Zum Hauptinhalt wechseln
Workday User Guide
Zuletzt aktualisiert: 2024-03-08
Concept: Security in People Analytics

Concept: Security in People Analytics

Workday enforces security when you:
  • Administer and configure People Analytics.
  • View the People Analytics application.
For the initial deployment of People Analytics, you work with a Workday consultant to determine which security settings best fit your organization and support your desired use of the application. However, you can use the
Configure People Analytics
report to make changes after the initial deployment. Any change you make to the domain security policy groups, organization hierarchies, or securing hierarchy will impact the data viewers see in the application.
When you view the People Analytics application using the
People Analytics
report, Workday uses its configurable security model to control which users have access to specific data. Workday controls access to the data in:
  • Focus Insights
  • KPIs
  • Visualizations
  • Specific data records on the Detailed Data tab
Although the People Analytics data comes from the business objects in your tenant, Workday resets all security domains configured for the business objects and applies new security that you define. The new security that Workday applies is determined by:
  • The specified groups in these People Analytics-related view domain security policies:
    • View: People Analytics
    • View: People Analytics Business Leader
    • View: People Analytics HR Business Partner
    • View: People Analytics Custom 1
    • View: People Analytics Custom 2
    • View: People Analytics Custom 3
  • The selected settings in the Security step when you configure a pipeline in People Analytics.
Workday applies the security to the data in the People Analytics application as well as the data sources used in the application.
You can control access to People Analytics data at these levels:
Security Level
Description
Data source level
The People Analytics view domains provide access to:
  • The People Analytics application
  • The data sources used in the application
When you give users access to 1 one of these view domains, you give access to view the application as well as its data sources.
Data source level security is sometimes known as table level security.
Row level
You can enforce row level security to control access to each data record in the data sources.
You configure row level security on the Security step when configuring the Hiring and Worker pipelines.
You can configure either:
  • Unconstrained access. Select Unconstrained Access, and use either a user-based or unconstrained role-based security group in the
    View: People Analytics
    domain security policy. With unconstrained access, users who have access to any of the People Analytics view domains have access to every data record.
  • Constrained access. Select either the Primary Hierarchy or Secondary Hierarchy, and use a role-based constrained security group in the security policy of any of the People Analytics view domains. The securing hierarchy that you select and the fields included in that hierarchy determine which users have access to specific records (rows) in the application. For more information, see Steps: Set Up Constrained Security to People Analytics.
Do not use user-based security groups in the People Analytics view domains when you select constrained access.
Field level
You can enforce field level security to restrict access to sensitive data in particular fields, enabling you to limit what viewers can see based on their role.
You configure field level security on the Security step when configuring the Hiring and Worker pipelines.
The Security step enables you to restrict access to sensitive data in fields and the People Analytics view domains that are available for restricting access to sensitive data. You can restrict access to 1 or more fields when users are in one of the view domains listed on the Security step.
When you specify a field in a domain, Workday removes access to the data in that field.
Ensure that a given user does not have access to more than 1 People Analytics-related view domain.

Field Level Security Fields

When you configure field level security, you can restrict different fields in the
Worker
and
Hiring
pipelines. Fields denoted with an asterisk (*) are used in People Analytics metrics.
You can restrict these fields in the worker pipeline:
  • Gender*
  • Tenure Category
  • Management Level
  • Job Family Group
  • Length of Service in Partial Years
  • Compa-Ratio*
  • High Potential*
  • High Performer*
  • High Performer*
  • Term Category*
  • Ethnicity
  • Generation
  • Intersection 1
  • Job Level
  • Compa-Ratio Range
  • Current Rating
  • Termination Reason
You can restrict these fields in the hiring pipeline:
  • Candidate Gender*
  • Candidate Ethnicity
  • Candidate Veteran Status
  • Candidate Disability

