Showing posts with label Configurable Security. Show all posts
Showing posts with label Configurable Security. Show all posts

Monday, 5 August 2013

Moving from PeopleSoft to Workday - security topics

Someone was asking me about moving from a PS environment, and how easily the current set up of users and security translates into Workday.  In our case, it didn't really, it was like starting over from scratch to define the security pieces.  I guess it depends though...if you're replicating your PS structures into WD and your users have the same powers as they did in PS, it might be a better fit for you.  As we are doing an HR transformation, redefining and improving our HR structures and core data is making our future system quite different than our current one.  A few things to consider:

1. You have the ability to assign HR roles to the org structure.  We have nothing like this in PS.  So in WD, if you have an org (similar to a dept in PSoft), you're able to identify who is assigned from the HR side to whatever roles that you'd like.  So person A is the HR Business Partner, person B is the HR Admin, etc.  The workflow then uses this data.  As PS doesn't have such fields, we're having to define this for conversion through outside excel spreadsheets.  Note:  this is different/additional to 'normal' security where user X is assigned the role of HR BP.

2. WD comes with defined roles.  Whether or not you use them is up to you, however, as they are pre-built, it might save you some time.  However, these roles may or may not mirror the ones in your company, or your current system.

3. WD works on the concept of domains, PS does not.  WD bundles like items into domains and 'it is what it is'.  In PS you're either working on the dept tree (pre 8.9) or with the more configurable security options, such as defining your own security sets.  We heavily utilize this feature in our PS 9.0, in particular with the location and grade fields.  When comparing to WD, however, it's an entirely different kettle of fish.  We found it to be an exercise of A) What roles do we see in the future?  Shared Service Centre rep, HR BP, etc.  Then B) What shall those roles see.  In PS you have the flexibility to add/remove pages, that doesn't exist with WD.  You either find a different domain without the item you want, or you show that item.

We were not able to map over anything from PS, but instead are doing manual mapping on spreadsheets, of users to the new roles.

How is WD security similar to PS?
  • Reporting security works the same; if you can see the online pages, then you can report on the data too.
  • Overall, it's a similar concept--set up roles, then assign people to them (either manual or automatic).
  • Users can be view only or can modify ('put' in WD terminology) data, just like in PS.
  • You can have access to create reports or only to run them, just like in PS.
  • Users can have multiple roles assigned.

Tips to prepare for a PS to WD implementation?  What to ask/bring during the sales cycle:
  • Query your users to get an overall picture.  How many active users are in PSOPRDEFN?  How many roles?  How many permission lists as far as population visibility goes?  In particular, if you have strict requirements, e.g. this role sees all Personal Data except for personal data tab 2 due to xyz, you'll want to have those documented.  That is where WD will struggle to fit your needs. 
  • WD is pretty good as isolating certain key data elements, such as birthdate or national ID, into their own domain.  But if your company keeps certain items hidden (for us, grade is highly sensitive, even though it's a core HR data element rather than being personal data), then you'll want to highlight those in the sales cycle to get a read out from WD.
  • If you've locked down your query tree, you'll want to bring that to the table, as to why it's locked down and users can only access certain tables.
  • If you use security other than the dept tree, you'll want to have that documented as well.  For example, we use PS security based on grade--so certain HR people have access to employees with high grades.  We set this up in PS based on 'if emp z is in grade q, then HR role 1 has access'.  This scenario seemed to be more difficult in WD, which seems so much more focused around the org.  So I'd suggest to know your non-dept tree security, to bring that to the table too.

Wednesday, 26 June 2013

Workday HCM security groups

I mentioned Workday security a while back.  Today, I'm thinking a lot about the concept of Workday 'security groups'.  In WD you assign users to groups.  The groups have various defined permissions.  If someone is in a group, they get those permissions.  A person can be a member of multiple groups.

 

A few key points:


1. Workday-delivered groups

Workday comes with some groups that get automatically assigned, based on WD's rules.  You cannot change/modify/delete etc. these groups.

