Skip to main content
Workday Education
Last Updated: 2026-07-10
Segment-Based Security

Segment-Based Security

Overview

Segmented security offers an additional level of security by limiting access to the values of a given secured item. Segment-based security groups grant membership based on included security groups such as job-based, role-based, or user-based. This chapter covers how to configure segment-based security to restrict access to segmented items, the primary use cases for segmented security, and the available segment types.

Objectives

By the end of this chapter, you will be able to:
  • Configure segmented security for expenses.
  • Identify use cases for segmented security.
  • Identify differences in configuration steps for segmented security across functional areas.

Segment-Based Security Groups

Segmented security allows you to define segments for granular access to the values of a secured item. For example, you can control the values that appear in prompts, such as the expense items available for a user when creating an expense report. Segment-based security groups allow you to configure which security groups can access what segment of values.
Some items available for segmentation are:
  • Expense Items
  • Integration Systems
  • Document Categories
  • Pay Components
  • Learning Categories
Segment-based security group expense example.
Segment-based security groups grant membership based on existing security groups, such as job-based, role-based, or user-based. Constraints depend on included security groups.
The configurable security framework answers three questions:
Configurable security asks these three questions.
By placing a segment-based security group in a security policy, members have constrained or unconstrained target access to values defined in permitted segments.
Segment-based security group example.
Configuration
To set up segment-based security groups, you must:
  1. Determine who needs access to what segment of values. Identify members with existing security groups or create new security groups if needed.
  2. Determine what values to secure in what segments. Create and maintain the security segments by adding values to needed segments.
    Note
    : Define values before adding them to segments (e.g., Expense Items, Document Categories).
  3. Determine which security groups can access which security segments. Create and maintain the segment-based security groups.
  4. Configure the segment-based security groups in the necessary domain security policies to enable segmented access.
You may need to complete an additional one-time configuration for certain types of segments. Refer to Workday Documentation for specific steps regarding the type of segmented security you would like to deploy.
Example
: To configure segments for compensation setup data, such as compensation plans, first select the Enable Compensation Setup Segment Security checkbox in the
Edit Tenant Setup - HCM
task.
In addition, you must maintain your security segments to keep them current with the values configured in Workday. Remember to add any new item values to existing security segments or create new security segments and segment-based security groups for new items you create.

Job-Based Security Groups

Use job-based security groups to identify members based on a single job criterion (e.g., job profile, job family, management level, exempt vs. nonexempt jobs). Target access can be constrained or unconstrained.
Relevant job criteria include:
  • Job Profile
  • Job Category
  • Job Family
  • Management Level
  • Work Shift
  • Include Exempt Jobs
  • Include Non-Exempt Jobs
Job-based security groups are common in other security group types such as segment-based and intersection.

