Permissions Required: Workday Security Administrator
To manage Integration Systems and Security Groups configurations, you'll need to be a member of the Security Administrator, Integration Administrator, and/or Implementers security group.
The naming conventions outlined below are for consistency and clarity, you may follow your own naming conventions as needed.
Create Integration System User
Using the Workday search bar, navigate to the Create Integration System User task.
-
Create a user named API_BankConnect.
- Assign a secure, alphanumeric password (we do not support the following special characters:
&,",',<and>) — make a note of this password as it will be needed to enable your outbound connectivity in a future step. - Do not require a new password at next sign in.
- Assign a secure, alphanumeric password (we do not support the following special characters:
You may choose to define additional ISU settings from the Edit Workday Account task. We recommend excluding the ISU from UI sessions as an additional security measure.
Exempt ISU from Password Expiration Rules
Using the Workday search bar, navigate to the Maintain Password Rules task.
In the System Users exempt from password expiration section (at the bottom of the page),add the ISU to the list of users exempt from password expiration.
Record ISU Username & Password
The ISU will be assigned to the API integration that delivers bank data to your Workday tenant; this password will be shared securely as part of your initial set-up.
Please make note of the username and password you have assigned, you will need to share these with your onboarding team.
Create Security Group
Using the Workday search bar, navigate to the Create Security Group task.
Create an Integration System Security Group (Unconstrained) type group named ISSG_API_BankConnect, then click OK.
Assign ISU to the Security Group
From the Edit Integration System Security Group task, assign the API_BankConnect user.
You can also add a comment about the purpose of this ISSG to help future Security Administrators understand the integration.
Assign Security Group Permissions
Using the Workday search bar, navigate to the View Security Group task.
Select the security group you want to assign permissions to.
Navigate to Maintain Domain Permissions for Security Group from the group's related actions menu.
Assign Integration Permissions to the security group; the following security policies should be added to the Integration Permissions:
| Put access | Get access |
|---|---|
|
Process: Bank Reconciliation Process: Bank Statement Set Up: Bank Entity |
Worker Data: Public Worker Reports Worker Data: Staffing Worker Data: Workers |
Put access provides both Get and Put access. This ISU will have access to fetch and update Financial Institution, Bank Account, and Bank Statement data from your Workday tenant. The ISU will also enable user-linking by fetching a list of employees from your Workday tenant.
Using the Workday search bar, navigate to the Activate Pending Security Policy Changes task.
Follow the prompts to activate the permissions you've just assigned: