Skip to main content
Administrator Guide
Last Updated: 2026-08-07
About Workday Agents

About Workday Agents

Workday AI agents are autonomous, conversational assistants that can answer questions and perform multistep actions to enable you to complete complex tasks and workflows. These agents use large language models (LLMs) that analyze data and learn patterns in order to produce predictions, recommendations, decisions, or generated content that influence or automate parts of a workflow.
Workday supports use of these types of agents:
  • First-party agents, which are Workday-built agents
  • Second-party agents, which are partner-built agents
  • Third-party agents, which are self-built agents
Every agent uses skills, which are the tasks or activities the agent can execute. Each skill consists of:
  • Tools, which are the resources the agent may use when executing the skill. For agents that interact with Workday, tools are Workday APIs.
  • Resources, which are the type of API that a tool uses. Examples: REST, SOAP, Graph, WQL.
  • One of these execution modes. You can't change a skill's execution mode
    • Ambient mode: The agent performs tasks as itself and has its own security permissions.
    • Delegate mode: The agent performs tasks on behalf of a human and uses the worker’s permissions.
You can’t delegate Workday agent interactions or use a proxy

Workday Agent System of Record (ASOR)

ASOR is a centralized framework for Workday agents that enables you to:
  • Find, add, register, configure, monitor, and manage your AI agents.
  • Leverage a single control center for governance, security, and auditing your agents, reducing administrative overhead.
  • View data insights, including usage and performance, to analyze and demonstrate the value and impact of your agents.
  • Provides the ability for agents to interact across systems.
You don’t need to purchase additional specific SKUs to use ASOR. Some agents, including those for HiredScore and Evisort, are not part of ASOR and can't be accessed through the
Agent Management Hub
.
ASOR creates and securely stores the private key client credentials, but you must ensure your security environment supports OAuth 2.0.
You can use these domains to manage your agents:
Domains
Considerations
Agent Compliance
Provides access to reports and data required for agent compliance.
Agent Management Hub
Provides access to the
Agent Management Hub
, which is the centralized hub for viewing and managing all agents.
Manage: Agents
Provides access to tasks for managing agents including configuration, activation, and deactivation in ASOR.
Reports: Agent Reporting
Provides access to view agent analytics and report data sources and filters for agent level reporting.
Reports: AI Agent Security
Provides access to reports about agent security information.
Setup: Agents
Provides access to setup tasks and activities for agents in ASOR.

Agent Management Hub

You can use the
Agent Management Hub
to manage your Workday-built, partner-built, and self-built agents through these phases:
  • Define an agent on its agent profile page in the
    Agent Management Hub
    . For external agents, you provide a definition for your agent through an API.
  • Register an agent in the
    Agent Management Hub
    to prepare it for configuration and activation. In order to register Workday-built agents in Production, you must opt in to the:
  • Configure your agent to specify which skills it uses and who can access it.
  • Activate your agent to enable users to interact with it based on the security permissions you configured.
  • Deactivate your agent when you no longer need it. This hides the agent from users but keeps it accessible in
    Agent Management Hub
    so you can reactivate it in the future as needed.
The
Agent Registry
section displays your registered agents, along with their status and when an administrator user in Workday last made updates to their configuration. You can click the name of an agent to view the agent’s profile, the available skills for the agent, and agent analytics reports.
We recommend that you regularly examine the audit log for agent actions. Workday doesn’t delete usage activities from previous weeks during the Sandbox refresh.

Agent Security

As you configure your agents, you can specify who has access to interact with the agent by providing security groups for each delegate execution mode skill. Example: You can specify Employee as Self to make a skill available to an employee who interacts with the agent. As long as a user is part of one of the security groups on one of the skills, they have access to interact with the agent.
Agent interaction security permissions are separate from tool execution permissions. Consider evaluating alignment between the security groups in the
Available To
prompt and the security groups that have permissions for the tools the agent may execute using the
View Security for Agent Skill
report. The agent interaction security groups do not have to be a 1:1 match with the security groups on API policies. In order for the tool execution to succeed, a user must be a member of a security group that’s both on the agent skill and on the API security policies.
Ambient execution mode skills don't require interaction access because they take action without human user interaction and operate on a schedule or set initiation.
Agent System User (ASU) accounts enable you to secure and manage your agents in Workday. Workday automatically generates an ASU for your agent after you complete the
Configure Agent
task. You can view your ASU accounts for your agents using the
All AI Agent Accounts
report (secured to the Workday Accounts domain in the System functional area). You can also view AI agent accounts using the
All Workday Accounts
task.
Agent developers can leverage ASUs to interact with Workday data through Agent Gateway. See Agent Security

Reporting

The
Overview
section of the
Agent Management Hub
provides access to these reports (secured to the
Reports: Agent Reporting
domain):
Report
Considerations
Active Agents
Available for all agents.
Total Agent Sessions Over Time
Only available for Workday-built agents.
Total Agent Sessions
Only available for Workday-built agents.
Total Unique Users
Only available for Workday-built agents.
In the
Analytics
tab of the
Agent Registry
section of the
Agent Management Hub
, you can click the name of an agent to view these agent analytics reports (secured to the
Reports: Agent Reporting
domain and only available for Workday-built agents):
  • Agent Sessions
  • Skill Interactions
  • Total Skill Interactions Over Time
  • Total Unique Users for the Agent
  • Total Unique Users for the Skills
The
Unregistered Workday Agents
section displays the
Find Unregistered Workday Agents
report (secured to the
Agent Management Hub
domain), where you can discover the Workday-built agents you’re eligible to register.
You can access these reports for agent security, compliance, and auditing:
Report
Considerations
Agent Input and Output Request Details
Secured to the
Agent Compliance
domain and only available for Workday-built agents.
All AI Agent Accounts
Secured to the
Workday Accounts
domain. Enables you to view your ASU accounts for your agents.
Generate Agent Input and Output Report
Secured to the
Agent Compliance
domain and only available for Workday-built agents. Access this report to view all agent accounts in your tenant. On the report, you can click the
Workday Account
related actions to view audit trails.
Input and Output Report For Registered Agents
Secured to the
Agent Compliance
domain and only available for Workday-built agents.
View AI Agent User Audit Trail
Secured to the
Reports: AI Agent Security
domain.
View Security for Agent Skill
Secured to these domains:
  • Security Administration
  • Manage: Agents
Displays detailed information about the agent’s tools APIs and the respective domain or business process security policies and permissions.
For additional agent reporting, you can use these data sources:
Data Source
Considerations
All Agent Definitions
Secured to the
Reports: Agent Reporting
domain. Provides fields for reporting on all registered and unregistered agent definitions.
All Agent Registrations
Secured to the
Reports: Agent Reporting
domain. Use in custom reports to analyze agent registrations.
Agent Input and Output Details
Secured to the
Agent Compliance
domain. Use to view your agent input and output interactions for the past 30 days.
You can also leverage these data sources (secured to the
Reports: Agent Reporting
domain) that provide usage analytics data for the past 30 days:
  • Agent Sessions by Day
  • Agent Sessions by Day
  • Agent Skill Interactions by Day
  • Agent Unique Users by Skills