment can edit related time off requests using these time-entry options:
    • Enter Time by Type
    • Enter Time by Week
    • Enter Time
    When workers or managers try to use the
    Enter Time
    Enter Time
    menu to add more time or time off to an existing time week that includes an absence table time off request, Workday prevents them completing the task. If your company has set up absence tables, we recommend that users request time off using another option on the
    Enter Time
    menu or micro-edit.
As you create new time offs, add them to time off security segments so that users can access the time offs in time off requests or corrections.
To hide an absence table from certain users, remove all of the tier time offs from the time off segment.