Skip to main content
Administrator Guide
Last Updated: 2026-06-26
Steps: Maintain Access to Learning Content

Steps: Maintain Access to Learning Content

You can restrict access to learning content using segmented security based on:
  • Security categories on courses.
  • Security categories on programs.
  • Topics.
Security categories on courses and programs provide more granular security. When you view a topic, you can only view programs or courses that you have permission to view based on the security category on the program or course. Programs and courses that have no security category are open to all users with access to Learning, provided they have access to the topic.
Topic-based segmented security applies separately to programs and courses. Learners can view a program when they have access to all of the topics associated with the program, but can only view each course within the program if they have access to the topics associated with the course.
For Workday Learning, powered by Sana:
  • Workers with content creator access need
    View
    and
    Modify
    permissins on the
    Manage: Learning Native Content
    domain. Use unconstrained groups when workers must see all native content; use constrained groups so workers see only content they own or that was explicitly shared with them.
  • Workers with Learning admin access need catalog and enrollment domains to add submitted Sana content to courses. See Setup Considerations: Workday Learning Powered by Sana.
  • User provisioning for Workday Learning, powered by Sana is separate from segmented security. Workers need provisioned integrated access to use
    Sana Create
    and to open
    Sana Content
    lessons, in addition to domain access. See Steps: Set Up User Provisioning for Workday Learning Powered by Sana.
  1. Access 1 of these tasks:
    • Create Learning Security Category
    • Create Learning Security Segment
    Create security segments to restrict access by security category or topic, or both.
    Security:
    Set Up: Learning Security Segments
    domain in the System functional area.
  2. If existing security groups don't meet your business requirements, create the security groups to associate with the security segments. Map these groups to 1 or more of the learning security category or topic security segments.
    The security groups that you grant access to in the
    Group Criteria
    section must be unconstrained.
  3. Edit Domain Security Policies.
    Grant your learning segment-based security groups access on the
    Learning Access
    domain so that members of these groups can access content on the
    Learning
    dashboard.
  4. Activate Pending Security Policy Changes.
  5. Access the
    Edit Tenant Setup - HCM
    task.
    In the
    Learning
    section, select the
    Enable Security Categories
    option to display a
    Security Category
    prompt on these tasks:
    • Create Course
    • Create Program
    • Edit Course
    • Edit Program
This example illustrates how to grant access for managers to a management-related topic and make other topics available to all.
  1. Create 3 topics:
    • Management
    • Health and Safety
    • Skills
  2. Create 2 learning topic security segments. Example:
    • Name the first segment
      Topics for Managers
      and select the
      Management
      topic.
    • Name the other segment
      Public Topics
      and select the
      Health and Safety
      and
      Skills
      topics.
  3. Create 2 segment-based security groups: 1 for managers and 1 for everyone else. Example:
    • Managers
    • Public
    For each of these security groups, select:
    • 1 or more groups from
      Group Criteria
      . Example:
      • For
        Managers
        , select
        Manager (Unconstrained)
        .
      • For
        Public
        , select:
        • All Contingent Workers
        • All Employees
    • The learning topic security segments to grant access to in
      Access Rights
      . Example:
      • Topics for Managers
      • Public Topics
Create learning content such as:
  • Programs, courses, and stand-alone lessons that contain topics.
  • Programs and courses with security categories.
Test the security policy changes.
In Production tenants, a search indexing job runs every 12 hours. In non-Production tenants, this job runs every 24 hours. Depending on the size of your learning catalog, the job itself can take a few hours to complete. The search indexing job is required to populate the
Learning
dashboard and for relevance searching in Learning. After configuring topic-based segmented security, security categories, and associated segment-based security groups and domains, ensure that you allow the appropriate amount of time to pass in your Production or non-Production tenant before testing these changes.
For each segment:
  • Sign in as a user who's a member of a segment-based security group associated with a topic or security category.
  • Verify that you can access the learning content for that segment.