Configure Integration Security for Information Reporting

Permissions Required: Workday Security Administrator

To manage Integration Systems and Security Groups configurations, you'll need to be a member of the Security Administrator, Integration Administrator, and/or Implementers security group.

The naming conventions outlined below are for consistency and clarity, you may follow your own naming conventions as needed.


Create Integration System User

  1. Using the Workday search bar, navigate to the Create Integration System User task.

Search Create ISU.png
  1. Create a user named API_BankConnect.

    • Assign a secure, alphanumeric password (we do not support the following special characters:  &, ", ', < and >) — make a note of this password as it will be needed to enable your outbound connectivity in a future step.
    • Do not require a new password at next sign in.
Create ISU Modal.png

You may choose to define additional ISU settings from the Edit Workday Account task. We recommend excluding the ISU from UI sessions as an additional security measure.

Exempt ISU from Password Expiration Rules

  1. Using the Workday search bar, navigate to the Maintain Password Rules task.

maintain password rules.png
  1. In the System Users exempt from password expiration section (at the bottom of the page),add the ISU to the list of users exempt from password expiration.

Maintain PW Rules.png

Record ISU Username & Password

The ISU will be assigned to the API integration that delivers bank data to your Workday tenant; this password will be shared securely as part of your initial set-up. 

Please make note of the username and password you have assigned, you will need to share these with your onboarding team.


Create Security Group

  1. Using the Workday search bar, navigate to the Create Security Group task.

Search Create Security Group.png
  1. Create an Integration System Security Group (Unconstrained) type group named ISSG_API_BankConnect, then click OK.

Create Security Group Dialog.png

Assign ISU to the Security Group

  1. From the Edit Integration System Security Group task, assign the API_BankConnect user.

Assign ISU to ISSG.png

You can also add a comment about the purpose of this ISSG to help future Security Administrators understand the integration.


Assign Security Group Permissions

  1. Using the Workday search bar, navigate to the View Security Group task.

Search View Security Group.png

  1. Select the security group you want to assign permissions to.

View Security Group Dialog.png
  1. Navigate to Maintain Domain Permissions for Security Group from the group's related actions menu.

Maintain Permissions ISSG Rel Action.png

  1. Assign Integration Permissions to the security group; the following security policies should be added to the Integration Permissions:

Maintain Domain Security ISSG.png

Put access Get access
Process: Bank Reconciliation
Process: Bank Statement
Set Up: Bank Entity
Worker Data: Public Worker Reports
Worker Data: Staffing
Worker Data: Workers

Put access provides both Get and Put access. This ISU will have access to fetch and update Financial Institution, Bank Account, and Bank Statement data from your Workday tenant. The ISU will also enable user-linking by fetching a list of employees from your Workday tenant.

  1. Using the Workday search bar, navigate to the Activate Pending Security Policy Changes task.

Search Activate Pending Security.png

  1. Follow the prompts to activate the permissions you've just assigned:

Activate Pending Security 2-steps.png