Skip to main content
Administrator Guide
Last Updated: 2023-06-23
Download PDF
Configure Security Policies for Agents

Configure Security Policies for Agents

  • Unique Ambient Agent Security Group is generated for ambient agents.
  • Security:
    Security Configuration
    domain in the System functional area.
Workday evaluates security differently based on the agent type:
  • Delegate Agents: Workday uses the security access of the invoking user. If the invoking user already has the required domain and business process permissions for the underlying tools, no updates are necessary. Use this procedure only if the invoking user requires additional access to domains securing the agent's tools.
  • Ambient Agents: Workday evaluates security solely against the permissions of the agent. When you activate a skill, ASOR generates a unique Ambient Agent Security Group (ASG). You must explicitly assign this ASG to the relevant domain or business process security policies to grant access to secured items, such as tools and APIs.
  1. Access the
    View Security for Agent Skill
    report from the related actions menu of an agent skill.
  2. Identify the domains that secure the tools within the skill.
  3. Search for and select the domain security policy for the REST API endpoint or data the agent needs to access.
  4. From the related actions menu of the domain security policy, select
    Security Policy
    Edit Domain Security Policy
    .
  5. Complete the task:
    Option
    Description
    Delegate Agent
    From the
    Security Groups
    prompt, select the security groups that include the invoking users who require access.
    Ambient Agent
    From the
    Security Groups
    prompt, select the Ambient Agent Security Group.
  6. Select the
    View
    and
    Modify
    check boxes to grant the security group access to securable items.
  7. Select the
    Get
    and
    Put
    check boxes to grant security groups access to integrations.
The agent can now perform the required actions on the secured domain. For delegate agents, the specific invoking users you updated now have the permissions required to use the agent's tools.