Examples:  All workers, All contingent workers, All terminated people, All users, Employee as Self, Manager's Manager, etc.

2. Workday security groups get assigned a 'context'. 

This context is not changeable and it dictates what we'd consider to be 'row-level' security.  There are 3 types of context possible:
  • Unconstrained - in such a group, the users have access to ALL data that the group allows. 
  • Constrained - imagine a more limited group, a subset that is contrained--such as by organization.
  • Mixed - a combination of the above two context.  A mixed group can be an 'intersection' or a subset of the two where they overlap, or an 'aggregation', so the two parts together, regardless of overlap.
It's a somewhat difficult concept to grasp by itself, but I found it starts to make a lot more sense once you look at the actual group definitions and configurations.

3. Security administration and on-going maintenance.

Excluding the system delivered ones, Workday groups can be manually assigned or auto-assigned.  More about this in a future post.  As well, user creation and termination of accounts can be automated.

Thursday, 6 June 2013

Configuring Workday HCM application security

We've been spending some time recently on our implementation, on defining Workday security.  I mentioned attending security class a few months back, here is an introduction to the key concepts.

If you are used to a PeopleSoft security model, just forget everything you know, this is a totally different world.  :) 

Functional Areas - Workday security comes pre-delivered with defined functional areas such as 'Benefits', 'Staffing', 'Jobs & Positions' or 'Compensation'.  Each of these areas is further divided into 'domains' and 'business processes'.

Business Processes - Each HR process in WD is set up as a 'business process'.  So the steps and the roles that can perform each step, as well as any approvals or notifications are defined.  Examples of a business process can be large like 'Hire' or smaller like 'Passport and Visa change'.  There's more to say about buisness processes, but we'll save that for another day. 

For today, imagine a swim lane flow chart in Visio with roles assigned to certain tasks.

Domain - This one can be difficult to grasp as it's quite foreign from anything I've seen in other HR Systems.  Basically, a domain is a collection of related securable items, such as tasks and reports.  WD delivers similar items together within domains, and you cannot change which items are assigned to which domains.  There are also sub-domains in some cases, but that's for a later day too.

To give you some ideas, a Domain would be 'Set Up: Jobs & Positions' and examples of sub-Domains under that would then be:
  • Set Up Job
  • Set Up Position
Other examples of Domains would be 'Job Profile: View' or 'Job Information'.

Domain Security Policy - This is where we can do some configuration.  While we cannot change what comes delivered in a Domain, with the domain security policy we control access to it.  So we control who can 'View and Modify' or 'View Only' or 'Get and Put'.

Within this security policy we address 'Securable Actions' and 'Securable Reporting Items'.  So for the Task 'Create Job Profile' or 'Delete Job Family', we say that it is a 'Modify' task rather than 'View' task. 

For individual fields that fall under this area, we can then define if those are viewable or not too.

So let's work with an example so far:
  • In the Functional area of 'Jobs & Positions' we have a Domain called 'Set Up: Jobs & Positions'.
  • We have Business Processes such as 'Edit Position' or 'Create Position'.
  • We apply a Domain Security Policy to 'Set Up: Jobs & Positions' so that various tasks are given either view or modify rights.
We then attach the above to a 'Security Group' via configuration tasks, and this is how a user is able to view tasks, perform function, etc.

I realize the above is quite a complex topic--you can see why this can be a full training course from Workday!  Let's talk some more about the User piece on a different day...

Monday, 1 April 2013

Thoughts on Workday training – a few months later & Configurable Security Fundamentals

It’s been a few months since I’ve had time to write here, but time to change that.  :-)

I had put some thoughts together back when I was first taking the Workday training courses, here and here. I’ve since taken a few more courses and am now sending my staff to the HCM Fundamentals course that I took, so a good time for a look back. I’ll start with the courses I’ve taken in the meantime…

The Configurable Security Fundamentals class
This is an ‘online only’ course, like a few of Workday’s offerings which are not offered in a classroom setting. As always, you can find more details about Workday courses here. It’s 10 hours spread over two days, so five hours each day. It explains everything about setting up Workday user security: configuration, security groups, domains, business process security, etc. The agenda was full and the class kept moving.

