Skip to main content
Administrator Guide
Last Updated: 2026-06-12
Set Up Deployment Agent in Implementation Environments

Set Up Deployment Agent in Implementation Environments

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
To use the Deployment Agent, you must configure it separately for each tenant (Implementation, Preview, or Sandbox). Setting up the agent in one tenant does not enable it in others. The primary setup steps require you to:
  • Configure security for the
    Deployment Agent
    task.
  • Activate the Deployment Agent in the Agent System of Record (ASOR).
Workday makes the domain for the Deployment Agent available when ASOR functionality is activated in the tenant. After you register and configure the agent, you can activate it in the
Agent Management Hub
.
To avoid manually reconfiguring the agent in your Sandbox tenants after each tenant refresh, we recommend also setting it up in your Production tenant. While the Deployment Agent is not accessible for use in Production environments, establishing the configuration there ensures it persists and propagates to your Sandbox tenants during standard refresh cycles. However, while your configuration persists, your chat history does not. A Sandbox tenant refresh permanently deletes all Deployment Agent chat history data.
  1. Sign in to the tenant you want to configure.
    • For Implementation or Preview tenants: Sign in directly to the specific tenant.
    • For Sandbox tenants: Sign in to your Production tenant to ensure the configuration persists across future tenant refreshes.
      If you need to use the agent in your Sandbox before the next refresh, complete this setup in Production and then also repeat it in your Sandbox tenant to cover the gap.
  2. Create the domain security policy for the Deployment Agent.
    If a policy already exists, skip this step. To verify if a policy exists:
    1. Access the
      Create Security Policy for Domain
      task.
    2. Select the
      For Domain
      prompt and enter:
      Deployment Agent
      .
      • If it doesn’t display, the policy exists. Skip this step.
      • If it does display, select it and click
        OK
        to create the policy.
  3. Edit the security policy and assign security groups.
    1. Search for
      View Domain
      and enter the domain name: Deployment Agent Users.
    2. From the related actions menu of the domain, select
      Domain
      Edit Security Policy Permissions
      .
    3. In the
      Report/Task Permissions
      or
      Integration Permissions
      grid, add a new row.
    4. In the new row, select the security groups to which you want to grant access. Example: Implementers.
    5. Select View permissions.
    6. Click
      OK
      .
      The ASOR agent requires these security groups when you configure the Deployment Agent in the Agent Management hub.
  4. (Optional) Assign users to security groups.
    If you haven't already done so, assign users to security policies by adding them to security groups included in the policy.
    • To assign multiple users to a single user-based security group: Access the
      Assign Users to User-Based Security Group
      task.
    • To assign a single user to 1 or more user-based security groups: Access the
      Assign User-Based Security Groups for Person
      task.
    You can combine multiple user-based security groups into an aggregation security group.
  5. Activate security policy changes.
    1. Access the
      Activate Pending Security Policy Changes
      task
    2. Enter a comment describing your changes.
    3. Review the pending changes and select the
      Confirm
      check box.
    4. Click
      OK
      to activate the changes.
  6. Register the Deployment Agent.
    You must register the Deployment Agent in the tenant before you can configure it.
    1. Access the
      Agent Management Hub
      report.
    2. Select the
      Unregistered Workday Agent
      tab.
    3. For the Deployment Agent, click
      Register
      .
    4. Select the
      Confirm
      check box, and then click
      OK
      to complete the registration.
      Workday moves the Deployment Agent to the
      Agent Registry
      tab.
  7. Configure the Deployment Agent.
    After you register the Deployment Agent, configure it in the tenant.
    1. On the
      Agent Registry
      tab, click the
      Deployment Agent
      name to configure it.
    2. From the profile view of the agent, click
      Configure Agent
      .
    3. In the
      Status
      column, use the toggle slide to enable the
      Configuration Intelligence Q&A
      skill.
    4. If available, enable any other relevant skills you want.
    5. For each enabled skill, populate the
      Available To
      prompt with the security groups that you want to provide access to for that specific skill.
      The security groups added to the
      Available To
      prompt for an agent establish the interaction policy of the agent.
      Ensure the security group you add also belongs to the
      Deployment Agent Users
      domain security policy. Workday displays an error validation when the security group you add here isn’t also part of the
      Deployment Agent Users
      security domain policy. Users in the security group won't have access to the Deployment agent in the tenant.
  8. Activate the Deployment Agent.
    When you complete agent configuration, you can activate the Deployment Agent in the tenant.
    1. Click
      Activate
      .
    2. If prompted, confirm activation.
    Once activated, the Deployment Agent becomes available for use by the members of the security groups you assigned to its skills. You can deactivate and reactivate agents at any time from the
    Agent Management Hub
    .
You can now access the Deployment Agent and view chat histories in your configured tenant. Each tenant isolates its own chat histories. You can't view a chat history from one tenant (such as Sandbox) in another tenant (such as Preview).
A Sandbox tenant refresh permanently deletes all Deployment Agent chat history data. While your agent configuration persists if you set it up in Production, you can't recover chat history data after a refresh.