Skip to main content
Administrator Guide
Last Updated: 2025-12-12
Reference: Tenant Security Requirements By Persona

Reference: Tenant Security Requirements By Persona

This table lists the security requirements in Workday for each implementation tool persona. Use the table to match user personas with implementation tool security requirements.
Users often have multiple responsibilities so you may need to combine permissions from several rows to match configuration management responsibilities. You add implemenation tool users to domain security policies in source and target tenants. In the Customer Central tenant, you set up tool access for them on the
Maintain Access to Customer Central Tooling
task.
Persona, Tool, and Responsibilities
Source Tenant Securitiy Domains
Target Tenant Security Domains
Customer Central Security
Self Auditor
Configuration Change Tracker:
  • Creates their own reports
  • Views only their own changes.
View and Modify permissions:
  • Manage: Configuration Change Management - Restricted
None
None
Global Auditor
Configuration Change Tracker:
  • Creates their own reports and views their own changes.
  • Views other users’ changes.
View, Modify, Get and Put permissions:
  • Configuration Change Management
None
None
Global Auditor
Tenant Compare:
  • Compares configurations across tenants.
View and Modify permissions:
  • Configuration Change Management
Get permissions:
  • Special OX Web Services
View and Modify permissions:
  • Configuration Change Management
Get permissions:
  • Special OX Web Services
Check box on the
Maintain Access to Customer Central Tooling
task:
  • Create & View Tenant Compare Reports
Self Packager
Configuration Change Tracker:
  • Creates and edits packages from their own reports.
View, Modify, Get, and Put permissions:
  • Manage: Configuration Change Management - Restricted
  • Manage: Configuration Change Management Migrations - Restricted
View and Modify permissions:
  • OX for Non-Implementers
None
Global Packager
Configuration Change Tracker:
  • Creates and edits packages from their own reports.
  • Creates and edits packages from others’ reports.
View, Modify, Get, and Put permissions:
  • Manage: Configuration Change Management Migrations
  • Configuration Change Management
OX for Non-Implementers
None
Traditional Self Migrator
Object Transporter
  • Migrates their own single instances.
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
Check box on the
Maintain Access to Customer Central Tooling
task:
  • Limit Object Transporter Access
Traditional Global Migrator
Migrates:
  • Their own single instances and standard packages
  • Others’ single instances and standard packages.
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
None
Advanced Self Migrator
Configuration Change Tracker
  • Migrates their own single instances and Advanced packages.
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
  • Manage: Configuration Change Management Migrations - Restricted
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
  • Manage: Configuration Change Management Migrations - Restricted
Check boxes on the
Maintain Access to Customer Central Tooling
task:
  • The OX Migration: Full Object Coverage
  • Limit Object Transporter Access
Advanced Global Migrator
Configuration Change Tracker
Migrates:
  • Their own single instances and Advanced packages.
  • Others’ single instances and Advanced packages.
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
  • Manage: Configuration Change Management Migrations
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
  • Manage: Configuration Change Management Migrations
Check box on the
Maintain Access to Customer Central Tooling
task:
  • The OX Migration: Full Object Coverage
Add-On Security Migrator
Security Policy Migration
  • Migrates security configurations.
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
View, Modify, Get, and Put permissions:
  • OX for Non-Implementers
  • Special OX Web Services
Check box on the
Maintain Access to Customer Central Tooling
task:
  • Migrate Security Configuration Packages
Add-On Configuration Extractor
Configuration Extracts
  • Extracts configuration packages to a file.
None
None
Check box on the
Maintain Access to Customer Central Tooling
task:
  • The Create Configuration Extracts
Add-On Configuration Extract Migrator
Configuration Extracts
  • Loads extracted configuration files to tenants.
None
None
Check box on the
Maintain Access to Customer Central Tooling
task:
  • The Migrate Configuration Extracts