Setup Considerations: Payroll Security
You can use this topic to help make decisions when planning your configuration and use of
payroll security. It explains:
- Why to set it up.
- How it fits into the rest of Workday.
- Downstream impacts and cross-product interactions.
- Security requirements and business process configurations.
- Questions and limitations to consider before implementation.
What It Is
Configurable payroll security:
- Offers a simple and customizable method to protect payroll data from unauthorized access or manipulation.
- Enables you to control access to payroll data, based on user roles and responsibilities, like:
- View payslips and payment dates.
- Set up company taxes.
Payroll security policies enable you to secure access to:
- Integrations with third-party organizations for wage garnishments.
- Pay calculation results reports and reporting items.
- Pay cycle worklets.
- Payslip configuration tasks.
- Report data sources (RDS) for payslips.
- Run pay calculation background processes.
- Termination business processes.
Business Benefits
Configure payroll security permissions to:
- Automate permission assignments for payroll data by grouping users based on similar attributes, saving you the effort of setting up permissions individually.
- Manage access to payroll integrations, reports, and data using a single security model. This model makes it easier to maintain access at scale.
- Meet company standards for auditing permissions in Workday using built-in audit trails.
- Limit access for nonpayroll users to only the payroll data they need to perform their jobs.
Use Cases
- Automatically add new users to a defined security group based on their position, such as:
- A user-based group for payroll administrators.
- Managers who need to review overtime or costing information.
- HR administrators who need to access aggregated payroll results and other nonsensitive portions of data.
- Provide different levels of access for different types of users in the same tenant. Example: Workers can only view their own payslips, but managers can view payslips for all their direct reports.
Questions to Consider
Question | Considerations |
|---|---|
How do you want to determine who can view items and perform actions in Workday
Payroll? | Workday provides different types of security groups to enable you to address your
payroll requirements. Workday groups similar items and actions into
different security policies. While you can't change the items and actions
secured to security policies, you can change the security groups associated
with the security policies. You can use these types of security groups to
control who has access and what they have access to:
Members in security groups with the unconstrained context
type can access all secured data instances. |
What level of permission do you want to provide to payroll tasks and
reports? | Workday groups similar tasks and reports into security domains. To provide access to
the tasks and reports, set View or Modify permission on the security
policies that secure them. Workday typically designates reports
and reporting items with View access. Users with Modify permissions can
access all tasks and reports secured to the domain. |
What level of permission do you want to provide to payroll business
processes? | You can set different permissions on both the security policies and steps for payroll
business processes. Example: Provide employees access to the Initiate
action on a business process. |
Do third-party resources need access to your Workday tenant? | You can use Service Centers to grant third-party contracted organizations access to
your Workday tenant while protecting sensitive data. Representatives from
those organizations:
|
Recommendations
When possible, use Workday-delivered payroll security groups instead of creating your
own. Doing so helps to ensure that the security group has access to the
payroll-specific data and tasks needed to perform their role. Workday-delivered
payroll security groups also enable you to:
- Benefit from banking setup questions and feedback about terminee security groups captured on Workday Community.
- Use Workday-verified security configurations for accounting and tax setup.
Grant access only to information and resources users require to accomplish their job
functions.
Use Workday-delivered reports to:
- Ensure that you provide users with correct permissions.
- Create and submit year-end tax data to government agencies.
Business Process Definitions
report data source (RDS).
Configure access to these domains as appropriate to ensure that all business process
administrators can build custom reports using this RDS:- Administration
- Definition View
- Manage: Business Process Definitions
Review all requirements for security groups and security policies before setting up
security.
Requirements
To set permissions for domains and business processes, enable the Workday Payroll functional
area and its security policies. Enabling a functional area doesn’t automatically
enable all the security policies in that area.
Limitations
You can’t:
- Change the actions available on security policies for business processes.
- Change the items within domains.
- Delete security policies.
- Move domains or business processes from 1 functional area to another.
Tenant Setup
No impact.
