Workday HRIS Integration Setup
This article explains how to configure the Workday HRIS integration with Ashby. Ashby connects to Workday using several Workday APIs, each of which requires varying user and permission configurations. The setup has three phases:
- Configuring Ashby's Integration System User (ISU)
- Creating the API Client for Integrations for Ashby
- Configuring domain security for Ashby's ISU
In each phase, we advise you to copy down important information that you need to configure within Ashby to connect your Ashby and Workday instances.
For an overview of the Workday API migration, see Workday ATS -> Ashby Recruiting API Migration GuideWorkday ATS -> Ashby Recruiting API Migration Guide.
For more on syncing Workday positions with Ashby and hired Ashby candidates with Workday, see WorkdayWorkday.
For frequently asked questions, see Workday Integration FAQWorkday Integration FAQ.
Configuring Ashby's Integration System User (ISU)
- Log in to your Workday application using an Administrator account.
- In the application's search box, search for create user and then select Create Integration System User.
- Enter a User Name and Password. As a username, we recommend Ashby_ISU.
Copy down the username and password for future configuration within Ashby. Some of Workday's Copy UI can copy unnecessary details of fields, so check that you are copying just the username and password.
- Leave the Require New Password at Next Sign In checkbox unchecked, as this user accesses Workday programmatically.
- Leave the Session Timeout Minutes field with its default value of 0, which prevents the user's sessions from timing out prematurely.
- Select the option Do Not Allow UI Sessions (this prevents the account from logging into Workday).
If possible, make sure the password does not expire. Otherwise, Ashby's sync stops when the password expires. You can do this by going to the Maintain Password Rules task and adding Ashby's ISU to the System Users exempt from password expiration field.
Create the API Client for Integrations for Ashby
For syncing and mapping certain fields, Ashby needs additional access to the Workday API to run custom reports. We run this report using Workday Query Language (WQL) via Workday's REST API. Access to the REST API requires a special API client to be configured.
- Open the Register API Client for Integrations task (via Workday search).
- Use the following configuration:
- Client Name: Ashby API Access
- Non-Expiring Refresh Tokens: ✅
- Scope: System, Recruiting, Staffing, Pre-Hire Process, Organizations and Roles, Jobs & Positions, Integration, Tenant Non-Configurable, Public Data (allows high level access to recruiting and reporting data; data within is still guarded by domain security).
- Included Workday Owned Scope: ✅ (access to "workday owned" fields)
- Click OK.
- On the page that appears, copy down the client ID and secret.
The client ID and secret are needed to configure REST API access for Ashby.
- On the same page, click the ... menu next to the client name in the blue header at the top, and then choose API Client > Manage Refresh Tokens for Integrations.
- In the Workday Account box in the dialog that appears, find and choose Ashby's ISU, and then click OK.
- On the next page, check the Generate New Refresh Token box, and then click OK.
- Copy down the refresh token that appears on the next page.
The refresh token is needed to configure REST API access for Ashby.
- Go to the View API Clients report (via Workday search).
- On this page, there are three "endpoints" at the top.
Copy these down. These endpoints are needed to configure REST API access for Ashby.
Collect final tenant information
Most of the Workday-side configuration is now done. We just need to collect a few final pieces of information before going to Ashby to configure the connection.
Workday Tenant ID
Your Workday Tenant ID is found in the URL when you're logged into Workday. For example, if the URL is https://impl.workday.com/example/d/home.html, your Tenant ID is "example."
Copy your Tenant ID down for configuration within Ashby.
WSDL URL
Your Web Services Description Language (WSDL) URL can be found by following the relevant Workday article. In short:
- Type Public Web Services in the Workday search bar.
- Under Reports, select Public Web Services.
- From the Public Web Services list, select any one and click the ellipsis icon to reveal a drop-down menu. Select Web Service > View WSDL, which displays the full WSDL XML in a separate window.
- Search the XML for a URL containing the text ccx/service. Copy that URL up to and including the ccx/service piece. This is the WSDL URL you add to Ashby. It may look something like https://wd2-impl-services1.workday.com/ccx/service.
Copy the WSDL URL for configuration within Ashby.
Configure security for Ashby's ISU
Create a security group
In this step, you create an unconstrained Integration System Security Group in Workday and assign the ISU created in the previous step to this group.
- In the search box, search for "security group" and then select Create Security Group.
- Complete the Create Security Group task.
- Select Integration System Security Group (Unconstrained) from the Type of Tenanted Security Group dropdown.
- After the security group is created, you see a page where you can assign members to the security group.
- Add the new ISU created in the previous step to this security group.
Configure domain security policy permissions
In this step, you grant "domain security" policy permissions that allow Ashby access to recruiting and HR data domains related to the Ashby Analytics integration.
- Enter Security Group Membership and Access in the search box and click on the report link.
- Search and select the security group created in the previous step.
- Click on the ellipsis ... next to the group name and from the menu, select Security Group > Maintain Domain Permissions for Security Group.
