Steps: Maintain Access to Request Types
- Understand segment-based security groups and segmented security.
- Determine how you want to restrict request type access for groups of workers.
You can configure security groups to restrict the availability of request types' details to members of designated security groups.
- Access theCreate Request Type Security Segmenttask.In theRequest Typeprompt, select the request types to include in the segment.Create enough segments to cover each unique security access requirement. Included values can cross multiple segments or be mutually exclusive. Workday recommends that you build from least to most restrictive.Security:Set Up: Request Type Security Segmentsdomain in the System functional area.
- Access theCreate Security Grouptask.Create the security groups to associate with the security segments if existing security groups don't meet your business requirements.Security:Security Configurationdomain in the System functional area.
- Segment-Based Security for the Request Framework is not supported in the Attachment Settings in BP Toolbar for the Request Business Process.
- Edit Domain Security Policies.
- Activate Pending Security Policy Changes.
- Test the security policy changes.For each security segment, sign in as a user of the associated segment-based security group. Then verify that you can only access the request types for that segment.
When you associate the request type with a security group, Workday restricts access to the details of these requests to members of that group.
You create a Change Organization Name request type segment and associate it to the Organization Administrators security group. On the
All Requests
report, only Organization Administrators can view the details of requests where the request type is Change Organization Name. A record of these requests, but not the request details, are visible to all users who have access to the All Requests
data source, including those who aren't in the Organization Administrators security group.