Set Up Granular Security for the Supplier Portal
- Set up the supplier portal.
- Verify that supplier contacts have supplier portal access throughSupplier Contact as Self.
- Security: These domains in the System functional area:
- Set Up: Security Fields
- Security Configuration
You can restrict which supplier portal areas each supplier contact can access by using supplier contact types with rule-based security groups.
For existing tenants, Workday automatically converts security policy permissions when you enable the feature. Each new child domain inherits permissions from the Process: Supplier Portal domain with a status of
Active - Inheriting parent permissions
. Supplier contacts retain their current access until you create and apply rule-based security groups. Workday supports membership rules only for business entity contacts and not access constraint rules.
- Access theMaintain Contact Types task.
- Add custom contact types, such as banking specialist or procurement specialist, that map to Supplier Contact.
- ClickOK.
- Access theMaintain Fields for Security Rulestask.
- Select these values:
OptionDescriptionRule Usage TypeSecurity Attribute - System UserBusiness ObjectBusiness Entity ContactFieldsContact TypeC- ClickOK.
- Access theCreate Security Ruletask.
- From theSecurity Rule Typemenu, selectMembership Rule.
- From theBusiness Objectprompt, selectBusiness EntityContact.
- ClickOK.
- Access theCreate Security Grouptask.
- From the Type of Tenanted Security group prompt, selectRule-BasedSecurity Group.
- Select these values:
OptionDescriptionBaseline Security GroupSupplier Contact as SelfInclude Members by RuleSelect your new membership rule.Access to InstancesUser access to Instances fromBaselineSecurity Group- ClickOK.
- Edit domain security policies forProcess: Supplier Portalor the relevant child domains. See Edit Domain Security PoliciesExamples:Process: Supplier Portal - Contact and Banking,Process: Supplier Portal - InvoicesAdd your rule-based security group to the policies for the portal domains you want to restrict. Workday introduces these child domains underProcess: Supplier Portal:
- Process: Supplier Portal - Purchase Orders
- Process: Supplier Portal - Invoice
- Process: Supplier Portal - Invoice Request
- Process: Supplier Portal - Payments
- Process: Supplier Portal - Receipts
- Process: Supplier Portal - Requisitions
- Process: Supplier Portal - Catalog
- Process: Supplier Portal - Contact and Banking
- Process: Supplier Portal - RFQs
- Process: Supplier Portal - Attachments
- Process: Supplier Portal - Printable Documents
- Process: Supplier Portal - Contingent Workers
- Access theFind Suppliersreport and select the supplier.
- On theSupplier Contactstab, assign the appropriate contact type to each supplier contact. Workday evaluates the contact type when it applies your supplier portal security rules.
Test supplier contact access. sign in as supplier contacts with different contact types and confirm they can access only the portal areas your domain policies allow.