Skip to main content
Administrator Guide
Last Updated: 2025-11-28
Configure Security for Configuration Change Tracker

Configure Security for Configuration Change Tracker

  • Customer Central security administrator account.
  • Security:
    Security Configuration
    domain in the System functional area.
Workday provides different security domains for Configuration Change Tracker users depending on whether they manage only their own configuration changes or also manage other users' changes:
  • Self Auditors or Packagers: These users only manage their own changes. Grant them permissions to domains that include the word, Restricted
  • Global Auditors or Packagers: These users manage others' changes, which includes self-management. Grant them permissions to global domains, which do not include the word, Restricted.
Consider creating separate security groups for these two user types.
  1. Sign on to the tenant as a security administrator.
  2. Access the
    Create Security Group
    task.
    Create a user-based security group for Configuration Change Tracker users. If your organization restricts the scope of some users to only their own configuration changes, consider creating a separate user-based security group for them so that you have different security groups for each type of user. Example: Configuration Change Tracker Self and Configuration Change Tracker Global.
  3. Access the
    Maintain Permissions for Security Group
    task.
    Depending on the user goal, add these domains and permissions to enable access to Configuration Change Tracker capabilities.
    To create Advanced configuration packages, you must assign a user both an auditor and packager domain.
    User
    Domain
    Permissions
    Self auditor
    Enables users to access Configuration Change Tracker and view and create their own reports.
    Manage: Configuration Change Management - Restricted
    View and Modify
    Global auditor
    Enables users to access Configuration Change Tracker, create their own reports, and view others' reports.
    Configuration Change Management
    View and Modify
    Self packager
    Enables users to create and edit thier own Advanced configuration packages from Change Tracker.
    Manage: Configuration Change Management Migrations - Restricted
    View and Modify
    Global packager
    Enables users to create and edit thier own and others' Advanced configuration packages from Change Tracker.
    Manage: Configuration Change Management Migrations
    View and Modify
    To migrate Advanced configuration packages from Configuration Change Tracker, you also have to configure user security for Object Transporter.
  4. Activate Pending Security Policy Changes.