Example: Troubleshoot Security Policy and Access Configuration with the Ask Skill
This example illustrates how a security administrator and tenant configuration specialist uses a CRAFT prompt to get assistance from the Deployment Agent Ask skill to diagnose and resolve role-based access issues for specific data fields within a Workday tenant.
You are a Workday security administrator and tenant configuration specialist. You want to use the Ask skill to troubleshoot why payroll specialists are unable to view specific custom compensation components in your Sandbox tenant. You need tenant-grounded security configuration troubleshooting so that you can:
- Enhance security audit accuracy: Instantly audit domain security policies without manually reviewing dozens of security group permissions.
- Ensure tenant configuration compliance: Verify role-based permissions align with organizational data governance guidelines across testing environments.
- Prevent implementation delays: Swiftly diagnose and resolve data access blockers during end-to-end security and role testing.
- Streamline security administration: Reduce manual effort spent tracing security across complex organizational hierarchies.
- Audit domain permissions: Quickly identify missing view or modify permissions for custom report fields and worker data.
- Have access to the Implementation, Sandbox, Preview or Customer Central tenant with the Deployment Agent task available in global search. See:
- Have the specific error message, code, or security policy ready to query.
- Sign in to the Implementation, Preview, Sandbox or Customer Central tenant.
- EnterDeployment Agentin global search and select theDeployment Agenttask to access the ASOR-enabled Deployment Agent that is tenant-aware (if the Tenant Inspection skill is enabled).
- Use the CRAFT method to provide a clear prompt that defines your role and the context of your request, including the conditional logic you need.Your prompt:I am a Workday security administrator. In my tenant, users assigned to the Payroll Specialist role cannot view the 'Bonus Plan Override' field on worker profiles. Please look in my tenant and inspect our security configuration to explain which domain security policy controls access to this field, which security groups currently have View access, and how to update the policy.
- Review the logic.The agent leverages the Ask skill to inspect tenant-grounded configuration parameters and provides targeted security troubleshooting recommendations:
- Identified domain security policy:Worker Data: Compensation Explicit.
- Current security configuration: The Payroll Specialist (Role-Based) security group is currently missing from theViewaccess permissions list for this domain policy.
- Recommended action: Access theEdit Domain Security Policy Permitstask, add the payroll specialist toViewaccess, and activate pending security policy changes.
- (Optional) If you are in Customer Central using theDeployment Agenttask, you can ask how this change could impact another of your implementation tenants if applied there.Example prompt:How would activating this security policy change impact downstream security group assignments in our impl2 tenant?
- Compare the suggested logic against the management level hierarchy of your tenant to verify it captures all levels correctly.
The Deployment Agent identifies the relevant domain security policy and required permissions, which prevents you from having to manually audit role assignments across multiple security screens.
Once the Deployment Agent provides the troubleshooting steps, perform the recommended security updates in the implementation environment to grant the necessary access.
After applying the changes, use the
Thumbs Up
or Thumbs Down
icon to rate the accuracy of the guidance provided.