Set Up AI Administrator Security Permissions
You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
- Select your profile avatar on Workday Community.
- SelectProfile.
- On your profile page, select your organization's name, which is beneath your name and next to your job title.
- View yourSubscription Service Agreementvalue.
If the value is:
- UMSA, the feature is automatically available. Keep data contributions enabled to ensure full agent functionality. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
- MSA, your organization must opt in to UMSA and enable this feature through Innovation Services.
UMSA is required for non-production and production tenants for Workday-Built agents. UMSA is not required for non-production tenants for self-built agents.
For information about how using agents impacts your Flex Credits, see: Workday Flex Credits Community page.
To use Sana Core and Sana Enterprise, you must:
- Purchase the Sana Enterprise SKU. This only applies to Sana Enterprise.
- Purchase the Core Human Capital Management or Core Financials SKU. This only applies to Sana Core.
- Sign the Universal Main Subscription Agreement (UMSA).When you sign the agreement, Workday provides your organization with complimentary Flex Credits that you can use towards Sana Core for Workday. Once you reach the allotted complimentary Flex Credit consumption, you must sign the Workday Flex Credits and Platform Entitlement Policy to continue to use Sana Core for Workday.
- Sign the Workday Flex Credits and Platform Entitlement Policy. This only applies to Sana Enterprise.
Security: You have security permission on these domains in the System functional area:
- Security Activation
- Security Configuration
The
Set Up AI Admin Security Permissions
task bundles all the necessary security configuration steps into a single task which when complete, initiates backend processing to get your organization set up to use Workday AI features.This is a one-time task for each tenant. The task simplifies granting security access for:
- Agent System of Record: Assign users access to manage and configure AI agent behavior and integrations in a central location.
- User Provisioning Workspace for Sana: Assign administrators to provision users to Sana.
- Platform Consumption Console: Assign users access to monitor and manage infrastructure resources that your agents use.
- Sana: Assign users as Sana administrators to configure Sana features in the Sana Workspace.
Workday sends a notification to security administrators in all your tenants (Production, Sandbox, Sandbox Preview, Implementation, and Implementation Preview) to access and complete the
Set Up AI Admin Security Permissions
task.
The security configuration notification expires in 30 days.
While you can configure areas of the
Set Up AI Admin Security Permissions
task separately, Workday recommends using the task to ensure all critical dependencies for your AI experience are met.Security administrators must complete all sections. Once you submit the task, you can’t edit it. You can manually update the configuration through the standard Workday security settings.
If multiple administrators are configuring this task, Workday processes the first configuration that's submitted.
- Access theAction Required: Review and Configure the Security for Sana and Workday Agentsnotification from the bell icon in Workday.If administrators never received this notification or it expired and was removed after 30 days, you can access theNotify Users to Configure Sana Agent Securitytask to resend the security configuration notification. The user must haveModifypermissions on theSecurity Configurationdomain to receive the notification. TheNotify Users to Configure Sana Agent Securitytask is only available in the tenant when you sign the UMSA. We don’t resend the notification if an administrator has already completed theSet Up AI Admin Security Permissionstask.
- In the notification, clickStart Configuration.
- As you complete theConfigure Security Policiessection on theConfigurationtab, consider:You only need to configure grids with anstatus. We display a:Incomplete
- status when domain security policies are configured. We hide theCompletedSecurity GroupandView or Add Users to Security Groupcolumns in the grid.
- Completed with Exceptionsstatus when at least 1 of the domain security policies in theDomain Security Policiescolumn isn't currently active or it has pending changes.
In theView or Add Users to Security Groupcolumn:- You can add members only when you create a new security group or select a group that's not used in other policies and doesn't have members.
- You can't add or remove members in the column when you select a security group that's currently used in other policies or it has existing members.
In theDetailscolumn, you can drill into each domain security policy configuration by clickingDetails. When you click the link, we display aView Domain Detailspop-up box where you can view the configuration.Option Description Agent System of RecordThis section enables you to configure access to the Agent System of Record workspace.TheDomain Security Policiescolumn displays all domain security policies you need to configure.In theSecurity Groupcolumn, select an existing user-based security group or create a new one.We display the members in theView or Add Users to Security Groupcolumn. Workday adds users in those groups to the domain security policies listed in theDomain Security Policiescolumn withViewandModifypermissions.Platform Consumption ConsoleThis section enables you to configure access to the Platform Consumption Console.TheDomain Security Policiescolumn displays all domain security policies you need to configure.In theSecurity Groupcolumn, select an existing user-based security group or create a new one.We only require a security group withView Onlypermission on theManagement Dashboard: Platform Consumption Consoledomain security policy.You can only add a security group to theManagement Dashboard: Platform Consumption Consoledomain using this task if there are no existing security groups withView OnlyorViewandModifypermissions configured on the domain security policy.Workday displays aCompletedstatus on thePlatform Consumption Consolegrid when these security configuration criteria are met.We display the members in theView or Add Users to Security Groupcolumn. Workday adds users in those groups to the domain security policies listed in theDomain Security Policiescolumn withView Onlypermission.User Provisioning WorkspaceThis section enables you to configure access to the User Provisioning workspace for Sana.TheDomain Security Policiescolumn displays all domain security policies you need to configure.In theSecurity Groupcolumn, select an existing user-based security group or create a new one.We display the members in theView or Add Users to Security Groupcolumn. Workday adds users in those groups to the domain security policies listed in theDomain Security Policiescolumn withViewandModifypermissions.When a domain is disabled and you access theSet Up AI Admin Security Permissionstask:- You can add security groups to the domain. Once you submit the changes on the task, this activates the domain.
- We display astatus if the domain has existing security groups.Completed
- As you complete theSet Up Sana Administratorssection on theConfigurationtab, consider:
Option Description Set Up Sana AdministratorsThis section enables you to define which users are Sana administrators. Workday automatically provisions these users into Sana upon activation.In theSecurity Groupcolumn, select an existing user-based security group or create a new one.Users with Sana administrator privileges can access and configure the Sana Workspace. - Select theActivate Pending Security Policy Changestab.To activate security policy changes in your tenant, you must have permission on theSecurity Activationdomain.
- As you complete theActivate Pending Security Policy Changestab, consider:
Option Description Security Policy gridsReview the security changes in the grids.Confirm check boxSelect the check box to submit all security policy changes.Workday activates all security policy changes in the grids including the security settings on theConfigurationtab. - ClickOKand then clickDone.
Workday automatically activates pending security policy changes and makes applicable tasks available. Workday might notify members of included security groups of additional tasks and actions they can take.
If assigning Sana administrator access to members in the security groups fails, we display a
Resubmit
button in the Set Up Sana Administration
section of the Configuration
tab. You can retry the provisioning by clicking the button. Workday attempts to assign the users with Sana administrator privileges.(Optional) If you need to update the configuration on this task, access the standard Workday security settings to manually make the changes.