Concept: Exception Audit Reports
Workday provides a number of exception audit reports that identify problem areas and explain the problem and solution for each exception.
- Business Process Exception Audit
- Workday recommends that you test changes to business processes in a preproduction tenant before migrating them to your production tenant. After you update a business process, run theBusiness Process Exception Auditreport to find all business process definitions with critical errors.When you initiate a business process event, Workday checks the business process definition to determine if a persisted exception exists on the definition.When you update a business process definition such that you create an error on the definition, Workday:
- Persists the exception immediately.
- Prevents the business process from running.
To provide an extra layer of safety, Workday runs a background process every hour to identify and persist all exceptions on business process definitions. These exceptions include exceptions caused by changes outside of the business process definition itself.Example: You remove a security group from a business process security policy without removing the group from the corresponding business process definition, causing an exception. If you don't edit the business process definition or run theBusiness Process Exception Auditreport to identify the exception, the background process:- Persists the exception.
- Prevents you from initiating the business process until you fix the problem.
If a business process is broken, Workday automatically sends aFix Business Processtask to Business Process Administrators and provides a link to correct the business process definition. - Security Exception Audit
- Security exceptions usually happen when a legitimate security configuration encounters a change in the security policy, making some access assignment invalid. Possible causes are when you activate a pending security policy change in which a:
- Security policy specifies a group that you’ve deleted from Workday.
- Business process security policy is missing a group that the business process still uses.
Before you remove a security group from a business process security policy, remove the group from the various business processes in each organization that has a custom version defined. However:- If you don't know all the places where you’ve used a security group.
- You have processes that are already running.
You can still change the policy. Workday displays a warning that the change will cause an exception.TheSecurity Exception Auditreport identifies any problem area. Workday explains the problem and solution for each exception. Generally, all you have to do is remove the invalid security group from the policy or business process.For already started business processes, reassign the step that routes to an invalid user, or rescind the process. In either case, change the business process definition for that organization to specify only valid security groups.You can also use theSecurity Exception Auditreport to find Intersection Security Groups that include organization-based security groups based on organization types that aren’t actual Organizations.When there are unexpected security groups configured on the business process policy for these security policy actions, we display a security exception entry on theBusiness Process Security Policy ExceptionsandSecurity Group Exceptionstabs:- Ad Hoc Approve
- Deny
- Deny (Web Service)
- Manual Send Back
- Request Reassignment
This ensures the right person has access to the business process allowed actions by validating security groups on the business process security policy actions. - Calculated Field Exception Audit
- Run theCalculated Field Exception Auditreport to revalidate your calculated fields and list any errors. You can test for errors and exceptions in advance using the Evaluate Expression function, taking the appropriate action.
- Integration Exception Audit
- If an Integration transport protocol requires you to encrypt the outbound file, and you select not to encrypt the output, you can save the EIB. You can't run it, however, until your Security Administrator approves the exception. Once your Security Administrator overrides this requirement by:
- Viewing the EIB or integration system in theIntegration Exception Auditreport.
- SelectingToggle Approve Unencrypted Transportas a related action.
You can also use theIntegration Exception Auditreport to:- Identify any EIBs that use theXmlToCSVandXmlToExceltransformations.
- Set theAlternate Output FormattoCSV.
- Scheduled Future EIBs Exception Audit
- To find scheduled EIBs that can't be launched due to insufficient security, access theScheduled Future EIBs Exception Auditreport. The report identifies EIBs that aren't runnable by the scheduled user. You can either change the security of the scheduled user or transfer ownership to another user. To transfer ownership, select from the related actions menu of the request.
- Unfilled Assigned Roles Audit
- Run theUnfilled Assigned Roles Auditreport to identify unfilled roles for organizations and other role-enabled items. Roles that are markedHide on View if Not Assignedon theMaintain Assignable Rolestask don't display on this report.It’s normal for inactive organizations to have unfilled roles.
- Custom Report Exception Audit Reports
- Workday delivers these custom report exception audit reports:
- Custom Report Exception Audit, which enables you to validate report definitions. Workday displays the report owner, error severity, and problem description or solution. An empty report output indicates no errors in your reports.
- Custom Report Exceptions by Owner, which displays custom report exceptions by report owner. Workday displays exceptions that include:
- Reports with terminated owners.
- Reports enabled as worklets but not available on any dashboards.
- Temporary reports past their deletion date.
- Reports not shared.
- Reports with items marked as Do Not Use.
- Custom Reports I Can Run Exception Audit, which displays custom reports that you can run that have exceptions. Workday displays the report owner, error severity, and problem description or solution. An empty report output indicates no errors in reports that you can run.
- Custom Reports on Menus Exception Audit, which enables you to see errors in entries for theMaintain Custom Reports on Menustask. An empty report output indicates no errors in your reports.
- Additional Exception Audit Reports
- Workday also provides these Exception Audit reports:
- Benefits Condition Rule Exception Audit
- Calculation Exception Audit
- Condition Rule Exception Audit
- Hierarchies with Duplicates Exception Audit
- Journal Entry Exception Audit
- Organization Assignment Exception Audit
- Organization Exception Audit
- Organization Type Exception Audit
- Payroll Exception Audit
- Position Group Exception Audit
- Report Specific Calculated Field Exception Audit
- Scheduled Future Reports Exception Audit
- Workers' Compensation Code Exception Audit
- Worklet Mappings Exception Audit