Concept: Security in People Analytics
Workday enforces security when you:
- Administer and configure People Analytics.
- View the People Analytics application.
For the initial deployment of People Analytics, you work with a Workday consultant to determine
which security settings best fit your organization and support your desired use of the
application. However, you can use the
Configure People Analytics
report to make changes after the initial deployment. Any change you make to the domain
security policy groups, organization hierarchies, or securing hierarchy will impact the
data viewers see in the application.If you want to make post-deployment changes to your security configuration, you might consider
requesting assistance with People Analytics Office Hours (available as a paid
service).
People Analytics Application Security
When you view the People Analytics application using the
People
Analytics
report, Workday uses its configurable security model to
control which users have access to specific data. Workday controls access to the
data in:- Stories
- KPIs
- Vizzes
- Specific data records
Although the People Analytics data comes from the business objects in your tenant,
Workday resets all security domains configured for the business objects and applies
new security that you define. The new security that Workday applies is determined
by:
- The specified groups in theView: People Analyticsdomain security policy
- The selected setting in the Security step when you configure a pipeline in People Analytics. You can configure unconstrained or constrained access.
Configuring People Analytics Security
When configuring People Analytics, you decide whether or not to constrain access to
the data in the People Analytics application. When you configure the Hiring and
Worker pipelines, you specify how to secure access to the data on the
Security
step.On the Security step, you can configure either:
- Unconstrained access. Select Unconstrained Access, and use either a user-based or unconstrained role-based security group in theView: People Analyticsdomain security policy.
- Constrained access. Select either the Primary Hierarchy or Secondary Hierarchy. The securing hierarchy that you select and the fields included in that hierarchy determine which users have access to specific data in the application. For more information, see Steps: Set Up Constrained Security to People Analytics.
Workday constrains access at the record level, not the field level.
This means that a user who is constrained at a specific level within the selected
hierarchy can view insights only for that level and subordinate levels.
How Contextual Security Works
When you provide constrained access to People Analytics, different users will see
different data. How Workday displays the data in People Analytics depends on:
- The content type
- The user’s role and organization level permissions
Content Type | Notes |
|---|---|
KPIs and Stories | Workday displays stories based on your org level security access at
Level 1, Level 2, and Level 3. |
Vizzes | Workday displays every viz, such as Gender Trend, but only calculated
on the records you have access to at any level. |
Security Domains and Groups
People Analytics uses these domains in the People Analytics and Prism Analytics
functional areas:
Domain | Details | Associated Reports and Tasks |
|---|---|---|
Manage: People Analytics
| Can configure, install, and maintain People Analytics. Supports unconstrained
security groups. |
|
View: People Analytics
| Can access the People Analytics application. Supports unconstrained
security groups and role-based constrained security
groups. |
|