Download PDF
Configure Security Policies for Agents
- Unique Ambient Agent Security Group is generated for ambient agents.
- Security:Security Configurationdomain in the System functional area.
Workday evaluates security differently based on the agent type:
- Delegate Agents: Workday uses the security access of the invoking user. If the invoking user already has the required domain and business process permissions for the underlying tools, no updates are necessary. Use this procedure only if the invoking user requires additional access to domains securing the agent's tools.
- Ambient Agents: Workday evaluates security solely against the permissions of the agent. When you activate a skill, ASOR generates a unique Ambient Agent Security Group (ASG). You must explicitly assign this ASG to the relevant domain or business process security policies to grant access to secured items, such as tools and APIs.
- Access theView Security for Agent Skillreport from the related actions menu of an agent skill.
- Identify the domains that secure the tools within the skill.
- Search for and select the domain security policy for the REST API endpoint or data the agent needs to access.
- From the related actions menu of the domain security policy, select .
- Complete the task:OptionDescriptionDelegate AgentFrom theSecurity Groupsprompt, select the security groups that include the invoking users who require access.Ambient AgentFrom theSecurity Groupsprompt, select the Ambient Agent Security Group.
- Select theViewandModifycheck boxes to grant the security group access to securable items.
- Select theGetandPutcheck boxes to grant security groups access to integrations.
The agent can now perform the required actions on the secured domain. For delegate agents, the specific invoking users you updated now have the permissions required to use the agent's tools.