Example: Set Up Security for an Implementation Tool Power User
This example illustrates how to set up domain security and implementation tool access for a Global Advanced Power User with additional permissions.
You’ve established a persona of Global Advanced Power User for a user based on these tenant configuration management responsibilities:
- Views other user’s configuration changes.
- Compares configurations across tenants.
- Creates and edits their own and other’s configuration packages.
- Migrates their own and other’s standard configuration packages from Object Transporter.
- Migrates their own and other’s Advanced configuration packages from Configuration Change Tracker.
The user also needs permissions to:
- Extract and load configuration extract files for Sandbox refreshes.
- Migrate security configuration packages.
These add-on responsibilities require these roles:
- Add-On Security Migrator.
- Add-On Configuration Extractor.
- Add-On Configuration Extract Migrator .
Workday requires user-based security groups for the domain security policies for the implementation tools. You decide to create a single user-based security group called Global Advanced Power Users. To plan your work, you create a source and target tenant security setup table to note the domain configurations required for each tenant.
Tenant | Security Domains and Permissions |
|---|---|
Source | View and Modify, Get, and Put permissions:
|
Target | View and Modify, Get, and Put permissions:
View and Modify permissions only:
|
You also create a Customer Central tenant security settings table to note the check boxes you must select for the power user on the
Maintain Access to Customer Central Tooling
task.User Access | Check Box Selection |
|---|---|
Migrate Advanced configuration packages in Configuration Change Tracker. | OX Migration: Full Object Coverage |
Compare configurations between tenants in Tenant Compare. | Create & View Tenant Compare Reports |
Extract configuration files (.dat) using Configuration Extracts. | Create Configuration Extracts |
Load configuration files (.dat) using Configuration Extracts. | Migrate Configuration Extracts |
Migrate security configuration packages. | Migrate Security Configuration Packages |
The order for security setup in each tenant doesn’t matter. You decide to set up security in the source tenant first, followed by the target tenant, and then the Customer Central tenant.
You follow this overall process:
- Create a security group: Global Advanced Power Users.
- Grant permissions to the security group .
- Add the user to the security group.
- Configure power user access to Deployment Tools in Customer Central.
Read:
- Security:Security Configurationdomain in the System functional area.
Customer Central tenant:
- Set up a Customer Central account for the user using Workday naming conventions.
- Provide tenant access to the user.
- Sign in as a security administrator to the source tenant for the power user.
- Create a security group for Global Advanced Power Users.
- Access theCreate Security Grouptask.
- On theType of Tenanted Security Groupprompt, selectUser-Based Security Group.
- Enter the name,Global Advanced Power Users.
- ClickOKand thenOKagain.
- ClickDone.
- Access the Global Advanced Power Users security group:
- Access theMaintain Permissions for Security Grouptask.
- On theSource Security Groupprompt, selectGlobal Advanced Power Users.
- ClickOK.
- Add rows with these values to theDomain Security Policy Permissionsgrid:View/Modify AccessDomain Security PolicyView and ModifyConfiguration Change ManagementGet and PutConfiguration Change ManagementView and ModifyManage: Configuration Change Management MigrationsGet and PutManage: Configuration Change Management MigrationsView and ModifyGet and PutOX for Non-ImplementersOX for Non-ImplementersView and ModifySpecial OX Web ServicesGet and PutSpecial OX Web Services
- ClickOKand thenDone.
- Access theActivate Pending Security Policy Changestask to activate your changes.
- Enter this comment to provide an audit trail of your changes:User-Based Security Group: Global Advanced Power Users.
- ClickOK.
- Select theConfirmcheck box.
- ClickOK.
- Access theAssign User-Based Security Groups for Persontask.
- On thePersonprompt, select the user and clickOK.
- On theUser-Based Groups to Assignprompt, select the Global Advanced Power Users group.
- ClickOKand thenDone.
- Sign in as a security administrator to the target tenant for the user.
- Create a security group for Global Advanced Power Users.
- Access theCreate Security Grouptask.
- On theType of Tenanted Security Groupprompt, selectUser-Based Security Group.
- Enter the name,Global Advanced Power Users.
- ClickOKand thenOKagain,
- ClickDone.
- Access the Global Advanced Power Users security group:
- Access the Maintain Permissions for Security Group task.
- On theSource Security Groupprompt, selectGlobal Advanced Power Users.
- ClickOK.
- Add rows with these values to theDomain Security Policy Permissionsgrid:View/Modify AccessDomain Security PolicyView and ModifyManage: Configuration Change Management MigrationsGet and PutManage: Configuration Change Management MigrationsView and ModifyConfiguration Change ManagementView and ModifyOX for Non-ImplementersGet and PutOX for Non-ImplementersView and ModifySpecial OX Web ServicesGet and PutSpecial OX Web Services
- ClickOKand thenDone.
- Access theActivate Pending Security Policy Changestask to activate your changes.
- Enter this comment to provide an audit trail of your changes:User-Based Security Group: Global Advanced Power Users.
- ClickOK.
- Select theConfirmcheck box.
- ClickOK.
- Access theAssign User-Based Security Groups for Persontask.
- On thePersonprompt, select the power user and clickOK.
- On theUser-Based Groups to Assignprompt, selectGlobal Advanced Power Users.
- ClickOKand thenDone.
- Sign in to Customer Central as a Customer Central security administrator.
- Access theMaintain Access to Customer Central Toolingtask.
- Select these check boxes for the power user:
- Create Security Configuration Packages
- OX Migration: Full Object Coverage
- Create Configuration Extracts
- Migrate Configuration Extracts
- Create & View Tenant Compare Reports
- ClickOK.