Skip to main content
Workday Education
Last Updated: 2026-07-10
Role-Based Security

Role-Based Security

Overview

This chapter covers role-based constrained security groups, which are one of the most common ways to configure security in Workday. Role-based constrained security groups use assignable roles to define membership and constrain members' access to assigned organizations. For example, you can constrain access for your support and leadership staff (e.g., managers, benefits partners) to only those organizations to which they have role assignments. You will learn how to create and configure assignable roles and role-based security groups. You will also see the importance of maintaining role assignments in your staffing transactions.

Objectives

By the end of this chapter, you will be able to:
  • Identify the purpose of role-based constrained security groups.
  • Configure a new assignable role and role-based security group.
  • Compare and contrast methods of assigning roles.
  • Examine options for constrained access to subordinate organizations.
  • Identify the importance of maintaining role assignments.

Role-Based Security Groups

Role-based constrained security groups are used frequently in Workday because they allow you to configure access for your support and leadership staff (e.g., managers, HR partners, accountants, recruiters). You can allow these workers to access needed tasks, reports, and business process steps, but constrain them to just the organizations that they support or lead. Only role-based constrained security groups allow you to individually assign worker positions to a role for a specific organization that they are not in.
Organizations
An organization is a basic building block in Workday. Use organizations to group workers and financial transactions for business process routing, security, analytics, and reporting purposes.
Organization Types
An individual worker or target instance or data can (and will) be associated with multiple types of organizations, as each organization applies to different business functions. For example, workers are hired into a supervisory organization, but can also be part of a:
  • Company
  • Cost center
  • Region
  • Custom organization
When it comes to configuring security in Workday, organizations play a large part in your security design. Organizations are a very common way to enforce target constraints on members of a security group. For example, you can constrain members to only see data for those workers in a given organization when running reports or tasks.
Organization Hierarchies
An important benefit of the organization model is the ability to arrange organizations into parent-child hierarchies. Organization hierarchies ease reporting requirements and also allow you to enforce target access constraints by hierarchy level. For example, with a location hierarchy organization, you can allow access to subordinate organizations without needing to individually specify each organization.
Organization hierarchy example.
Assignable Roles
Role-based security groups use a concept called an assignable role (or "role") as the criteria for membership. A role represents the responsibilities a given assignee has for viewing, reporting, or managing data related to a given role-enabled instance, such as for an organization.
For example, using assignable roles, you can allow a controller for a particular company to only access financial transactions and accounts related to the company they support. You can allow a payroll partner to only access employee pay data based on the pay group they support.
You can think of assigning the role to the "chair" that the worker is in, rather than to the worker. Workers become members of a role-based security group when someone assigns their "chair" (position or job) to the assignable role referenced in the security group definition. Tying the role assignment to the worker's "chair," and not directly to the worker, allows for easier maintenance. For instance, if a worker changes jobs or leaves the company, you can leave the role assignments on the unfilled position. That way, the worker who back-fills the position will assume those role assignments.
How role-based security groups work.
Some examples of assignable roles and their assignments in GMS are:
Assignable Role
Enabled for Organization Type
Role-Enabled Instance
Position / Job
Manager
Supervisory
IT HelpDesk Department
Manager, IT HelpDesk - Jared Ellis
Accountant
Company, Company Hierarchy
Global Modern Services, Ltd (Canada)
Tax Accountant - Andrew Walton
Payroll Partner
Pay Group
GBR Monthly
Director, Payroll Operations - Ella Phillips
Cost Center Manager
Cost Center, Cost Center Hierarchy
33000 Global Support Center
Vice President, Global Support - Susan Steinberg
HR Partner by Location
Location Hierarchy
Japan & Asia/Pacific
HR Manager - Fumi Endo

