Skip to main content
Administrator Guide
Last Updated: 2026-07-24
Set Up AI Administrator Security Permissions

Set Up AI Administrator Security Permissions

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
UMSA is required for non-production and production tenants for Workday-Built agents. UMSA is not required for non-production tenants for self-built agents.
For information about how using agents impacts your Flex Credits, see: Workday Flex Credits Community page.
To use Sana Core and Sana Enterprise, you must:
  • Purchase the Sana Enterprise SKU. This only applies to Sana Enterprise.
  • Purchase the Core Human Capital Management or Core Financials SKU. This only applies to Sana Core.
  • Sign the Universal Main Subscription Agreement (UMSA).
    When you sign the agreement, Workday provides your organization with complimentary Flex Credits that you can use towards Sana Core for Workday. Once you reach the allotted complimentary Flex Credit consumption, you must sign the Workday Flex Credits and Platform Entitlement Policy to continue to use Sana Core for Workday.
  • Sign the Workday Flex Credits and Platform Entitlement Policy. This only applies to Sana Enterprise.
Security: You have security permission on these domains in the System functional area:
  • Security Activation
  • Security Configuration
The
Set Up AI Admin Security Permissions
task bundles all the necessary security configuration steps into a single task which when complete, initiates backend processing to get your organization set up to use Workday AI features.
This is a one-time task for each tenant. The task simplifies granting security access for:
  • Agent System of Record: Assign users access to manage and configure AI agent behavior and integrations in a central location.
  • User Provisioning Workspace for Sana: Assign administrators to provision users to Sana.
  • Platform Consumption Console: Assign users access to monitor and manage infrastructure resources that your agents use.
  • Sana: Assign users as Sana administrators to configure Sana features in the Sana Workspace.
Workday sends a notification to security administrators in all your tenants (Production, Sandbox, Sandbox Preview, Implementation, and Implementation Preview) to access and complete the
Set Up AI Admin Security Permissions
task.
The security configuration notification expires in 30 days.
While you can configure areas of the
Set Up AI Admin Security Permissions
task separately, Workday recommends using the task to ensure all critical dependencies for your AI experience are met.
Security administrators must complete all sections. Once you submit the task, you can’t edit it. You can manually update the configuration through the standard Workday security settings.
If multiple administrators are configuring this task, Workday processes the first configuration that's submitted.
  1. Access the
    Action Required: Review and Configure the Security for Sana and Workday Agents
    notification from the bell icon in Workday.
    If administrators never received this notification or it expired and was removed after 30 days, you can access the
    Notify Users to Configure Sana Agent Security
    task to resend the security configuration notification. The user must have
    Modify
    permissions on the
    Security Configuration
    domain to receive the notification. The
    Notify Users to Configure Sana Agent Security
    task is only available in the tenant when you sign the UMSA. We don’t resend the notification if an administrator has already completed the
    Set Up AI Admin Security Permissions
    task.
  2. In the notification, click
    Start Configuration
    .
  3. As you complete the
    Configure Security Policies
    section on the
    Configuration
    tab, consider:
    You only need to configure grids with an
    Incomplete
    status. We display a:
    • Completed
      status when domain security policies are configured. We hide the
      Security Group
      and
      View or Add Users to Security Group
      columns in the grid.
    • Completed with Exceptions
      status when at least 1 of the domain security policies in the
      Domain Security Policies
      column isn't currently active or it has pending changes.
    In the
    View or Add Users to Security Group
    column:
    • You can add members only when you create a new security group or select a group that's not used in other policies and doesn't have members.
    • You can't add or remove members in the column when you select a security group that's currently used in other policies or it has existing members.
    In the
    Details
    column, you can drill into each domain security policy configuration by clicking
    Details
    . When you click the link, we display a
    View Domain Details
    pop-up box where you can view the configuration.
    Option Description
    Agent System of Record
    This section enables you to configure access to the Agent System of Record workspace.
    The
    Domain Security Policies
    column displays all domain security policies you need to configure.
    In the
    Security Group
    column, select an existing user-based security group or create a new one.
    We display the members in the
    View or Add Users to Security Group
    column. Workday adds users in those groups to the domain security policies listed in the
    Domain Security Policies
    column with
    View
    and
    Modify
    permissions.
    Platform Consumption Console
    This section enables you to configure access to the Platform Consumption Console.
    The
    Domain Security Policies
    column displays all domain security policies you need to configure.
    In the
    Security Group
    column, select an existing user-based security group or create a new one.
    We only require a security group with
    View Only
    permission on the
    Management Dashboard: Platform Consumption Console
    domain security policy.
    You can only add a security group to the
    Management Dashboard: Platform Consumption Console
    domain using this task if there are no existing security groups with
    View Only
    or
    View
    and
    Modify
    permissions configured on the domain security policy.
    Workday displays a
    Completed
    status on the
    Platform Consumption Console
    grid when these security configuration criteria are met.
    We display the members in the
    View or Add Users to Security Group
    column. Workday adds users in those groups to the domain security policies listed in the
    Domain Security Policies
    column with
    View Only
    permission.
    User Provisioning Workspace
    This section enables you to configure access to the User Provisioning workspace for Sana.
    The
    Domain Security Policies
    column displays all domain security policies you need to configure.
    In the
    Security Group
    column, select an existing user-based security group or create a new one.
    We display the members in the
    View or Add Users to Security Group
    column. Workday adds users in those groups to the domain security policies listed in the
    Domain Security Policies
    column with
    View
    and
    Modify
    permissions.
    When a domain is disabled and you access the
    Set Up AI Admin Security Permissions
    task:
    • You can add security groups to the domain. Once you submit the changes on the task, this activates the domain.
    • We display a
      Completed
      status if the domain has existing security groups.
  4. As you complete the
    Set Up Sana Administrators
    section on the
    Configuration
    tab, consider:
    Option Description
    Set Up Sana Administrators
    This section enables you to define which users are Sana administrators. Workday automatically provisions these users into Sana upon activation.
    In the
    Security Group
    column, select an existing user-based security group or create a new one.
    Users with Sana administrator privileges can access and configure the Sana Workspace.
  5. Select the
    Activate Pending Security Policy Changes
    tab.
    To activate security policy changes in your tenant, you must have permission on the
    Security Activation
    domain.
  6. As you complete the
    Activate Pending Security Policy Changes
    tab, consider:
    Option Description
    Security Policy grids
    Review the security changes in the grids.
    Confirm check box
    Select the check box to submit all security policy changes.
    Workday activates all security policy changes in the grids including the security settings on the
    Configuration
    tab.
  7. Click
    OK
    and then click
    Done
    .
Workday automatically activates pending security policy changes and makes applicable tasks available. Workday might notify members of included security groups of additional tasks and actions they can take.
If assigning Sana administrator access to members in the security groups fails, we display a
Resubmit
button in the
Set Up Sana Administration
section of the
Configuration
tab. You can retry the provisioning by clicking the button. Workday attempts to assign the users with Sana administrator privileges.
(Optional) If you need to update the configuration on this task, access the standard Workday security settings to manually make the changes.