Concept: Access to Worker Information
You can secure access to worker names, contact information, and personal information
through a combination of domain and business process security policies. You can constrain
access by organization context.
- Domain security policies determine who can view or modify each type of worker information in business processes, tasks, related actions, worker profiles, and reports. To manage permissions, use theDomain Security Policies for Functional Areareport.
- Business process security policies determine who can perform actions in theContact Change,Home Contact Change,Work Contact Change,Personal Information Change,Legal Name Change, andPreferred Name Changebusiness processes. To manage permissions, use theBusiness Security Policies for Functional Areareport.
- Role-based security groups limit access to secured items (such as reports, tasks, and data) to members of specific organizations.
Worker Profiles
To view personal and contact information on worker profiles, set up domain
security:
Section | Domains | Notes |
|---|---|---|
Contact Information
| Person Data: Home Contact Information
Person Data: Work
Contact Information Self-Service: Home Contact
Information
Self-Service: Work Contact Information | When you disable these security policies, you can't see the
Contact section of the worker profiles. |
Personal Information
| Person Data: Personal Information
Self-Service: Personal
Information | When you disable these security policies, you can't see the
Personal Information section of the worker
profiles. The Self-Service: Personal Data and Person:
Personal Data parent domains don't provide access to personal
information, but can be used for subdomains to inherit
permissions. |
Public and Private Contact Information
You can designate each type of contact information (except home addresses) as public or
private. The designation only affects the visibility of contact information on worker
profiles and worker preview cards. Anyone with view permission on the
Worker Data:
Public Worker Reports
domain can see public contact information on worker
profiles and worker preview cards.A worker's home address is always private unless it's also their work address, in which
case you can make the home address public.
For broader access to contact information, you must have permission on the
Person
Data: Work Contact Information
and Person Data: Home Contact Information
domains. These domains provide access to both public and private contact information in
these places: - Change Contact Information,Contact Information, andWork Contact Information for Workerstandard reports.
- Change Contact InformationandView Contact Informationrelated actions on workers.
- WorkerContacttab on worker profiles.
Workday recommends that you limit permission on these domains to administrators. Don't
assign the
All Users
, All Employees
, All Contingent Workers
, All
Retirees
, or All Terminees
security groups to the Person Data: Work
Contact Information
and Person Data: Home Contact Information
domains if
you want to restrict visibility of private contact information. You can further restrict access to
worker information by creating an intersection security group. This group enables
only administrators or specific organization roles to view directory information. It
also excludes workers from search results, organization profiles and charts, and
reports.
Security Permissions
Workers secured to actions in the
Contact Change
, Home Contact Change
,
Work Contact Change
, Personal Information Change
, Legal Name
Change
, and Preferred Name Change
business processes need these domain
security permissions to view and modify data in the business processes: - Groups assigned to the initiation or review steps in the business processes require modify permission on the domains that control access to each type of information.
- Groups with view all, view completed only, approve, cancel, or rescind permission in the business processes require view permission (at a minimum) on the domains that control access to each type of information.
Access the
Template-Driven Business Process Security
report to
confirm that the business process and domain security permissions are aligned.