Concept: Roles Assignments, Positions and Role Inheritance
Roles are groupings of people with specific permissions and responsibilities. Example: Manager, recruiter, and HR partner. Roles enable security control for objects such as organizations, service centers, and spend categories.
- A role assigner is a business object that you assign a role to. It's also called a role-enabled object.
- A role assignee is a person, worker, position, or position restriction assigned to a role.
- A role assignment is the combination of a role assigner and a role.
- A role maintainer manages and assigns roles. They assign a role assignee to a role assigner.
To make a role assignable, you must configure at least 1 security group in the
Assigned/Reviewed by Security Groups
field on the Maintain Assignable Roles
task. To assign the role, you must be a member of at least 1 security group listed in the Assigned/Reviewed by Security Groups
field. Any member listed in the security group is a role maintainer and ensures that authorized members approve each role assignment. When you don't configure a security group for a role, Workday marks the role as inactive and doesn't display it in the Role
section of the worker profile. See Set Up Assignable Roles.In the
Maintain Assignable Roles
task, Workday delivers Workday Roles
that you can map to a relevant role assigner type. Example:
- HR Partner, when mapped to a relevant role assigner type, has full initiation and approval capabilities.
- HR Business Partner, when mapped to a relevant role assigner type, has some rights for initiation, but less rights for modifying data.
To inactivate a role with existing assignments, you must remove the existing assignments before you remove all the security groups. If you remove the security groups before removing the existing assignments, you can't approve the removal of the existing role assignments later.
Consider these methods when you're assigning roles:
Method | Description |
|---|---|
Role assignment as a related action on a role-enabled object | When you assign roles from a related action on a role-enabled object, you only see roles that you have permission to assign. There's no business process event created for the role assignment to approve. When you save, the role assignment takes effect according to the effective date. |
Role assignment as a subprocess of a staffing event | The Assign Roles business process is available as a subprocess on these staffing events:
Assign Roles - Change Assignment for Worker subprocess rather than the Assign Roles to Worker subprocess when both actions are available.
You can automatically populate the old and new positions in Assignees to Add and Assignees to Remove with these options:
|
Role assignment as a related action on a worker, position, or position restriction | You can assign roles by accessing these tasks from the related actions menu of a worker, position, or position restriction:
When you select from the related actions menu of a worker, Workday only displays roles that the worker is eligible for in the Roles prompt. It doesn't display the roles the user has permission to assign. |
When you create a role-enabled object | You can assign roles directly to a role-enabled business object by selecting from the related actions menu. You use the Maintain Assignable Roles task to configure all of your assignable roles. |
EIB with the Assign Roles web service | The Assign Roles web service supports time zones for role assignments. You can configure security by selecting from the related actions menu of the Assign Roles business process. |
Assign Self-Assign Roles business process | When you enable Restricted to 'Assign Self-Assign Roles' business process for a self-assign role on the Maintain Assignable Roles task, Workday uses these business processes to assign the role:
You can configure these business process definitions with the appropriate Approval steps. |
Workday initiates the
Assign Roles
business process when you assign roles using a related action on a worker or position, or a subprocess. You can't rescind a role assignment that you complete as part of a business process event. The Workday-delivered Review Changed Role Assignments
Action
step automatically routes to the role maintainer for the role-enabled object where the role is assigned. You can't remove this step from the business process definition.Example: You're a Compensation Administrator with permission to initiate the
Assign Roles
business process. You can use the business process to assign the Compensation Partner role to a worker or to propose any role assignment for a worker.
- When you're assigned a security group in the column of theMaintain Assignable Rolestask for the Compensation Partner role, the business process routes the review step to yourYour Tasksfor your approval.
- When you propose roles that you don't have permission to assign, Workday determines which security group is the role maintainer for each proposed role. Workday routes theReview Changed Role AssignmentsActionstep to the members of all relevant security groups for approval.
If a role has been configured for an
Approval
step, the business process routes to the role-based security group of the role-enabled object of the position assigned to the role. Workday recommends that role assigner types that aren't assigned to a worker position from a staffing transaction aren't configured for an Approval
step because the step will go unassigned. Example: Project or Spend Category.
Audit entries are created in Workday each time a change is made to an instance. In the case of role assignments, this can be a worker. An audit entry is created when a change is approved and the approver will display in the audit trail for the worker.
When you assign a restricted role using the
Assign Roles
business process or the Assign Roles - Change Assignments
subprocess, Workday only displays workers that are eligible for the role in the Assign To
prompt based on the restrictions you set.Positions and Workers
In a position management staffing model, assignable roles enable you to move a worker's role automatically when you change their position. When you assign a role to a position, the role is associated with that position. When a worker changes positions, they don't retain roles associated with their previous position. When you hire a worker into an open position, the worker gains all roles associated with that position.
Workday assigns business processes routing to workers based on their assigned roles. You can add roles to a business process by including the appropriate role-based security groups to the business process security policy.
When role assignments are used in downstream integrations, we recommend selecting a reorganization effective date that's after the position availability date.
Staffing Models and Positions
In the job management staffing model, whenever you assign a role to a job, a worker always fills the job. When you terminate a worker, Workday:
- Inactivates the job.
- No longer assigns the job to any roles.
- Removes the security access that the job or job restriction gave the worker.
In the position management staffing model, when you terminate a worker and leave the position open, the position is unfilled but Workday still applies the position or position restriction to the role.
The position will still be displayed in the
Role Assignment Audit History
report for both staffing models unless the position is closed.Role Inheritance
Workday recommends that you assign roles to the highest level and configure role inheritance wherever possible to improve performance.
Subordinate organizations inherit role assignments when you set the
Access Rights to Organizations
of the security group for the role to:
- Applies to Current Organization and All Subordinates.
- Applies to Current Organization and Subordinates to Level.
- Applies to Current Organization and Unassigned Subordinates, when you don't assign a role to the subordinate organization.
You can assign a role to any level in a hierarchy, or you can configure the level to inherit a role from the superior organization. You can't assign a role to a level in a hierarchy and you can't inherit a role from a superior organization until you link that role to a role-based security group with access rights other than Current Only.
Workday doesn't display role inheritance when:
- You set theAccess Rights to Organizationsof all the role-based security groups toApplies to Current Organization Only.
- The role isn't linked to any role-based security groups.
There's a discrepancy between the
Get Workers
web service and the UI task and the web service doesn't take the access rights into account.