Set Up Deployment Agent in Implementation Environments and Customer Central
You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
- Select your profile avatar on Workday Community.
- SelectProfile.
- On your profile page, select your organization's name, which is beneath your name and next to your job title.
- View yourSubscription Service Agreementvalue.
If the value is:
- UMSA, the feature is automatically available. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
- MSA, your organization must opt in to UMSA.
- Implementation, Sandbox, and Preview Tenants
- Security:Reports: AI Agent Securitydomain in the System functional area.
- Customer Central Tenant
- Enable OAuth clients by selecting theOAuth Client 2.0 Enabledcheck box in theEdit Tenant Setup - Securitytask.
- (Optional) To provide auditing access to to users:Security:Reports: AI Agent Securitydomain in the System functional area.
You configure the Deployment Agent separately in each Implementation, Preview, Sandbox, and Customer Central tenant. Workday doesn't enable the agent in all tenants when you set it up in 1. You must configure security for the
Deployment Agent
task and activate the agent in the Agent System of Record (ASOR). To avoid manually reconfiguring the agent in your Sandbox tenants after each tenant refresh, we recommend also setting it up in your Production tenant. Though the Deployment Agent isn't accessible for use in Production environments, you ensure it persists and propagates to your Sandbox tenants during standard refresh cycles when you establish the configuration in Production. Workday permanently deletes all Deployment Agent chat history data when you refresh the Sandbox tenant.
- Sign in to the tenant you want to configure.
- For Implementation or Preview tenants: Sign in directly to the specific tenant.
- For Sandbox tenants: Sign in to your Production tenant to ensure the configuration persists across future tenant refreshes.If you need to use the agent in your Sandbox before the next refresh, complete this setup in Production and repeat it in your Sandbox tenant to cover the gap.
- Create the domain security policy for the Deployment Agent.If a policy already exists, skip this step. To verify if a policy exists:
- Access theCreate Security Policy for Domaintask.
- Select theFor Domainprompt and enter:Deployment Agent.
- If it doesn’t display, the policy exists. Skip this step.
- If it does display, select it and clickOKto create the policy.
- Edit the security policy and assign security groups.
- Search forView Domainand enter the domain name: Deployment Agent Users.
- From the related actions menu of the domain, select .
- In theReport/Task Permissionsgrid, add a new row.
- In the new row, select the security groups to which you want to grant access. Example: Implementers.
- SelectViewpermissions.
- ClickOK.The Agent System of Record requires these security groups when you configure the Deployment Agent in theAgent Management Hub.
- (Optional) Assign users to security groups.If you haven't already done so, assign users to security policies by adding them to security groups included in the policy.
- To assign multiple users to a single user-based security group: Access theAssign Users to User-Based Security Grouptask.
- To assign a single user to 1 or more user-based security groups: Access theAssign User-Based Security Groups for Persontask.
You can combine multiple user-based security groups into an aggregation security group. - Activate security policy changes.
- Access theActivate Pending Security Policy Changestask
- Enter a comment describing your changes.
- Review the pending changes and select theConfirmcheck box.
- ClickOKto activate the changes.
- Register the Deployment Agent.You must register the Deployment Agent in the tenant before you can configure it.
- Access theAgent Management Hubreport.
- Select theUnregistered Workday Agenttab.
- For the Deployment Agent, clickRegister.
- Select theConfirmcheck box, and then clickOKto complete the registration.Workday moves the Deployment Agent to theAgent Registrytab.
- Configure the Deployment Agent.After you register the Deployment Agent, configure its skills in the tenant.
- On theAgent Registrytab, clickDeployment Agent.
- From the profile view of the agent, clickConfigure Agent.
- In theStatuscolumn, use the toggle slide to enable the skills you want.Example: To enable the Deployment Agent Ask skill, enable both the Tenant Inspection and Implementation Knowledge skills. For specific steps, see Enable Deployment Agent Ask Skill.
- For each enabled skill, populate theAvailable Toprompt with the security groups that you want to provide access to for that specific skill.The security groups added to theAvailable Toprompt for an agent establish the interaction policy of the agent.Ensure the security groups you add also belong to theDeployment Agent Usersdomain security policy. Workday displays an error validation when the security group you add here isn’t also part of this policy. Users in the security group won't have access to the Deployment Agent in the tenant.
- Activate the Deployment Agent.When you complete agent configuration, you can activate the Deployment Agent in the tenant.
- ClickActivate.
- If prompted, confirm activation.
You can now access the Deployment Agent and view chat histories in the configured tenant. Workday isolates chat histories by tenant. Example: You can’t view data from a Sandbox tenant within a Preview tenant.
Workday retains chat histories for 14 days before permanently deleting them.
You can activate or deactivate the Deployment Agent at any time in the
Agent Management Hub
. If you configured the agent in your Production tenant for Sandbox refreshes, you must deactivate it in Production; otherwise, the agent automatically reactivates in the Sandbox during the next refresh.