Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Concept: Security in People Analytics

Concept: Security in People Analytics

Workday enforces security when you:
  • Administer and configure People Analytics.
  • View the People Analytics application.
For the initial deployment of People Analytics, you work with a Workday consultant to determine which security settings best fit your organization and support your desired use of the application. However, you can use the
Configure People Analytics
report to make changes after the initial deployment. Any change you make to the domain security policy groups, organization hierarchies, or securing hierarchy will impact the data viewers see in the application.
If you want to make post-deployment changes to your security configuration, you might consider requesting assistance with People Analytics Office Hours (available as a paid service).

People Analytics Application Security

When you view the People Analytics application using the
People Analytics
report, Workday uses its configurable security model to control which users have access to specific data. Workday controls access to the data in:
  • Stories
  • KPIs
  • Vizzes
  • Specific data records
Although the People Analytics data comes from the business objects in your tenant, Workday resets all security domains configured for the business objects and applies new security that you define. The new security that Workday applies is determined by:
  • The specified groups in the
    View: People Analytics
    domain security policy
  • The selected setting in the Security step when you configure a pipeline in People Analytics. You can configure unconstrained or constrained access.

Configuring People Analytics Security

When configuring People Analytics, you decide whether or not to constrain access to the data in the People Analytics application. When you configure the Hiring and Worker pipelines, you specify how to secure access to the data on the
Security
step.
On the Security step, you can configure either:
  • Unconstrained access. Select Unconstrained Access, and use either a user-based or unconstrained role-based security group in the
    View: People Analytics
    domain security policy.
  • Constrained access. Select either the Primary Hierarchy or Secondary Hierarchy. The securing hierarchy that you select and the fields included in that hierarchy determine which users have access to specific data in the application. For more information, see Steps: Set Up Constrained Security to People Analytics.
Workday constrains access at the record level, not the field level.
This means that a user who is constrained at a specific level within the selected hierarchy can view insights only for that level and subordinate levels.

How Contextual Security Works

When you provide constrained access to People Analytics, different users will see different data. How Workday displays the data in People Analytics depends on:
  • The content type
  • The user’s role and organization level permissions
Content Type
Notes
KPIs and Stories
Workday displays stories based on your org level security access at Level 1, Level 2, and Level 3.
Vizzes
Workday displays every viz, such as Gender Trend, but only calculated on the records you have access to at any level.

Security Domains and Groups

People Analytics uses these domains in the People Analytics and Prism Analytics functional areas:
Domain
Details
Associated Reports and Tasks
Manage: People Analytics
Can configure, install, and maintain People Analytics.
Supports unconstrained security groups.
  • Configure People Analytics
  • People Analytics Activities
  • People Analytics Data Quality
  • People Analytics
View: People Analytics
Can access the People Analytics application.
Supports unconstrained security groups and role-based constrained security groups.
  • People Analytics