Skip to main content
Administrator Guide
Last Updated: 2025-02-21
Setup Considerations: Payroll Security

Setup Considerations: Payroll Security

You can use this topic to help make decisions when planning your configuration and use of payroll security. It explains:
  • Why to set it up.
  • How it fits into the rest of Workday.
  • Downstream impacts and cross-product interactions.
  • Security requirements and business process configurations.
  • Questions and limitations to consider before implementation.
Refer to detailed task instructions for full configuration details.

What It Is

Configurable payroll security:
  • Offers a simple and customizable method to protect payroll data from unauthorized access or manipulation.
  • Enables you to control access to payroll data, based on user roles and responsibilities, like:
    • View payslips and payment dates.
    • Set up company taxes.
Payroll security policies enable you to secure access to:
  • Integrations with third-party organizations for wage garnishments.
  • Pay calculation results reports and reporting items.
  • Pay cycle worklets.
  • Payslip configuration tasks.
  • Report data sources (RDS) for payslips.
  • Run pay calculation background processes.
  • Termination business processes.

Business Benefits

Configure payroll security permissions to:
  • Automate permission assignments for payroll data by grouping users based on similar attributes, saving you the effort of setting up permissions individually.
  • Manage access to payroll integrations, reports, and data using a single security model. This model makes it easier to maintain access at scale.
  • Meet company standards for auditing permissions in Workday using built-in audit trails.
  • Limit access for nonpayroll users to only the payroll data they need to perform their jobs.

Use Cases

  • Automatically add new users to a defined security group based on their position, such as:
    • A user-based group for payroll administrators.
    • Managers who need to review overtime or costing information.
    • HR administrators who need to access aggregated payroll results and other nonsensitive portions of data.
  • Provide different levels of access for different types of users in the same tenant. Example: Workers can only view their own payslips, but managers can view payslips for all their direct reports.

Questions to Consider

Question
Considerations
How do you want to determine who can view items and perform actions in Workday Payroll?
Workday provides different types of security groups to enable you to address your payroll requirements. Workday groups similar items and actions into different security policies. While you can't change the items and actions secured to security policies, you can change the security groups associated with the security policies.
You can use these types of security groups to control who has access and what they have access to:
  • Role-based.
    Example: Payroll partner. Has access to selected payroll tasks and to view selected data for the pay groups they support.
  • Segment-based.
    Example: Administrator for payroll business processes. Has access to create and maintain payroll business processes. This security is a decentralized version of Business Process Administrator.
  • User-based.
    Example: Payroll administrator. Has access to view payroll data and perform payroll tasks for all workers in all pay groups.
Members in security groups with the unconstrained context type can access all secured data instances.
What level of permission do you want to provide to payroll tasks and reports?
Workday groups similar tasks and reports into security domains. To provide access to the tasks and reports, set View or Modify permission on the security policies that secure them.
Workday typically designates reports and reporting items with View access. Users with Modify permissions can access all tasks and reports secured to the domain.
What level of permission do you want to provide to payroll business processes?
You can set different permissions on both the security policies and steps for payroll business processes. Example: Provide employees access to the
Initiate
action on a business process.
Do third-party resources need access to your Workday tenant?
You can use Service Centers to grant third-party contracted organizations access to your Workday tenant while protecting sensitive data. Representatives from those organizations:
  • Have limited access to your Workday tenant.
  • Can support a subset of workers in your organization.
  • Aren't workers, but can perform tasks in Workday within a predefined scope.

Recommendations

When possible, use Workday-delivered payroll security groups instead of creating your own. Doing so helps to ensure that the security group has access to the payroll-specific data and tasks needed to perform their role. Workday-delivered payroll security groups also enable you to:
  • Benefit from banking setup questions and feedback about terminee security groups captured on Workday Community.
  • Use Workday-verified security configurations for accounting and tax setup.
Grant access only to information and resources users require to accomplish their job functions.
Use Workday-delivered reports to:
  • Ensure that you provide users with correct permissions.
  • Create and submit year-end tax data to government agencies.
Grant unconstrained access to business process administrators on the
Business Process Definitions
report data source (RDS). Configure access to these domains as appropriate to ensure that all business process administrators can build custom reports using this RDS:
  • Administration
  • Definition View
  • Manage: Business Process Definitions
Review all requirements for security groups and security policies before setting up security.

Requirements

To set permissions for domains and business processes, enable the Workday Payroll functional area and its security policies. Enabling a functional area doesn’t automatically enable all the security policies in that area.

