Skip to main content
Administrator Guide
Last Updated: 2025-12-12
Concept: Implementation Tool Personas

Concept: Implementation Tool Personas

We recommend that you create personas to best use implementation tools in Workday. Although you don’t assign personas in Workday, you can configure security for each implementation tool user depending on the persona you’ve established for them.
A user's persona determines whether they can manage changes made by any user in the tenant, or only the configuration changes they personally create. Establishing the correct persona ensures that users have only the access they need to perform their specific implementation or administrative functions.
Implementation tool personas enable you to define who accesses these tools and to what extent they can use the features:
  • Configuration Change Tracker
  • Object Transporter
  • Configuration Extracts
  • Tenant Compare
By determining these personas, you can enforce granular security controls for configuration changes in your tenant environments. You determine a user's persona by these main factors:
Factor
Description
Core capabilities
What tenant configuration management jobs a user has, such as auditing or comparing, packaging, and migrating tenant changes.
Scope
  • What configuration changes a user can access.
  • The type of configuration package the user can migrate.
Special permissions
When the user has 1 or both of these responsibilities:
  • Migrates security policy changes.
  • Extracts configurations from tenants.
  • Loads extracted configuration files to tenants.

Process for Building Personas

As a best practice before you configure user access to implementation tools or their domain security in tenants, determine the persona of each implementation tool user. After you determine the personas, you’ll more readily know which domains to secure and which levels of access to select on the Maintain Access to Customer Central Tooling task. Workday recommends that you develop and refine personas in this sequence:
  1. Determine the core capabilities for implemenation tool users.
  2. For Auditor or Packager personas, refine their persona to include the scope of their responsibilities.
  3. For Migrator or Power User personas, refine their persona to include the type of packages they can migrate.
  4. Determine whether any implementation tool users need additional permissions.

Determine Core Capabilities

You can start building personas by determining each implementation user’s configuration management responsibilities across tenants. Use the table to match each user's responsibilities with a core capability. A user may have more than 1 responsibility.
User Responsibility
Core Persona
Monitor and review changes
Views and tracks configuration changes but can't package or migrate them. They are a "look, don't touch" user. They can create their own reports.
Auditor
Manage Configuration Packages (create and edit)
Builds and modifies (creates and edits) configuration packages but can't migrate them to other tenants.
Packager
Migrate packages
Deploys existing packages across tenant environments, but doesn't necessarily create or edit them.
Migrator
All of the above
Views, creates, edits, and migrates packagess. This is a combination of all capabilities.
Power User

Determine Scope for Auditors and Packagers

For each implementation tool user who has a core capability of Auditor or Packager, refine the persona further to include the scope of their responsilbity for managing changes in the tenant.
Use the table to match scope of responsibility with a refined persona that includes scope.
User Scope
Scope Persona
User as self
The user only needs to work with their own changes and packages.
Self Auditor
Self Packager
Any user
The user also needs to view other users’ changes or use others’ packages.
Global Auditor
Global Packager

Determine Scope for Migrators and Power Users

For each implementation tool user with an Migrator or Power User persona, determine whose packages they can migrate and the type of package they can handle.
Use the table to match scope of responsibility and package type with a refined migration persona.
User Scope for Packages
Type of Packages
Migration Persona
User as self
The user only needs to migrate their own single instances and packages with Object Transporter.
Standard packages only
Traditional Self Migrator
User as self
The user also needs to migrate their own Advanced packages with Configuration Change Tracker.
Standard packages in Object Transporter
Advanced packages in Configuration Change Tracker
Advanced Self Migrator
Any user
The user only needs baseline access to migrate other’s OX-enabled configurations, in which Object Transporter adds necessary dependencies at the time of migration. This means users don't necessarily know all the dependencies that Object Transporter will migrate before migration starts.
Standard packages only
Traditional Global Migrator
Any user
In addition to thier own and others' instances and standard packages, the user also needs to migrate other users’ Advanced packages with with Configuration Change Tracker
Standard packages in Object Transporter
Advanced packages in Configuration Change Tracker
Advanced Global Migrator

Determine Special Permissions

Determine whether any implementation tool users need added permissions. Workday requires additional access to security configuration packages and configuration extracts.
Use the table to map additional permissions to Add-On roles.
Add-On Permission
Add-On Role
Security configuration packages
The user needs to migrate security policies.
Add-On Security Migrator
Configuration file extracts
The user needs to extract configurations from a tenant.
Example: Users may need to extract configurations while Sandbox tenants refresh.
Add-On Configuration Extractor
Configuration file loads
The user needs to migrate (load) extracted configurations.
Example: Users may need to load extracted configurations to the Sandbox tenant after a refresh
Add-On Configuration Extract Migrator