Skip to content
English
  • There are no suggestions because the search field is empty.

What permissions does Tilt's Integration System User need in Workday?

Grant the right Domain Security Policies — here's exactly what Tilt's ISU needs to read your data.

Tilt's Integration System User (ISU) needs a specific set of Domain Security Policies granted through the security group you created — these control what employee, staffing, and payroll data Tilt can read.

Who this applies to / Prerequisites

  • Workday admins setting up the Tilt integration.
  • You've already created the ISU and its security group (see the previous two articles).

Steps

  1. Type Maintain Permissions for Security Group in the top search bar and select the task from the dropdown.
  2. Set Operation to Maintain and Source Security Group to the security group you created.
  3. Click OK.
  4. Add the following Domain Security Policies, each with Get access unless noted otherwise:

What if it doesn't work

  • If you can't find Worker Data: Workers in the dropdown when editing permissions, access it a different way: run the Domain Security Policies for Functional Area report, then add Tilt's Integration System Security Group (ISSG) to the Integration Permissions section for that domain and grant it Get access.
  • If pay calendar or payroll-related data still isn't syncing, confirm the standard Workday Domain Security Policy parent-child relationships still exist — specifically, that Set Up: Payroll lists Set Up: Payroll (Payment Election Rules) as an inheriting policy. If it doesn't, Tilt's payroll-related permissions may not apply as expected.
  • If you made your security group constrained rather than unconstrained (see the previous article), you must separately adjust the Worker Data: Workers Security Policy to only allow access to workers in your specific business or country.

Limits and exceptions

  • These permissions cover the standard one-way integration only. If you also use leave data pushback (2-way integration), you need additional permissions — see the next article.
  • Tilt expects Workday's standard Domain Security Policies and their default parent-child relationships to be intact. Heavily customized Workday configurations may need extra review.
  • Changes made here don't take effect until you activate them — see "How do I activate pending security policy changes in Workday?"

Related questions

  • How do I add permissions for Tilt's 2-way integration (leave data pushback) in Workday?
  • How do I activate pending security policy changes in Workday?