Concept: Implementation Tool Personas
We recommend that you create personas to best use implementation tools in Workday. Although you don’t assign personas in Workday, you can configure security for each implementation tool user depending on the persona you’ve established for them.
A user's persona determines whether they can manage changes made by any user in the tenant, or only the configuration changes they personally create. Establishing the correct persona ensures that users have only the access they need to perform their specific implementation or administrative functions.
Implementation tool personas enable you to define who accesses these tools and to what extent they can use the features:
- Configuration Change Tracker
- Object Transporter
- Configuration Extracts
- Tenant Compare
By determining these personas, you can enforce granular security controls for configuration changes in your tenant environments. You determine a user's persona by these main factors:
Factor | Description |
|---|---|
Core capabilities | What tenant configuration management jobs a user has, such as auditing or comparing, packaging, and migrating tenant changes. |
Scope |
|
Special permissions | When the user has 1 or both of these responsibilities:
|
Process for Building Personas
As a best practice before you configure user access to implementation tools or their domain security in tenants, determine the persona of each implementation tool user. After you determine the personas, you’ll more readily know which domains to secure and which levels of access to select on the Maintain Access to Customer Central Tooling task. Workday recommends that you develop and refine personas in this sequence:
- Determine the core capabilities for implemenation tool users.
- For Auditor or Packager personas, refine their persona to include the scope of their responsibilities.
- For Migrator or Power User personas, refine their persona to include the type of packages they can migrate.
- Determine whether any implementation tool users need additional permissions.
Determine Core Capabilities
You can start building personas by determining each implementation user’s configuration management responsibilities across tenants. Use the table to match each user's responsibilities with a core capability. A user may have more than 1 responsibility.
User Responsibility | Core Persona |
|---|---|
Monitor and review changes
Views and tracks configuration changes but can't package or migrate them. They are a "look, don't touch" user. They can create their own reports. | Auditor |
Manage Configuration Packages (create and edit)
Builds and modifies (creates and edits) configuration packages but can't migrate them to other tenants. | Packager |
Migrate packages
Deploys existing packages across tenant environments, but doesn't necessarily create or edit them. | Migrator |
All of the above
Views, creates, edits, and migrates packagess. This is a combination of all capabilities. | Power User |
Determine Scope for Auditors and Packagers
For each implementation tool user who has a core capability of Auditor or Packager, refine the persona further to include the scope of their responsilbity for managing changes in the tenant.
Use the table to match scope of responsibility with a refined persona that includes scope.
User Scope | Scope Persona |
|---|---|
User as self
The user only needs to work with their own changes and packages. | Self Auditor
Self Packager |
Any user
The user also needs to view other users’ changes or use others’ packages. | Global Auditor
Global Packager |
Determine Scope for Migrators and Power Users
For each implementation tool user with an Migrator or Power User persona, determine whose packages they can migrate and the type of package they can handle.
Use the table to match scope of responsibility and package type with a refined migration persona.
User Scope for Packages | Type of Packages | Migration Persona |
|---|---|---|
User as self
The user only needs to migrate their own single instances and packages with Object Transporter. | Standard packages only | Traditional Self Migrator |
User as self
The user also needs to migrate their own Advanced packages with Configuration Change Tracker. | Standard packages in Object Transporter Advanced packages in Configuration Change Tracker | Advanced Self Migrator |
Any user
The user only needs baseline access to migrate other’s OX-enabled configurations, in which Object Transporter adds necessary dependencies at the time of migration. This means users don't necessarily know all the dependencies that Object Transporter will migrate before migration starts. | Standard packages only | Traditional Global Migrator |
Any user
In addition to thier own and others' instances and standard packages, the user also needs to migrate other users’ Advanced packages with with Configuration Change Tracker | Standard packages in Object Transporter Advanced packages in Configuration Change Tracker | Advanced Global Migrator |
Determine Special Permissions
Determine whether any implementation tool users need added permissions. Workday requires additional access to security configuration packages and configuration extracts.
Use the table to map additional permissions to Add-On roles.
Add-On Permission | Add-On Role |
|---|---|
Security configuration packages
The user needs to migrate security policies. | Add-On Security Migrator |
Configuration file extracts
The user needs to extract configurations from a tenant. Example: Users may need to extract configurations while Sandbox tenants refresh. | Add-On Configuration Extractor |
Configuration file loads
The user needs to migrate (load) extracted configurations. Example: Users may need to load extracted configurations to the Sandbox tenant after a refresh | Add-On Configuration Extract Migrator |