Skip to main content
Administrator Guide
Last Updated: 2026-05-01
Steps: Set Up Security for Workday Everywhere Using Sana Self-Service Agent

Steps: Set Up Security for Workday Everywhere Using Sana Self-Service Agent

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
  • UMSA
    , the feature is automatically available. You can skip the
    Enable Innovation Services Feature and AI Data Contributions for MSA Customers
    step. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
  • MSA
    , you must enable this feature through Innovation Services using the
    Enable Innovation Services Feature and AI Data Contributions for MSA Customers
    step.
Note: UMSA customers don't have Innovation Services tasks and reports in their tenants as these are for MSA customers only. UMSA customers can ignore all information regarding Innovation Services.
You can set up security to enable workers to perform some Workday self-service tasks directly in these workspaces:
  • Microsoft 365 Copilot
  • Microsoft Teams
  • Slack
  1. Complete additional setup steps required by your organization's subscription service agreement. See Streamlining Feature Adoption and the Workday AI Home Page.
    On the
    Innovation Services and Data Selection Opt-In
    task, select the
    Workday Everywhere
    service on the
    Available Services
    tab in the
    People Experience
    category.
  2. Activate Workday Everywhere.
    1. Access the
      Maintain Functional Areas
      task.
    2. Search for Workday Everywhere in the Functional Area column.
    3. Select the
      Enabled
      check box for the Workday Everywhere functional area.
    Security: Security Configuration
    domain in the
    System
    functional area.
  3. Edit Domain Security Policies.
    1. Set up the:
      • Workday Everywhere Administrator
        domain in the Workday Everywhere functional area.
      • Security Activation subdomain of the
        Security Administration
        domain in the System functional area.
      • WQL for Workday Extend
        subdomain of the
        Workday Extend
        domain in the System functional area to enable integration with Microsoft 365 Copilot, Microsoft Teams, or Slack workspace.
    2. Grant the All Employees security group View and Get access to these domains in the System functional area:
      • View: Public Innovation Services Items.
      • WQL for Workday Extend
        subdomain of the
        Workday Extend
        domain.
    3. Grant the All Employees security group View and Get access to these domains in the System functional area.
      • View: Public Innovation Services Items
        .
      • WQL for Workday Extend WQL for Workday Extend
        subdomain of the
        Workday Extend domain.
    4. Grant the All Employees security group View and Modify access to the
      Workday Everywhere User
      domain in the Workday Everywhere functional area.
      This access enables workers to use Workday in their Microsoft 365 Copilot, Microsoft Teams, or Slack workspace. Workday recommends that you:
    5. (Optional) Grant these security groups View and Modify access to the
      Workday Everywhere User
      domain in the Workday Everywhere functional area to enable contingent workers to use Workday Everywhere:
      • All Contingent Workers.
      • Contingent Worker as Self.
      Feature availability for contingent workers depends on your tenant configurations.
    6. (Optional) Add managers as a security group with View and Modify access to these domains in the Time Off and Leave functional area:
      • Worker Data: Time Off (Time Off Balances Manager View)
        . Permits managers to receive Slack or Microsoft Teams notifications that enable them to approve time off requests for their workers.
        Workday does not support notifications in Microsoft 365 Copilot.
      • Worker Data: Time Off (Time Off Manager View)
        .
  4. Activate Pending Security Policy Changes.