Skip to main content
Administrator Guide
Last Updated: 2025-09-05
Concept: Customer Central Users

Concept: Customer Central Users

When a Named Support Contact requests a Customer Central tenant, Workday creates it during the specified maintenance window and provides wd-tenantowner credentials. Workday sends these credentials to the requestor and any other named NSCs or tenant managers. You must use the wd-tenantowner account to create 2 other required accounts:
  • Customer Central Security Administrator
  • Customer Central Administrator
Once created, the Customer Central Administrator account can create Customer Central User accounts. Customer Central Administrators don't have to create a Customer Central User account for themselves.
If you have any issues, use the Customer Care link for your Customer Central Tenant in the Tenant Management section of your Customer Center.

Customer Central Security Model

  • Customer Central has a unique security model in which Workday automatically sets specific roles and permissions that you can't change. This model means that a single account can’t have multiple roles.
  • A Customer Central Administrator account includes all the permissions of a User account. Customer Central Administrators don't need to create Customer Central User accounts for themselves.
  • A Security Administrator account has access to a separate set of features that focus on security. The features are unrelated to the set belonging to the Central Administrator or User. You can designate a Security Administrator account as a Workday certified implementer to restrict it to the Workday Virtual Clean Room (VCR). However, doing so doesn't give the account access to additional implementer-only features, as it does with Central Administrator.

Customer Central Roles

Role
Details
Useful Tasks and Reports
Tenant Owner (wd-tenantowner)
  • Suitable for:
    • Named Support Contact
    • Engagement Manager
  • Created automatically by Workday.
  • Creates Customer Central Security Administrator and Customer Central Administrator accounts. Workday recommends creating at least 2 of each.
  • Create Security Administrator
  • Maintain Security Administrators
  • Create Central Administrator
  • Maintain Central Administrators
Customer Central Security Administrator
  • Suitable for:
    • Named Support Contact
    • Engagement Manager
  • Identical to the Security Administrator role in a regular Workday tenant.
  • Edits Workday and Customer Central account information.
  • Sets password rules and resets forgotten passwords.
  • Maintains feature opt-ins.
  • Manages authentication policies.
  • Creates additional Customer Central Security Administrators.
  • Select which users can migrate:
    • Configuration Packages.
    • Security Configuration Packages.
  • Create Security Administrator
  • Maintain Security Administrators
  • Edit Customer Central Account For User
  • Maintain Password Rules
  • Maintain Access to Customer Central Tooling
  • Maintain Feature Opt-Ins
  • Maintain User Name Rules
  • All Workday Accounts
  • Signons and Attempted Signons
  • Configuration Change Tracker
Customer Central Administrator
  • Suitable for:
    • Named Support Contact
    • Engagement Manager
    • Functional Lead
    • Data Conversion Lead
    • Data Conversion team member
  • Creates Customer Central User accounts.
  • Creates additional Customer Central Administrator accounts.
  • Edits Workday and Customer Central account information.
  • Manages tenant access for users.
  • Performs migration with Object Transporter.
  • Create Central Administrator
  • Maintain Central Administrators
  • Create Customer Central User
  • Maintain Customer Central Users
  • Edit Customer Central Account For User
  • Manage Password Challenge Questions (Do Not Use)
  • Manage Tenant Access
  • Maintain Customer Tenants
  • Configuration Catalog
  • Object Transporter Migration Reports
  • Migrate Configuration Package
  • Configuration Change Tracker
Customer Central User
  • Suitable for:
    • Customer
    • Implementer
  • Accesses user features.
  • Performs data migration and load activities (implementer only).
  • Performs migration with Object Transporter.
  • Configuration Catalog
  • Object Transporter Migration Reports (OX).
  • Migrate Configuration Package
  • Configuration Change Tracker