Skip to main content
Administrator Guide
Last Updated: 2025-12-26
Reference: Security Domains for the Expense Report Event Business Process

Reference: Security Domains for the Expense Report Event Business Process

List of security domains under the Expenses functional area:
Domain
Description
Process: Expense Reports
Grants access to users with company-based or unconstrained roles to manage expense reports and related reporting. For more granular control on expense report actions, you can grant permissions on these various subdomains:
  • Process: Expense Report - Attachments
    : This subdomain grants access to add attachments after expense reports are approved.
  • Process: Expense Report - Cancel
    : This subdomain grants access to cancel expense reports. To modify expense reports, you must also grant access to the
    Process: Expense Report - Core
    subdomain.
  • Process: Expense Report - Change:
    This subdomain grants access to change expense reports. To modify expense reports, you must also grant access to the
    Process: Expense Report - Core
    subdomain.
  • Process: Expense Report - Core
    : This subdomain grants access to create or modify expense reports for workers and non-workers. To create expense reports for workers or non-workers, you must also configure the initiating action in the Expense Report business process.
  • Process: Expense Report - Other:
    This subdomain grants access to additional tasks not directly related to managing expense reports, such as tasks for travel profile, mileage accumulator, and any available fix tasks for expense report. To perform fix tasks, users must also have modify access to the
    Process: Expense Report - Core
    subdomain. Travel profile tasks do not require Core.
  • Process: Expense Report - Reporting:
    This subdomain grants access to report data sources and filters for expense report reporting.
  • Process: Expense Report - View
    : This subdomain grants access to view expense reports.
Access Expense Item (Segmented)
Controls which users can access which expense items.
Manage: Expense Report for Pre-Hire
Provides access to manage expense reports on behalf of pre-hires and view related reporting
Manage: Payment Election
Provides access to manage payment elections on behalf of others and view related reporting.
Organization: Manage Central Travel Card Transactions
Provides access to manage central travel card transactions for organizations configured on the corporate credit card billing account.
Print: Expense Report
This non-configurable domain derives its security from the View or View/Modify permissions from the
Process: Expense Report - View
domain.
Process: Expense Report Work Area
Provides access to the Expense Report Work Area report, which enables users to take action on expense reports awaiting approval, such as reviewing, sending back, or approving them.
Process: Receivable Repayment
Grants access to users with company-based or unconstrained roles to manage receivable repayments. For more granular control on receivable repayment actions, you can grant permissions on these various subdomains:
  • Process: Receivable Repayment - Cancel
    : This subdomain grants access to cancel receivable repayments. To modify receivable repayments, you must also grant access to the
    Process: Receivable Repayment - Core
    subdomain.
  • Process: Receivable Repayment - Core
    :This subdomain grants access to create or modify receivable repayments.
  • Process: Receivable Repayment - Reporting
    :This subdomain grants access to report data sources and filters for expense receivable repayment reporting.
  • Process: Receivable Repayment - View
    :This subdomain grants access to view receivable repayments.
Process: Spend Authorization
Grants access to users with company-based or unconstrained roles to manage spend authorizations and related reporting. For more granular control on spend authorization actions, you can grant permissions on these various subdomains:
  • Process: Spend Authorization - Cancel
    : This subdomain grants access to cancel spend authorizations. Users must also have modify access to the
    Process: Spend Authorization - Core
    subdomain.
  • Process: Spend Authorization - Change
    : This subdomain grants access to change spend authorizations. Users must also have modify access to the
    Process: Spend Authorization - Core
    subdomain.
  • Process: Spend Authorization - Close
    : This subdomain grants access to close spend authorizations. Users must also have modify access to the
    Process: Spend Authorization - Core
    subdomain.
  • Process: Spend Authorization - Core
    : This subdomain grants access to create or modify spend authorizations for workers. To create spend authorizations for workers, you must also configure the initiating action in the Spend Authorization business process.
