Skip to main content
Administrator Guide
Last Updated: 2024-01-12
Concept: Roles Assignments, Positions and Role Inheritance

Concept: Roles Assignments, Positions and Role Inheritance

Roles are groupings of people with specific permissions and responsibilities. Example: Manager, recruiter, and HR partner. Roles enable security control for objects such as organizations, service centers, and spend categories.
  • A role assigner is a business object that you assign a role to. It's also called a role-enabled object.
  • A role assignee is a person, worker, position, or position restriction assigned to a role.
  • A role assignment is the combination of a role assigner and a role.
  • A role maintainer manages and assigns roles. They assign a role assignee to a role assigner.
To make a role assignable, you must configure at least 1 security group in the
Assigned/Reviewed by Security Groups
field on the
Maintain Assignable Roles
task. To assign the role, you must be a member of at least 1 security group listed in the
Assigned/Reviewed by Security Groups
field. Any member listed in the security group is a role maintainer and ensures that authorized members approve each role assignment. When you don't configure a security group for a role, Workday marks the role as inactive and doesn't display it in the
Role
section of the worker profile. See Set Up Assignable Roles.
In the
Maintain Assignable Roles
task, Workday delivers
Workday Roles
that you can map to a relevant role assigner type. Example:
  • HR Partner
    , when mapped to a relevant role assigner type, has full initiation and approval capabilities.
  • HR Business Partner
    , when mapped to a relevant role assigner type, has some rights for initiation, but less rights for modifying data.
To inactivate a role with existing assignments, you must remove the existing assignments before you remove all the security groups. If you remove the security groups before removing the existing assignments, you can't approve the removal of the existing role assignments later.
Consider these methods when you're assigning roles:
Method
Description
Role assignment as a related action on a role-enabled object
When you assign roles from a related action on a role-enabled object, you only see roles that you have permission to assign. There's no business process event created for the role assignment to approve. When you save, the role assignment takes effect according to the effective date.
Role assignment as a subprocess of a staffing event
The
Assign Roles
business process is available as a subprocess on these staffing events:
  • Change Job
  • End Contingent Worker Contract
  • End Additional Job
  • End International Assignment
  • Inactivate Service Center Representative
  • Request Leave of Absence
  • Request Return from Leave of Absence
  • Termination
Workday recommends that you configure these staffing events to use the
Assign Roles - Change Assignment for Worker
subprocess rather than the
Assign Roles to Worker
subprocess when both actions are available.
You can automatically populate the old and new positions in
Assignees to Add
and
Assignees to Remove
with these options:
  • Copy role assignments.
  • Remove role assignments.
  • Transfer role assignments.
If you rescind or correct the parent staffing business process, Workday doesn't automatically rescind or correct the role assignments in the subprocess. Workday reflects the changes in a worker’s profile only if the overall status of the Assign Roles business process is completed.
Role assignment as a related action on a worker, position, or position restriction
You can assign roles by accessing these tasks from the related actions menu of a worker, position, or position restriction:
  • Security Profile
    >
    Assign Roles - Add/Remove
  • Security Profile
    >
    Assign Roles - Change Assignments
When you select
Security Profile
Assign Roles - Add/Remove
from the related actions menu of a worker, Workday only displays roles that the worker is eligible for in the
Roles
prompt. It doesn't display the roles the user has permission to assign.
When you create a role-enabled object
You can assign roles directly to a role-enabled business object by selecting
Roles
Assign Roles
from the related actions menu. You use the
Maintain Assignable Roles
task to configure all of your assignable roles.
EIB with the
Assign Roles
web service
The
Assign Roles
web service supports time zones for role assignments. You can configure security by selecting
Business Process Policy
Edit
from the related actions menu of the
Assign Roles
business process.
Assign Self-Assign Roles
business process
When you enable
Restricted to 'Assign Self-Assign Roles'
business process for a self-assign role on the
Maintain Assignable Roles
task, Workday uses these business processes to assign the role:
  • Assign Self-Assign Roles
  • Mass Assign Self-Assign Roles
You can configure these business process definitions with the appropriate
Approval
steps.
Workday initiates the
Assign Roles
business process when you assign roles using a related action on a worker or position, or a subprocess. You can't rescind a role assignment that you complete as part of a business process event. The Workday-delivered
Review Changed Role Assignments
Action
step automatically routes to the role maintainer for the role-enabled object where the role is assigned. You can't remove this step from the business process definition.
Example: You're a Compensation Administrator with permission to initiate the
Assign Roles
business process. You can use the business process to assign the Compensation Partner role to a worker or to propose any role assignment for a worker.
  • When you're assigned a security group in the
    column of the
    Maintain Assignable Roles
    task for the Compensation Partner role, the business process routes the review step to your
    Your Tasks
    for your approval.
  • When you propose roles that you don't have permission to assign, Workday determines which security group is the role maintainer for each proposed role. Workday routes the
    Review Changed Role Assignments
    Action
    step to the members of all relevant security groups for approval.
If a role has been configured for an
Approval
step, the business process routes to the role-based security group of the role-enabled object of the position assigned to the role. Workday recommends that role assigner types that aren't assigned to a worker position from a staffing transaction aren't configured for an
Approval
step because the step will go unassigned. Example: Project or Spend Category.
Audit entries are created in Workday each time a change is made to an instance. In the case of role assignments, this can be a worker. An audit entry is created when a change is approved and the approver will display in the audit trail for the worker.
When you assign a restricted role using the
Assign Roles
business process or the
Assign Roles - Change Assignments
subprocess, Workday only displays workers that are eligible for the role in the
Assign To
prompt based on the restrictions you set.

