Skip to main content
Administrator Guide
Last Updated: 2026-03-13
FAQ: Segmented Security for Time Off

FAQ: Segmented Security for Time Off

Why can users view and request previously hidden time offs?
Unconstrained security groups aren't context-sensitive. When users are members of unconstrained security groups such as
Absence Administrator
or
Manager (Unconstrained)
in addition to
Employee as Self
and enter time off for themselves, they have both sets of permissions. They can view all of the time offs that they're eligible for.
To resolve this situation, remove the unconstrained security groups from your time off segment-based security groups. Use constrained versions of the security groups instead so that users see the appropriate time offs for each context.
Constrained groups are context-sensitive. When users are members of constrained security groups such as
Absence Partner
or
Manager
with access to specific time off security segments, they can only view the appropriate time offs when entering time off for another worker using the:
  • Manage Absence
    report.
  • Request Absence
    task.
When members of the
Absence Partner
group enter time off for themselves, they use the
Employee as Self
context and can only view the appropriate time offs for Employee Self Service (ESS). However, if you've a time off segment for workers and another for the
Absence Partner
role, when absence partners support their own organization, they can request time off using time offs in both segments. To prevent this, ensure that a different absence partner supports those absence partners' organizations.
Why do users sometimes have view-only access to a time off request?
When users try to correct a time off that's secured by a time off segment that they don't have access to, Workday provides view only access to the time off request and displays a message explaining why they can't correct it.