Concept: Security for Custom Objects
Custom Objects and Security Domains
The
Custom Object Management
security domain secures custom object administration. This domain contains users and groups that can view and modify Custom Object definitions.Manage security for custom objects and fields at the custom object level. Custom fields for a custom object inherit the custom object security.
Define the security policy on a custom object using domains for the security policies. The union of all View, Modify, and Integration custom object domain permissions control access to the tasks for the custom object and associated fields.
REST API Security for Custom Objects
When you create a custom object, specify the security domain. To view the security domains for a custom object, use the
View Custom Object
report. When registering your API client, verify that the selected Scope (the Functional Area) includes security domains for the custom objects.Permissions Affecting Custom Objects
View permissions on security domains control whether you can view:
- Business objects that support profile groups and custom fields. Custom fields that are available on the Additional Data profile tab include: academic unit, academic unit hierarchy, job application, job profile, job requisition, position restriction, and worker profiles. To add the profile tab, use theConfigure Profile Grouptask.
- Custom fields in a report.
- Custom object data as a related action on extended business objects.
Modify permissions control editing custom object data as a related action on an extended business object. Example: Worker object.
Integration permissions control whether an integration can get or put data, independent of the Workday integration tool you're using. Your ability to create an integration is independent of the custom object integration domain permissions.
Example: An Integration Partner can create and run an inbound Enterprise Interface Builder (EIB) that includes custom fields that the Integration Partner can access. However, the inbound EIB updates values
only
for:- Custom fields for which the worker has Put access.
- Workers in organizations that the worker has access through an Integration System Security Group (Constrained).
To view the security policy on a custom object, select as a related action on the custom object. When you view a security domain, Workday displays a
Custom Objects
section if any custom objects are secured to that domain. To view the associated custom fields, select the custom object.Custom Objects and Security Groups
Types of security groups:
Security Group | Description |
|---|---|
Role-based (constrained) | All users in the security group have access to a subset of data instances (rows) that the security group can access. |
Role-based (unconstrained) | All users in the security group have access to all data instances secured by the security group. |
User-based | Primarily for Administrative users. Add a worker directly to the group. The worker can't inherit membership in the group. All users in the security group have access to all data instances secured by the security group. |
Result of assigning a security group to a custom domain:
Assignment | Result |
|---|---|
Role-based group (constrained) to a custom domain. | Assignee can't view or edit custom object data. |
Role-based group (unconstrained) or user-based group to a custom domain. | Assignee can view and edit custom object data. |
When you assign a role, ensure the:
- Role for the custom object security group is enabled for the domain.
- Users to grant access are assigned the role, or have inherited the role for the domain.
For a custom domain, the type of custom object to be secured is unknown. Therefore, Workday can't restrict the domain to enforce a role-based group type. Set the role-based group type.
Using a role-based group (constrained) is valid if the business object is contextually secured. Example: Cost Center is contextually secured. However, other extensible custom objects aren't. Example: Job Profile. Using a role-based (constrained) security group of HR Partner to control access to Job Profile custom objects is invalid.
A role-based group (constrained) evaluates security using the target object. A role-based group (unconstrained) doesn't evaluate security. Example: If a worker has the role HR Partner for any organization, then they're a member of the HR Partner role-based group (unconstrained).
Custom Object Management and Reporting Tasks
- Security Analysis for Securable Item and Account
- Security Analysis for Workday Account
- View Security for Calculated Field
- View Security for Securable Item