Positions and Workers

In a position management staffing model, assignable roles enable you to move a worker's role automatically when you change their position. When you assign a role to a position, the role is associated with that position. When a worker changes positions, they don't retain roles associated with their previous position. When you hire a worker into an open position, the worker gains all roles associated with that position.
Workday assigns business processes routing to workers based on their assigned roles. You can add roles to a business process by including the appropriate role-based security groups to the business process security policy.
When role assignments are used in downstream integrations, we recommend selecting a reorganization effective date that's after the position availability date.

Staffing Models and Positions

In the job management staffing model, whenever you assign a role to a job, a worker always fills the job. When you terminate a worker, Workday:
  • Inactivates the job.
  • No longer assigns the job to any roles.
  • Removes the security access that the job or job restriction gave the worker.
We recommend using an unconstrained security group when using the job management staffing model.
In the position management staffing model, when you terminate a worker and leave the position open, the position is unfilled but Workday still applies the position or position restriction to the role.
The position will still be displayed in the
Role Assignment Audit History
report for both staffing models unless the position is closed.

Role Inheritance

Workday recommends that you assign roles to the highest level and configure role inheritance wherever possible to improve performance.
Subordinate organizations inherit role assignments when you set the
Access Rights to Organizations
of the security group for the role to:
  • Applies to Current Organization and All Subordinates
    .
  • Applies to Current Organization and Subordinates to Level
    .
  • Applies to Current Organization and Unassigned Subordinates
    , when you don't assign a role to the subordinate organization.
When an organization without a role assignment inherits a role assignee, Workday searches for the role assignment on a superior organization. When the role isn’t assigned on any superior organization, Workday unassigns any business process tasks routed to the role-based security group.
You can assign a role to any level in a hierarchy, or you can configure the level to inherit a role from the superior organization. You can't assign a role to a level in a hierarchy and you can't inherit a role from a superior organization until you link that role to a role-based security group with access rights other than Current Only.
Workday doesn't display role inheritance when:
  • You set the
    Access Rights to Organizations
    of all the role-based security groups to
    Applies to Current Organization Only.
  • The role isn't linked to any role-based security groups.
There's a discrepancy between the
Get Workers
web service and the UI task and the web service doesn't take the access rights into account.