Concept: Business Processes
A business process in Workday is a set of tasks that people initiate, act upon, and complete in order to accomplish a desired business objective. When you initiate a business process, Workday routes the tasks to the responsible roles (users who are capable of completing the tasks based on their membership in security groups) and enforces security and business rules throughout the business process.
Any user with the appropriate role can initiate a business process. Once initiated, the business process notifies users in the responsible roles as it processes each step and receives feedback when each step is complete, so it can move on to the next step. Note that steps in a business process can be conditional.
All business processes are based on a business process definition; you can't create a business process in Workday without first defining it. Workday's default business processes are delivered definitions and can be customized to meet your needs. You can copy the business process to any supervisory organization and tailor it as necessary, creating different versions of the same business process for different organizations. The business process logic is inherited, so a subordinate organization uses the business process definition of the superior organization unless you specify a custom definition for the subordinate organization.
If a business process doesn't have a default definition, you can use the
Create Business Process Definition (Default Definition)
task to create and configure the default definition.The
Business Process Types with Default Definitions in Use
report displays default business processes that are in use.The
Business Process Configuration Options
report displays which organization types you can associate with a business process.Example
Hire
is a simple 2-step business process:- A person with the appropriate role (such as a manager or HR Partner) initiates the business process by completing theHire Employeetask in Workday.
- Workday routes thePropose Compensationstep to the person with the appropriate role (such as a manager or HR Partner) to propose compensation for the candidate.
The business process is
complete
when either the final step (Propose Compensation
, in this case) or the designated completion step is carried out.Business Process Definitions
The business process definition is the list of steps (tasks) that comprise the business process and the roles responsible for completing them.
For optimal business process performance, Workday recommends that you limit the number of steps on a business process definition.
We support a maximum of 72 consecutive, non-manual steps on a business process. A non-manual step is a step that's automatically processed by the system without user interaction. Example: Not required steps, an
Integration
step, or a Report
step. If you have business processes with 72 consecutive, non-manual steps, Workday recommends that you evaluate the business process definition to reduce the number of these consecutive steps or configure a rule-based business process definition with conditional steps.Workday provides a read-only graphical view of business processes. You can use this graphical view to communicate designs, confirm designs, and confirm workflow changes. To view the diagram of a business process, either click
View Diagram
on the View Business Process Definition
page, or from the related actions menu of the business process, select .You can't change the step type of existing steps when you edit a business process definition. If you want to change the step type, you can remove the step and add a new step with a new step type on the business process definition.
When you copy or link to a business process definition, you can't set an effective date that's before the original business process creation date.
To view a list of business processes in Workday, you can:
- Run theBusiness Process Definitionsreport.
- Select as a related action on a supervisory organization. Workday displays business processes associated with the selected organization.
For audit reporting, you can tag instances of business processes. This enables you to track and report on business process configuration changes in your tenant such as changes made to a business process definition. Note that you can't apply an audit tag to dynamic business processes. As a result, audit trail entries won't be created in the
Audit Trail Report
for dynamic business processes.The
Inactivate Orphaned Business Process Definitions
task enables you to filter and inactivate business process definitions that are active but orphaned. Meaning, the business process definition:
- Isn't set as a default definition.
- Doesn't have organizations associated with them.
- Isn't part of a rule-based business process definition.
On the
Inactivate Orphaned Business Process Definitions
task, the Business Process Definitions to Inactivate
field displays orphaned business process definitions that you can inactivate. When you select the Confirm
check box and then OK
, Workday inactivates the listed business process definitions. If you don't see business process definitions listed in this field and you select the Confirm
check box, no changes are made to the tenant because there are no active but orphaned definitions to inactivate.For certain steps of manually advanceable business process types, you can mark them as
Do Not Advance
. You can use this feature to eliminate the risk of fraud in cases where a user may advance an event to completion without approval. By marking critical steps in a business process definition as Do Not Advance
, you also reduce the risk of accidental manual advancement of an event. An event cannot be advanced from or through a step that is marked as Do Not Advance
including methods such as the Advance Manually
related action on a business process event, or through the Advance Business Process
Mass Operation Management type. This functionality is only available for steps that you can assign to a security group. Steps that you can't assign to a security group, with the exception of a Report
step, can't be marked as Do Not Advance
.Business Processes and Security
Each step within a business process definition is associated with a security group that defines who is responsible for that step. In addition, the business process definition is governed by a business process security policy that determines who can:
- Start the business process.
