Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Reference: Security Domains and Drive Item Management

Reference: Security Domains and Drive Item Management

This table describes the security domains that control access to the item types that Drive manages.
Domain
Notes
Drive
Enables administrators and self-service users to:
  • Access the
    Drive
    main menu option on a web browser and the
    Drive
    worklet on mobile.
  • Share files with other users in the
    Drive
    or
    View Drive File and Media
    domain. (Additionally, for each item that you want to share, make sure the recipient is in any other required domains for the item type. Example: If you want to share a Worksheets workbook, the person you're sharing with must be in the
    Worksheets
    domain.)
  • Upload and manage files such as XLSX, DOCX, PDF, and PPTX, if you selected to support them in your tenant.
  • Upload and manage Worksheets workbook files if the user is in the
    Worksheets
    domain.
  • Create and manage folders.
  • Upload media (video and packaged content) files if Workday detects that a signed Workday Media Cloud Terms and Conditions order form exists.
  • View media (video and packaged content) files.
Drive Administrator
Enables administrators to access the:
  • Configure Group Sharing in Drive
    task: For each item type that Drive supports, select whether to let self-service users share that item type with specific unconstrained security groups. Optionally, select to allow only Drive administrators to share items with security groups.
  • Drive Permanent File Delete
    task: Permanently delete certain types of Drive items.
  • Remove Drive Shares
    task: Remove all users' shared access permissions for a particular item.
  • Remove Share Recipient from Drive
    task: Remove a particular user's shared access to up to 1,000 items.
  • Transfer Ownership of Drive Items
    task: Transfer up to 1,000 Drive items owned by 1 user to a different user.
  • Drive Admin Hub
    report: Access reports that are secured to the
    Reports: Drive Admin
    domain and tasks that are secured to the
    Drive Administrator
    domain.
  • Drive Usage Summary
    report: View an overview of Drive usage in the tenant.
  • View Drive Items for User
    report: View the Drive items that a user owns or has access to.
  • View Shares for Drive Item
    report: View the sharing details for an individual Drive item.
Drive Web Services
Enables developers to use the Public Drive Web Services:
  • Get Drive Document Content
  • Get Tenant Setup Group Share Configurations
  • Put Drive Document Content
  • Put Tenant Setup Group Share Configurations
Owner permission is required.
The web services are available for file types such as PDF, DOCX, PPT, JPG, and more. We currently don't support folders, or items in product-specific areas such as:
  • Discovery boards
  • Folders
  • Media files (including ZIP files)
  • Notification templates
  • Worksheets workbooks
Drive doesn't automatically convert files that you upload using a web service. Example: When you upload a CSV file from the Drive user interface, Drive automatically converts the CSV file to a Worksheets workbook. This conversion doesn't occur when you upload a file using the Put Drive Document Content web service.
Reports: Drive Admin
Enables administrators to view report fields related to Drive, for all Drive items in the tenant, and for all Workday accounts enabled for Drive.
When you have access to this domain, you can see these reports:
  • Drive Item History (Standard)
  • Drive Items Permission Audit (Standard)
Reports: Drive User
Enables users to view report fields related to Drive, for only the Drive items in the tenant that the user owns or that were shared with the user.
Users can see these items in the Drive file viewer, but they need access to the Reports: Drive User domain in order to see the items in a report.
View Drive File and Media
Enables users to view files or media items that other users share from Drive, without requiring that the user have access to the
Drive
domain.
Examples:
  • You don't want to give Drive access to pre-hires but you want to share an onboarding video with them. You can add the pre-hires to the View Drive File and Media domain, and then share the URL for the video.
  • If you shared a DOCX file using a link and you gave View permission to everyone, users with the link can view the file even if they don't have access to Drive.
This domain doesn't provide view access to files that are managed using another security domain. Example: Users with access to the
View Drive File and Media
domain can't view Learning course files or Worksheets workbooks.
Drive: Viewers
Drive: Owner
Drive: Seer
These are special domains that Drive manages automatically depending on the user's access to individual Drive items. These domains aren't viewable using the View Domain report and they're not configurable.
Slides
Applicable for adding and managing presentations using Slides.
Worksheets
Applicable to Workday Worksheets and products that integrate with it, such as Planning, Payroll, and Projects for Resource Forecasting.
Notification Designer
Applicable for adding and managing notification templates using Notification Designer.
Manage: Media
Applicable to Workday Media Cloud.
Discovery Boards: Create
Applicable for adding and editing discovery boards.