Setup Considerations: Audit Trails
You can use this topic to help make decisions when planning your configuration and use of audit
trails. It explains:
- Why to set it up.
- How it fits into the rest of Workday.
- Downstream impacts and cross-product interactions.
- Security requirements and business process configurations.
- Questions and limitations to consider before implementation.
Refer to detailed task instructions for full configuration details.
What It Is
Audit trails is a method of tagging, monitoring, and reporting on changes to instances of
business processes, certain report types, user-based security groups, domain
security policies, and integration systems in your tenant. Audit trails track:
- What changed.
- Who changed it.
- When it was changed.
Business Benefits
Audit trails is the quickest and most efficient way to identify configuration changes
in your tenant. It allows you to:
- Identify changes and verify whether they're appropriate.
- Fix inappropriate changes quickly.
- Meet change management compliance standards.
Use Cases
You can use audit tags to:
- Track a change on a calculation field that you use in a condition rule that is in turn used in a step in a business process.
- Track a change to a filter in a row on a custom report.
- Track a change to a security group or a change to permissions on a domain security policy.
Questions to Consider
Question | Consideration |
|---|---|
What instances of business processes, report types, user-based security
groups, domain security policies, and integration systems do you want to
audit? | Determine which instances of business processes, report types, security
groups, domain security policies, and integration systems are in scope for
your audit. Tag those instances and view changes in the Audit Trail
Report. |
Do you want to limit users' access to audit some or all
instances? |
Restrict access to audit tags by assigning them to
audit tag segments. Only users who belong to a segment-based security group
in the Set Up: Audit Tags and Assignments - Add Only domain or the
Set Up: Audit Tags and Assignments domain can access these audit
tags. |
Which instances that you want to audit are supported in the new Audit
Trail Report? | Determine which instances you want to audit. You can audit instances of
business processes, report types, security groups, domain security policies,
and integration systems using the Audit Trail Report and the Audit Trail
Configuration Report. You can audit other instances not reported on in the
Audit Trail Report and the Audit Trail Configuration Report using one of the
reports in "Reporting" below. |
Recommendations
We recommend that you use the Audit Trail Report and the Audit Trail Configuration Report
together. The Audit Trail Report reports on the relationships that are relevant to
each instance you tag for auditing. The Audit Trail Configuration Report reports on
the relationships
Workday uses
to find changes on instances related to your
primary (tagged) instances. Requirements
No impact.
Limitations
We enable you to audit only instances of:
- Business processes.
- Certain report types.
- Domain security policies.
- Integration systems.
- User-based security groups.
Tenant Setup
No impact.
Security
Domains | Considerations |
|---|---|
Audit Tag (Segmented) in the System functional area | Enables you to create and edit audit tag segments and to assign audit
tags to audit tag segments. |
Set Up: Audit Tags and Assignments in the System functional
area | Enables you to create, edit, and delete audit tags and audit tag
assignments. |
Set Up: Audit Tags and Assignments – Add Only in the System functional
area | Enables you to create and edit audit tags and audit tag
assignments. |
Business Processes
No impact.
Reporting
Report | Considerations |
|---|---|
Audit Trail | You can tag instances of business processes, certain report types,
user-based security groups, domain security policies and integrations, and
run the report for the tagged instances to view the lineage of
changes. |
Audit Trail Configuration Report | You can view:
|
Audit Tag by Tag | You can view all active and inactive audit tags in your tenant, as well
as tagged instances under each audit tag. |
Business Process Security Policy History | You can view changes made to 1 or more business process security
policies within a selected date range. This report shows the date of change
and the person who made the change. |
Business Process Security Policies Changed Within Time Range | You can view all changes made to business process security policies
within a selected date range. This report shows the date of change and the
person who made the change. |
Domain Security Policy History | You can view changes made to 1 or more domain security policies within
a selected date range. This report shows the date of change and the person
who made the change. |
Domain Security Policies Changed Within Time Range | You can view all changes made to domain security policies within a
selected date range. This report shows the date of change and the user who
made the change. |
View Audit Tag | You can view all audit tags in your tenant. |
View Audit Tag Segment | You can view all audit tag segments in your tenant. |
View User or Task or Object Audit Trail (UTO) | You can view changes made to any instances within a time range and by a
specific user. Workday generates this report instantly and displays it in
your tenant. It has a maximum displayable limit, so, if necessary, you can
run the Create Audit Log task to generate the same report as a background
process that produces an Excel file. |
Worker Change History | You can view a summary of worker changes in 1 or more organizations for
a selected date range. |
Processed Transactions for Range, System Account, Task and Business
Object
data source to view changes to various instances that none of the Workday
delivered reports address. Integrations
You can run these audit trails web services to upload and retrieve data through an
EIB.
Web Services | Considerations |
|---|---|
Get Audit Tag Assignments | To add primary instances to, or remove primary instances from, audit
tags, use both the Get Audit Tag Assignments and the Put Audit Tag
Assignments web services. |
Get Audit Tags | To add a tag to an instance, use both the Get Audit Tags and the Put
Audit Tag web services. |
Get Audit Tag Segments | Use this web service to secure an audit tag. |
Put Audit Tag | To add a tag to an instance, use both the Get Audit Tags and the Put
Audit Tag web services. |
Put Audit Tag Assignment | To add primary instances to, or remove primary instances from, audit
tags, use both the Get Audit Tag Assignments and the Put Audit Tag
Assignments web services. |
Put Audit Tag Segment | Use this web service to secure an audit tag. |
Connections and Touchpoints
Workday offers a Touchpoints Kit with resources to help you understand configuration
relationships in your tenant. Learn more about the Workday Touchpoints
Kit on Workday Community.