FAQ: Agent Security
- Where are OAuth tokens and token validity stored?
- Workday stores OAuth tokens and token validity settings in the Workday Object Management System (OMS).
- How does Workday mitigate risk if OAuth or session tokens are compromised?
- Workday provides preventive controls to help protect against replay attacks from OAuth clients. If session or access tokens are compromised, an attacker could replay requests within the token's lifetime.Workday can't detect compromised credentials on your behalf. If you suspect compromise, disable the affected OAuth 2.0 client to protect against further use of those credentials. You enforce this control on the customer side.
- Can I customize access token expiry for agents?
- For first-party (1P) agents, you can customize how long access tokens remain valid when you configure OAuth Client and OAuth Client for Integrations settings.For third-party (3P) agents, access token expiry customization isn't available yet. Workday will add this capability in a future release.For more on how token-related activity is recorded, see Concept: User Activity Logging.
- Are access token and refresh token expiry configurable?
- Yes. For integration clients, access token and refresh token settings, including expiry, are fully configurable today. For third-party (3P) agents, access token expiry customization is coming in a future release.
- How are Agent System Users (ASUs) managed and stored? Do they use the same Workday accounts as Integration System Users (ISUs)?
- Workday stores and manages ASUs in the Workday Object Management System (OMS).Similar to an Integration System User (ISU), each agent uses Agent System User (ASU) accounts. Each agent has a unique identity, or user account, so you have unambiguous control over what the agent can access and clear transparency for auditing.
- Unique identity: Each agent has a unique ASU account.
- Mode-specific accounts: An agent can have up to 2 ASUs—1 for delegate execution and 1 for ambient execution. Each ASU has a dedicated OAuth 2.0 client.
- Management: When you configure skills in the Agent System of Record (ASOR), Workday automatically generates and manages the required ASUs. For example, activating an ambient skill triggers creation of the necessary ambient ASU.
- What are the key differences between ASUs and Integration System Users (ISUs)?
- ASUs and ISUs both provide dedicated system user accounts in Workday. ASUs are tied to the tools and skills that you configure, manage, and audit in ASOR. ISUs support integration use cases and aren't scoped to agent skills in ASOR.For more information, see Concept: Agent Security.
- How are agent skills populated, controlled, and configured by Workday and/or the customer?
- You configure agent skills in ASOR under your organization's security administrator.Workday and your organization enable skills based on your agent design and security requirements. Map high-risk or sensitive transactions in your tenant to the skills that Workday and your organization have enabled.You can monitor and audit AI agent transactions and activity using theView AI Agent Users Audit Trailreport.