Limitations

You can’t:
  • Change the actions available on security policies for business processes.
  • Change the items within domains.
  • Delete security policies.
  • Move domains or business processes from 1 functional area to another.

Tenant Setup

No impact.

Security

Functional Areas
Considerations
Banking and Settlement
Security domains in this functional area enable you to:
  • Manage bank account transfers, ad hoc transactions, positive pay files, and payment returns.
  • Print checks, payslips, and pay advices.
  • Review bank statements and manage reconciliations.
  • Settle payments electronically and by credit card.
  • Set up financial institutions and bank accounts.
  • Set up and manage prenoting and escheatment.
  • Set up and process outsourced banking and print services.
  • View account, check, and direct deposit registers.
Common Financial Management
Security domains in this functional area enable you to:
  • Establish and maintain currency and tax rates.
  • Manage period and year-end processing.
  • Perform period-end processing and view-related reporting.
  • Set up company-related accounting details and view-related reporting.
  • Set up worktags and custom validations.
Core Payroll
Security domains in this functional area enable you to configure and use these basic Payroll features that are common to all Payroll countries:
  • Accumulations.
  • Balances.
  • Deductions.
  • Earnings.
  • Income withholding orders.
  • Payment elections.
  • Payroll history.
  • Payroll input.
  • Payroll processes.
  • Settlement.
The domains also secure access to the:
  • Employee Self Service Pay
    dashboard, which helps employees understand their pay by viewing payslips, comparing periods, and reviewing pay trends.
  • Pay Cycle Command Center
    dashboard, which payroll administrators and partners can configure to gain operational insight into a specific pay cycle.
  • Pay On-Demand
    self-service request for Payroll for the U.S., which employees can access to receive accumulated but not yet paid wages.
  • Process Monitor
    report, which payroll administrators in unconstrained user-based security groups on the
    Process: Run Batch Calculations (Pay Calculation)
    domain security policy can access to view all types of background processes that are running or ran in the past.
Expenses
Security domains in this functional area enable you to:
  • Administer expense report tasks for workers and pre-hires.
  • Process prenotes.
  • Record cash advance repayments.
  • Set up self-service payment elections and expense reporting for employees and contingent workers.
Integration
Security domains in this functional area enable you to:
  • Create and configure integrations such as Cloud Connect for Third-Party Payroll and Enterprise Interface Builders (EIBs).
  • Launch integrations immediately or schedule them to run once or multiple times in the future.
  • Set up the integration systems to submit tax data to ADP, Ceridian, and MasterTax.
  • View integration reports using the
    Process Monitor
    or
    Integration Events
    report.
Organizations and Roles
Security domains in this functional area enable you to:
  • Define membership rules and view organization audits and reports.
  • Set up and administer pay groups.
  • Set up and manage all company structures.
Payroll Interface
Security domains in this functional area enable you to:
  • Assign and view reconciliation items.
  • Configure an import of external payroll results or payslips.
  • Configure Cloud Connect for Third-Party Payroll integrations that send data from Workday and receive data from third-party payroll system into Workday.
  • Configure event-driven integrations to a third-party system.
  • Configure integrations for local payroll data.
  • Employee self-service transactions for employees paid through payroll interface, including federal tax withholding elections and payment elections.
  • Manage errors from external payroll systems.
  • Send worker, compensation, benefit deductions, and time-off data on an incremental or one-time basis.
  • Set up earnings, deductions, pay accumulations, pay balances, and pay groups.
  • Set up global payroll reconciliation.
  • View uploaded payroll results from third-party systems.
System
Security domains in this functional area enable you to:
  • Access tenant setup for payroll.
  • Configure security for functional areas, security groups, domain security policies, and security policies for business processes.
  • Manage business process definitions.
  • Segregate management of different business process definitions by different users.
  • Set up, maintain, and report on business processes.
  • View reports to analyze security configuration.
USA Payroll
Security domains in this functional area enable you to configure and use features specific to Payroll for the U.S., Puerto Rico, Guam, and the U.S. Virgin Islands, such as:
  • Company tax data.
  • Payroll commitments.
  • Withholding orders.
  • Worker tax data.
  • Year-end reporting form W-2, W-2R, W-2GU, and W-2VI boxes and employee forms.
Worktags
Security domains in this functional area enable you to manage Workday-delivered and custom worktags. You can:
  • Configure primary, additional, and required worktag types for taggable transaction types.
  • Enable worktag types for related worktag taggable types.
  • Retrieve and load default and allowed values using web services for any related worktag taggable type.
You're responsible for testing and validating that security domain settings meet your business needs.