Types of Segments

Segmented security is only available in certain areas of Workday. Workday determines the items available to segment.
Securable items often configured with segmented security include:
  • Document Categories
  • Integration Systems
  • Pay Components
  • Requisition Spend Categories (Procurement)
Common types of security segments.
Create Security Segments
Explore the below examples of creating security segments to understand how granular segments can be.
Create Learning Security Segment
Use the
Create Learning Security Segment
task to provide specific users permission to create and access learning content.
A screenshot of the Create Learning Security Segment window. The Learning Security Segment Name field contains the text "Sales and Marketing Learning Security Segment." There are two radio button options allowing you to select one of two fields, Learning Catalog or Learning Topic. Learning Topic is selected. The Learning Topic field is set to Sales and Marketing, with a multitude of other Learning Topic options available to select in the dropdown below the field. The Learners With Access field is blank. The Inactive checkbox is unchecked.
You can secure:
  • At the program and course level by associating the content with a security category segment.
  • At the topic level.
You can also do a combination of topic and security category-based segmented security. Access to a security category on a program or course takes precedence over access to a topic. If you want to enable learners to select from the complete list of topic preferences, do not restrict access on a topic-by-topic basis.
Create Business Process Security Segment
Use the
Create Business Process Type Security Segment
task to configure security segments for business process definitions. This allows you to control which business processes a business process administrator can access.
A screenshot of the Create Business Process Type Security Segment window. The Name field contains the text "Staffing Business Process Security Segment." The Business Process Type field is set to Termination, Change Job, Change Work Space, and Close Position, with a few other Business Process Type options available to select in the dropdown below the field. The Functional Area field is blank.
For example, Jordan and Taylor are business process administrators. You want Jordan to have access to only staffing-related business processes and Taylor to have access to only finance-related business processes. You can meet these requirements by creating business process type security segments using functional areas and/or specific business process types.
Access to the following business process components cannot be segmented:
  • Rules
  • To Dos
  • Checklists
  • Calculated Dates
Create Integration Security Segment
Use the
Create Integration System Security Segment
task to configure segments based on categories, templates, or specific integration systems. Note that we cover integration system security segments in detail in another chapter.
A screenshot of the Create Integration System Security Segment window. The Name field contains the text "Templates: Remittance." Under the Selection Criteria section, there are radio buttons for four field options: By Category, by Template, Specific Integration System, and All Integration Systems. By Template field is selected, and set to WPN - Generic Remittance, with a multitude of other By Template options available to select in the dropdown below the field.
Security Policy Configuration for Segments
The domain security policy configuration requirements for segmented security vary across Workday functional areas. For each type of segmented security, you must configure administrator access to create and edit security segments. Also configure user access to view the designated segments. Place segment-based security groups on the appropriate domain security policy in the relevant functional area. This table lists many of the different types of segments currently available in Workday. Please follow the latest documentation and release updates for new segment types. To create and manage the security segments for each type, you must have access to the domain listed in the Setup Domain column. To give workers segmented access to values, you must configure the segment-based security groups to the domains listed in the Access Domain column. Remember that the segment-based security group type allows you to specify which included security groups should have access to which security segment of values.
Segment Type
Setup Domain
Access Domain
Ad Hoc Payment Spend Category
Cash Management Segmented Setup
Access Ad Hoc Payment Spend Category (Segmented)
Audit Tag
Set Up: Audit Tag Security Segments
Set Up: Audit Tags and Assignments - Add Only Set Up: Audit Tags and Assignments
Bank Account
Cash Management Segmented Setup
Access Ad Hoc Payment Bank Account (Segmented)
Benchmark Subcategory
Benchmark Management
Benchmark Values
Business Process Type
Security Configuration
Manage: Business Process Definitions
Campaign Category
Set Up: Campaign Type Categories
Administer Campaigns
Compensation Setup
Set Up: Compensation Security Segments
Varies
Compensation Plan Assignment
Set Up: Compensation Security Segments
Worker Data: Funded Plan Assignments Self-Service: Funded Plan Assignments
Country-Specific Personal Information
Country Segment Setup
Person Data: Personal Data
Customer
Set Up: Customer Security Segments
Access Customer (Segmented)
Document Category
Set Up: Document Category Security Segments
Worker Data: Add Worker Documents Worker Data: Edit and Delete Worker Documents
Expense Item
Set Up: Expense Item Security Segments
Access Expense Item (Segmented)
Integration System
Security Configuration / Integration Security
Multiple
Investor
Investor Segmented Setup
Access Investor (Segmented)
Learning Security Category
Set Up: Learning Security Segments
Learning Access
Learning Topic
Set Up: Learning Security Segments
Learning Access
Leave Type
Set Up: Leave of Absence
Access Leave Type (Segmented)
Ledger Account
Set Up: Ledger Account Security Segments
Access Ledger Account (Segmented)
Message Queue
Integration Build
Message Queue (Segmented)
Metric
Metric Management
Metrics in Review or Metrics Published
Pay Component
Set Up: Payroll (Calculations - Payroll Specific)
Reports: Pay Calculation Results
Questionnaire
Set Up: Questionnaire Security Segments
Questionnaire Creation and Distribution Questionnaire Results Candidate Data: Questionnaires
Recruiting Assessment Category
Set Up: Recruiting Assessment Category Security Segments
Candidate Data: Assessment Results
Reference Letter
Set Up: Reference Letters
Set Up: Reference Letter Segment
Request Type
Set Up: Request Type Security Segments
View: Requests
Requisition Spend Category
Set Up: Procurement Security Segments
Access Requisition Spend Category (Segmented)
Requisition Supplier
Set Up: Procurement Security Segments
Access Requisition Supplier (Segmented)
Student Holds
Set Up: Hold Reason Segments
Access Hold Reasons Manage: Apply Holds
Student Notes
Set Up: Students Notes Security Segment
Manage: Add Student Notes
Supplier
Set Up: Supplier Security Segments
Access Supplier (Segmented)
Supplier Contract
Set Up: Procurement Security Segments
Access Requisition Supplier Contract (Segmented)
Supplier Contract Type
Set Up: Supplier Contract Security Segments
Access Supplier Contract Type (Segmented)
Supplier Link
Set Up: Procurement Security Segments
Access Requisition Supplier Link (Segmented)
Talent Statement Type
Set Up: Skills and Experience
Access Talent Statement Type (Segmented)
Time Off
Set Up: Time Off
Access Time Off (Segmented)
Important
: When adding a segment-based security group to a domain security policy, remove any references in the security policy to the included security groups.
Note
: Workday delivers some additional segments for use in segment-based security groups (e.g., plan types). When selecting segments for the segment-based group, select Security Segments (Workday Owned) to view the available segments.

Use Case: Document Categories

Because Workday secures worker documents to a single domain, customers frequently use segmented security with document categories. Without segmentation, security groups with permission to the Worker Data: Add Worker Documents and Worker Data: Edit and Delete Worker Documents domains would be able to view all documents for a given worker. By using document category values to identify the type of document and then using segment-based security, you can configure access to specific document category values.
Example
: Benefits partners and administrators may be able to view and modify worker documents in the Benefits document category via the Documents - Benefits Categories segment-based security group.
Use the
Create Document Category Security Segment
and
Edit Document Category Security Segment
tasks to define segments of values. Workday secures these tasks to the Set Up: Document Category Security Segments domain. Define document categories using the
Maintain Document Categories
task. A given document category security segment can contain one or more document category values and a segment-based security group can give members access to one or more security segments.
Edit Document Category Security Segment task.
The following example gives the recruiter-related security groups access to view worker contract-related documents, such as offer letters and employment contracts.
The recruiter-related security groups can view worker contract-related documents.
In addition to domain access for worker documents, also look for worker documents attached as part of a business process event. Security groups with View All access to the business process will be able to access documents associated with the event. You can also configure access to attachments separately.

Chapter 8 Summary

  • Segmented security uses defined segments to allow for granular access to the values of a given secured item.
  • Segment-based security groups grant members access to defined segments of values.
  • The included security groups define the membership.
  • Segmented security is only available in certain areas of Workday.