Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Setup Considerations: Audit Tags

Setup Considerations: Audit Tags

You can use this topic to help make decisions when planning your configuration and use of audit tags. It explains:
  • Why to set it up.
  • How it fits into the rest of Workday.
  • Downstream impacts and cross-product interactions.
  • Security requirements and business process configurations.
  • Questions and limitations to consider before implementation.
Refer to detailed task instructions for full configuration details.

What It Is

Audit tags is a method of tagging, monitoring, and reporting on changes to instances of business processes, certain report types, user-based security groups, domain security policies, and integration systems in your tenant. Audit tags track:
  • What changed.
  • Who changed it.
  • When it was changed.

Business Benefits

Audit tags is the quickest and most efficient way to identify configuration changes in your tenant. It allows you to:
  • Identify changes and verify whether they're appropriate.
  • Fix inappropriate changes quickly.
  • Meet change management compliance standards.

Use Cases

You can use audit tags to:
  • Track a change on a calculation field that you use in a condition rule that is in turn used in a step in a business process.
  • Track a change to a filter in a row on a custom report.
  • Track a change to a security group or a change to permissions on a domain security policy.

Questions to Consider

Question
Consideration
What instances of business processes, report types, user-based security groups, domain security policies, and integration systems do you want to audit?
Determine which instances of business processes, report types, security groups, domain security policies, and integration systems are in scope for your audit. Tag those instances and view changes in the
Audit Trail Report
.
Do you want to limit users' access to audit some or all instances?
Restrict access to audit tags by assigning them to audit tag segments. Only users who belong to a segment-based security group in the
Set Up: Audit Tags and Assignments - Add Only
domain or the
Set Up: Audit Tags and Assignments
domain can access these audit tags.
Which instances that you want to audit are supported in the new Audit Trail Report?
Determine which instances you want to audit. You can audit instances of business processes, report types, security groups, domain security policies, and integration systems using the Audit Trail Report and the
Audit Trail Configuration Report
. You can audit other instances not reported on in the
Audit Trail Report
and the
Audit Trail Configuration Report
using one of the reports in "Reporting" below.

Recommendations

We recommend that you use the
Audit Trail Report
and the
Audit Trail Configuration Report
together. The
Audit Trail Report
reports on the relationships that are relevant to each instance you tag for auditing. The
Audit Trail Configuration Report
reports on the relationships
Workday uses
to find changes on instances related to your primary (tagged) instances.

Requirements

No impact.

Limitations

We enable you to audit only instances of:
  • Business processes.
  • Certain report types.
  • Domain security policies.
  • Integration systems.
  • User-based security groups.

Tenant Setup

No impact.

Security

Domains
Considerations
Audit Tag (Segmented)
in the System functional area
Enables you to create and edit audit tag segments and to assign audit tags to audit tag segments.
Set Up: Audit Tags and Assignments
in the System functional area
Enables you to create, edit, and delete audit tags and audit tag assignments.
Set Up: Audit Tags and Assignments – Add Only
in the System functional area
Enables you to create and edit audit tags and audit tag assignments.

Business Processes

No impact.

Reporting

Report
Considerations
Audit Trail Report
You can tag instances of business processes, certain report types, user-based security groups, domain security policies and integrations, and run the report for the tagged instances to view the lineage of changes.
Audit Trail Configuration Report
You can view:
  • What relationships Workday uses to find changes on instances related to your primary (tagged) instances.
  • The date on which Workday includes the relationships in the Audit Trail Report.
  • When the instances and relationships changed in your tenant.
Audit Tag by Tag
You can view all active and inactive audit tags in your tenant, as well as tagged instances under each audit tag.
Business Process Security Policy History
You can view changes made to 1 or more business process security policies within a selected date range. This report shows the date of change and the person who made the change.
Business Process Security Policies Changed Within Time Range
You can view all changes made to business process security policies within a selected date range. This report shows the date of change and the person who made the change.
Domain Security Policy History
You can view changes made to 1 or more domain security policies within a selected date range. This report shows the date of change and the person who made the change.
Domain Security Policies Changed Within Time Range
You can view all changes made to domain security policies within a selected date range. This report shows the date of change and the user who made the change.
View Audit Tag
You can view all audit tags in your tenant.
View Audit Tag Segment
You can view all audit tag segments in your tenant.
View User or Task or Object Audit Trail (UTO)
You can view changes made to any instances within a time range and by a specific user. Workday generates this report instantly and displays it in your tenant. It has a maximum displayable limit, so, if necessary, you can run the Create Audit Log task to generate the same report as a background process that produces an Excel file.
Worker Change History
You can view a summary of worker changes in 1 or more organizations for a selected date range.
You can also write custom reports using the
Processed Transactions for Range, System Account, Task and Business Object
data source to view changes to various instances that none of the Workday delivered reports address.

Integrations

You can run these audit tags web services to upload and retrieve data through an EIB.
Web Services
Considerations
Get Audit Tag Assignments
To add primary instances to, or remove primary instances from, audit tags, use both the Get Audit Tag Assignments and the Put Audit Tag Assignments web services.
Get Audit Tags
To add a tag to an instance, use both the Get Audit Tags and the Put Audit Tag web services.
Get Audit Tag Segments
Use this web service to secure an audit tag.
Put Audit Tag
To add a tag to an instance, use both the Get Audit Tags and the Put Audit Tag web services.
Put Audit Tag Assignment
To add primary instances to, or remove primary instances from, audit tags, use both the Get Audit Tag Assignments and the Put Audit Tag Assignments web services.
Put Audit Tag Segment
Use this web service to secure an audit tag.

Connections and Touchpoints

Workday offers a Touchpoints Kit with resources to help you understand configuration relationships in your tenant. Learn more about the Workday Touchpoints Kit on Workday Community.