  • Process: Spend Authorization - Reporting
    : This subdomain grants access to report data sources and filters for spend authorization reporting.
  • Process: Spend Authorization - View
    : This subdomain grants access to view spend authorizations.
  • Process: Spend Control and Analysis (Expenses)
    : This domain provides access to view spend analytics and to freeze spend for an organization.
Process: Spend Authorization Mass Close
Grants access to spend authorization mass close documents and view related reporting.
Process: Spend Control and Analysis (Expenses)
Provides access to view spend analytics and to freeze spend for an organization.
Process Travel Booking
Provides access to load travel booking records and view related reporting.
Process Travel Booking Files
Enables users to load and manage travel-related files that originate from external sources. You can add only unrestricted users to this domain.
Reports: Expense Report Payment
Provides access to view a specific expense report payment.
Reports: Organization Expense Report Reporting
Grants access to users with organization-based roles to view expense reports and related expense report line level reporting. For more granular control on spend expense reporting actions, you can grant permissions on these various subdomains:
  • Reports: Organization Expense Report Line Reporting
    : This subdomain grants access to users with organization-based roles to report data sources and filters for expense report line level reporting.
  • View: Organization Expense Report
    : This subdomain grants access to users with organization-based roles to view expense reports applicable to their organizations.
Self-Service: Expense Report
Provides self-service access to process expense reports and view related reporting. This domain also secures the Expenses worklet on the Workday home page. For more granular control on spend expense reports, you can grant permissions on these various subdomains:
  • Self-Service: Automated Expenses
    : Enables users to access a streamlined expense workflow and user interface that includes automated expense creation when Workday receives credit card transactions or scanned receipts. This workflow also includes automated merging for credit card transactions and receipts that relate to the same expense.
  • Self-Service Expense Reports - Attachments
    : This domain provides self-service access to add attachments to expense reports after they have been approved. Workday recommends to grant Modify access to this domain carefully, as it allows for the deletion of attachments on approved and paid expense reports.
  • Self-Service: Receipt Scanning
    : Provides users access to the Receipt Scanning feature.
Set Up: Payment Election
Provides self-service access to process payment elections and view related reporting.
Self-Service: Receivable Repayments
Provides self-service access to their Receivable Repayments.
Self-Service: Travel Booking
Provides self-service access to view and modify travel booking records linked to a worker.
Self-Service: Spend Authorization
Provides self-service access to process spend authorizations and view related reporting.
Set Up: Expense Item
Provides access to set up expense items and view related reporting.
Set Up: Expense Protect
Grants users with unconstrained roles access to Expense Protect Setup.
Set Up: Expense Processing
Provides access to managing expense Company assignments that differ from payroll Company assignments.
Set Up: Payment Election
Grants access to set up payment election processing details and view related reporting.
View: Expense Item
Provides access to view a specific expense item.
View: Payee Bank Account for Settlement
Controls who can view payee bank account information.
Worker Data: Expense Report
Grants access to view expense reports for a worker.
Worker Data: Payment Elections by Organization
Grants access to set up payment election processing details and view related reporting for selected workers within organizations where you have access via role on the worker's pay group or company. (User-based/non-contextual groups will be able to access all workers.)
Worker Data: Spend Authorization
Provides access to spend authorizations for a worker.
Worker Data: Travel Profile
Provides access to manage a worker's Travel Profile.
Manage: Expense Report
Secures the Find Expense Report report and enables users with access to edit expense reports that have been saved for later.
Manage: Expense Advance Repayment
Provides access to record receipt of expense advance repayment and view related reporting.(Applicable for Cash Advances functionality).
Manage: Unlock Payment Election Access
Enables users to unlock individuals blocked from managing bank details and payment elections due to multiple failed verification attempts.
Process: Expense Report Payment/Settlement
Provides access to perform the settlement function for expense payments and view related reporting.
Process: Expense Report Payment Escheatment
Provides access to perform expense report and credit card expense payments escheatment and view related reporting.