Skip to main content
Administrator Guide
Last Updated: 2025-07-25
Set Up Security for Job Changes

Set Up Security for Job Changes

This topic is relevant to the legacy change job experience. We plan to retire this topic in a future release.
Security:
Business Process Administration
or
Manage: Business Process Definitions
, and
Security Configuration
domains in the System functional area.
Set up security to give managers and administrators access to the
Change Job
business process and each of its content areas.
  • The business process security policy specifies who can start or complete actions in the
    Change Job
    business process.
  • Domain security policies give you field-level control over who can view or modify data in each content area.
  1. Enable these domain security policies:
    Option Description
    Staffing functional area
    Staffing Actions
    Staffing Organizations
    (for consolidated templates)
    Advanced Compensation functional area (for consolidated templates)
    Add Compensation Management Plans
    Change Compensation Management Plans
  2. Access the
    View Business Process Template
    report.
  3. Select the
    Change Job
    business process type.
  4. Edit the business process security policy:
    1. Under
      Attachment Settings
      , define attachments security to restrict who can add, edit, and view attachments in business process events.
    2. Select
      Business Process Policy
      Edit
      from the related actions menu of the business process type.
    3. Under
      Who Can Start the Business Process
      , select the security groups you want to grant access to for each initiating action.
      Since the
      Change Job
      business process has multiple initiating actions, you can limit the types of job changes available to different roles. Example: You can restrict access to the
      Change Contingent Worker Details
      task, but provide broader access to the
      Change Location
      and
      Request Transfer
      tasks.
      To hide tasks that aren't relevant, leave the security groups empty.
    4. Under
      Who Can Do Action Steps in the Business Process
      , select the security groups you want to be able to complete review steps in the business process.
      Ensure that you grant permissions to the same groups that you assigned to the review steps in the business process definition.
    5. Under
      Who Can Do Actions on Entire Business Process
      , grant permissions to the
      HR Partner
      ,
      HR Administrator
      , or other relevant HR role in your organization.
      To ensure that business process validations run, you must also grant
      View All
      permission to the roles that can initiate the business process.
    6. Select
      OK
      , then
      Done
      to return to the
      View Business Process Template
      report.
  5. On the
    Section Groups
    tab, review the template sections and their task dependencies to decide which roles need access to each section.
  6. Select the
    Task Security
    tab to grant security permissions on each domain:
    1. Select
      Domain
      Edit Security Policy Permissions
      from the related actions menu of a domain.
    2. Grant access to the domain by selecting security groups and specifying whether they have permission to view or modify data.
      To prevent problems caused by incomplete data, grant permissions on domains that contain required fields:

        Staffing Actions: Administrator

        Staffing Actions: Change Job Date and Reason

        Staffing Actions: Job Profile

        Staffing Actions: Location

        Staffing Actions: Select or Create Position
        (for position management organizations)

        Staffing Actions: Move Manager's Team
        (for job changes that move a manager to a different organization)

        Staffing Organizations: Grant, Fund, Program, Gift
        (for required costing organizations)

      Your domain security policy configuration for the Staffing Actions domains doesn’t apply to Change Job templates that use the enhanced user interface.
    3. Select
      OK
      , then
      Done
      to return to the
      View Business Process Template
      report.
  7. (Optional) If you consolidated
    Change Job
    with
    Assign Employee Collective Agreement
    ,
    Change Organization Assignments for Worker
    , and
    Propose Compensation Change
    , set up security for these processes.
    To retain a simplified workflow, Workday doesn't display the
    Compensation
    section to role-based security groups for these initiating actions:
    • Change Contingent Worker Details
    • Change Location
    • Request Transfer
    If you're consolidating
    Change Job
    with
    Assign Employee Collective Agreement
    , ensure that you also grant security permissions to the
    Worker Data: Collective Agreements
    domain.
  8. Access the
    Activate Pending Security Policy Changes
    task to confirm your changes.
The table lists the recommended security domains for managers:
Domain
Secures These Actions
Staffing Actions: Change Job Date and Reason
Effective date, reason, proposed manager, proposed organization, headcount options
Staffing Actions: Select or Create Position
Existing or new position (for position management organizations)
Staffing Actions: Job Profile
Job profile, job title
Staffing Actions: Business Title
Business title
Staffing Actions: Location
Location, scheduled hours, work hours profile, work shift, work space
Staffing Actions: Contract Details
Purchase order, supplier, contract end date, pay rate, currency, frequency, assignment details
Staffing Actions: Attachments
Document link, category, comment
Staffing Organizations: Cost Center
Cost center
Staffing Organizations: Move Manager's Team
Move team or keep team in current organization
Access the
Template-Driven Business Process Security
report to confirm that the
Change Job
business process and domain security permissions are aligned.