Skip to main content
Administrator Guide
Last Updated: 2023-07-14
Setup Considerations: Roles

Setup Considerations: Roles

You can use this topic to help make decisions when planning your configuration and use of roles functionality. It explains:
  • Why to set it up.
  • How it fits into the rest of Workday.
  • Downstream impacts and cross-product interactions.
  • Security requirements and business process configurations.
  • Questions and limitations to consider before implementation.
Refer to detailed task instructions for full configuration details.

What It Is

A role, when combined with its role-based security groups, represents the permissions and responsibilities of an assignee for viewing, reporting, or managing data related to objects in Workday.

Business Benefits

Roles functionality in Workday enables you to:
  • Control security access for objects such as organizations, service centers, and spend categories.
  • Directly assign the membership of a role-based security group. You can map more than 1 security group to a role so you can configure different levels of access across a role-enabled object.
  • Use Workday-delivered roles or create your own customized roles to meet your business needs.
  • Configure contextual security and business process routing, reducing the number of security groups that you have to maintain.
  • Grant and remove access automatically as workers fill or vacate positions.

Use Cases

Product or Feature
Example Use Cases
Financial
You can grant access to data related to specific customers or suppliers. Select based on the company that the role is assigned to.
Example: Assign a role to company that enables the financial controller to access only the financial transactions and accounts related to their company.
HCM
You can configure the
Change Job
business process to route an employee transfer to the HR partner role in the proposed organization for review or approval.
Example: HR partner role automatically routes transfer requests.
Pay
You can grant access to employee pay data based on the pay group the payroll partner is assigned to.
Example: Enable access for payroll partners in a pay group to run pay calculations for their assigned pay groups.
Recruiting
You can specify that a worker must first be assigned to the recruiter role to then be assigned as the primary recruiter role for a job requisition.
Example:
  • The recruiter role can view job requisitions for the supervisory organizations they support.
  • The primary recruiter role can modify and process candidates for the job requisitions they’re assigned to.

Questions to Consider

Questions
Considerations
Do you need to limit access to data?
Consider if the data that you grant access to is contextually sensitive by organization. Determine whether the role assignee needs access to that type of information for everyone in the tenant. If not, you can restrict access to data for people they support.
Do you need to assign roles for people in different time zones?
Consider the time zone in which role-based security group assignments take effect so that workers have access to data immediately upon assuming a role.
Should the role be restricted to a single role assigner type?
Consider if the worker is in a leadership role. When a leadership role isn’t restricted to a single assignment, organization charts can display multiple leaders.
Example:
  • 1 manager per supervisory organization.
  • 1 cost center manager per cost center.

Recommendations

  • Assign a unique name for each role so you can easily identify different roles and role assignments.
  • Enable roles for only 1 organization type to simplify business process routing and security access, and improve role-based report performance.

Requirements

  • Configure 1 or more security groups for each role in the
    Assigned/Reviewed by Security Groups
    field on the
    Maintain Assignable Roles
    task. You can create a security group using the
    Create Security Group
    task.
  • When you enable roles for a hierarchy, you must also enable them for the corresponding organization type to enable role inheritance from the hierarchy to the selected organizations. Example: Cost center hierarchy and cost center organization type.

Limitations

No impact.

Tenant Setup

The
Time Zone Configuration
section of the
Edit Tenant Setup - System
task enables you to set the time zone in which role assignments take effect based on either the:
  • Assignee location.
  • Tenant default.
If you leave the
Role Assignment Time Zone Option
blank, Workday populates the time zone as Pacific Time.

Security

To maintain role configurations, enable security for the
Set Up: Assignable Roles
domain in the Organizations and Roles functional area.
When you configure a role-based security group, you determine domain and business process security for roles. You don't configure security for the roles directly. You determine role assignees' access to data when you create role-based security groups.

Business Processes

Business Processes
Considerations
Assign Roles
You can initiate this business process when you assign roles using a related action on a worker or position. Workday initiates it as a subprocess when you configure role assignments on certain staffing events.
We recommend using the
Assign Roles - Add/Remove
or
Assign Roles - Change Assignments
related actions to run this business process.
Assign Self-Assign Roles
For self-assign roles, when the
Restricted to 'Assign Self-Assign Roles'
business process is enabled on the
Maintain Assignable Roles
task, these business processes are used to assign the role:
  • Assign Self-Assign Roles
  • Mass Assign Self-Assign Roles

Reporting

Reports
Considerations
View Assignable Roles
You can use the
View Assignable Roles
report to track:
  • Role configurations including security groups and access rights associated with each role.
  • Security groups, including which can assign specific roles.
You can also view which security groups can assign specific roles. This report also includes security group and access rights information associated with each role.
Security History
Displays changes to roles and security for an organization in the specified time and date range.
View Roles
Displays:
  • Currently assigned roles for the organization.
  • The inheritance status of each role.
View Role Assignment Audit History
Displays an audit trail of role assignment snapshots for the organization.
View Role Assignment History
Displays the role assignment history for the organization.
View Worker Roles Audit
Displays Workday account information, roles, user-based security groups, job-based security groups, and process-maintained roles for each worker in the organization.

Integrations

You can use the
Assign Roles
web service to support time zones for role assignments.

Connections and Touchpoints

Workday offers a Touchpoints Kit with resources to help you understand configuration relationships in your tenant. Learn more about the Workday Touchpoints Kit on Workday Community.