Set Up AI Administrator Security Permissions
You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
- Select your profile avatar on Workday Community.
- SelectProfile.
- On your profile page, select your organization's name, which is beneath your name and next to your job title.
- View yourSubscription Service Agreementvalue.
If the value is:
- UMSA, the feature is automatically available. Keep data contributions enabled to ensure full agent functionality. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
- MSA, your organization must opt in to UMSA and enable this feature through Innovation Services.
UMSA is required for non-production and production tenants for Workday-Built agents. UMSA is not required for non-production tenants for self-built agents.
For information about how using agents impacts your Flex Credits, see: Workday Flex Credits Community page.
To use Sana Core and Sana Enterprise, you must:
- Purchase the Sana Enterprise product. This only applies to Sana Enterprise.
- Purchase the Core Human Capital Management or Core Financials product. This only applies to Sana Core.
- Sign the UMSA.When you sign the agreement, Workday provides your organization with complimentary Flex Credits that you can use towards Sana Core for Workday. Once you reach the allotted complimentary Flex Credit consumption, you must sign the Workday Flex Credits and Platform Entitlement Policy to continue to use Sana Core for Workday.
- Sign the Workday Flex Credits and Platform Entitlement Policy. This only applies to Sana Enterprise.
Security: These domains in the System functional area:
- Security Activation
- Security Configuration
You can bundle all the necessary security configuration steps on the
Set Up AI Admin Security Permissions
task, which enables you to initiate back-end processing for your organization to use Workday AI features.You can set up AI admin security permissions once for each tenant. The task enables you to grant security access for:
- Agent System of Record: Assign users access to manage and configure AI agent behavior and integrations in a central location.
- User Provisioning Workspace for Sana: Assign administrators to provision users to Sana.
- Platform Consumption Console: Assign users access to monitor and manage infrastructure resources that your agents use.
- Sana: Assign users as Sana administrators to configure Sana features in the Sana Workspace. Users with Sana administrator privileges can access and configure the Sana Workspace.
Workday sends a notification to security administrators in all your tenants to access and complete the task.
The security configuration notification expires in 30 days.
You can configure sections of the
Set Up AI Admin Security Permissions
task separately, but Workday recommends using the task to ensure you meet all critical dependencies for your AI experience.Security administrators must complete all sections. Once you submit the task, you can’t edit it. You can manually update the configuration through the standard Workday security settings.
When multiple administrators are configuring this task, Workday processes the first configuration submitted.
- Access theAction Required: Review and Configure the Security for Sana and Workday Agentsnotification in Workday.If administrators never received this notification or it expired and was removed after 30 days, you can access theNotify Users to Configure Sana Agent Securitytask to resend the security configuration notification. The user must have Modify permissions on theSecurity Configurationdomain to receive the notification. TheNotify Users to Configure Sana Agent Securitytask is only available in the tenant when you sign the UMSA. We don’t resend the notification if an administrator has already completed theSet Up AI Admin Security Permissionstask.
- ClickStart Configuration.
- Complete theConfigure Security Policiessection on theConfigurationtab:You only need to configure grids with anIncompletestatus. We display a:
- Completedstatus when domain security policies are configured. We don't display theSecurity GroupandView or Add Users to Security Groupcolumns in the grid.
- Completed with Exceptionsstatus when at least 1 of the domain security policies in theDomain Security Policiescolumn isn't currently active or has pending changes.
Option Description Domain Security PoliciesDisplays all the domain security policies you need configure for each workspace.Security GroupSelect an existing user-based security group or create a new one. Workday adds users in those groups to the domain security policies listed in theDomain Security Policiescolumn with View and Modify permissions.For the Platform Consumption Console, we only require a security group with View permission on theManagement Dashboard: Platform Consumption Consoledomain security policy. You can only add a security group to theManagement Dashboard: Platform Consumption Consoledomain using this task if there are no existing security groups with View or View and Modify permissions configured on the domain security policy. Workday displays aCompletedstatus on thePlatform Consumption Consolegrid when these security configuration criteria are met.View or Add Users to Security GroupWorkday automatically displays the members of the security groups you selected in theSecurity Groupcolumn.You can add members only when you create a new security group or select a group that's not used in other policies and doesn't have members. You can't add or remove members when you select a security group that's currently used in other policies or has existing members.When a domain is disabled and you access theSet Up AI Admin Security Permissionstask:- You can add security groups to the domain. Once you submit the changes on the task, this activates the domain.
- We display aCompletedstatus if the domain has existing security groups.
- Complete theActivate Pending Security Policy Changestab.Review the security changes on theConfigurationtab before activating the changes. To activate security policy changes in your tenant, you must have permission on theSecurity Activationdomain.Select theConfirmcheck box and clickOK.
- ClickDone.
Workday automatically activates pending security policy changes and makes applicable tasks available. Workday might notify members of included security groups of additional tasks and actions they can take.
If assigning Sana administrator access to members in the security groups fails, we display a
Resubmit
button in the Set Up Sana Administration
section of the Configuration
tab. You can retry the provisioning by clicking the button. Workday attempts to assign the users with Sana administrator privileges.(Optional) If you need to update the configuration on this task, access the standard Workday security settings to manually make the changes.