Skip to main content
Administrator Guide
Last Updated: 2026-02-06
Download PDF
Set Up Self-Service Agent

Set Up Self-Service Agent

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
Flex credits are only required for registering and using agents in your production tenants. You won’t be able to register and use any agents in production until you’ve opted into these agreements. uMSA is required for non-Production and Production tenants for Workday-Built agents. uMSA won’t be required for non-Production tenants for self-built agents.
  • Opt-in to the Workday Flex Credits and Platform Entitlement Policy - only required for usage in production tenants.
  • Security: These domains in the Agent System of Record functional area:
    • Agent Compliance
    • Agent Management Hub
    • Manage: Agents
    • Reports: Agent Reporting
    • Reports: AI Agent Security
    • Setup: Agents
  • Security: The
    Workday Graph API Applications
    domain in the System functional area.
You can register, configure, and activate the Self-Service agent in Workday using the
Agent Management Hub
.
  1. Access the
    Agent Management Hub
    report.
  2. Select the
    Unregistered Workday Agent
    tab.
  3. For the
    Self-Service Agent
    , click
    Register
    .
  4. Select the
    Confirm
    check box, and then click
    OK
    to complete the registration.
    Workday moves the
    Self-Service Agent
    to the
    Agent Registry
    tab.
  5. Select the
    Agent Registry
    tab and then click on the
    Self-Service Agent
    name to configure the agent.
  6. From the agent's profile view, click
    Configure Agent
    .
  7. From the
    Status
    column, make each relevant skill available by enabling the toggle slider.
  8. For each available
    Skill
    , populate the
    Available To
    prompt with the security groups that you want to provide access to for that specific skill.
    Example: For the
    ESS - Human Capital Management - Base
    skill, select the
    Employee As Self
    security group to provide employees access to this skill and for the
    MSS - Human Capital Management - Base
    skill, select the
    Manager
    and
    Management Chain
    security groups to only provide managers in a management chain access to the skill.
    Workday evaluates both user access to the agent and the user access to the APIs the agent is executing as tools at runtime, so Workday recommends that you evaluate alignment between the security groups in the
    Available To
    prompt and the security groups that have permissions for the
    Tools
    the agent might execute. Use the
    View Security for Agent Skill
    report to view detailed information about the agent’s tool APIs and the respective domain or business process security policies and permissions. We also recommend that you consult the Self-Service-Agent-Security-Troubleshooting Sheet for additional security troubleshooting.
    Workday automatically defaults the ESS skills as active with
    Employee as Self
    as the
    Available To
    security group. While you can override these defaults, you must keep the
    Guide
    skill as always active because this is the core skill the agent is required to run on.
  9. Click
    Activate
    .
Workday displays the Workday chat bubble icon in the global navigation for you and your employees. Employees that have access to the security groups you specified for each skill and the domain or business process security policy associated with the APIs that make up each skill can use the Self-Service Agent.