Steps: Set Up Constrained Security to People Analytics
Security:
Manage: People Analytics
domain in these functional areas:- People Analytics
- Prism Analytics
You can provide constrained access to the People Analytics report. To provide
constrained access:
- Specify a hierarchy on the Security step when you configure the worker and hiring pipelines.
- Use role-based constrained security group in theView: People Analyticsdomain security policy.
The hierarchy that you select and the fields included in that hierarchy determine
which users have access to specific content in the application. Example: You map
these fields:
Target Field | Mapped Business Object and Source Field | Example Value |
|---|---|---|
Level 1 | Supervisory Organization - 2nd level of the hierarchy | Sales and Marketing |
Level 2 | Supervisory Organization - 3rd level of the hierarchy | North America Marketing |
Assigned Organization | Worker - Supervisory Organization | Leads Generation |
A People Analytics user who has constrained access at Level 1 can view stories
related to Level 1 and its subordinates. Therefore, a user who is assigned a role in
Sales and Marketing sees stories Sales and Marketing and North America
Marketing.
A People Analytics user who is assigned a role in North American Marketing (mapped to
Level 2) can see stories related to North American Marketing, but not to Sales and
Marketing.
Workday secures data in People Analytics at the table level and record level. Users
who have access to a record in People Analytics have access to every field in that
record.
If you need to change the security settings after the initial deployment of People
Analytics, you might consider requesting support through People Analytics Office
Hours (available as a paid service) to ensure that the change won't cause security
issues.
- Access theConfigure People Analyticsreport.
- SelectEditfor theWorkerpipeline, and proceed to theSecuritystep.
- On theSecuritystep, select eitherPrimary HierarchyorSecondary Hierarchy.The hierarchy you select must be a valid Prism securing entity field. See Hierarchy Requirements.
- On theReviewstep, selectFinishto save the changes to the Worker pipeline.
- Configure theHiringpipeline, and select the same securing hierarchy on theSecuritystep.
- SelectRun Installationon theConfigure People Analyticsreport.Wait for the installation activity to complete before proceeding so that Workday can finish securing the data records. Make sure that Workday secures the data records before you provide access to constrained users.
- Create security groups for your application viewers, and assign users.When configuring role-based constrained security groups, ensure that:
- The security group type matches the securing hierarchy that you specified. Example: You use Primary Hierarchy as the securing hierarchy, and map the Supervisory Organization field to the Assigned Organization target field. You create a security group of type Roles - Supervisory. Example: You use Secondary Hierarchy as the securing hierarchy, and map the Location field to the Level 3 target field. You create a security group of type Roles - Location Hierarchy.
- In theAccess Rights to Organizationssection, you selectApplies To Current Organization And All Subordinates.
- In theAccess Rights to Multiple Job Workerssection, you selectRoles have access to the positions they support.
- Add the role-based constrained security groups to theView: People Analyticsdomain security policy. Provide both View and Modify permissions.