Steps: Manage Access to Documents
You can use segmented security to control who can create, edit, or view documents within a specified document category.
Examples:
- Configure security to enable benefits administrators to manage benefits documents only.
- Enable managers to view workers' employment documents but not their personal documents.
The
Reviewed Documents
section on the worker profile includes the Standard Documents
and the Generated Documents
grids. Workday secures the Standard Documents
grid using these domains:- Worker Data: Add Worker Documents
- Self-Service: Add Worker Documents
Workday secures the
Generated Documents
grid using these domains:- Worker Data: View Generated Documents
- Self-Service: View Generated Documents
Ensure that you have access to these domains to view worker documents on worker profiles if you're associated with the business process that routes the document.
- Access theCreate Document Category Security Segmenttask.Create a security segment for each document category.Security:Set Up: Document Category Security Segmentsdomain in the System functional area.
- Configure segment-based security groups to provide access to documents in each security segment.Repeat this procedure for each security segment that you created in step 2.
- Edit theDocument Librarydomain in the System functional area and these domains in thePerson Data: Personal Datasection of the Personal Data functional area:
- Worker Data: Add Worker Documents
- Worker Data: Edit and Delete Worker Documents
- Worker Data: View Generated Documents
- In theReport/Task Permissionssection, add the new segment-based security groups and remove all existing security groups that are restricted by the new segment-based security groups.
If a security group is assigned to a domain and/or business process security policy and is also in a segment-based security group that's assigned to the domain and/or business process security policy, Workday ignores the segment-based security group and honors the security group instead.- Example: The Manager security group is assigned to a domain and business process security policy. This group also belongs to a separate segment-based security group that's assigned to the same domain and business process security policy. In this scenario, Workday grants access based on the Manager security group configuration.Security:Security Configurationin the System functional area.If a document is generated through an integration, users also need access to theIntegration Event,Integration Debug,Integration Process, orIntegration Builddomain in the Integration functional area.
- Activate Pending Security Policy Changes.
- (Optional) Maintain Worker Documents.Provide access to all worker document categories for users who aren't members of a segment-based security group.
On the
Maintain Worker Documents
task, you can view documents attached through a business process when you have View permissions on the business process security policy, even if you aren't a member of a segment-based security group. You can also view worker documents on the Documents
tab of a worker's profile when you're associated with the business process that routes the document.