Skip to main content
Workday User Guide
Last Updated: 2024-12-13
Edit Prism Data Source Security

Edit Prism Data Source Security

  • Security:
    Prism: Manage Data Source
    domain in the Prism Analytics functional area.
Before you make Prism data in a table or dataset available for analysis, configure the security (security domains and securing entities) that Workday applies to the data in the Prism data source. You configure the data source security by editing the table or dataset, but Workday applies the security to the data in the Prism data source.
The configured securing entities work with the configured security domains and their security groups to determine which users have access to which rows, fields, and field values in a Prism data source.
A securing entity is an Instance or Multi-Instance field that you use to constrain access to particular instance values for reporting and analytics. A securing entity:
  • Is typically a role-enabled Instance field, such as Cost Center or Supervisory Organization.
  • Is the Person Instance field (secured to the
    Person Data: Person Reports
    domain) for self-service security groups.
  • Determines which instance values Workday displays to a user based on the role assigned to the user.
Use securing entities to control row-level and field value-level access in a Prism data source for users in constrained security groups.
For a user to have access to a particular row or field value in a Prism data source, they must be a member of 1 of these security groups:
  • An unconstrained security group that has permissions on a domain configured in the data source security.
  • A constrained security group that has permissions on a domain configured in the data source security, and the corresponding securing entity is configured.
Workday restricts user access to data in a Prism data source for these security groups:
  • All unconstrained
  • Role-based constrained
  • Aggregation when role-based
  • Intersection when role-based
Workday has tested and supports using securing entity fields that use these business objects:
  • Company
  • Company Hierarchy
  • Cost Center
  • Cost Center Hierarchy
  • Person
  • Location Hierarchy
  • Region
  • Region Hierarchy
  • Supervisory Organization
When no data source security is configured for the Prism data source, Workday applies the
Prism: Default to Dataset Access
security domain. The
Prism: Default to Dataset Access
domain provides contextual access to a Prism data source based on your access to the underlying table or dataset.
You can’t explicitly configure the
Prism: Default to Dataset Access
security domain when you define data source security. When you access the
View Data Source Security
or
Edit Table
tasks and they indicate that the
Prism: Default to Dataset Access
security domain has been configured, that means that no domain has been configured explicitly. To view the domain that’s currently applied to a Prism data source, access the
View Prism Data Source
report.
  1. Access the
    Edit Data Source Security
    task for the table or dataset you want to apply security to.
  2. In the
    Domains
    prompt, select 1 or more security domains to use to determine who can see the Prism data source.
    If you specify a security domain that has a constrained security group, then you must specify an appropriate securing entity.
  3. (Optional) In the
    Securing Entities
    prompt, select 1 or more fields in the dataset. Workday lists the Instance or Multi-Instance fields in the table or dataset that act as securing entities.
    The securing entities work with the:
    • Data Source Security
      domains to determine row-level access for a user.
    • Field Level Security
      domains to determine field value-level access for a user.
    Workday uses any in common logic when evaluating the contextual security using a Multi-Instance field.
    When you specify more than 1 securing entity that relates to the same security group, Workday uses the OR condition between them. Depending on how your security groups are set up, a user might see some additional rows or field values. Make sure you test the report results to ensure that the report produces expected results for each user.
  4. In the
    Default Domain(s) for Dataset Fields
    prompt, select 1 or more security domains that Workday applies to every field in the Prism data source unless you override the domain for a particular field in the next section.
    When you add new fields to the table or dataset, Workday applies this default domain to the new fields. You might want to consider specifying a domain with more restrictive access. Then you can override the default domain on a per field basis to allow more access as necessary.
  5. (Optional) You can select different domains to apply to specific fields to override the default domains.
  6. Review any
    Security Configuration Audit
    messages to learn more about any issues with the configured securing entities and domains.
  7. (Optional) Click
    Back
    to make any changes to the configured security options based on the audit messages.
  8. Select the
    Apply Security
    check box to apply your changes.
    If you want to restrict access to rows using any of these security group types, Workday can't honor those restrictions:
    • Segment-based security groups
    • Job-based security groups
    • Manager's Manager security group
  9. (Required for datasets) Publish the dataset again to apply the new security configuration to the Prism data source.
Workday saves the security information. You can view the current security status by selecting
Actions
Security
View Data Source Security
.
Suppose that you select these domains containing these security groups. To enforce contextual security at the row-level and field value-level, then use these fields as securing entities:
Security Domain
Contains This Security Group
Use This Securing Entity
Custom Domain 28
HR Partner (By Location)
Location
Custom Domain 29
Manager
Supervisory Organization
Custom Domain 30
HR Administrator
None required.
HR Administrator is an unconstrained security group, so it doesn't require a securing entity.
Public Reporting Items
None.
None required.
This domain provides access to all publicly available fields and Workday-delivered data sources.
Create the Prism data source by enabling the table for analysis or publishing the dataset. Workday applies the security restrictions to the data in the Prism data source.