Skip to main content
Administrator Guide
Last Updated: 2026-09-18
Set Up Granular Security for the Supplier Portal

Set Up Granular Security for the Supplier Portal

  • Set up the supplier portal.
  • Verify that supplier contacts have supplier portal access through
    Supplier Contact as Self
    .
  • Security: These domains in the System functional area:
    • Set Up: Security Fields
    • Security Configuration
You can restrict which supplier portal areas each supplier contact can access by using supplier contact types with rule-based security groups.
For existing tenants, Workday automatically converts security policy permissions when you enable the feature. Each new child domain inherits permissions from the Process: Supplier Portal domain with a status of
Active - Inheriting parent permissions
. Supplier contacts retain their current access until you create and apply rule-based security groups.
Workday supports membership rules only for business entity contacts and not access constraint rules.
  1. Access the
    Maintain Contact Types task
    .
    1. Add custom contact types, such as banking specialist or procurement specialist, that map to Supplier Contact.
    2. Click
      OK
      .
  2. Access the
    Maintain Fields for Security Rules
    task.
    1. Select these values:
    Option
    Description
    Rule Usage Type
    Security Attribute - System User
    Business Object
    Business Entity Contact
    Fields
    Contact TypeC
    1. Click
      OK
      .
  3. Access the
    Create Security Rule
    task.
    1. From the
      Security Rule Type
      menu, select
      Membership Rule.
    2. From the
      Business Object
      prompt, select
      Business Entity
      Contact.
    3. Click
      OK
      .
  4. Access the
    Create Security Group
    task.
    1. From the Type of Tenanted Security group prompt, select
      Rule-Based
      Security Group.
    2. Select these values:
    Option
    Description
    Baseline Security Group
    Supplier Contact as Self
    Include Members by Rule
    Select your new membership rule.
    Access to Instances
    User access to Instances from
    Baseline
    Security Group
    1. Click
      OK
      .
  5. Edit domain security policies for
    Process: Supplier Portal
    or the relevant child domains. See Edit Domain Security PoliciesExamples:
    Process: Supplier Portal - Contact and Banking
    ,
    Process: Supplier Portal - Invoices
    Add your rule-based security group to the policies for the portal domains you want to restrict. Workday introduces these child domains under
    Process: Supplier Portal
    :
    • Process: Supplier Portal - Purchase Orders
    • Process: Supplier Portal - Invoice
    • Process: Supplier Portal - Invoice Request
    • Process: Supplier Portal - Payments
    • Process: Supplier Portal - Receipts
    • Process: Supplier Portal - Requisitions
    • Process: Supplier Portal - Catalog
    • Process: Supplier Portal - Contact and Banking
    • Process: Supplier Portal - RFQs
    • Process: Supplier Portal - Attachments
    • Process: Supplier Portal - Printable Documents
    • Process: Supplier Portal - Contingent Workers
  6. Access the
    Find Suppliers
    report and select the supplier.
  7. On the
    Supplier Contacts
    tab, assign the appropriate contact type to each supplier contact. Workday evaluates the contact type when it applies your supplier portal security rules.
Test supplier contact access. sign in as supplier contacts with different contact types and confirm they can access only the portal areas your domain policies allow.