Skip to main content

Workday: Advanced HCM Integration

Advanced HCM Data Integration securely connects Emissary with ATS and HCM platforms like Workday to sync candidate and employee data and automate workflows.

Advanced HCM Data Integration enables organizations to seamlessly retrieve candidate and employee data from their Applicant Tracking System (ATS) or Human Capital Management (HCM) platform, including systems such as Workday. By securely synchronizing workforce data, Emissary ensures recruiting and employee information remains current and accessible, allowing teams to automate workflows, personalize communications, and build integrations without the need for manual data exports or maintenance.

How It Works

When integrating with Workday, Emissary authenticates using a dedicated Integration System User (ISU) provided by the organization. The ISU is a service account created specifically for system-to-system integrations and is granted only the permissions required to access the necessary candidate and employee data. Using the organization’s Workday web services and reports, Emissary securely retrieves information on a scheduled basis, ensuring data remains up to date while adhering to the organization’s security and access controls.

Setup

To configure a new Workday integration, an administrator must create both an Integration System Security Group (ISSG) and an Integration System User (ISU).

Integration System Security Group

First, create an ISSG and grant it the required domain permissions by assigning the appropriate Report/Task and Integration permissions for each Workday security domain used by the integration, then activate the pending security policy changes.

  1. Access the Create Security Group task and create an Integration System Security Group. (e.g. named: EMISSARY_ISSG)

  2. Select Integration System Security Group (Unconstrained) as the Type of Tenanted Security Group prompt.

  3. To grant the security group access to the domains required by your integration, follow these steps for each domain:

Operation

Domain Security Policy

Functional Areas

Candidates

–

–

Get and Put

Candidate Data: Attachments

Recruiting

Get Only

Prospects

Recruiting

Get Only

View Confidential Prospects

Recruiting

Get Only

All Prospects

Recruiting

Get Only

Candidate Data: Job Application

Recruiting

Employees

–

–

Get Only

Worker Data: Job Details

Staffing

Get Only

Worker Data: Public Worker Reports

Staffing

Get Only

Worker Data: Current Staffing Information

Staffing

Get Only

Worker Data: Organization Information

Staffing

Get Only

Worker Data: Skills Reporting

Worker Profile and Skills

Get Only

HCM All Organizations

Staffing

Get Only

Worker Data: Workers

Staffing

Get Only

Worker Data: All Positions

Staffing

Get Only

Worker Data: Skills and Experience

Worker Profile and Skills

Get Only

Worker Data: External Skill Source

Worker Profile and Skills

Organizations

–

–

Get Only

Manage: Organization Integration

Organizations and Roles

Work Locations

–

–

Get Only

Manage: Location

Organizations and Roles

  1. Access the View Domain report and find the domain.

  2. As a related action on the domain, select Domain > Edit Security Policy Permissions.

  3. Add the security group that you created in Step 1 to the Report/Task Permissions and select View and Modify.

  4. Add the security group that you created in Step 1 to the Integration Permissions and select Get and Put.

  5. Use the Activate Pending Security Policy Changes task to activate the changes that you made in Step 2.

Integration System User

Next, create an ISU using a dedicated service account with a non-expiring session, assign the newly created ISSG to the user, and exempt the ISU from password expiration. This ensures Emissary can securely authenticate with Workday and access the candidate and employee data required by the integration without interruption.

  1. Access the Create Integration System User task and configure a system user account for the integration (e.g. named: EMISSARY_ISU). Keep the Session Timeout Minutes default value of 0 to prevent session expiration. An expired session can cause the integration to time out before it successfully completes. Optionally you can activate Do Not Allow UI Sessions, since UI won’t be used. Create a strong secure password and copy it for further reference.

  2. As a related action on the system user, select Security Profile > Assign Integration System Security Groups.

  3. At the Integration System Security Group to Assign prompt, select the security group that you created in Step 1.

  4. Access the Maintain Password Rules task and add the integration system user made in step 1 to the System Users exempt from password expiration field.

Configure in Emissary

After the Workday Integration System User (ISU) has been created, the integration can be configured in Emissary by providing a small set of connection details. These include the ISU Username and ISU Password created during the previous setup steps, the Workday Organization ID (also known as the Workday tenant or organization identifier), and the API Domain, which corresponds to the Workday cloud instance hosting your organization’s environment (for example, wd1-services1.myworkday.com). Once these values are entered, Emissary can securely authenticate with Workday and establish a connection to retrieve candidate and employee data.

  1. Log in to Emissary and select the Integrations page on the main side bar

  2. Click on Add Integration

  3. Name your integration and select the ATS/type, in this case Workday

  4. Fill in each of the requested parameters and click Save

  5. The system will check the provided credentials and if they work properly it will let you know that you are done with the integration process.

Configuration Parameters

API Domain & Organization ID (tenant name)

You can obtain both these values at the same time from a WSDL definition

  1. Run Public Web Services report

  2. Select the first report and click on Related Actions -> Web Service -> View WSDL

  3. A new tab will open with the contents of the WSDL definition. Scroll until the end of the file and look for the line that starts with soapbind:address

<soapbind:address location="https://wd2-impl-services1.workday.com/ccx/service/emissary_dpt1/Absence_Management/v47.0"/>

From there you can extract the API domain: wd2-impl-services1.workday.com and the Organization ID (tenant name): emissary_dpt1

Did this answer your question?