Business Processes

Workday doesn't secure business processes to domains, but each business process definition has its own business process security policy.
You associate each step within a business process definition with a security group.
Workday enables you to configure segment-based security groups with access to view and manage specific business process definitions. Business process segmentation applies only to business process definitions.
Segment-based security groups can include any type of security group, including role-based security groups. When you use a role-based security group, the member can only maintain business processes affiliated with the organizations they have an assigned role for. Example: A payroll partner's role in:
  • Absence Requests
  • Benefit Enrollments
  • Compensation Changes
  • Job Changes
  • One Time Payments
  • Terminations
  • Time Entry and submission
Secure the segment-based security group to the
Manage: Business Process Definitions
security domain. This domain only includes tasks related to defining business processes.
Workday doesn't enable segmented security on these business process components:
  • Calculated dates
  • Checklists
  • Rules
  • To Dos

Reporting

Dashboard or Report
Considerations
Action Summary for Security Group
report
View the security policies associated with a specified security group.
Business Process Security Policies for Functional Area
report
View all security policies for business processes within a functional area.
Business Process Types and Initiating Security Groups
report
View all business processes and the security groups that have permission to initiate them.
Compare Permissions of Two Security Groups
report
Compare the security policy permissions for 2 security groups.
Domain Security Policies for Functional Area
report
View all domain security policies for Payroll in a functional area.
Employee Self Service Pay
dashboard
View insights so employees understand their pay by viewing payslips, comparing periods, and reviewing any pay trends.
Functional Areas
report
View all functional areas, and the domains and business processes in them.
Pay Cycle Command Center
dashboard
View operational insights into specific pay cycles.
Process Monitor
report
View all types of background processes that are running or ran in the past.
Security Analysis for Security Groups
report
View the secured items associated with security groups.
Security Exception Audit
report
View errors and warnings involving your security configuration.
View Security for Securable Item
report
View how Workday secures delivered items.
View Security Group
report
View security groups and the associated security policies and configuration details.
View Security Groups for User
report
View the security groups that a person is a member of.
View Web Service Operations Security Groups
report
Identify the security groups that you need to be a member of to run a specified web service.
Web Service Security Audit
report
View the security groups that can run web service tasks.

Integrations

Workday provides several security domains that secure access to integration templates and integration systems. These domains separate the permissions to configure an integration from the permissions to run an integration and view integration output. You can also segment integration templates and integrations, then grant access separately for each segment.
All integrations access Workday data using web service operations and Reports-as-a-Service. Workday secures these items to various security domains:
  • Custom reports.
  • RDSs.
  • Report fields.
  • Web service operations.
Integrations and applications that access Workday must have Get and Put access to the domains that include the web service operations. Also, they must have the View access to the domains that include the RDSs and report fields. In addition, outbound EIBs require access to the custom report that they use as an RDS. These accounts can control permissions:
  • Associated Integration System User (ISU) account (for Connectors, Studio integrations, and external applications).
  • The role of the person who runs an EIB integration. Example: Payroll administrator.

Connections and Touchpoints

Touchpoint
Consideration
Absence
Enable Payroll security in this functional area to configure:
  • Leaves of absence.
  • Time off plans to track balances in Absence Management.
  • Pay for workers on leaves of absence.
Banking and Settlement
Enable Payroll security in this functional area to:
  • Manage bank account transfers, ad hoc transactions, positive pay files, and payment returns.
  • Print checks, payslips, and pay advices.
Benefit Plans
Enable Payroll security in this functional area to:
  • Associate a benefit plan to earnings and deductions.
  • Enable Workday to process contributions and payments to the plan through payroll.
Compensation
Enable Payroll security in this functional area to:
  • Calculate payroll.
  • Create compensation schedules.
  • Map compensation elements to earnings.
Core Payroll
Payroll security in this functional area enables you to configure and use these basic Payroll features that are common to all Payroll countries:
  • Accumulations.
  • Balances.
  • Deductions.
  • Earnings.
  • Income withholding orders.
  • Payment elections.
  • Payroll history.
  • Payroll input.
  • Payroll processes.
  • Settlement.
HCM
Provide employee and job-related data for payroll processing, such as:
  • Employee status.
  • Personal information.
Payroll Interface
  • Assign and view reconciliation items.
  • Configure an import of external payroll results or payslips.
Workday offers a Touchpoints Kit with resources to help you understand configuration relationships in your tenant. Learn more about the Workday Touchpoints Kit on Workday Community.