Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Example: Set Up Security for an Implementation Tool Power User

Example: Set Up Security for an Implementation Tool Power User

This example illustrates how to set up domain security and implementation tool access for a Global Advanced Power User with additional permissions.
You’ve established a persona of Global Advanced Power User for a user based on these tenant configuration management responsibilities:
  • Views other user’s configuration changes.
  • Compares configurations across tenants.
  • Creates and edits their own and other’s configuration packages.
  • Migrates their own and other’s standard configuration packages from Object Transporter.
  • Migrates their own and other’s Advanced configuration packages from Configuration Change Tracker.
The user also needs permissions to:
  • Extract and load configuration extract files for Sandbox refreshes.
  • Migrate security configuration packages.
These add-on responsibilities require these roles:
  • Add-On Security Migrator.
  • Add-On Configuration Extractor.
  • Add-On Configuration Extract Migrator .
Workday requires user-based security groups for the domain security policies for the implementation tools. You decide to create a single user-based security group called Global Advanced Power Users. To plan your work, you create a source and target tenant security setup table to note the domain configurations required for each tenant.
Tenant
Security Domains and Permissions
Source
View and Modify, Get, and Put permissions:
  • Configuration Change Management
  • Manage: Configuration Change Management Migrations
  • OX for Non-Implementers
  • Special OX Web Services
Target
View and Modify, Get, and Put permissions:
  • Manage: Configuration Change Management Migrations
  • OX for Non-Implementers
  • Special OX Web Services
View and Modify permissions only:
  • Configuration Change Management
You also create a Customer Central tenant security settings table to note the check boxes you must select for the power user on the
Maintain Access to Customer Central Tooling
task.
User Access
Check Box Selection
Migrate Advanced configuration packages in Configuration Change Tracker.
OX Migration: Full Object Coverage
Compare configurations between tenants in Tenant Compare.
Create & View Tenant Compare Reports
Extract configuration files (.dat) using Configuration Extracts.
Create Configuration Extracts
Load configuration files (.dat) using Configuration Extracts.
Migrate Configuration Extracts
Migrate security configuration packages.
Migrate Security Configuration Packages
The order for security setup in each tenant doesn’t matter. You decide to set up security in the source tenant first, followed by the target tenant, and then the Customer Central tenant.
You follow this overall process:
  1. Create a security group: Global Advanced Power Users.
  2. Grant permissions to the security group .
  3. Add the user to the security group.
  4. Configure power user access to Deployment Tools in Customer Central.
Read: Source and target tenants:
  • Security:
    Security Configuration
    domain in the System functional area.
Customer Central tenant:
  1. Sign in as a security administrator to the source tenant for the power user.
  2. Create a security group for Global Advanced Power Users.
    1. Access the
      Create Security Group
      task.
    2. On the
      Type of Tenanted Security Group
      prompt, select
      User-Based Security Group
      .
    3. Enter the name,
      Global Advanced Power Users
      .
    4. Click
      OK
      and then
      OK
      again.
    5. Click
      Done
      .
  3. Access the Global Advanced Power Users security group:
    1. Access the
      Maintain Permissions for Security Group
      task.
    2. On the
      Source Security Group
      prompt, select
      Global Advanced Power Users
      .
    3. Click
      OK
      .
  4. Add rows with these values to the
    Domain Security Policy Permissions
    grid:
    View/Modify Access
    Domain Security Policy
    View and Modify
    Configuration Change Management
    Get and Put
    Configuration Change Management
    View and Modify
    Manage: Configuration Change Management Migrations
    Get and Put
    Manage: Configuration Change Management Migrations
    View and Modify
    Get and Put
    OX for Non-Implementers
    OX for Non-Implementers
    View and Modify
    Special OX Web Services
    Get and Put
    Special OX Web Services
  5. Click
    OK
    and then
    Done
    .
  6. Access the
    Activate Pending Security Policy Changes
    task to activate your changes.
    1. Enter this comment to provide an audit trail of your changes:
      User-Based Security Group: Global Advanced Power Users.
    2. Click
      OK
      .
    3. Select the
      Confirm
      check box.
    4. Click
      OK
      .
  7. Access the
    Assign User-Based Security Groups for Person
    task.
    1. On the
      Person
      prompt, select the user and click
      OK
      .
    2. On the
      User-Based Groups to Assign
      prompt, select the Global Advanced Power Users group.
    3. Click
      OK
      and then
      Done
      .
  8. Sign in as a security administrator to the target tenant for the user.
  9. Create a security group for Global Advanced Power Users.
    1. Access the
      Create Security Group
      task.
    2. On the
      Type of Tenanted Security Group
      prompt, select
      User-Based Security Group
      .
    3. Enter the name,
      Global Advanced Power Users
      .
    4. Click
      OK
      and then
      OK
      again,
    5. Click
      Done
      .
  10. Access the Global Advanced Power Users security group:
    1. Access the Maintain Permissions for Security Group task.
    2. On the
      Source Security Group
      prompt, select
      Global Advanced Power Users
      .
    3. Click
      OK
      .
  11. Add rows with these values to the
    Domain Security Policy Permissions
    grid:
    View/Modify Access
    Domain Security Policy
    View and Modify
    Manage: Configuration Change Management Migrations
    Get and Put
    Manage: Configuration Change Management Migrations
    View and Modify
    Configuration Change Management
    View and Modify
    OX for Non-Implementers
    Get and Put
    OX for Non-Implementers
    View and Modify
    Special OX Web Services
    Get and Put
    Special OX Web Services
  12. Click
    OK
    and then
    Done
    .
  13. Access the
    Activate Pending Security Policy Changes
    task to activate your changes.
    1. Enter this comment to provide an audit trail of your changes:
      User-Based Security Group: Global Advanced Power Users.
    2. Click
      OK
      .
    3. Select the
      Confirm
      check box.
    4. Click
      OK
      .
  14. Access the
    Assign User-Based Security Groups for Person
    task.
    1. On the
      Person
      prompt, select the power user and click
      OK
      .
    2. On the
      User-Based Groups to Assign
      prompt, select
      Global Advanced Power Users
      .
    3. Click
      OK
      and then
      Done
      .
  15. Sign in to Customer Central as a Customer Central security administrator.
    1. Access the
      Maintain Access to Customer Central Tooling
      task.
    2. Select these check boxes for the power user:
      • Create Security Configuration Packages
      • OX Migration: Full Object Coverage
      • Create Configuration Extracts
      • Migrate Configuration Extracts
      • Create & View Tenant Compare Reports
    3. Click
      OK
      .