How Constrained Access Security Works

When you provide constrained access to People Analytics at either the row level or field level, different users will see different data. How Workday displays the data in People Analytics depends on:
  • What type of security group the user is in, either unconstrained or constrained.
  • Which security domain the user has access to.
  • The configured settings on the Security step.
  • The user’s role and organization level permissions.
  • The content type:
Content Type
Row Level Security Notes
Field Level Security Notes
KPIs and Focus Insights
When the user is in an unconstrained security group, Workday displays KPIs and focus insights based on all data records.
When the user is in a constrained security group, Workday displays KPIs and focus insights based on your org level security access at Level 1, Level 2, and Level 3.
Users who are constrained at a specific level within the selected hierarchy can view KPIs and focus insights only for that level and subordinate levels.
When Workday restricts field access, it restricts access for users in all security groups, either unconstrained or constrained.
Workday restricts field access only when the metric calculation for the given KPI or focus insight uses a restricted field.
When the population of workers is from 1 to 5 inclusive in any of the included data snapshots, then in order to protect worker identities, Workday:
  • Displays an empty state on the KPI card.
  • Doesn’t generate or display any focus insight card.
When the population of workers is 0 or 6 or greater for all included data snapshots, Workday behaves differently depending on the location in the UI:
  • KPI or focus insight card. Displays the KPI or focus insight card.
  • Top Drivers tab. Hides Top Drivers that have a population of 5 or less workers. Top Drivers are only available for focus insights.
  • Detailed Data tab. Hides the restricted fields on the Detailed Data tab. However, when the restricted field is used in the metric for the focus insight, then Workday displays an empty state on the Detailed Data tab for that focus insight. Example: The focus insight is about females and the Gender field is restricted.
Visualizations
When the user is in an unconstrained security group, Workday displays every visualization based on all data records.
When the user is in a constrained security group, Workday displays every visualization, but only calculated on the data records you have access to at any level.
How Workday enforces field level security depends on how the People Analytics pipelines are configured:
  • Standard. Workday enforces security strictly by displaying an empty state in a visualization instead of the data regardless of the population count.
  • Threshold. Similarly to KPIs and Focus Insights, Workday displays aggregated data in a visualization when the minimum population threshold of 6 is met, and hides restricted fields on the
    Detailed Data
    tab. However, when the restricted field is used as a filter on the
    Detailed Data
    tab, Workday displays an empty state on the
    Detailed Data
    tab for that visualization.
Workday uses some of the restricted fields in metrics. When you restrict a field used in a metric, you might lose some KPIs and focus insights depending on the worker count during any given data snapshot. Workday recommends that you evaluate the impact of restricting these fields in order to balance the need for restricted access with the need for greater visibility into your organization. Your security configuration also defines the minimum headcount required for KPIs to be calculated and displayed. Example: You restrict the Gender field and one area of your organization only had 4 workers for 1 of the months included in the metric analysis. Workday will not generate or display any focus insights or KPIs on Female Representation.
Workday uses these restricted fields in People Analytics metrics:
  • Compa-Ratio
  • Gender
  • High Performer
  • High Potential
  • Last Promotion Date
  • Term Category

Security Domains and Groups

People Analytics uses these domains in the People Analytics and Prism Analytics functional areas:
Domain
Details
Associated Reports and Tasks
Manage: People Analytics
Can configure, install, and maintain People Analytics.
Supports unconstrained security groups.
  • Configure People Analytics
  • People Analytics Activities
  • People Analytics Data Quality
  • People Analytics
View: People Analytics
Can access the People Analytics application.
Use this domain when you want to provide access to view People Analytics without removing access to particular fields.
Supports unconstrained security groups and role-based constrained security groups.
Doesn’t support Aggregation or Intersection groups even when they are role-based.
  • People Analytics
  • View: People Analytics Business Leader
  • View: People Analytics HR Business Partner
  • View: People Analytics Custom 1
  • View: People Analytics Custom 2
  • View: People Analytics Custom 3
Can access the People Analytics application.
Use these domains when configuring field level security to remove access to sensitive data in particular fields.
Supports unconstrained security groups and role-based constrained security groups.
Doesn’t support Aggregation or Intersection groups even when they are role-based.
  • People Analytics