Example: Create Security Segments on Journey Categories
You can create security segments and assign security permissions to journey categories for an individual or a group.
This example illustrates how you can use security segments to control journeys categories to suit the needs of your organization. We'll create segments to:
- Restrict users from accessing a specific journey category.
- Grant access to certain individuals or groups to configure, distribute, or report on Journeys.
These domains in the Journeys functional area:
Domain | Permissions | Actions |
|---|---|---|
Manage: Journey Builders
|
| Users with Modify Permissions :
Users with View Permissions:
If a user has Modify Permissions for this domain and has been granted permissions for Who Can Start the Business Process , they can configure journey distribution to distribute journeys.
When you add segment-based security groups to this domain, users can only configure categories they have access to, for distributing journeys. |
Set Up: Journey Administration
| Unconstrained Groups | Users can create and modify a journey category. |
- To configure segment-based security, enter your Workday tenant.
- Access theDomain Security Policies for Functional Areaand enterJourneysin theFunctional Areatab.The security domains for the Journeys functional area are listed on the left-hand side.
- (Optional) Remove users from theSet Up: Journey Administrationif you want to restrict their access to create, edit, and view journey category functionalities.
- As you complete the task, consider:FieldDescriptionType of Tenanted Security GroupSelectSegment-Based Security Group.NameEnter a name of the group that you want to segment out.Onboarding JourneysSecurity GroupsSelect the security group that you want to have access to the journey categories you're segmenting out.Onboarding Administrator
- To configure distribute permissions, navigate to theEdit Business Process Security Policytask, and clickJourney Distributionfrom theBusiness Process Typeprompt.You can create aDistribute Journeyssecurity group that enables HR partners to distribute journeys but doesn't grant permissions to the Onboarding Administrator group to distribute journeys.You must have permission to start the .
- Activate Pending Security Policy Changes after completing the configuration process.
The security groups enable the HR partner and Onboarding Administrator to access information based on their segment-based permissions.
- Logan, HR partner, has unconstrained access. When they navigate to theJourneys Workspace, they're able to:
- See all the individuals with configured journeys in the tenant.
- View, edit, and distribute any journey category.
- Create new journey categories.You must have access to theSet Up: Journey Administrationdomain in the journey functional area.
- Daniel, HR partner, is responsible for all the relocations in their organization and therefore has access only toModifyandDistributeaccess to specific journey categories such as relocation journeys. When they navigate to theJourneys Workspace, they:
- Can view and edit theOpen Enrollment JourneysandOnboarding Journeys.
- Can't view or edit theTransition to Managers Journeys.
- Can create a report on specific categories limited to enrollment and onboarding.
- James Walker, Onboarding Administrator, can view, preview, look at metrics, edit, and distribute these categories in these tenants.
- Onboarding - Product Management
- Onboarding - Sales
- Onboarding - Software Engineering