- Perform action steps within the business process.
- Perform actions on the entire business process.
- Approve, correct, cancel, and rescind steps.
- Reassign tasks.
When you access and view a business process security policy and there are unexpected security groups in any of these business process actions, we display a warning message that identifies the security groups and the business process action they are configured on:
- Ad Hoc Approve
- Deny
- Deny (Web Service)
- Manual Send Back
- Request Reassignment
This enables you to identify the invalid security groups and remove them from the security policy and ensure the right person has access to business process allowed actions.
If a business process security policy has existing unexpected security groups configured for any of the 5 business process actions and you make any changes to the security policy, you can still save your changes. Workday displays the warning message about the unexpected security groups. If you see the warning message, Workday recommends that you thoroughly test your configuration to ensure that it doesn't cause any unintended access to data and the routing rules behave as expected.
If you see unintended data access in your tenant, we recommend that you remove the security group from the business process security policy. When you remove unexpected security groups from any of the above business process actions and save your changes, you won't be able to add the security groups back to those business process actions. You also won’t be able to search for the security group in any of those 5 business process action prompts.
To identify unexpected security groups on business process security policies, you can access the
Security Exception Audit
report to view audit entries on these tabs:
- Business Process Security Policy Exceptions
- Security Group Exceptions
When you tag a business process and make changes to a business process security policy, audit trail entries are created. In the
Audit Trail Report
:
- When you edit a business process security policy for the first time and save it without making any changes, Workday adds multiple entries to the report.
- An audit trail entry is created in the report when a security change is made to business process security policy even before you activate the change.
- When you update security policy permission prompts, theLineagecolumn of the report displays the path to the section on the business process security policy, but doesn't specify the actual prompt that was changed.
When you have inactive security groups in your tenant and the security groups are associated with allowed actions that are no longer available on the business process security policy, you can remove the inactive security groups. Any user with permission on these domains can remove the inactive security groups by accessing the
Remove Inactive Security Groups from Unavailable Actions
task:
- Business Process Administration
- Security Activation
- Security Configuration
The
Remove Inactive Security Groups from Unavailable Actions
task helps you identify and remove inactive security groups.Before you run the
Remove Inactive Security Groups from Unavailable Actions
task, Workday highly recommends that you access the Activate Pending Security Policy Changes
task to confirm and activate existing security changes. After you run the Remove Inactive Security Groups from Unavailable Actions
task, you must access the Activate Pending Security Policy Changes
task again to complete the process. If you don't see the business process type on the Activate Pending Security Policy Changes
task, continue to confirm the pending security policy changes. Determine if you need to remove inactive security groups in your tenant before you proceed.Once you remove the security group and access the
Security Exception Audit
report, Workday won't display the security group on the Business Process Security Policy Exceptions
tab. The Remove Inactive Security Groups from Unavailable Actions
task doesn't address audit items that might display on these Security Exception Audit
report tabs:
- Domain Security Policy Exceptions
- Security Group Exceptions
Share Your Business Process Definitions
You can use the
Business Process Definition
data source to share information about your business process definitions with key stakeholders. Example: You can create a custom report that displays a selected set of business process definitions, along with the initiating security groups, the individual workflow steps, and the custom notifications that comprise each definition. This report can be shared or exported for use by upper management, project managers, or customer managers.The
Business Process Definition
data source is secured by the Manage: Business Process Definitions
security domain.