FAQ: Pre-Hire Segmented Security
What's a Constrained Pre-Hire?
A constrained Pre-Hire is a Pre-Hire that’s associated with an organization in Workday:
- If Hired: Workday associates them with the organization into which they’ve been hired
- If Terminated: Workday associates them with the organization into which they were hired
- In Progress Hire: Workday associates them with the organization targeted for the hire.
- In Progress Hire Offer/Employment Agreement: Workday associates them with the organization from the job requisition used in the hire.
What is an Unconstrained Pre-Hire?
An unconstrained Pre-Hire is a Pre-Hire that has no association with an organization in Workday. Example: A Pre-Hire that an authorised user creates using the
Create Pre-Hire
task. An authorised user with access to any Pre-Hire has visibility of all unconstrained Pre-Hires. How does this feature impact a worker with an unconstrained security group?
Workers with an unconstrained security role (Example: HR Admins who operate across the company) won’t experience any changes to their access to Pre-Hires following opt-in to the enhancements. Their unconstrained security role ensures that they can view both constrained Pre-Hires (regardless of their organization) and unconstrained Pre-Hires.
How does this feature impact a worker with a constrained security group?
Previously, workers with a constrained security group (Example: A Manager who operates within an organization) can only view Pre-Hires within the organization to which they have access plus any unconstrained Pre-Hires. Workday now enables customers to configure which workers can access unconstrained Pre-Hires.
Are there any exceptions to the Pre-Hire security logic?
There may be some exceptions to this enhanced Pre-Hire security logic throughout Workday applications, where the business logic would not benefit from this enhancement. Examples:
Background Check
, Contract Contingent Worker
, Hire Employee
, Offer
.In these cases, your authorized users need access to all Pre-Hires in your tenant (including any terminated worker Pre-Hire profiles) to mitigate against the creation of duplicate Pre-Hire profiles and support the hire and recruitment processes effectively. This enhancement could potentially introduce a poor experience. Example: Where an authorized user can create a Pre-Hire but not hire them. To prevent this, Workday maintains the existing security that governs access to the task, regardless of whether the customer opts into this enhancement . Provided the user has access to the tasks and Pre-Hire security domains, they’ll continue to have access to both constrained and unconstrained Pre-Hires within these tasks and processes.
How does restricting access to unconstrained Pre-Hires impact the recruitment process and duplicate management functionality?
The duplicate management functionality arises when a newly created Pre-Hire (through a new application) matches key criteria of an existing Pre-Hire. Workday considers a Pre-Hire that’s created through the recruitment process to be a constrained Pre-Hire.
- Where the recruiter has constrained security access, the existing process is maintained. Provided the recruiter has appropriate access to the organisation of the legacy Pre-Hire profile (existing process), the duplicate management functionality works as expected.
- Where the recruiter has constrained security access and they don’t have access to the organizations of the legacy Pre-Hire profile, the duplicate management functionality may not work. However, this would be an existing restriction around access to legacy Pre-Hire profiles.
- Where the recruiter has unconstrained security access, they can see the Pre-Hires associated with all and no organizations, assuming there’s no negative impact to duplicate management.
How does this enhancement impact the Create Pre-Hire task and duplicate management functionality?
Create Pre-Hire
task and duplicate management functionality?When an authorised user accesses the stand-alone
Create Pre-Hire
task after opting into the feature, they’ll lose access to any Pre-Hires they create unless they can access the necessary domains as listed below.If they attempt to hire a Pre-Hire using the
Hire Employee
task or the recruitment process, they’ll be able to access and complete the process as normal. When a user creates a new Pre-Hire with the same name and country as an existing Pre-Hire, Workday triggers the 'Pre-Hire already exists' exception, regardless of their security configuration. How can I ensure a worker with a Constrained Security Group can access Unconstrained Pre-Hires?
- Access theCreate Security Grouptask.
- Create a segment-based security group using the new Unconstrained Pre-Hire segment: From the Access to Segments drop-down menu, selectSecurity Segments (Workday Owned)>Pre-Hire Security Segment.
- Add the unconstrained security group (Example:Manager (Unconstrained)) for the required role (Example:Managerrole) to the Unconstrained Pre-Hire Segment-Based Security group.
- Identify the security domains or business process security policies that are impacted or control access to the task, data, or business process for which they want the role to retain access.
- Add the new segmented Pre-Hire security group to the appropriate domain security policy or business process policy, ensuring that they provide the required level of access (Example:ViewandModify).
Recommendations:
- To ensure the existing constrained security access is retained, the original security group should be left in place.
- If opted in, segment-based security configuration should be the same for these tasks:
- Create Pre-Hire
- Edit Pre-Hire
- View Pre-Hire
Which security domains should I update for this enhancement?
In order to correctly implement this enhancement, we strongly recommend that you update these domains as according to your organization’s needs:
- Manage: Expense Report for Pre-Hire
- Manage Pre-Hire Data (User-Based Groups only)
- Manage Pre-Hire Process
- Manage Pre-Hire Process: Consider Pre-Hires
- Manage Pre-Hire Process: Enter Pre-Hire Interviews
- Manage Pre-Hire Process: Hire Eligibility Status Comment
- Manage Pre-Hire Process: Manage Pre-Hires
- Manage Pre-Hire Process: Pre-Hire Eligibility
- Manage Pre-Hire Process: View Pre-Hire
- Manage Pre-Hire Process: View Pre-Hire Interviews
- Manage Pre-Hire Process: Worker Hire Eligibility
- Offer / Employment Agreement: Collective Agreement
- Offer / Employment Agreement: Employee Contracts
- Offer / Employment Agreement: Notice Period
- Offer / Employment Agreement: Probation Period
- Pre-Hire Data: Employment Agreement
- Pre-Hire Data: Business Title
- Pre-Hire Data: End Date
- Pre-Hire Data: Scheduled Weekly Hours
- Pre-Hire Data: Start Date and Location
- Pre-Hire Data: Term Time
- Pre-Hire Data: Name and Contact Information
- Pre Hire Data: Names
- Pre Hire Data: Contact Information
- Pre-Hire Demographics by Organization
- Pre-Hire Personal Data
- Pre-Hire Personal Data: Age/Marital Status
- Pre-Hire Personal Data: Ethnicity/Disability/Religion/Country of Birth
- Pre-Hire Personal Data: Gender
- Pre-Hire Personal Data: ID Information
- Pre-Hire Personal Data: Medical Exams
- Pre-Hire Personal Data: Military/Citizenship/Political/Nationalities
- Pre-Hire Personal Data: Personal Information
- Pre-Hire Personal Data: Sexual Orientation & Gender Identity
- Pre-Hire Personal Data: Social Benefits Locality
- Pre-Hire Personal Data: Web Services with Details
- Pre-Hire Process Development
- Pre-Hire Process: Mass Action on Job Requisitions
- Pre-Hire: Skills and Experience
- Reports: Job Requisition and Positions
- Reports: Manager (Pre-Hire)
- Reports: Open Positions
- Set Up: Pre-Hire Process
These domains are for unconstrained security groups and aren’t impacted:
- Manage Pre-Hire Data: Delete Pre-Hires
- Manage Pre-Hire Data: Mark Pre-Hires for Deletion
- Pre-Hire Data: Background Check Status
- Search: Pre-Hire by Private Email Address
Do I need to update my business process security policy?
Yes, we recommend that you update your business process security policy if you’ve opted into this feature.
How does this enhancement affect my web services?
If a constrained role is used to submit the web service request, access to the unconstrained Pre-Hire should be configured on the domain securing the web service, as outlined above. If an unconstrained role is used to submit the web service, no update is required.