Sidenote: the format/structure for online courses appears to be the same. You receive a pdf manual a day or two before the course, along with log-in details to *your* tenant, as well as technical details of logging in so that you can test your computer in advance. On course day, you can log in via the pc for both the online course plus voice, or you can log in to view the presentation and dial in separately to the call via phone. I’d say 90-95% of the people used the pc for audio. Overall, there were around 20 or 22 people attending normally.

The structure of the online courses is similar to the classroom training, the instructor walks through a powerpoint, explains the concepts and then you get to work through the exercises in the manual in your tenant.

The good
  • no travel costs
  • even though it’s online, it’s still a full schedule, similar to what you’d get in a classroom environment. The pricing structure reflects this as well: it’s the same 600 USD per unit, whether it is in-person or online. Sidenote: I noticed that when I took the course in October 2012, it was 8 hours total, they’ve since increased it to 10 hours, so perhaps others found it to be too quick.
  • the instructor will stay on an extra 30 min beyond the end of the class on day 1, in case you have questions. As well, this is offered for 30 min before/30 min after on day 2.
  • the instructor can log into *your* tenant, so if you have messed up an exercise, they can try and sort you out while people are working on the next one or on a break.
The bad
  • there is 30 min at the beginning of day 1 of ‘meet and greet’, similar to if you were in a classroom session. With 20 people saying what their role is, it began to drag a big.
  • the instructor has pre-set expectations of how quickly the class should move. Not having the face to face contact perhaps can be an impediment to ‘reading’ if people really understand things.
  • In this course, the instructor in addition walked through the exercise before you were unleashed to do the exercise. As an occasional instructor myself, I found that a little odd, to be shown the concepts, an example and then the actual exercise itself, she did it. We then replicated the exact same exercise. So in the back of my head, I wonder if it’s too difficult, the exercises ‘as is’ to be in an online course, as the HCM course I took did not follow this heavy hand-holding.
  • scheduling - this one deserves more of a read-out…
I know I start to sound like a broken record here, but Workday’s scheduling is not indicative of a global player. Considering it’s an online course, I would expect a little more flexibility in the offer times, but once again, it’s 9 AM California time or 9 AM New York time, and on a Thurs/Fri rather than other days. For those of us in places around the world, that begins to get old very fast. My security class had a 5 PM start in the UK, so I worked a full day and then got online for another few hours of intense training.

Taking a short look today (Apr 25, 2013), Workday is offering three security sessions in the coming weeks, two in May and one in June. All three of them are on Pacific time, 9 AM-2 PM, although at least on a Mon/Tues or Tues/Wed. Looking at my handy timezone calculator, that looks like the following around the world:

LocationDateStartDateFinish
San FranciscoThurs Apr 259:00 AM Thurs Apr 25  2:00 PM
LondonThurs Apr 255:00 PMThurs Apr 2510:00 PM
ParisThurs Apr 256:00 PMThurs Apr 2511:00 PM
SingaporeFri Apr 26midnightFri Apr 265:00 AM
TokyoFri Apr 261:00 AMFri Apr 266:00 AM
 
If you are a US-based company, with only US customers, then that is perfectly fine. But considering that Workday keeps claiming that they are global in nature, I find this to be appalling, in particular when you consider that these are online classes, so they could occasionally put one in a European or Asian timezone, even though that might mean that the instructor is doing odd hours for the two days. For whatever reason, Workday insists on putting everything into the California timezone. OK, timezone rant now over…

Overall though, I’d say the security class was quite good. I’m not sure if you’d need to send your entire team there, or rather, send one person who will bring back the manual. If you have that plus access to a test tenant, you can start to play around with security to understand how it works, while reviewing the manual. In addition, I’d recommend that you check out the Workday Community, a lot of people post questions/issues related to security, and often through reading those, you can get some ideas of pitfalls and how certain setups may make your security maintenance more difficult.