Edit Prism Data Source Security
- Security:Prism: Manage Data Sourcedomain in the Prism Analytics functional area.
Before you make Prism data in a table or dataset available for analysis, configure the security
(security domains and securing entities) that Workday applies to the data in the
Prism data source. You configure the data source security by editing the table or
dataset, but Workday applies the security to the data in the Prism data source.
The configured securing entities work with the configured security domains and their
security groups to determine which users have access to which rows, fields, and
field values in a Prism data source.
A securing entity is an Instance or Multi-Instance field that you use to constrain access to
particular instance values for reporting and analytics. A securing entity:
- Is typically a role-enabled Instance field, such as Cost Center or Supervisory Organization.
- Is the Person Instance field (secured to thePerson Data: Person Reportsdomain) for self-service security groups.
- Determines which instance values Workday displays to a user based on the role assigned to the user.
Use securing entities to control row-level and field value-level access in a Prism data source
for users in constrained security groups.
For a user to have access to a particular row or field value in a Prism data source, they must
be a member of 1 of these security groups:
- An unconstrained security group that has permissions on a domain configured in the data source security.
- A constrained security group that has permissions on a domain configured in the data source security, and the corresponding securing entity is configured.
Workday
restricts user access to data in a Prism data source for these security groups:
- All unconstrained
- Role-based constrained
- Aggregation when role-based
- Intersection when role-based
Workday has tested and supports using securing entity fields that use these business
objects:
- Company
- Company Hierarchy
- Cost Center
- Cost Center Hierarchy
- Person
- Location Hierarchy
- Region
- Region Hierarchy
- Supervisory Organization
- Access theEdit Data Source Securitytask for the table or dataset you want to apply security to.
- In theDomainsprompt, select 1 or more security domains to use to determine who can see the Prism data source.If you specify a security domain that has a constrained security group, then you must specify an appropriate securing entity.
- (Optional) In theSecuring Entitiesprompt, select 1 or more fields in the dataset. Workday lists the Instance or Multi-Instance fields in the table or dataset that act as securing entities.The securing entities work with the:
- Data Source Securitydomains to determine row-level access for a user.
- Field Level Securitydomains to determine field value-level access for a user.
Workday uses any in common logic when evaluating the contextual security using a Multi-Instance field.When you specify more than 1 securing entity that relates to the same security group, Workday uses the OR condition between them. Depending on how your security groups are set up, a user might see some additional rows or field values. Make sure you test the report results to ensure that the report produces expected results for each user. - In theDefault Domain(s) for Dataset Fieldsprompt, select 1 or more security domains that Workday applies to every field in the Prism data source unless you override the domain for a particular field in the next section.When you add new fields to the table or dataset, Workday applies this default domain to the new fields. You might want to consider specifying a domain with more restrictive access. Then you can override the default domain on a per field basis to allow more access as necessary.
- (Optional) You can select different domains to apply to specific fields to override the default domains.
- Review anySecurity Configuration Auditmessages to learn more about any issues with the configured securing entities and domains.
- (Optional) ClickBackto make any changes to the configured security options based on the audit messages.
- Select theApply Securitycheck box to apply your changes.If you want to restrict access to rows using any of these security group types, Workday can't honor those restrictions:
- Segment-based security groups
- Job-based security groups
- Manager's Manager security group
Workday saves the security information. You can view the current security status by selecting
.
Suppose that you select these domains containing these security groups. To enforce contextual
security at the row-level and field value-level, then use these fields as securing
entities:
Security Domain | Contains This Security Group | Use This Securing Entity |
|---|---|---|
Custom Domain 28 | HR Partner (By Location) | Location |
Custom Domain 29 | Manager | Supervisory Organization |
Custom Domain 30 | HR Administrator | None required. HR Administrator is an unconstrained security group, so it doesn't
require a securing entity. |
Public Reporting Items | None. | None required. This domain provides access to all publicly available fields and
Workday-delivered data sources. |
Create the Prism data source by enabling the table for
analysis or publishing the dataset. Workday applies the security restrictions to the
data in the Prism data source.