Security
Functional Areas | Considerations |
|---|---|
Banking and Settlement | Security domains in this functional area enable you to:
|
Common Financial Management | Security domains in this functional area enable you to:
|
Core Payroll | Security domains in this functional area enable you to configure and
use these basic Payroll features that are common to all Payroll
countries:
The domains also secure access to the:
|
Expenses | Security domains in this functional area enable you to:
|
Integration | Security domains in this functional area enable you to:
|
Organizations and Roles | Security domains in this functional area enable you to:
|
Payroll Interface | Security domains in this functional area enable you to:
|
System | Security domains in this functional area enable you to:
|
USA Payroll | Security domains in this functional area enable you to configure and
use features specific to Payroll for the U.S., Puerto Rico, Guam, and the
U.S. Virgin Islands, such as:
|
Worktags | Security domains in this functional area enable you to manage
Workday-delivered and custom worktags. You can:
|
You're responsible for testing and validating that security domain settings meet your
business needs.
Business Processes
Workday doesn't secure business processes to domains, but each business process
definition has its own business process security policy.
You associate each step within a business process definition with a security
group.
Workday enables you to configure segment-based security groups with access to view
and manage specific business process definitions. Business process segmentation
applies only to business process definitions.
Segment-based security groups can include any type of security group, including
role-based security groups. When you use a role-based security group, the member can
only maintain business processes affiliated with the organizations they have an
assigned role for. Example: A payroll partner's role
in:
- Absence Requests
- Benefit Enrollments
- Compensation Changes
- Job Changes
- One Time Payments
- Terminations
- Time Entry and submission
Secure the segment-based security group to the
Manage: Business Process
Definitions
security domain. This domain only includes tasks related to
defining business processes.Workday doesn't enable segmented security on these business process components:
- Calculated dates
- Checklists
- Rules
- To Dos
Reporting
Dashboard or Report | Considerations |
|---|---|
Action Summary for Security Group
report | View the security policies associated with a specified security
group. |
Business Process Security Policies for Functional
Area report | View all security policies for business processes within a functional
area. |
Business Process Types and Initiating Security
Groups report | View all business processes and the security groups that have
permission to initiate them. |
Compare Permissions of Two Security Groups
report | Compare the security policy permissions for 2 security
groups. |
Domain Security Policies for Functional Area
report | View all domain security policies for Payroll in a functional area. |
Employee Self Service Pay dashboard | View insights so employees understand their pay by viewing payslips,
comparing periods, and reviewing any pay trends. |
Functional Areas report | View all functional areas, and the domains and business processes in
them. |
Pay Cycle Command Center dashboard | View operational insights into specific pay cycles. |
Process Monitor report | View all types of background processes that are running or ran in the
past. |
Security Analysis for Security Groups
report | View the secured items associated with security groups. |
Security Exception Audit report | View errors and warnings involving your security
configuration. |
View Security for Securable Item
report | View how Workday secures delivered items. |
View Security Group report | View security groups and the associated security policies and
configuration details. |
View Security Groups for User report | View the security groups that a person is a member of. |
View Web Service Operations Security Groups
report | Identify the security groups that you need to be a member of to run a
specified web service. |
Web Service Security Audit report | View the security groups that can run web service tasks. |
Integrations
Workday provides several security domains that secure access to integration templates
and integration systems. These domains separate the permissions to configure an
integration from the permissions to run an integration and view integration output.
You can also segment integration templates and integrations, then grant access
separately for each segment.
All integrations access Workday data using web service operations and
Reports-as-a-Service. Workday secures these items to various security domains:
- Custom reports.
- RDSs.
- Report fields.
- Web service operations.
Integrations and applications that access Workday must have Get and Put access to the
domains that include the web service operations. Also, they must have the View
access to the domains that include the RDSs and report fields. In addition, outbound
EIBs require access to the custom report that they use as an RDS. These accounts can
control permissions:
- Associated Integration System User (ISU) account (for Connectors, Studio integrations, and external applications).
- The role of the person who runs an EIB integration. Example: Payroll administrator.
Connections and Touchpoints
Touchpoint | Consideration |
|---|---|
Absence | Enable Payroll security in this functional area to configure:
|
Banking and Settlement | Enable Payroll security in this functional area to:
|
Benefit Plans | Enable Payroll security in this functional area to:
|
Compensation | Enable Payroll security in this functional area to:
|
Core Payroll | Payroll security in this functional area enables you to configure and
use these basic Payroll features that are common to all Payroll
countries:
|
HCM | Provide employee and job-related data for payroll processing, such
as:
|
Payroll Interface |
|
Workday offers a Touchpoints Kit with resources to help you understand configuration
relationships in your tenant. Learn more about the Workday Touchpoints
Kit on Workday Community.