Set Up Deployment Agent in Implementation Environments
You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
- Select your profile avatar on Workday Community.
- SelectProfile.
- On your profile page, select your organization's name, which is beneath your name and next to your job title.
- View yourSubscription Service Agreementvalue.
If the value is:
- UMSA, the feature is automatically available. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
- MSA, your organization must opt in to UMSA.
- Security:Reports: AI Agent Securitydomain in the System functional area.
To use the Deployment Agent, you must configure it separately for each tenant (Implementation, Preview, or Sandbox). Setting up the agent in one tenant does not enable it in others. The primary setup steps require you to:
- Configure security for theDeployment Agenttask.
- Activate the Deployment Agent in the Agent System of Record (ASOR).
Workday makes the domain for the Deployment Agent available when ASOR functionality is activated in the tenant. After you register and configure the agent, you can activate it in the
Agent Management Hub
. To avoid manually reconfiguring the agent in your Sandbox tenants after each tenant refresh, we recommend also setting it up in your Production tenant. While the Deployment Agent is not accessible for use in Production environments, establishing the configuration there ensures it persists and propagates to your Sandbox tenants during standard refresh cycles. However, while your configuration persists, your chat history does not. A Sandbox tenant refresh permanently deletes all Deployment Agent chat history data.
- Sign in to the tenant you want to configure.
- For Implementation or Preview tenants: Sign in directly to the specific tenant.
- For Sandbox tenants: Sign in to your Production tenant to ensure the configuration persists across future tenant refreshes.If you need to use the agent in your Sandbox before the next refresh, complete this setup in Production and then also repeat it in your Sandbox tenant to cover the gap.
- Create the domain security policy for the Deployment Agent.If a policy already exists, skip this step. To verify if a policy exists:
- Access theCreate Security Policy for Domaintask.
- Select theFor Domainprompt and enter:Deployment Agent.
- If it doesn’t display, the policy exists. Skip this step.
- If it does display, select it and clickOKto create the policy.
- Edit the security policy and assign security groups.
- Search forView Domainand enter the domain name: Deployment Agent Users.
- From the related actions menu of the domain, select .
- In theReport/Task PermissionsorIntegration Permissionsgrid, add a new row.
- In the new row, select the security groups to which you want to grant access. Example: Implementers.
- Select View permissions.
- ClickOK.The ASOR agent requires these security groups when you configure the Deployment Agent in the Agent Management hub.
- (Optional) Assign users to security groups.If you haven't already done so, assign users to security policies by adding them to security groups included in the policy.
- To assign multiple users to a single user-based security group: Access theAssign Users to User-Based Security Grouptask.
- To assign a single user to 1 or more user-based security groups: Access theAssign User-Based Security Groups for Persontask.
You can combine multiple user-based security groups into an aggregation security group. - Activate security policy changes.
- Access theActivate Pending Security Policy Changestask
- Enter a comment describing your changes.
- Review the pending changes and select theConfirmcheck box.
- ClickOKto activate the changes.
- Register the Deployment Agent.You must register the Deployment Agent in the tenant before you can configure it.
- Access theAgent Management Hubreport.
- Select theUnregistered Workday Agenttab.
- For the Deployment Agent, clickRegister.
- Select theConfirmcheck box, and then clickOKto complete the registration.Workday moves the Deployment Agent to theAgent Registrytab.
- Configure the Deployment Agent.After you register the Deployment Agent, configure it in the tenant.
- On theAgent Registrytab, click theDeployment Agentname to configure it.
- From the profile view of the agent, clickConfigure Agent.
- In theStatuscolumn, use the toggle slide to enable theConfiguration Intelligence Q&Askill.
- If available, enable any other relevant skills you want.
- For each enabled skill, populate theAvailable Toprompt with the security groups that you want to provide access to for that specific skill.The security groups added to theAvailable Toprompt for an agent establish the interaction policy of the agent.Ensure the security group you add also belongs to theDeployment Agent Usersdomain security policy. Workday displays an error validation when the security group you add here isn’t also part of theDeployment Agent Userssecurity domain policy. Users in the security group won't have access to the Deployment agent in the tenant.
- Activate the Deployment Agent.When you complete agent configuration, you can activate the Deployment Agent in the tenant.
- ClickActivate.
- If prompted, confirm activation.
Once activated, the Deployment Agent becomes available for use by the members of the security groups you assigned to its skills. You can deactivate and reactivate agents at any time from theAgent Management Hub.
You can now access the Deployment Agent and view chat histories in your configured tenant. Each tenant isolates its own chat histories. You can't view a chat history from one tenant (such as Sandbox) in another tenant (such as Preview).
A Sandbox tenant refresh permanently deletes all Deployment Agent chat history data. While your agent configuration persists if you set it up in Production, you can't recover chat history data after a refresh.