Setup Considerations: Payroll Security
You can use this topic to help make decisions when planning your configuration and use of payroll security. It explains:
- Why to set it up.
- How it fits into the rest of Workday.
- Downstream impacts and cross-product interactions.
- Security requirements and business process configurations.
- Questions and limitations to consider before implementation.
What It Is
Configurable payroll security:
- Offers a simple and customizable method to protect payroll data from unauthorized access or manipulation.
- Enables you to control access to payroll data, based on user roles and responsibilities, like:
- View payslips and payment dates.
- Set up company taxes.
Payroll security policies enable you to secure access to:
- Integrations with third-party organizations for wage garnishments.
- Pay calculation results reports and reporting items.
- Pay cycle worklets.
- Payslip configuration tasks.
- Report data sources (RDS) for payslips.
- Run pay calculation background processes.
- Termination business processes.
Business Benefits
Configure payroll security permissions to:
- Automate permission assignments for payroll data by grouping users based on similar attributes, saving you the effort of setting up permissions individually.
- Manage access to payroll integrations, reports, and data using a single security model. This model makes it easier to maintain access at scale.
- Meet company standards for auditing permissions in Workday using built-in audit trails.
- Limit access for nonpayroll users to only the payroll data they need to perform their jobs.
Use Cases
- Automatically add new users to a defined security group based on their position, such as:
- A user-based group for payroll administrators.
- Managers who need to review overtime or costing information.
- HR administrators who need to access aggregated payroll results and other nonsensitive portions of data.
- Provide different levels of access for different types of users in the same tenant. Example: Workers can only view their own payslips, but managers can view payslips for all their direct reports.
Questions to Consider
Question | Considerations |
|---|---|
How do you want to determine who can view items and perform actions in Workday Payroll? | Workday provides different types of security groups to enable you to address your payroll requirements. Workday groups similar items and actions into different security policies. While you can't change the items and actions secured to security policies, you can change the security groups associated with the security policies.
You can use these types of security groups to control who has access and what they have access to:
Members in security groups with the unconstrained context type can access all secured data instances. |
What level of permission do you want to provide to payroll tasks and reports? | Workday groups similar tasks and reports into security domains. To provide access to the tasks and reports, set View or Modify permission on the security policies that secure them.
Workday typically designates reports and reporting items with View access. Users with Modify permissions can access all tasks and reports secured to the domain. |
What level of permission do you want to provide to payroll business processes? | You can set different permissions on both the security policies and steps for payroll business processes. Example: Provide employees access to the Initiate action on a business process. |
Do third-party resources need access to your Workday tenant? | You can use Service Centers to grant third-party contracted organizations access to your Workday tenant while protecting sensitive data. Representatives from those organizations:
|
Recommendations
When possible, use Workday-delivered payroll security groups instead of creating your own. Doing so helps to ensure that the security group has access to the payroll-specific data and tasks needed to perform their role. Workday-delivered payroll security groups also enable you to:
- Benefit from banking setup questions and feedback about terminee security groups captured on Workday Community.
- Use Workday-verified security configurations for accounting and tax setup.
Grant access only to information and resources users require to accomplish their job functions.
Use Workday-delivered reports to:
- Ensure that you provide users with correct permissions.
- Create and submit year-end tax data to government agencies.
Business Process Definitions
report data source (RDS). Configure access to these domains as appropriate to ensure that all business process administrators can build custom reports using this RDS:
- Administration
- Definition View
- Manage: Business Process Definitions
Review all requirements for security groups and security policies before setting up security.
Requirements
To set permissions for domains and business processes, enable the Workday Payroll functional area and its security policies. Enabling a functional area doesn’t automatically enable all the security policies in that area.
Limitations
You can’t:
- Change the actions available on security policies for business processes.
- Change the items within domains.
- Delete security policies.
- Move domains or business processes from 1 functional area to another.
Tenant Setup
No impact.
