Skip to main content
Administrator Guide
Last Updated: 2025-03-14
Concept: Exception Audit Reports

Concept: Exception Audit Reports

Workday provides a number of exception audit reports that identify problem areas and explain the problem and solution for each exception.
Business Process Exception Audit
Workday recommends that you test changes to business processes in a preproduction tenant before migrating them to your production tenant. After you update a business process, run the
Business Process Exception Audit
report to find all business process definitions with critical errors.
When you initiate a business process event, Workday checks the business process definition to determine if a persisted exception exists on the definition.
When you update a business process definition such that you create an error on the definition, Workday:
  • Persists the exception immediately.
  • Prevents the business process from running.
To provide an extra layer of safety, Workday runs a background process every hour to identify and persist all exceptions on business process definitions. These exceptions include exceptions caused by changes outside of the business process definition itself.
Example: You remove a security group from a business process security policy without removing the group from the corresponding business process definition, causing an exception. If you don't edit the business process definition or run the
Business Process Exception Audit
report to identify the exception, the background process:
  • Persists the exception.
  • Prevents you from initiating the business process until you fix the problem.
If a business process is broken, Workday automatically sends a
Fix Business Process
task to Business Process Administrators and provides a link to correct the business process definition.
Security Exception Audit
Security exceptions usually happen when a legitimate security configuration encounters a change in the security policy, making some access assignment invalid. Possible causes are when you activate a pending security policy change in which a:
  • Security policy specifies a group that you’ve deleted from Workday.
  • Business process security policy is missing a group that the business process still uses.
Before you remove a security group from a business process security policy, remove the group from the various business processes in each organization that has a custom version defined. However:
  • If you don't know all the places where you’ve used a security group.
  • You have processes that are already running.
You can still change the policy. Workday displays a warning that the change will cause an exception.
The
Security Exception Audit
report identifies any problem area. Workday explains the problem and solution for each exception. Generally, all you have to do is remove the invalid security group from the policy or business process.
For already started business processes, reassign the step that routes to an invalid user, or rescind the process. In either case, change the business process definition for that organization to specify only valid security groups.
You can also use the
Security Exception Audit
report to find Intersection Security Groups that include organization-based security groups based on organization types that aren’t actual Organizations.
When there are unexpected security groups configured on the business process policy for these security policy actions, we display a security exception entry on the
Business Process Security Policy Exceptions
and
Security Group Exceptions
tabs:
  • Ad Hoc Approve
  • Deny
  • Deny (Web Service)
  • Manual Send Back
  • Request Reassignment
This ensures the right person has access to the business process allowed actions by validating security groups on the business process security policy actions.
Calculated Field Exception Audit
Run the
Calculated Field Exception Audit
report to revalidate your calculated fields and list any errors. You can test for errors and exceptions in advance using the Evaluate Expression function, taking the appropriate action.
Integration Exception Audit
If an Integration transport protocol requires you to encrypt the outbound file, and you select not to encrypt the output, you can save the EIB. You can't run it, however, until your Security Administrator approves the exception. Once your Security Administrator overrides this requirement by:
  • Viewing the EIB or integration system in the
    Integration Exception Audit
    report.
  • Selecting
    Toggle Approve Unencrypted Transport
    as a related action.
You can run the EIB an unlimited number of times. However, if you edit the EIB later, your Security Administrator must reapprove the override.
You can also use the
Integration Exception Audit
report to:
  • Identify any EIBs that use the
    XmlToCSV
    and
    XmlToExcel
    transformations.
  • Set the
    Alternate Output Format
    to
    CSV
    .
Scheduled Future EIBs Exception Audit
To find scheduled EIBs that can't be launched due to insufficient security, access the
Scheduled Future EIBs Exception Audit
report. The report identifies EIBs that aren't runnable by the scheduled user. You can either change the security of the scheduled user or transfer ownership to another user. To transfer ownership, select
Scheduled Future Processes
Transfer Ownership
from the related actions menu of the request.
Unfilled Assigned Roles Audit
Run the
Unfilled Assigned Roles Audit
report to identify unfilled roles for organizations and other role-enabled items. Roles that are marked
Hide on View if Not Assigned
on the
Maintain Assignable Roles
task don't display on this report.
It’s normal for inactive organizations to have unfilled roles.
Custom Report Exception Audit Reports
Workday delivers these custom report exception audit reports:
  • Custom Report Exception Audit
    , which enables you to validate report definitions. Workday displays the report owner, error severity, and problem description or solution. An empty report output indicates no errors in your reports.
  • Custom Report Exceptions by Owner
    , which displays custom report exceptions by report owner. Workday displays exceptions that include:
    • Reports with terminated owners.
    • Reports enabled as worklets but not available on any dashboards.
    • Temporary reports past their deletion date.
    • Reports not shared.
    • Reports with items marked as Do Not Use.
  • Custom Reports I Can Run Exception Audit
    , which displays custom reports that you can run that have exceptions. Workday displays the report owner, error severity, and problem description or solution. An empty report output indicates no errors in reports that you can run.
  • Custom Reports on Menus Exception Audit
    , which enables you to see errors in entries for the
    Maintain Custom Reports on Menus
    task. An empty report output indicates no errors in your reports.
Additional Exception Audit Reports
Workday also provides these Exception Audit reports:
  • Benefits Condition Rule Exception Audit
  • Calculation Exception Audit
  • Condition Rule Exception Audit
  • Hierarchies with Duplicates Exception Audit
  • Journal Entry Exception Audit
  • Organization Assignment Exception Audit
  • Organization Exception Audit
  • Organization Type Exception Audit
  • Payroll Exception Audit
  • Position Group Exception Audit
  • Report Specific Calculated Field Exception Audit
  • Scheduled Future Reports Exception Audit
  • Workers' Compensation Code Exception Audit
  • Worklet Mappings Exception Audit