Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Steps: Set Up Constrained Security to People Analytics

Steps: Set Up Constrained Security to People Analytics

Security:
Manage: People Analytics
domain in these functional areas:
  • People Analytics
  • Prism Analytics
You can provide constrained access to the People Analytics report. To provide constrained access:
  • Specify a hierarchy on the Security step when you configure the worker and hiring pipelines.
  • Use role-based constrained security group in the
    View: People Analytics
    domain security policy.
The hierarchy that you select and the fields included in that hierarchy determine which users have access to specific content in the application. Example: You map these fields:
Target Field
Mapped Business Object and Source Field
Example Value
Level 1
Supervisory Organization - 2nd level of the hierarchy
Sales and Marketing
Level 2
Supervisory Organization - 3rd level of the hierarchy
North America Marketing
Assigned Organization
Worker - Supervisory Organization
Leads Generation
A People Analytics user who has constrained access at Level 1 can view stories related to Level 1 and its subordinates. Therefore, a user who is assigned a role in Sales and Marketing sees stories Sales and Marketing and North America Marketing.
A People Analytics user who is assigned a role in North American Marketing (mapped to Level 2) can see stories related to North American Marketing, but not to Sales and Marketing.
Workday secures data in People Analytics at the table level and record level. Users who have access to a record in People Analytics have access to every field in that record.
If you need to change the security settings after the initial deployment of People Analytics, you might consider requesting support through People Analytics Office Hours (available as a paid service) to ensure that the change won't cause security issues.
  1. Access the
    Configure People Analytics
    report.
  2. Select
    Edit
    for the
    Worker
    pipeline, and proceed to the
    Security
    step.
  3. On the
    Security
    step, select either
    Primary Hierarchy
    or
    Secondary Hierarchy
    .
    The hierarchy you select must be a valid Prism securing entity field. See Hierarchy Requirements.
  4. On the
    Review
    step, select
    Finish
    to save the changes to the Worker pipeline.
  5. Configure the
    Hiring
    pipeline, and select the same securing hierarchy on the
    Security
    step.
  6. Select
    Run Installation
    on the
    Configure People Analytics
    report.
    Wait for the installation activity to complete before proceeding so that Workday can finish securing the data records. Make sure that Workday secures the data records before you provide access to constrained users.
  7. Create security groups for your application viewers, and assign users.
    When configuring role-based constrained security groups, ensure that:
    • The security group type matches the securing hierarchy that you specified. Example: You use Primary Hierarchy as the securing hierarchy, and map the Supervisory Organization field to the Assigned Organization target field. You create a security group of type Roles - Supervisory. Example: You use Secondary Hierarchy as the securing hierarchy, and map the Location field to the Level 3 target field. You create a security group of type Roles - Location Hierarchy.
    • In the
      Access Rights to Organizations
      section, you select
      Applies To Current Organization And All Subordinates
      .
    • In the
      Access Rights to Multiple Job Workers
      section, you select
      Roles have access to the positions they support
      .
  8. Add the role-based constrained security groups to the
    View: People Analytics
    domain security policy. Provide both View and Modify permissions.