Security
Functional Areas | Considerations |
|---|---|
Banking and Settlement | Security domains in this functional area enable you to:
|
Common Financial Management | Security domains in this functional area enable you to:
|
Core Payroll | Security domains in this functional area enable you to configure and use these basic Payroll features that are common to all Payroll countries:
The domains also secure access to the:
|
Expenses | Security domains in this functional area enable you to:
|
Integration | Security domains in this functional area enable you to:
|
Organizations and Roles | Security domains in this functional area enable you to:
|
Payroll Interface | Security domains in this functional area enable you to:
|
System | Security domains in this functional area enable you to:
|
USA Payroll | Security domains in this functional area enable you to configure and use features specific to Payroll for the U.S., Puerto Rico, Guam, and the U.S. Virgin Islands, such as:
|
Worktags | Security domains in this functional area enable you to manage Workday-delivered and custom worktags. You can:
|
You're responsible for testing and validating that security domain settings meet your business needs.
Business Processes
Workday doesn't secure business processes to domains, but each business process definition has its own business process security policy.
You associate each step within a business process definition with a security group.
Workday enables you to configure segment-based security groups with access to view and manage specific business process definitions. Business process segmentation applies only to business process definitions.
Segment-based security groups can include any type of security group, including role-based security groups. When you use a role-based security group, the member can only maintain business processes affiliated with the organizations they have an assigned role for.
Example: A payroll partner's role in:
- Absence Requests
- Benefit Enrollments
- Compensation Changes
- Job Changes
- One Time Payments
- Terminations
- Time Entry and submission
Secure the segment-based security group to the
Manage: Business Process Definitions
security domain. This domain only includes tasks related to defining business processes.Workday doesn't enable segmented security on these business process components:
- Calculated dates
- Checklists
- Rules
- To Dos
Reporting
Dashboard or Report | Considerations |
|---|---|
Action Summary for Security Group report | View the security policies associated with a specified security group. |
Business Process Security Policies for Functional Area report | View all security policies for business processes within a functional area. |
Business Process Types and Initiating Security Groups report | View all business processes and the security groups that have permission to initiate them. |
Compare Permissions of Two Security Groups report | Compare the security policy permissions for 2 security groups. |
Domain Security Policies for Functional Area report | View all domain security policies for Payroll in a functional area. |
Employee Self Service Pay dashboard | View insights so employees understand their pay by viewing payslips, comparing periods, and reviewing any pay trends. |
Functional Areas report | View all functional areas, and the domains and business processes in them. |
Pay Cycle Command Center dashboard | View operational insights into specific pay cycles. |
Process Monitor report | View all types of background processes that are running or ran in the past. |
Security Analysis for Security Groups report | View the secured items associated with security groups. |
Security Exception Audit report | View errors and warnings involving your security configuration. |
View Security for Securable Item report | View how Workday secures delivered items. |
View Security Group report | View security groups and the associated security policies and configuration details. |
View Security Groups for User report | View the security groups that a person is a member of. |
View Web Service Operations Security Groups report | Identify the security groups that you need to be a member of to run a specified web service. |
Web Service Security Audit report | View the security groups that can run web service tasks. |
Integrations
Workday provides several security domains that secure access to integration templates and integration systems. These domains separate the permissions to configure an integration from the permissions to run an integration and view integration output. You can also segment integration templates and integrations, then grant access separately for each segment.
All integrations access Workday data using web service operations and Reports-as-a-Service. Workday secures these items to various security domains:
- Custom reports.
- RDSs.
- Report fields.
- Web service operations.
Integrations and applications that access Workday must have Get and Put access to the domains that include the web service operations. Also, they must have the View access to the domains that include the RDSs and report fields. In addition, outbound EIBs require access to the custom report that they use as an RDS. These accounts can control permissions:
- Associated Integration System User (ISU) account (for Connectors, Studio integrations, and external applications).
- The role of the person who runs an EIB integration. Example: Payroll administrator.
Connections and Touchpoints
Touchpoint | Consideration |
|---|---|
Absence | Enable Payroll security in this functional area to configure:
|
Banking and Settlement | Enable Payroll security in this functional area to:
|
Benefit Plans | Enable Payroll security in this functional area to:
|
Compensation | Enable Payroll security in this functional area to:
|
Core Payroll | Payroll security in this functional area enables you to configure and use these basic Payroll features that are common to all Payroll countries:
|
HCM | Provide employee and job-related data for payroll processing, such as:
|
Payroll Interface |
|
Workday offers a Touchpoints Kit with resources to help you understand configuration relationships in your tenant. Learn more about the Workday Touchpoints Kit on Workday Community.