Concept: Sharing Tables and Datasets
Workday enables you to have fine-grained control over what you can do with tables and
datasets. Sharing tables and datasets is a way to control access to individual tables
and datasets.
When your tenant is set up for table and dataset sharing, table owners and dataset owners can
share a table or dataset with another user or security group. Example: You can control
who can view a dataset, edit the schema of a table, insert data into a table, or delete
table data.
How Inherited Permissions Work to Enable Table and Dataset Sharing
Workday provides sharing permission control using Workday roles, Workday-owned
security groups, and inherited permissions.
Most Workday roles are tied to an organization. However, table-related and dataset-related
Workday roles are tied to an object type, the table or dataset. By tying a role to
an object type, Workday enables you to control which permissions a user inherits for
a particular table or dataset.
Workday maps each table-related and dataset-related role to a Workday owned
security group, and that security group automatically inherits permissions from 1 or
more security domains.
Example: Workday maps the Workday role "Table Schema Editor" to the "Prism Table Schema Editor
(Workday Owned)" security group, and that security group inherits View and Modify
permissions on the
Prism: Tables Manage Schema
domain.Example: Workday maps the Workday role "Prism Dataset Editor" to the "Prism
Dataset Editor (Workday Owned)" security group, and that security group inherits
View and Modify permissions on the
Prism: Datasets Manage
domain.As a result of these connections, you can enable table and dataset sharing by
creating a tenant-specific role and mapping it to a table-related or dataset-related
Workday role. The tenant-specific role becomes the table or dataset permission that
you can share with others.