Skip to main content
Connect your Workday tenant to TOTAL for insider threat detection. This guide walks through the one-time setup your Workday administrator needs to complete. TOTAL connects to Workday using OAuth 2.0 (Client Credentials Grant). All access is read-only.

What you’ll need

  • Access to the Workday Developer Site (developer.workday.com) with Company Administrator permissions
  • Workday tenant admin access to create users and security groups
  • About 30 minutes

What TOTAL reads from Workday

TOTAL queries Workday for:
  • User activity — what users do inside Workday (report runs, data downloads, exports, configuration changes)
  • Business process events — HR workflow events like job changes, terminations, promotions, and other staffing actions
  • Worker profiles — employee identity, job, department, manager, org structure
  • Goals and feedback — employee goals, development items, feedback events, check-ins
  • Talent and succession — succession plans, mentorships
All access is read-only. TOTAL never writes to or modifies data in your Workday tenant.

Permissions

TOTAL needs View access to the security domains below. Each domain group controls a different type of data — the more you enable, the richer the threat profile TOTAL can build. We appreciate access to all of them, but TOTAL will work with whatever your organization is comfortable sharing. User activity — what users do inside Workday (downloads, report runs, data access):
  • System Auditing
Business process events — HR workflow events as timestamped records (job changes, staffing actions):
  • Public Business Processes
  • Core Navigation
Worker identity — name, job, department, manager:
  • Worker Data: Public Worker Reports
  • Self-Service: Current Staffing Information
Data queries — targeted queries against your Workday data:
  • Workday Query Language
  • WQL for Workday Extend
  • Workday Graph API Applications
  • Graph API Descriptor
Goals and PIPs — employee goals, performance improvement plans:
  • Worker Data: Employee Goals
  • Self-Service: Employee Goals
Feedback — feedback from colleagues and managers:
  • Worker Data: Anytime Feedback
  • Self-Service: Anytime Feedback
  • Worker Data: Role Requested Feedback
  • Worker Data: Self Requested Feedback
  • Self-Service: Role Requested Feedback
  • Self-Service: Self Requested Feedback
Development items — development plans and improvement items:
  • Worker Data: Development Items
  • Self-Service: Development Items
Check-ins — 1:1 meeting notes between workers and managers:
  • Worker Data: Check-Ins
  • Self-Service: Check-Ins
Service dates — hire date, continuous service date, seniority:
  • Worker Data: Service Dates
  • Self-Service: Service Dates
Succession and mentoring — succession plans, mentorship relationships:
  • Worker Data: Succession
  • Worker Data: Mentoring
  • Self-Service: Mentoring
Leave and time off — leaves of absence, vacation, sick days:
  • Worker Data: Leave of Absence
  • Self-Service: Leave of Absence
  • Worker Data: Time Off
  • Worker Data: Time Off (Time Off Balances)
  • Self-Service: Time Off
  • Self-Service: Time Off Balances
Job change details — title, position, location, reason:
  • Staffing Actions
  • Staffing Actions: Business Title
  • Staffing Actions: Change Job Date and Reason
  • Staffing Actions: Job Profile
  • Staffing Actions: Location
  • Staffing Actions: Contract Details
Skills — worker skills and competencies:
  • Person Data: Skills
  • Self-Service: Skills
Help cases — employee HR cases and support tickets:
  • Help Case Data
  • Self Service: Help Case Management

Setup steps

Step 1: Create an Integration System User

The ISU is a service account TOTAL uses to authenticate. It cannot log into the Workday UI.
  1. In your Workday tenant, search for and run the Create Integration System User task
  2. Enter a username (e.g. ISU_TOTAL)
  3. Check Do Not Allow UI Sessions
  4. Keep Session Timeout Minutes at 0 (prevents session expiration)

Step 2: Create a Security Group

  1. Search for and run the Create Security Group task
  2. Set Type of Tenanted Security Group to Integration System Security Group (Unconstrained)
  3. Enter a group name (e.g. ISSG_TOTAL)
  4. Add the ISU you created in Step 1

Step 3: Grant security domain permissions

  1. Search for and run the Maintain Permissions for Security Group task (or from the security group’s related actions: Security Groups → Maintain Domain Permissions for Security Group)
  2. Grant View access to the security domains listed in the Permissions section above

Step 4: Activate security policy changes

Search for and run the Activate Pending Security Policy Changes task. Domain permission changes are not active until this step is completed.

Step 5: Register an API Client

Scopes control which functional areas the API Client can access. They apply to REST APIs, WQL queries, and Graph API — all three use the same scopes.
  1. Go to the Workday Developer Site (developer.workday.com)
  2. From the Console section, select API Clients
  3. Click Create API Client
  4. Enter a client name (e.g. TOTAL)
  5. Select these Scopes (functional areas):
  1. Save the Client ID and Client Secret — the secret is masked if you navigate away from the page

Step 6: Create a Client Credentials Mapping

This links the API Client to the ISU, so TOTAL authenticates as the ISU.
  1. In your Workday tenant, search for and run the Create Client Credentials Mapping task
  2. Enter the Client ID from Step 5
  3. Select the ISU from Step 1

Step 7: Enable User Activity Logging

User activity logging is off by default. Without it, TOTAL cannot see behavioral data (report runs, data downloads, etc.).
  1. Search for and run the Edit Tenant Setup - System task
  2. Check Enable User Activity Logging
Note: Workday retains activity logs for the last 30 days.

Connect to TOTAL

In the TOTAL integrations page, select Workday and enter: TOTAL will validate the connection by requesting an access token and verifying it can read your tenant.

Regional API Gateways

Each Workday account is associated with a region. You must use the correct API Gateway for your region. Using the wrong one returns a 401 error. You can find your API Gateway URL on your profile on the Workday Developer Site.

Technical details

  • Auth flow: OAuth 2.0 Client Credentials Grant
  • Token expiry: 60 minutes (TOTAL refreshes automatically)
  • Access: Read-only (View permissions only, no Modify/Put)