About Workday Agents
Workday AI agents are autonomous, conversational assistants that can answer questions and perform multistep actions to enable you to complete complex tasks and workflows. These agents use large language models (LLMs) that analyze data and learn patterns in order to produce predictions, recommendations, decisions, or generated content that influence or automate parts of a workflow.
Workday supports use of these types of agents:
- First-party agents, which are Workday-built agents
- Second-party agents, which are partner-built agents
- Third-party agents, which are self-built agents
Every agent uses skills, which are the tasks or activities the agent can execute. Each skill consists of:
- Tools, which are the resources the agent may use when executing the skill. For agents that interact with Workday, tools are Workday APIs.
- Resources, which are the type of API that a tool uses. Examples: REST, SOAP, Graph, WQL.
- One of these execution modes. You can't change a skill's execution mode
- Ambient mode: The agent performs tasks as itself and has its own security permissions.
- Delegate mode: The agent performs tasks on behalf of a human and uses the worker’s permissions.
You can’t delegate Workday agent interactions or use a proxy
Workday Agent System of Record (ASOR)
ASOR is a centralized framework for Workday agents that enables you to:
- Find, add, register, configure, monitor, and manage your AI agents.
- Leverage a single control center for governance, security, and auditing your agents, reducing administrative overhead.
- View data insights, including usage and performance, to analyze and demonstrate the value and impact of your agents.
- Provides the ability for agents to interact across systems.
You don’t need to purchase additional specific SKUs to use ASOR. Some agents, including those for HiredScore and Evisort, are not part of ASOR and can't be accessed through the
Agent Management Hub
. ASOR creates and securely stores the private key client credentials, but you must ensure your security environment supports OAuth 2.0.
You can use these domains to manage your agents:
Domains
| Considerations
|
|---|---|
Agent Compliance
| Provides access to reports and data required for agent compliance. |
Agent Management Hub
| Provides access to the Agent Management Hub , which is the centralized hub for viewing and managing all agents. |
Manage: Agents
| Provides access to tasks for managing agents including configuration, activation, and deactivation in ASOR. |
Reports: Agent Reporting
| Provides access to view agent analytics and report data sources and filters for agent level reporting. |
Reports: AI Agent Security
| Provides access to reports about agent security information. |
Setup: Agents
| Provides access to setup tasks and activities for agents in ASOR. |
Agent Management Hub
You can use the
Agent Management Hub
to manage your Workday-built, partner-built, and self-built agents through these phases:
- Define an agent on its agent profile page in theAgent Management Hub. For external agents, you provide a definition for your agent through an API.
- Register an agent in theAgent Management Hubto prepare it for configuration and activation. In order to register Workday-built agents in Production, you must opt in to the:
- Configure your agent to specify which skills it uses and who can access it.
- Activate your agent to enable users to interact with it based on the security permissions you configured.
- Deactivate your agent when you no longer need it. This hides the agent from users but keeps it accessible inAgent Management Hubso you can reactivate it in the future as needed.
The
Agent Registry
section displays your registered agents, along with their status and when an administrator user in Workday last made updates to their configuration. You can click the name of an agent to view the agent’s profile, the available skills for the agent, and agent analytics reports.We recommend that you regularly examine the audit log for agent actions. Workday doesn’t delete usage activities from previous weeks during the Sandbox refresh.
Agent Security
As you configure your agents, you can specify who has access to interact with the agent by providing security groups for each delegate execution mode skill. Example: You can specify Employee as Self to make a skill available to an employee who interacts with the agent. As long as a user is part of one of the security groups on one of the skills, they have access to interact with the agent.
Agent interaction security permissions are separate from tool execution permissions. Consider evaluating alignment between the security groups in the
Available To
prompt and the security groups that have permissions for the tools the agent may execute using the View Security for Agent Skill
report. The agent interaction security groups do not have to be a 1:1 match with the security groups on API policies. In order for the tool execution to succeed, a user must be a member of a security group that’s both on the agent skill and on the API security policies.Ambient execution mode skills don't require interaction access because they take action without human user interaction and operate on a schedule or set initiation.
Agent System User (ASU) accounts enable you to secure and manage your agents in Workday. Workday automatically generates an ASU for your agent after you complete the
Configure Agent
task. You can view your ASU accounts for your agents using the All AI Agent Accounts
report (secured to the Workday Accounts domain in the System functional area). You can also view AI agent accounts using the All Workday Accounts
task. Agent developers can leverage ASUs to interact with Workday data through Agent Gateway. See Agent Security
Reporting
The
Overview
section of the Agent Management Hub
provides access to these reports (secured to the Reports: Agent Reporting
domain):
Report | Considerations |
|---|---|
Active Agents
| Available for all agents. |
Total Agent Sessions Over Time
| Only available for Workday-built agents. |
Total Agent Sessions
| Only available for Workday-built agents. |
Total Unique Users
| Only available for Workday-built agents. |
In the
Analytics
tab of the Agent Registry
section of the Agent Management Hub
, you can click the name of an agent to view these agent analytics reports (secured to the Reports: Agent Reporting
domain and only available for Workday-built agents):
- Agent Sessions
- Skill Interactions
- Total Skill Interactions Over Time
- Total Unique Users for the Agent
- Total Unique Users for the Skills
The
Unregistered Workday Agents
section displays the Find Unregistered Workday Agents
report (secured to the Agent Management Hub
domain), where you can discover the Workday-built agents you’re eligible to register.You can access these reports for agent security, compliance, and auditing:
Report | Considerations |
|---|---|
Agent Input and Output Request Details
| Secured to the Agent Compliance domain and only available for Workday-built agents. |
All AI Agent Accounts
| Secured to the Workday Accounts domain. Enables you to view your ASU accounts for your agents. |
Generate Agent Input and Output Report
| Secured to the Agent Compliance domain and only available for Workday-built agents. Access this report to view all agent accounts in your tenant. On the report, you can click the Workday Account related actions to view audit trails. |
Input and Output Report For Registered Agents
| Secured to the Agent Compliance domain and only available for Workday-built agents. |
View AI Agent User Audit Trail
| Secured to the Reports: AI Agent Security domain. |
View Security for Agent Skill
| Secured to these domains:
Displays detailed information about the agent’s tools APIs and the respective domain or business process security policies and permissions. |
For additional agent reporting, you can use these data sources:
Data Source | Considerations |
|---|---|
All Agent Definitions
| Secured to the Reports: Agent Reporting domain. Provides fields for reporting on all registered and unregistered agent definitions. |
All Agent Registrations
| Secured to the Reports: Agent Reporting domain. Use in custom reports to analyze agent registrations. |
Agent Input and Output Details
| Secured to the Agent Compliance domain. Use to view your agent input and output interactions for the past 30 days. |
You can also leverage these data sources (secured to the
Reports: Agent Reporting
domain) that provide usage analytics data for the past 30 days:
- Agent Sessions by Day
- Agent Sessions by Day
- Agent Skill Interactions by Day
- Agent Unique Users by Skills