Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Concept: Access to Worker Information

Concept: Access to Worker Information

You can secure access to worker names, contact information, and personal information through a combination of domain and business process security policies. You can constrain access by organization context.
  • Domain security policies determine who can view or modify each type of worker information in business processes, tasks, related actions, worker profiles, and reports. To manage permissions, use the
    Domain Security Policies for Functional Area
    report.
  • Business process security policies determine who can perform actions in the
    Contact Change
    ,
    Home Contact Change
    ,
    Work Contact Change
    ,
    Personal Information Change
    ,
    Legal Name Change
    , and
    Preferred Name Change
    business processes. To manage permissions, use the
    Business Security Policies for Functional Area
    report.
  • Role-based security groups limit access to secured items (such as reports, tasks, and data) to members of specific organizations.

Worker Profiles

To view personal and contact information on worker profiles, set up domain security:
Section
Domains
Notes
Contact Information
Person Data: Home Contact Information
Person Data: Work Contact Information
Self-Service: Home Contact Information
Self-Service: Work Contact Information
When you disable these security policies, you can't see the
Contact
section of the worker profiles.
Personal Information
Person Data: Personal Information
Self-Service: Personal Information
When you disable these security policies, you can't see the
Personal Information
section of the worker profiles.
The
Self-Service: Personal Data
and
Person: Personal Data
parent domains don't provide access to personal information, but can be used for subdomains to inherit permissions.

Public and Private Contact Information

You can designate each type of contact information (except home addresses) as public or private. The designation only affects the visibility of contact information on worker profiles and worker preview cards. Anyone with view permission on the
Worker Data: Public Worker Reports
domain can see public contact information on worker profiles and worker preview cards.
A worker's home address is always private unless it's also their work address, in which case you can make the home address public.
For broader access to contact information, you must have permission on the
Person Data: Work Contact Information
and
Person Data: Home Contact Information
domains. These domains provide access to both public and private contact information in these places:
  • Change Contact Information
    ,
    Contact Information
    , and
    Work Contact Information for Worker
    standard reports.
  • Change Contact Information
    and
    View Contact Information
    related actions on workers.
  • Worker
    Contact
    tab on worker profiles.
Workday recommends that you limit permission on these domains to administrators. Don't assign the
All Users
,
All Employees
,
All Contingent Workers
,
All Retirees
, or
All Terminees
security groups to the
Person Data: Work Contact Information
and
Person Data: Home Contact Information
domains if you want to restrict visibility of private contact information.
You can further restrict access to worker information by creating an intersection security group. This group enables only administrators or specific organization roles to view directory information. It also excludes workers from search results, organization profiles and charts, and reports.

Security Permissions

Workers secured to actions in the
Contact Change
,
Home Contact Change
,
Work Contact Change
,
Personal Information Change
,
Legal Name Change
, and
Preferred Name Change
business processes need these domain security permissions to view and modify data in the business processes:
  • Groups assigned to the initiation or review steps in the business processes require modify permission on the domains that control access to each type of information.
  • Groups with view all, view completed only, approve, cancel, or rescind permission in the business processes require view permission (at a minimum) on the domains that control access to each type of information.
Access the
Template-Driven Business Process Security
report to confirm that the business process and domain security permissions are aligned.