Workday
Using Workday as the authoritative HR source that drives joiner, mover and leaver events in IdentityIQ.
The Workday connector aggregates worker data from Workday and uses it as the authoritative source for identities. Attributes like department, job and status flow into the Identity Cube and trigger lifecycle events, so Workday changes drive access changes automatically.
- Workday is typically the authoritative HR source
- Aggregates workers, not IT accounts
- Drives identity attributes and lifecycle events
- Usually read-only into IdentityIQ
- Pre-hire and termination dates enable timely access
Workday is most often used as the authoritative HR source that drives the entire identity lifecycle, when Workday says someone is hired, transferred or terminated, SailPoint reacts. It can also be governed as a target for Workday security groups.
Connector type and how it connects
The Workday integration is a REST/API-based connector. It connects to Workday web services/APIs with an integration system user (ISU). As with every connector, the flow is the same: authenticate to Workday, read accounts and entitlements during aggregation, and write changes during provisioning.
Onboarding the source
- 1. Configure the connection and credentials for Workday.
- 2. Map the account schema, mapping Workday worker attributes to identity attributes (as an authoritative source) and, where relevant, Workday security groups to entitlements.
- 3. Set the correlation logic so Workday accounts attach to the right identities (typically on a stable key such as employee ID or email).
- 4. Run account aggregation and confirm accounts and entitlements load.
- 5. Verify correlation, watching for uncorrelated/orphan accounts.
Provisioning capabilities
As an authoritative source, Workday drives joiner/mover/leaver events downstream; as a target, SailPoint can manage Workday security group assignments. The authoritative role is the more common and higher-value use.
Entitlements and what to govern
When governing Workday as a target, security groups are the entitlements. As an authoritative source, the focus is instead on clean worker-attribute mapping that feeds every downstream decision.
Troubleshooting
When Workday aggregation or provisioning fails, work through the usual causes in order:
- Verify the ISU credentials and the web-service permissions granted to it.
- Confirm the correct Workday endpoint/tenant and API version.
- Check network access to Workday.
- Validate worker-attribute mapping and effective-dating handling.
Common pitfalls
- Credential expiry (tokens/secrets/certs) silently breaking the connector.
- Insufficient rights on the Workday service account for the operations you need.
- Schema or correlation misconfiguration leaving accounts uncorrelated.