Set Up Security for Workday Everywhere Using Sana Self-Service Agent
You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
- Select your profile avatar on Workday Community.
- SelectProfile.
- On your profile page, select your organization's name, which is beneath your name and next to your job title.
- View yourSubscription Service Agreementvalue.
If the value is:
- UMSA, the feature is automatically available. You can skip theEnable Innovation Services Feature and AI Data Contributions for MSA Customersstep. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
- MSA, you must enable this feature through Innovation Services using theEnable Innovation Services Feature and AI Data Contributions for MSA Customersstep.
Note: UMSA customers don't have Innovation Services tasks and reports in their tenants as these are for MSA customers only. UMSA customers can ignore all information regarding Innovation Services.
You can set up security to enable workers to perform some Workday self-service tasks directly in these workspaces:
- Gemini Enterprise
- Microsoft 365 Copilot
- Microsoft Teams
- Slack
- Complete additional setup steps required by your organization's subscription service agreement. See Sign the Universal Main Subscription Agreement (UMSA): Unlock AI Agents, Sana, Flex Credits, and Workday Innovation.
- Access theInnovation Services and Data Selection Opt-Intask.
- On theAvailable Servicestab, select theWorkday Everywhereservice in thePeople Experiencecategory.
- Activate Workday Everywhere.
- Access theMaintain Functional Areastask.
- In theFunctional Areacolumn, search forWorkday Everywhere.
- Select theEnabledcheck box for the Workday Everywhere functional area.
Security: Security Configurationdomain in the System functional area. - Set up the:
- Workday Everywhere Administratordomain in the Workday Everywhere functional area.
- Security Activation subdomain of theSecurity Administrationdomain in the System functional area.
- WQL for Workday Extendsubdomain of theWorkday Extenddomain in the System functional area to enable integration with Gemini Enterprise, Microsoft 365 Copilot, Microsoft Teams, or Slack workspace.
- Grant the All Employees security group View and Get access to these domains in the System functional area:
- View: Public Innovation Services Items.
- WQL for Workday Extendsubdomain of theWorkday Extenddomain.
- Grant the All Employees security group View and Get access to these domains in the System functional area.
- View: Public Innovation Services Items.
- WQL for Workday Extend WQL for Workday Extendsubdomain of theWorkday Extend domain.
- Grant theAll Employees security group View and Modifyaccess to theWorkday Everywhere Userdomain in the Workday Everywhere functional area.This access enables workers to use Workday in their Gemini Enterprise, Microsoft 365 Copilot, Microsoft Teams, or Slack workspace. Workday recommends that you:
- Add the Employee As Self security group to this domain.
- Test the workspaces with selected security groups before adding the All Employees security group to this domain. See Workday for Slack and Workday for Microsoft Teams FAQ.
- (Optional) Grant these security groups View and Modify access to theWorkday Everywhere Userdomain in the Workday Everywhere functional area to enable contingent workers to use Workday Everywhere:
- All Contingent Workers.
- Contingent Worker as Self.
Feature availability for contingent workers depends on your tenant configurations.