Concept: Segmented Security for Time Entry Codes
You can use segment-based security to ensure that workers, managers, administrators, and integration system users only have access to the time entry codes relevant to their roles and responsibilities.
When you configure segmented security, Workday filters the time entry codes available on time entry tasks, including mass actions performed through web services, and only displays time entry codes that meet both of these conditions:
- The user's security role has access to the time entry code through a security segment.
- The worker is eligible for the time entry code.
When managers and administrators enter time for a worker, Workday filters time entry codes based on both:
- Their own role and segment security configuration.
- The worker's eligibility for time entry codes.
Workers and managers can view time clock events and time blocks that contain time entry codes for which they don’t have segment security permissions, but they can't edit or delete this time.
Example Use Cases
- Certain codes, such as Special Duty, might be applicable to workers, but you want to restrict workers from selecting them. You can use segmented security to ensure that only a manager or administrator can create a time entry with these specific codes.
- You can restrict workers from editing or deleting time entries imported through integrations to ensure data audit integrity.
- You can ensure worker-created time entries remain the record of truth by restricting administrators and managers from altering them.