Configuring Role-Based Security

The steps for configuring role-based security are as follows:
  1. Create an assignable role (or identify an existing role), enabled for a specific organization type (or role-enabled instance).
  2. Create a role-based (constrained or unconstrained) security group, specifying the assignable role as the group criteria. If constrained, specify the access to subordinate organizations as needed (e.g., COUS, COAS).
  3. Assign roles to a specific position (or job) for each target organization (or instance).
  4. Edit security policy permissions to include the security group.
  5. Activate the pending security policy changes.
  6. Test access.
View and Maintain Assignable Roles
Run the
View Assignable Roles
report to access assignable roles already configured in your tenant.
Use the
Maintain Assignable Roles
task to add, remove, and maintain assignable roles. The required fields are Role Name, Enabled For, and Assigned by Security Groups.
Maintain Assignable Roles
Note
: The Assigned By Security Groups field establishes the role maintainers, which are security groups whose members can approve assignments for this role. Role maintainers can assign members of the role only within the organizations they support.
The available fields in the
View Assignable Roles
and
Maintain Assignable Roles
tasks are:
Field
Definition
Role Name
This field allows you to provide a name for your assignable role. Common names include the terms "partner," "manager," or "analyst."
Workday Role (Optional)
There are certain Workday-provided roles, such as the Manager or Benefits Partner roles, that Workday uses for nonsecurity purposes, such as populating worklets or generating reports. Only the roles that appear in the prompt are available to map. Once you have mapped them, they no longer appear in the prompt list.
Enabled for
This field allows you to select the types of organizations for which you want to maintain and assign this role.
Note
: Configure a single role for a single organization type, when possible. Configuring a role for multiple organization types can make it difficult to determine how a user is able to access a particular secured item. The exception is for organization types where there is role inheritance between a hierarchy and its included organizations, such as cost center hierarchy and cost center.
Default Role
An unassigned role can inherit from a superior organization. This field allows you to select another role as the default assignment. Available default roles are other roles that are valid for the same organization type.
Self-Assign
Select this option to default the role assignment to the organization creator's primary position. If you select Yes for Self-Assign, you can also select the Restricted to 'Assign Self-Assign Roles' BP field.
Restricted to 'Assign Self-Assign Roles' BP
With this option selected, Workday automatically assigns the creator of an organization to fill the role for the organization they are creating.
Restricted to Single Assignment
This field allows you to restrict the role assignment to one position. Do not select this option for the Workday Manager role if you wish to allow the assignment of multiple managers to a supervisory organization.
Hide on View if Not Assigned
When viewing an organization, you can determine the roles enabled for that organization type and the assignments. With this option, you can choose to hide unassigned roles.
If selected, noninherited unassigned roles will not display on the following reports:
  • The
    Unassigned Roles Audit
    report
  • The
    Support Roles
    report on Worker profile
  • The
    View Roles
    report for Organizations
There is no impact on the
Unfilled Assigned Roles Audit
report.
Do not hide roles you need to audit, such as roles used in your business process routing.
Is Leader / Is Supporting
Select for roles whose assignees should display as leaders in the organization chart and organization preview. Workers assigned to an Is Leader role display in the supervisory or matrix organization name when you select Include Manager Name. These options also drive the delivered
My Leadership Roles
and
My Support Roles
reports.
Show inherited assignees for Security Groups
Displays all inherited role assignments for the selected security group when viewing the Support Roles page of the Worker Profile and the Roles tab of the organization.
Role Assignees Restricted to
This field allows you to restrict a given role to members of a defined security group. When assigning the role, only members of the security group specified will be available.
Assigned by Security Groups
This field allows you to specify all security groups whose members can approve role assignments for this role. Workday automatically assigns members of this designation to the Role Maintainer security group for the given role.
Assignable Role Usages
This Usage button displays:
  • Any Workday roles defined for this assignable role.
  • The total role assignment count.
  • The total assignable role relationship count.
  • The role-based security groups defined for the role.
Role-Based Security Groups
This field contains the number of role-based security groups associated with this role. You may select the number for a list of those security groups.
Security Note
: The Set Up: Assignable Roles security domain secures the
View Assignable Roles
and
Maintain Assignable Roles
tasks.

Methods of Assigning Roles

Role assignments involve associating a worker's position or job with a given assignable role for a given organization or role-enabled instance (e.g., project, fund, supplier contract).
You can assign roles in several ways:
  • At the organization or role-enabled instance level.
  • At the worker position or job level.
  • To an unfilled position.
  • As a step in a business process.
  • Via a web service (e.g., integration).
Assign Roles to an Organization
To assign roles for a given role-enabled instance (e.g., an organization): Navigate to an organization's Related Actions, then select Roles > Assign Roles.
When assigning roles using this method, keep these considerations in mind:
  • Only members of the Role Maintainer security group can assign roles at the role-enabled instance or organization level.
  • Users can only access roles they can assign.
  • The assignment does not involve a business process. Therefore, you cannot enforce approvals with this method.
Assign Roles to a Worker's Position or Job
To assign roles directly to a worker's position or job, navigate to their Related Actions, then select Security Profile, and choose one of the following actions:
Related Action
Definition
Assign Roles - Add/Remove
This option enables you to add roles, remove selected roles, remove all roles, and copy role assignments from another worker.
Assign Roles - Change Assignments
This option enables you to propose multiple roles for multiple assignees. The role assignment grid initially populates with the worker's primary position, and then you can propose changes.
These tasks provide:
  • Common actions such as add, remove, copy, and maintain roles.
  • Visibility into the role assignments of a worker.
  • The option to update later-dated assignments.
If the worker assigning the role is not in the Role Maintainer security group, the system routes an approval step for the role assignment to the Role Maintainer.
Note
: Configure security groups permitted to access these actions (and more) by editing the security policy permissions for the
Assign Roles
business process.
Assign Roles via an Integration
Workday provides a web service operation for role assignments. Configure permitted security groups in the
Assign Roles
business process security policy to control who can access the web service operation.

