Workday
Quick answer
The Workday connector aggregates worker data from Workday and uses it as the authoritative source for identities. Attributes like department, job and status flow into the Identity Cube and trigger lifecycle events, so Workday changes drive access changes automatically.
Key takeaways
- Workday is typically the authoritative HR source
- Aggregates workers, not IT accounts
- Drives identity attributes and lifecycle events
- Usually read-only into IdentityIQ
- Pre-hire and termination dates enable timely access
Workday is most often used as the authoritative HR source that drives the entire identity lifecycle, when Workday says someone is hired, transferred or terminated, SailPoint reacts. It can also be governed as a target for Workday security groups.
Connector type and how it connects
The Workday integration is a REST/API-based connector. It connects to Workday web services/APIs with an integration system user (ISU). As with every connector, the flow is the same: authenticate to Workday, read accounts and entitlements during aggregation, and write changes during provisioning.
Onboarding the source
- 1. Configure the connection and credentials for Workday.
- 2. Map the account schema, mapping Workday worker attributes to identity attributes (as an authoritative source) and, where relevant, Workday security groups to entitlements.
- 3. Set the correlation logic so Workday accounts attach to the right identities (typically on a stable key such as employee ID or email).
- 4. Run account aggregation and confirm accounts and entitlements load.
- 5. Verify correlation, watching for uncorrelated/orphan accounts.
Provisioning capabilities
As an authoritative source, Workday drives joiner/mover/leaver events downstream; as a target, SailPoint can manage Workday security group assignments. The authoritative role is the more common and higher-value use.
Entitlements and what to govern
When governing Workday as a target, security groups are the entitlements. As an authoritative source, the focus is instead on clean worker-attribute mapping that feeds every downstream decision.
Troubleshooting
When Workday aggregation or provisioning fails, work through the usual causes in order:
- Verify the ISU credentials and the web-service permissions granted to it.
- Confirm the correct Workday endpoint/tenant and API version.
- Check network access to Workday.
- Validate worker-attribute mapping and effective-dating handling.
Common pitfalls
- Credential expiry (tokens/secrets/certs) silently breaking the connector.
- Insufficient rights on the Workday service account for the operations you need.
- Schema or correlation misconfiguration leaving accounts uncorrelated.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
In most deployments Workday is the?
- A. Lifecycle events. Status and department changes fire joiner/mover/leaver events.
- B. Read-only. IdentityIQ reads worker data; it rarely writes back to Workday.
- C. Authoritative HR source. Workday defines identities as the authoritative source.
Show answer
C. Authoritative HR source. Workday defines identities as the authoritative source.
Authoritative HR source. Workday defines identities as the authoritative source.
IdentityIQ's Workday connector is usually?
- A. Authoritative HR source. Workday defines identities as the authoritative source.
- B. Read-only. IdentityIQ reads worker data; it rarely writes back to Workday.
- C. Lifecycle events. Status and department changes fire joiner/mover/leaver events.
Show answer
B. Read-only. IdentityIQ reads worker data; it rarely writes back to Workday.
Read-only. IdentityIQ reads worker data; it rarely writes back to Workday.
Workday attribute changes trigger?
- A. Lifecycle events. Status and department changes fire joiner/mover/leaver events.
- B. Authoritative HR source. Workday defines identities as the authoritative source.
- C. Read-only. IdentityIQ reads worker data; it rarely writes back to Workday.
Show answer
A. Lifecycle events. Status and department changes fire joiner/mover/leaver events.
Lifecycle events. Status and department changes fire joiner/mover/leaver events.