Concept: Security in People Analytics
Workday enforces security when you:
- Administer and configure People Analytics.
- View the People Analytics application.
For the initial deployment of People Analytics, you work with a Workday consultant to determine which security settings best fit your organization and support your desired use of the application. However, you can use the
Configure People Analytics
report to make changes after the initial deployment. Any change you make to the domain security policy groups, organization hierarchies, or securing hierarchy will impact the data viewers see in the application.When you view the People Analytics application using the
People Analytics
report, Workday uses its configurable security model to control which users have access to specific data. Workday controls access to the data in:
- Focus Insights
- KPIs
- Visualizations
- Specific data records on the Detailed Data tab
Although the People Analytics data comes from the business objects in your tenant, Workday resets all security domains configured for the business objects and applies new security that you define. The new security that Workday applies is determined by:
- The specified groups in these People Analytics-related view domain security policies:
- View: People Analytics
- View: People Analytics Business Leader
- View: People Analytics HR Business Partner
- View: People Analytics Custom 1
- View: People Analytics Custom 2
- View: People Analytics Custom 3
- The selected settings in the Security step when you configure a pipeline in People Analytics.
Workday applies the security to the data in the People Analytics application as well as the data sources used in the application.
You can control access to People Analytics data at these levels:
Security Level | Description |
|---|---|
Data source level | The People Analytics view domains provide access to:
When you give users access to 1 one of these view domains, you give access to view the application as well as its data sources. Data source level security is sometimes known as table level security. |
Row level | You can enforce row level security to control access to each data record in the data sources. You configure row level security on the Security step when configuring the Hiring and Worker pipelines. You can configure either:
Do not use user-based security groups in the People Analytics view domains when you select constrained access. |
Field level | You can enforce field level security to restrict access to sensitive data in particular fields, enabling you to limit what viewers can see based on their role. You configure field level security on the Security step when configuring the Hiring and Worker pipelines. The Security step enables you to restrict access to sensitive data in fields and the People Analytics view domains that are available for restricting access to sensitive data. You can restrict access to 1 or more fields when users are in one of the view domains listed on the Security step. When you specify a field in a domain, Workday removes access to the data in that field. Ensure that a given user does not have access to more than 1 People Analytics-related view domain. |
Field Level Security Fields
When you configure field level security, you can restrict different fields in the
Worker
and Hiring
pipelines. Fields denoted with an asterisk (*) are used in People Analytics metrics.You can restrict these fields in the worker pipeline:
- Gender*
- Tenure Category
- Management Level
- Job Family Group
- Length of Service in Partial Years
- Compa-Ratio*
- High Potential*
- High Performer*
- High Performer*
- Term Category*
- Ethnicity
- Generation
- Intersection 1
- Job Level
- Compa-Ratio Range
- Current Rating
- Termination Reason
You can restrict these fields in the hiring pipeline:
- Candidate Gender*
- Candidate Ethnicity
- Candidate Veteran Status
- Candidate Disability
How Constrained Access Security Works
When you provide constrained access to People Analytics at either the row level or field level, different users will see different data. How Workday displays the data in People Analytics depends on:
- What type of security group the user is in, either unconstrained or constrained.
- Which security domain the user has access to.
- The configured settings on the Security step.
- The user’s role and organization level permissions.
- The content type:
Content Type | Row Level Security Notes | Field Level Security Notes |
|---|---|---|
KPIs and Focus Insights | When the user is in an unconstrained security group, Workday displays KPIs and focus insights based on all data records.
When the user is in a constrained security group, Workday displays KPIs and focus insights based on your org level security access at Level 1, Level 2, and Level 3. Users who are constrained at a specific level within the selected hierarchy can view KPIs and focus insights only for that level and subordinate levels. | When Workday restricts field access, it restricts access for users in all security groups, either unconstrained or constrained.
Workday restricts field access only when the metric calculation for the given KPI or focus insight uses a restricted field. When the population of workers is from 1 to 5 inclusive in any of the included data snapshots, then in order to protect worker identities, Workday:
When the population of workers is 0 or 6 or greater for all included data snapshots, Workday behaves differently depending on the location in the UI:
|
Visualizations | When the user is in an unconstrained security group, Workday displays every visualization based on all data records.
When the user is in a constrained security group, Workday displays every visualization, but only calculated on the data records you have access to at any level. | How Workday enforces field level security depends on how the People Analytics pipelines are configured:
|
Workday uses some of the restricted fields in metrics. When you restrict a field used in a metric, you might lose some KPIs and focus insights depending on the worker count during any given data snapshot. Workday recommends that you evaluate the impact of restricting these fields in order to balance the need for restricted access with the need for greater visibility into your organization. Your security configuration also defines the minimum headcount required for KPIs to be calculated and displayed. Example: You restrict the Gender field and one area of your organization only had 4 workers for 1 of the months included in the metric analysis. Workday will not generate or display any focus insights or KPIs on Female Representation.
Workday uses these restricted fields in People Analytics metrics:
- Compa-Ratio
- Gender
- High Performer
- High Potential
- Last Promotion Date
- Term Category
Security Domains and Groups
People Analytics uses these domains in the People Analytics and Prism Analytics functional areas:
Domain | Details | Associated Reports and Tasks |
|---|---|---|
Manage: People Analytics | Can configure, install, and maintain People Analytics.
Supports unconstrained security groups. |
|
View: People Analytics | Can access the People Analytics application.
Use this domain when you want to provide access to view People Analytics without removing access to particular fields. Supports unconstrained security groups and role-based constrained security groups. Doesn’t support Aggregation or Intersection groups even when they are role-based. |
|
| Can access the People Analytics application.
Use these domains when configuring field level security to remove access to sensitive data in particular fields. Supports unconstrained security groups and role-based constrained security groups. Doesn’t support Aggregation or Intersection groups even when they are role-based. |
|