Skip to main content
Administrator Guide
Last Updated: 2024-01-12
Concept: Talent Pool Security

Concept: Talent Pool Security

Talent pool information is only visible to users who have a role on the talent pool, regardless of their access to the workers or workers' organizations. To control access to talent pool information, you can:
  • Create restricted talent pools.
  • Create private talent pools.
  • Use intersection security groups.

Talent Pool Domains

Talent Pools use these domains to secure the Talent Pool tasks:
Domain
Description
Talent Pool: Create
in the Talent Pipeline functional area
Determines who can create new talent pools.
Talent Pool: Restricted View
in the Talent Pipeline functional area
Restricts a manager’s view of the talent pool membership list to just those workers who are in their supervisory organization. Enable this domain to manage private talent pools.
Private Talent Pool: Create
in the Talent Pipeline functional area
Determines who can create private talent pools.
Private Talent Pool: View and Edit
in the Talent Pipeline functional area
Determines who can view, edit, and delete private talent pools.
Talent Pool: View and Edit
in the Recruiting and Talent Pipeline functional areas
Determines who can view, edit, and delete existing talent pools.
Talent Pool: Manage Membership
in the Recruiting and Talent Pipeline functional areas
Determines who can tag, add, and remove members from static talent pools.
Worker Data: Succession Plan - Any
in the Talent Pipeline functional area
Determines who can view talent pools in custom reports without edit access.
To create a view only role for talent pools, create a custom report secured to the
Worker Data: Succession Plan - Any
domain.
Private Talent Pool (Limited Owner Access)
in the Talent Pipeline functional area
Workday recommends that you only enable the
Private Talent Pool (Limited Owner Access)
domain to provide users with access to private talent pools that they created after they've been removed from a role.
Provides users with access to deleting private talent pools that they created after they've been removed from a role. This domain also provides them with limited access to viewing and editing some attributes, such as name, description, and inactive status.
Workday recommends adding an intersection security group that includes Employee as Self and the applicable unconstrained security group that has permission to create private talent pools.

Talent Pool Roles

Since workers assigned to talent pool roles have access to talent pool member information, use caution when assigning them. A common set of roles involved in talent pools are Managers, Talent Pool Administrators, and HR Partners.
  • Steve is a manager with several talent pools.
  • Maria is a Talent Pool Administrator who can see all of Steve's talent pools including the members in the pools. Maria can also see the information you've configured in the talent pool reports.
  • Jill is the HR Partner for Steve's organization. Although Jill also has modify permission on the
    Talent Pool: Create
    and
    Talent Pool: View and Edit
    domains, she can't see Steve's talent pools because she doesn't have a role on the talent pool.
  • Maria gives Jill a talent pool role to enable her to access Steve's talent pools. Jill can see the other worker's data in the talent pool, including workers outside her organization.
  • Jill creates a new talent pool for Steve's organization. Because she creates the talent pool, she automatically has a role on the talent pool.

Restricted Talent Pools

You can create a restricted talent pool to limit access to its member information. Only workers with a role on the talent pool secured to the
Talent Pool: Restricted View
domain can see restricted talent pools:
  • In tasks and reports.
  • At the tag prompt.
  • On worker preview cards.
Restricted Talent Pools provide managers and other designated roles insight into talent pools for workers in their organizations. This restriction enables them to only access information about their own employees within the talent pool.

Private Talent Pools

Use the
Create Private Talent Pool
task to create private talent pools. You're the only person who can view the private talent pools that you create, and they only display the workers in your supervisory organization. You must also have security access to these domains in the Talent Pipeline functional area:
  • Private Talent Pool: Create
  • Private Talent Pool: View and Edit
  • Talent Pool: Restricted View

Intersection Security for Talent Pools

To restrict access to talent pool member compensation details, you can create an intersection security group. This group restricts managers so that they can only view compensation information for workers that they manage, but enables them to view other information for the talent pool members that they don't manage.
Intersection security for talent pools requires Managers and Talent Managers to have roles and constrained role-based security groups. After you create the intersection security group for the 2 roles, replace the Manager security group on all compensation domains with the new Manager and Talent Manager intersection group. Add the Talent Manager security group to the domain.