- Add the following domains to the Domain Security Policies list:
In rows where multiple domains are listed, all domains after the first may be included or inherited by the first domain, depending on your Workday instance's security configuration. Where no reason is listed, the reason is the same as the nearest row above.
Domain Security Policy | Operation | Reason |
|---|---|---|
Manage: Organization Integration | Get Only | Get list of supervisory organizations and cost center for offers, positions, and job requisitions |
Integration Build | Get Only | Access to low-level identifiers to connect Workday objects together (e.g. a job to a location) |
Worker Data: All Positions | Get Only and View Only | Sync worker position data into Ashby Openings and view Overlap settings on Position Restrictions |
Worker Data: Public Worker Reports | Get Only | Get list of workers for user sync |
Job Requisition Data | Get Only | Sync job requisition data |
Manage: Evergreen Requisitions | Get Only | Sync evergreen requisition data |
Job Information | Get Only | Get information about job profiles, job families, and job family groups |
Manage: Location | Get Only | Get list of available locations |
Reporting Audits | Get Only | Allows running reports via REST API WQL |
Worker Data: Active and Terminated Workers | Get Only | Access data source Workers for HCM Reporting to sync Employee fields |
Worker Data: Workers | Get Only | Allows Ashby to run the Get_Workers API |
Manage Pre-Hire Process: Manage Pre-Hires | Get and Put | Get pre-hire records and allow Ashby to set fields on pre-hire records (e.g. Referred_By) |
Manage Pre-Hire Process: Consider Pre-Hires | Get Only | Get job considerations for pre-hires |
Workday Query Language | View and Modify | "View and Modify" appears to be required here, even though we can only run queries that fetch data. |
Compensation Change: Salary | View and Modify | Allows Ashby to override the position salary plan when creating an offer. |
Person Data: Work Contact Information | Get Only | Allows Ashby to connect the Employee list with Workday Worker using work email. |
Person Data: Public Work Email Address Integration | Get Only | Allows Ashby to connect the Employee list with Workday Worker using work email in the Get_Workers web service. |
Person Data: ID Information | Get Only | Allows Ashby to connect the Employee list with Workday Worker using work email. |
Manage: Custom Organization | Get Only | Allows Ashby to navigate organization hierarchies (e.g. Cost Center, Supervisory, custom org) |
Non-Worker Data: Compensation Pay Range (*see note) | Get Only / View Only | ONLY: If you want to display Compensation data (range, grade, grade profile) fields from Positions in Workday to Ashby |
Worker Data: Compensation Pay Range (*see note) | Get Only / View Only | ONLY: If you want to display Compensation data (range, grade, grade profile) fields from Positions in Workday to Ashby |
Set Up: Stock (*see note) | Get Only | ONLY: If you are overriding the Stock Plan Target at the time of offer |
Configure business process permissions
Ashby needs access to recruiting-specific business processes. To give Ashby the right access, go to each business process as follows (using "hire" as an example in step 1):
- Go to bp: hire.
- Select Related Actions (... menu at the top) > Business Process Policy, then click Edit.
- Scroll to Who Can Start the Business Process.
- In the Initiating Action: Hire Employee (Web Service) section, add Ashby's Integration System Group (ISG) to the Security Groups list.
- Scroll down to Who Can Do Actions on Entire Business Process.
- Go to the View All section.
- Add Ashby's ISG.
Ashby needs this for the following recruiting business processes (substitute each of the following in for your Workday search):
- Hire
- Change Job
- Contract Contingent Worker
- Create Position (uncommon: only if you need to create new Positions in Workday from a hire in Ashby)
After adding all of the above business process permissions, run Activate Pending Security Policy Changes.
Configure the connection in Ashby
Now that you have collected all the information needed, you are ready to configure the connection in Ashby. Go to https://app.ashbyhq.com/admin/integrations/marketplace/workday, and you see the screen below.
Steps
Your Workday Tenant ID is case-sensitive, so take care when entering it in step 2.
- In the Webservice Endpoint URL field, paste the WSDL URL (it may look something like https://wd2-impl-services1.workday.com/ccx/service).
- Add your Workday Tenant Name (case sensitive).
- In the ISU Username field, enter the ISU username you created for Ashby.
- In the ISU Password field, paste the ISU password.
- In the REST API Base URL field, paste the "host" part of the endpoints you copied when configuring the REST API client. It looks something like https://wd5-services1.myworkday.com, which is just the part of the URLs that end in myworkday.com. They should all be the same, though yours may start with wd4-services1, for example.
- In the REST API Client ID field, paste the client ID you copied when configuring the REST API client.
- In the REST API Client Secret field, paste the client secret you copied when configuring the REST API client.
- In the REST API Client Refresh Token field, paste the refresh token you copied when configuring the REST API client.
- In the Workday Tenant URL field, you may leave it blank. If you find the Open in Workday button is not working correctly, update this using the portion of your Workday Tenant URL for tasks starting with https:// through /d. It looks something like https://wd5-impl.workday.com/example/d.
Once this is complete, let us know, and we'll monitor the initial sync to make sure all is well. An Edit Authentication Policy task may need to be run to take your ISU into account.