Role Assignment Considerations

Role Inheritance
When you assign a role for an organization to a worker's position or job, subordinate organizations without an existing role assignment typically inherit that assignment. Role assignees' target access depends on the security group configuration.
Report
: Use the
Roles for Organization and Subordinates
report to view roles and role assignments for a particular organization and up to two subordinate levels. The report lists the worker who fills each role, and whether the role is assigned or inherited.
Time Zone Settings
Use the
Edit Tenant Setup - System
task to configure the time zone setting for role assignments. You can use the assignee's location or a tenant-configured default time zone as the time zone option. Once you select a time zone option, the effective time zone field will show in role assignment tasks and reports. If you do not configure time zone options in the tenant, you will not see the effective time zone field around role assignments. The system will use the Workday default Pacific time zone.
Resource
: See Appendix B for more information.

Access Rights to Organizations

For constrained role-based security groups, there are four options for configuring access rights to organizations:
Access Rights
Definition
Current Organization Only (COO)
Constrains members to organizations where they have the role assignment.
An organizational chart template illustrating the Current Organization Only (COO) access rule, which dynamically constrains data visibility strictly to the nodes where a user holds a valid role assignment.
Current Organization and Unassigned Subordinates (COUS)
Constrains members to organizations where they have the role assignment and subordinate organizations that do not have someone assigned to the role.
An organizational chart template illustrating the Current Organization and Unassigned Subordinates (COUS) access rule, where user data visibility extends into unassigned child nodes.
Current Organization and All Subordinates (COAS)
Constrains members to organizations and subordinate organizations, regardless of whether they have someone assigned to the role.
An organizational chart template illustrating the Current Organization and All Subordinates (COAS) access rule, demonstrating full data visibility down through all subordinate nodes.
Current Organization and Subordinates to Level
Constrains members to organizations and subordinate organizations, down to a number of levels in the hierarchy.
An organizational chart template illustrating the Current Organization and Subordinates to Level access rule, restricting user data visibility down to a fixed number of hierarchical tiers.
Access rights to organizations section of the View Role-Based Security Group task.
Access Rights to Multiple Job Workers
There are three options for configuring access rights to workers who have multiple jobs:
Option
Description
Role has access to the positions they support
Grants access only for the job or position that you assign to the role in the specified organization.
Example: Sarah has a primary position at Company 1 that Mark manages and a secondary position at Company 2 that Susan manages. When you select this option:
  • Mark can access Sarah's person data and primary position data for Company 1.
  • Susan can access Sarah's person data and secondary position data for Company 2.
Role for primary job has access to all positions
Grants access to assignees who have a role in the organization associated with the primary job or position. Denies access to assignees who have a role in the organization associated with an additional job or position.
Example: Sarah has a primary position at Company 1 that Mark manages and a secondary position at Company 2 that Susan manages. When you select this option, only Mark can access Sarah's:
  • Person data.
  • Primary position data for Company 1.
  • Secondary position data for Company 2.
Role has access to all positions
Grants access to assignees who have a role in the organization associated with the primary or additional job or position.
Example: Sarah has a primary position at Company 1 that Mark manages and a secondary position at Company 2 that Susan manages. When you select this option, both Mark and Susan can access Sarah's:
  • Person data.
  • Primary position data for Company 1.
  • Secondary position data for Company 2.

One Role, Multiple Security Groups

Each role-based security group can only reference one assignable role. However, you can have several role-based security groups for the same role, with different access rights for each security group.
For example, you can use the same Manager role in a number of role-based security groups to express whether the user:
  1. Has a direct relationship to the worker (role-based constrained security group: Manager).
  2. Is in the organization chain for the worker (role-based constrained security group: Management Chain).
  3. Has a direct relationship to the worker's primary position (role-based constrained security group: Primary Manager).
  4. Is anyone in the role (role-based unconstrained security group: Manager (Unconstrained)).
One role with multiple security groups.
Each role-based security group that uses that same assignable role will have varying access rights to organizations to distinguish the different target access constraints desired.
Exercise: Organization Access Rights
For the following organization charts, consider which organizations each manager supports, for each access right option (COO, COUS, COAS, and Unconstrained). Use the tables below to check your answers.
Original manager role assignments:
Organization access rights - original manager role assignments.
Summary of the role assignees' target access:
A table titled Summary Before New Role Assignment detailing four security scenarios for the Manager role across various security groups, member target access, and security policies.
New manager role assignee:
Organization access rights with new assignee.
Summary of the role assignees' target access:
A table titled Summary After New Role Assignment outlining updated roles, security groups, and access permissions for a new assignee named Omar.

Role Maintenance

It is important to maintain your organization's role assignments, as these assignments directly drive membership in role-based security groups. Unassigned roles can result in unassigned tasks since the system could send business process steps to role-based constrained security groups with no members for an organization.
The best way to avoid unassigned roles and tasks is to set up processes to ensure you are monitoring and maintaining role assignments and security groups.
Assign Roles Subprocess
Workday allows Action steps in certain business processes that can trigger subprocesses for assigning roles. These subprocesses ensure that someone reviews and reassigns role assignments during worker staffing changes.
The primary subprocess for assigning roles on a staffing transaction is Assign Roles - Change Assignments for Worker.
Security Note
: This subprocess initiates the
Assign Roles
business process. Remember to configure permitted security groups for these initiating actions in the
Assign Roles
business process security policy. The action step in the staffing business process definition must route to a permitted security group.
Example: Change Job
The following image shows an example of the
Change Job
business process definition. Notice how we have configured two of the steps to address needed changes in role-based and user-based security groups for the worker changing jobs.
Note that you can configure entry condition rules so that the system executes a step only when certain conditions are true. In this case, the worker must have at least one existing role-based or user-based security group for those steps to execute.
Change Job business process definition with steps to review user-based security groups and assign roles.
The action step Assign Roles - Change Assignments for Worker initiates the
Assign Roles
business process as a subprocess. This step allows you to determine what to do with the role assignments of the transferred worker. The options are:
  • Transfer role assignments from the old position to the new position.
  • Copy role assignments from the old position to the new position.
  • Copy role assignments to the new position from another position.
  • Remove role assignment from the old position.
  • Manually specify assignees for each role.
Important
: Assign Roles - Change Assignments for Worker is the recommended subprocess for Change Job. It allows you to determine what to do with the role assignments regardless of the staffing model in use.
Position Management vs. Job Management
Changes to role assignments as a result of
Change Job
business process events differ when using position management vs. job management staffing models.
If the transferred worker is in a position, the roles can remain unfilled on the position. Then, when another worker backfills that position, they will assume the role assignment.
If the transferred worker is in a job, you can optionally transfer the role assignments with the worker. You may be using the tenant setting: Change Job Use Default Organizations for Job Management, which removes role assignments for workers moving between job management organizations. If so, you can also use the Copy Role Assignments service step to automatically reassign roles to the worker. Configure the step after the Complete step of the business process definition. You cannot use the Copy Role Assignments step with future-dated role assignments or workers with multiple jobs.
Reminder
: Whether using job management or position management, it is important to audit for unassigned roles or roles left on unfilled positions. If the security group access rights include unassigned subordinates, the assignee in the superior organization will automatically fill an unfilled role.
Audit Role Assignments
You can audit your role assignments using the
Unassigned Roles Audit
report. You can also find tasks that are unassigned due to empty security group membership using the
Unassigned Tasks
report.
Reports
Below is a summary of reports related to assignable roles:
Report
Description
My Leadership Roles
Displays your position's assigned leadership roles. (You will also appear on the organization chart as the leader of any organizations to which your position has a leadership role.)
My Supporting Roles
Displays your position's assigned supporting roles.
Role Assignments for Worker Position
Displays an overview of assignable roles, security group membership, and access rights for the specified worker. The role information includes whether the role is inherited or directly assigned, and whether the role is active or inactive. You can limit results to specific roles as well as filter out inactive organizations and inherited role assignments.
Role Assignment Permissions
Displays the security group whose members can administer each role. Enables you to view or edit which security groups can assign workers to each assignable role.
Roles for Organization and Subordinates
Displays the organization hierarchy of subordinate organizations. Enables you to select an organization in the hierarchy to view all the assignable roles, the worker in each, and whether they fill that role by assignment.
Unassigned Roles Audit
Displays roles for which no positions are assigned. Details include the organization type, unassigned roles, and the minimum roles to assign to each role.
Unfilled Assigned Roles Audit
Displays roles assigned to unfilled positions. Enables you to include or exclude inactive roles in the results.
View Assignable Roles
Displays an overview of all assignable roles, including: the types of organizations for which each role is enabled; the default role, if any; and whether the role is restricted to single assignment, is hidden if not assigned, or is a leadership role. You can also see which security groups may assign specific roles. This report also includes security group and access right information associated with each role.
Worker Roles Audits
Displays the workers in a specified organization and any assignable roles, user-or job-based security groups, or process-maintained roles to which they belong.

Chapter 5 Summary

  • Use Role-based constrained security groups to grant your support and leadership staff access to targets in assigned organizations.
  • Membership in role-based security groups occurs via role assignments for the assignable role defined in the security group.
  • Access rights to subordinate organizations are dependent on the configuration of the role-based constrained security group.
  • It is important to maintain role assignments in your staffing transactions, such as change job or termination.