TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Workday

Estimated reading: 3 minutes 2155 views

Set up Workday for automated tests with TrustCloud

TrustCloud’s API-based integrations map seamlessly to your frameworks and controls to power automated evidence collection, continuous monitoring, and predictive risk analysis. Let’s explore how you can set up Workday for automated tests.

By granting TrustCloud limited access to metadata through a service principal account, you can ensure that your systems remain compliant with your adopted controls. TrustCloud’s focus on trust, security, and simplifying compliance makes it a valuable asset in the GRC landscape.

Read our GRC Launchpad article: Integrations to learn more.

Explore 100+ evidence collection integrations to power evidence collection and real-time risk analysis.

Purpose

Once you set up your compliance program, TrustCloud works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests against systems in your product and business stack and verifies that they are properly configured.

This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Workday account so that TrustOps can validate and generate evidence for your compliance program.

Instructions to grant TrustCloud limited access

  1. Go to ‘Create Security Group’ in Workday and create an ‘Integration System Security Group’.
  2. Grant permissions to your newly created security group. For each domain, to grant access,
    1. Go to the ‘View Domain’ report and find the domains listed below
    2. Click on ‘Domain’ and then click on ’Edit Security Policy Permissions’.
    3. Add the security group, and grant permissions for GET.
    4. Required domains for the Workday HRIS integration:
      1. Worker Data: Workers
      2. Worker Data: All Positions
      3. Worker Data: Current Staffing Information
      4. Worker Data: Employment Data
      5. Worker Data: Organization Information
    5. Additionally, grant access to the following security policies:
      1. Integration Build
      2. Integration Process
      3. Integration Debug
      4. Integration Event
    6. Activate these permissions by clicking ‘Activate Pending Security Policy Changes’.
    7. Go to ‘Create Integration System User (ISU)’ and configure a user to integrate with TrustOps.
    8. Set the ‘Session Timeout Minutes’ to 0 to prevent session expiration.
    9. Go to ‘Maintain Password Rules’ and add the ISU to the ‘System Users’ exempt from a password expiration.
    10. Optionally, enable the ‘Do Not Allow UI Sessions’ checkbox to block the ISU from logging in through the Workday UI.
    11. After creating the ‘Integration System User’, click on ‘Security Profile’ and  click on “Assign Integration System Security Groups”.
    12. Select the security group you created previously, go to ‘View Integration System Report’, and access the ‘Connector’ or ‘Studio integration’.
    13. Go to Workday Account. Click on ‘Edit’ and select ‘Integration System User’.
    14. Copy the username and password for future reference.
    15. Retrieve the Tenant ID. It can be found in the URL when you are logged into Workday. For example, if the URL of your Workday UI is https://impl.workday.com/sample_company/d/home.html, your tenant ID is sample_company.
    16. Retrieve the Workday WSDL URL that is used as the base URL for every API request. The WSDL URL can be found here: https://community.workday.com/articles/6120#endpoint. If you are unsure, then use https://wd2-impl-services1.workday.com/ccx/service/.
    17. Provide the user name, Password, Tenant ID, and Workday WSDL URL into TrustOps.

Data feeds

Types of control testing that TrustCloud enables with Workday:

  1. Access Requests
  2. Access Termination

To automate the continuous monitoring of these controls, TrustCloud pulls the following sample of data feeds from Workday.

Read Only: Employee Details
   - employee display/preferred name
   - work email
   - employment start date
   - employment end date
   - employee latest role start date
   - department
   - job title
   - manager

Additional Information

For additional details, you can refer to the API Deck Workday Integration guide.

Join the conversation

You might also be interested in

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Google Cloud Platform

This document outlines the steps you can take to grant TrustCloud access to only...

Bitbucket

Instructions to grant TrustCloud read-only access to your Bitbucket organization...

Hybrid Data Fabric

The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external...

Okta

Set up Okta for automated tests with TrustCloud! This document outlines the steps you...

ServiceNow

Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps...

Tenable.io

This document outlines the steps you can take to grant TrustCloud access to only...

Jira Cloud

Set up Jira Cloud for Jira Ticket as Evidence with TrustCloud! This document outlines...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue