Skip to main content
Administrator Guide
Last Updated: 2026-06-26
Steps: Set Up Segmented Security for Time Entry Codes

Steps: Set Up Segmented Security for Time Entry Codes

You use segment-based security to control which time entry codes workers, managers, and administrators can use. When you configure segmented security, users only have access to the time entry codes relevant to their roles and responsibilities.
When a worker lacks access to the default time entry code configured on their time entry template, Workday restricts them from using the
Location-Based Mobile Check In
task.
  1. Access the
    Create Time Entry Code Security Segment
    task.
    Create segments for each security role and add the time entry codes you want the role to have access to. We recommend that you set up all the time entry code security segments you'll need before enabling segmented security for time entry codes.
    Security:
    Set Up: Time Tracking
    domain in the Time Tracking functional area.
  2. Create segment-based security groups that grant security groups access to the new time entry code security segments. You can create separate groups for different roles. Example: Create separate groups for workers and managers. When you create segment-based security groups for workers, include 1 or both of these Workday-delivered security groups:
    • Employee As Self
    • Contingent Worker As Self
  3. Edit Domain Security Policies
    Add the segment-based security groups you created to the
    Access Time Entry Code (Segmented)
    domain policy in the Time Tracking functional area and give them View and Modify permission.
    If you want ISUs and administrators to have access to all time entry codes, add them to the
    Access Time Entry Code (Segmented)
    domain policy. Example: Add Timekeepers.
  4. Access the
    Edit Tenant Setup - HCM
    task.
    In the
    Time Tracking
    section, select the
    Enable Segment Security for Time Entry Codes
    check box.
    Security:
    Set Up: Tenant Setup - HCM
    domain in the System functional area.
Your workers are eligible for the Jury Duty time entry code, but you only want managers and not workers to be able to enter and edit time with that time entry code. Include Jury Duty on the time entry code security segment for managers but not on the segment for workers.
As you create new time entry codes, add them to time entry code security segments so that users can access them during time entry tasks.
You can access the:
  • All Time Entry Codes Security Segments
    report to view time entry code segments, their associated time entry codes, security group details, and the domains the security groups belong to.
  • Run Time Configuration Analyzer Tool
    task to check whether all time entry codes belong to a time entry code security segment. Users can’t access any time entry codes that aren’t secured to a segment unless they are secured directly to the domain.
  • View Time Configuration Analyzer Results
    report and check the
    Warnings
    tab for a list of all time entry codes that aren't associated with at least 1 segment.