Skip to main content
Administrator Guide
Last Updated: 2026-09-18
Set Up Deployment Agent in Implementation Environments and Customer Central

Set Up Deployment Agent in Implementation Environments and Customer Central

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
Implementation, Sandbox, and Preview Tenants
Customer Central Tenant
You configure the Deployment Agent separately in each Implementation, Preview, Sandbox, and Customer Central tenant. Workday doesn't enable the agent in all tenants when you set it up in 1. You must configure security for the
Deployment Agent
task and activate the agent in the Agent System of Record (ASOR).
To avoid manually reconfiguring the agent in your Sandbox tenants after each tenant refresh, we recommend also setting it up in your Production tenant. Though the Deployment Agent isn't accessible for use in Production environments, you ensure it persists and propagates to your Sandbox tenants during standard refresh cycles when you establish the configuration in Production. Workday permanently deletes all Deployment Agent chat history data when you refresh the Sandbox tenant.
  1. Sign in to the tenant you want to configure.
    • For Implementation or Preview tenants: Sign in directly to the specific tenant.
    • For Sandbox tenants: Sign in to your Production tenant to ensure the configuration persists across future tenant refreshes.
      If you need to use the agent in your Sandbox before the next refresh, complete this setup in Production and repeat it in your Sandbox tenant to cover the gap.
  2. Create the domain security policy for the Deployment Agent.
    If a policy already exists, skip this step. To verify if a policy exists:
    1. Access the
      Create Security Policy for Domain
      task.
    2. Select the
      For Domain
      prompt and enter:
      Deployment Agent
      .
      • If it doesn’t display, the policy exists. Skip this step.
      • If it does display, select it and click
        OK
        to create the policy.
  3. Edit the security policy and assign security groups.
    1. Search for
      View Domain
      and enter the domain name: Deployment Agent Users.
    2. From the related actions menu of the domain, select
      Domain
      Edit Security Policy Permissions
      .
    3. In the
      Report/Task Permissions
      grid, add a new row.
    4. In the new row, select the security groups to which you want to grant access. Example: Implementers.
    5. Select
      View
      permissions.
    6. Click
      OK
      .
      The Agent System of Record requires these security groups when you configure the Deployment Agent in the
      Agent Management Hub
      .
  4. (Optional) Assign users to security groups.
    If you haven't already done so, assign users to security policies by adding them to security groups included in the policy.
    • To assign multiple users to a single user-based security group: Access the
      Assign Users to User-Based Security Group
      task.
    • To assign a single user to 1 or more user-based security groups: Access the
      Assign User-Based Security Groups for Person
      task.
    You can combine multiple user-based security groups into an aggregation security group.
  5. Activate security policy changes.
    1. Access the
      Activate Pending Security Policy Changes
      task
    2. Enter a comment describing your changes.
    3. Review the pending changes and select the
      Confirm
      check box.
    4. Click
      OK
      to activate the changes.
  6. Register the Deployment Agent.
    You must register the Deployment Agent in the tenant before you can configure it.
    1. Access the
      Agent Management Hub
      report.
    2. Select the
      Unregistered Workday Agent
      tab.
    3. For the Deployment Agent, click
      Register
      .
    4. Select the
      Confirm
      check box, and then click
      OK
      to complete the registration.
      Workday moves the Deployment Agent to the
      Agent Registry
      tab.
  7. Configure the Deployment Agent.
    After you register the Deployment Agent, configure its skills in the tenant.
    1. On the
      Agent Registry
      tab, click
      Deployment Agent
      .
    2. From the profile view of the agent, click
      Configure Agent
      .
    3. In the
      Status
      column, use the toggle slide to enable the skills you want.
      Example: To enable the Deployment Agent Ask skill, enable both the Tenant Inspection and Implementation Knowledge skills. For specific steps, see Enable Deployment Agent Ask Skill.
    4. For each enabled skill, populate the
      Available To
      prompt with the security groups that you want to provide access to for that specific skill.
      The security groups added to the
      Available To
      prompt for an agent establish the interaction policy of the agent.
      Ensure the security groups you add also belong to the
      Deployment Agent Users
      domain security policy. Workday displays an error validation when the security group you add here isn’t also part of this policy. Users in the security group won't have access to the Deployment Agent in the tenant.
  8. Activate the Deployment Agent.
    When you complete agent configuration, you can activate the Deployment Agent in the tenant.
    1. Click
      Activate
      .
    2. If prompted, confirm activation.
You can now access the Deployment Agent and view chat histories in the configured tenant. Workday isolates chat histories by tenant. Example: You can’t view data from a Sandbox tenant within a Preview tenant.
Workday retains chat histories for 14 days before permanently deleting them.
You can activate or deactivate the Deployment Agent at any time in the
Agent Management Hub
. If you configured the agent in your Production tenant for Sandbox refreshes, you must deactivate it in Production; otherwise, the agent automatically reactivates in the Sandbox during the next refresh.