Concept: User Type Permissions in Settings
Security roles and permissions are the foundation for managing user access in Workday VNDLY, providing control over what users can do within the application. You can assign each user one or more roles on their user profile, granting them the permissions associated with those roles.
As an administrator, you can grant or remove different permissions to certain user types. You can also grant or remove permissions for profile roles that encompass many different roles. You find these roles by selecting
More
> Company Settings
>Security
>Security Settings
.Roles
A role is a set of security permissions assigned to a user that defines what actions they can perform and what information they have access to within VNDLY. VNDLY provides a core set of roles, which you can also clone and customize. Or, you can create new roles to fit your organization's needs. For more information, see Create Security Roles.
There are 3 profile roles:
- All Candidates: Candidates and contractors that only sign in to do their personal timekeeping or expenses.
- All Employers: Any client user that is also granted some other role in the system.
- All Vendors: Any vendor users associated as contacts on a vendor profile.
VNDLY grants these profile roles a set of default permissions.
Policies
On the
Policies
tab, you can create and manage security policies. Policies help enforce more granular access control based on the options. For more information, see Set Up Security Policies.Once you create a
policy
, you can assign it to the security roles on the Roles
tab.Permissions
The
Permissions
tab provides a list of every available permission in VNDLY and their definitions. This list is for your reference so you can add them to roles on the Roles
tab.Configuration
You can manage various tenant-wide security policies on the
Configuration
tab.Example: In the
Reporting Hierarchy Access
section, you can grant managers visibility into modules like Jobs
, Timesheets
, and Work Orders
based on their reporting structure.You can configure these settings:
Option
| Description
|
Reporting Hierarchy Access
| Enable visibility for managers into their reporting structure. |
Session Management
| Configure global and inactive session expiration timeouts in seconds. |
Sign-up Token Expiration
| Set the duration for which new user invitation links are valid. |
Password Management
| Configure password requirements. |
Multi-factor Authentication
| Enable MFA and specify user types . Examples: Client, Vendor, Contractor. |
Vendor Auth
| Allow vendors to manage authentication settings. |