Advanced HCM Data Integration enables organizations to seamlessly retrieve candidate and employee data from their Applicant Tracking System (ATS) or Human Capital Management (HCM) platform, including systems such as Workday. By securely synchronizing workforce data, Emissary ensures recruiting and employee information remains current and accessible, allowing teams to automate workflows, personalize communications, and build integrations without the need for manual data exports or maintenance.
How It Works
When integrating with Workday, Emissary authenticates using a dedicated Integration System User (ISU) provided by the organization. The ISU is a service account created specifically for system-to-system integrations and is granted only the permissions required to access the necessary candidate and employee data. Using the organization’s Workday web services and reports, Emissary securely retrieves information on a scheduled basis, ensuring data remains up to date while adhering to the organization’s security and access controls.
Setup
To configure a new Workday integration, an administrator must create both an Integration System Security Group (ISSG) and an Integration System User (ISU).
Integration System Security Group
First, create an ISSG and grant it the required domain permissions by assigning the appropriate Report/Task and Integration permissions for each Workday security domain used by the integration, then activate the pending security policy changes.
Access the Create Security Group task and create an Integration System Security Group. (e.g. named: EMISSARY_ISSG)
Select Integration System Security Group (Unconstrained) as the Type of Tenanted Security Group prompt.
To grant the security group access to the domains required by your integration, follow these steps for each domain:
Operation | Domain Security Policy | Functional Areas |
Candidates | – | – |
Get and Put | Candidate Data: Attachments | Recruiting |
Get Only | Prospects | Recruiting |
Get Only | View Confidential Prospects | Recruiting |
Get Only | All Prospects | Recruiting |
Get Only | Candidate Data: Job Application | Recruiting |
Employees | – | – |
Get Only | Worker Data: Job Details | Staffing |
Get Only | Worker Data: Public Worker Reports | Staffing |
Get Only | Worker Data: Current Staffing Information | Staffing |
Get Only | Worker Data: Organization Information | Staffing |
Get Only | Worker Data: Skills Reporting | Worker Profile and Skills |
Get Only | HCM All Organizations | Staffing |
Get Only | Worker Data: Workers | Staffing |
Get Only | Worker Data: All Positions | Staffing |
Get Only | Worker Data: Skills and Experience | Worker Profile and Skills |
Get Only | Worker Data: External Skill Source | Worker Profile and Skills |
Organizations | – | – |
Get Only | Manage: Organization Integration | Organizations and Roles |
Work Locations | – | – |
Get Only | Manage: Location | Organizations and Roles |
Access the View Domain report and find the domain.
As a related action on the domain, select Domain > Edit Security Policy Permissions.
Add the security group that you created in Step 1 to the Report/Task Permissions and select View and Modify.
Add the security group that you created in Step 1 to the Integration Permissions and select Get and Put.
Use the Activate Pending Security Policy Changes task to activate the changes that you made in Step 2.
Integration System User
Next, create an ISU using a dedicated service account with a non-expiring session, assign the newly created ISSG to the user, and exempt the ISU from password expiration. This ensures Emissary can securely authenticate with Workday and access the candidate and employee data required by the integration without interruption.
Access the Create Integration System User task and configure a system user account for the integration (e.g. named: EMISSARY_ISU). Keep the Session Timeout Minutes default value of 0 to prevent session expiration. An expired session can cause the integration to time out before it successfully completes. Optionally you can activate Do Not Allow UI Sessions, since UI won’t be used. Create a strong secure password and copy it for further reference.
As a related action on the system user, select Security Profile > Assign Integration System Security Groups.
At the Integration System Security Group to Assign prompt, select the security group that you created in Step 1.
Access the Maintain Password Rules task and add the integration system user made in step 1 to the System Users exempt from password expiration field.
Configure in Emissary
After the Workday Integration System User (ISU) has been created, the integration can be configured in Emissary by providing a small set of connection details. These include the ISU Username and ISU Password created during the previous setup steps, the Workday Organization ID (also known as the Workday tenant or organization identifier), and the API Domain, which corresponds to the Workday cloud instance hosting your organization’s environment (for example, wd1-services1.myworkday.com). Once these values are entered, Emissary can securely authenticate with Workday and establish a connection to retrieve candidate and employee data.
Log in to Emissary and select the Integrations page on the main side bar
Click on Add Integration
Name your integration and select the ATS/type, in this case
WorkdayFill in each of the requested parameters and click
SaveThe system will check the provided credentials and if they work properly it will let you know that you are done with the integration process.
Configuration Parameters
API Domain & Organization ID (tenant name)
You can obtain both these values at the same time from a WSDL definition
Run Public Web Services report
Select the first report and click on Related Actions -> Web Service -> View WSDL
A new tab will open with the contents of the WSDL definition. Scroll until the end of the file and look for the line that starts with soapbind:address
<soapbind:address location="https://wd2-impl-services1.workday.com/ccx/service/emissary_dpt1/Absence_Management/v47.0"/>
From there you can extract the API domain: wd2-impl-services1.workday.com and the Organization ID (tenant name): emissary_dpt1
