Workday Human Capital Management lets you manage employee records, payroll, recruiting, and workforce analytics in one platform. Integrating with Make enables automated HR data sync, onboarding workflows, and real-time updates between Workday and other business tools.
The Workday Human Capital Management app is available on the Make Enterprise plan.
Requirements
To use the Workday Human Capital Management app in Make, you must have an active Workday account with appropriate permissions to access the web services. For subscription, refer to the Workday Human Capital Management pricing page.
Workday recommends using an Integration System User (ISU) to integrate with external services such as Make for the following reasons:
ISUs carry all operations and documents under the ISU, rather than using a worker specifically for integration and workflow activities
Integrations using an ISU will not stop working if a worker's security profile changes or they are no longer an employee
Each ISU can and should be limited to a single integration, such as Make, for security reasons
The ISU must have the mandatory permissions to perform the required actions for your scenario. If you receive an error that states The task submitted is not authorized when building a scenario, the ISU does not have sufficient permissions.
To create an ISU task and configure the ISU account for the integration, follow these steps:
1
In your Workday account search bar, search for and select the Create Integration System User task.
2
Enter the following details and click OK.
User Name - Enter the name of the user. We recommended including ISU in the user name for easy identification.
Generate Random Password - Select if you want to generate a random password for the user.
New Password - Enter a password according to the password requirements.
New Password Verify - Re-enter the password to confirm.
Require New Password at Next Sign In - Select the checkbox to enable the new password settings on the user's next login.
Session Timeout Minutes Enforced - This field cannot be edited.
Session Timeout Minutes - Leave the Session Timeout Minutes as the default value of 0 to prevent session expiration. An expired session can cause the integration to time out before it successfully completes.
Do Not Allow UI Sessions - This field can be checked as ISUs do not typically require the UI.
You have successfully created the ISU and a list of security groups are assigned by default. This default list can differ for customer environments specifications.
To avoid integration errors due to expired passwords, Workday recommends preventing the ISU password from expiring. Go to the Maintain Password Rules task and add the ISU to the System Users exempt from password expiration field.
An Integrated System Security Group (ISSG) will be used to create a connection between the ISU, Domain, and Web Service.
To create a security group task, follow these steps:
1
In your Workday account search bar, search for and select the Create Security Group task.
2
Enter the following details and click OK.
Type of Tenanted Security Group - Select Integration System Security Group (Constrained) or (Unconstrained).
Name -Enter a name for the security group. We recommend including ISSG in the name for easy identification.
To assign the ISSG to the ISU:
1
Open the security group created in the above section, enter the following details, and click OK.
Name - Enter the security group name.
Comment - Add applicable notes.
Integration System Users - Select the ISU created in the section above.
2
To validate the relation between the ISU and the security group, search for and select the View Security Groups for User task.
3
In the Person field, select the account and click OK.
4
Verify that the created Security Group is now assigned to the ISU.
In this section, you will configure the domain settings for the ISU.
There are several ways to access the Domain Settings screen, Make recommends following the steps defined in this section.
Continue from the Custom report created in the previous section.
The following screens contain examples for configuring domain settings for Web Service Operation Name, Get Worker Profile based on the Web Service Matrix, Get an Employee module.
1
Filter the report by Web Service Operation Name and select the relevant domain. For example, Get Worker Profile.
2
Click the three dots menu > Domain > Edit Security Policy Permissions.
3
Confirm the action by clicking OK.
In this section, you will activate the security policy changes.
1
In the Workday Search box, enter Activate Pending Security Policy Changes and select that task.
2
Enter a brief comment describing the change.
3
Click OK.
4
Mark the Confirm checkbox in the dialog box.
5
Click OK to make these changes active.
Your security group can now execute the Get Worker web service
To validate the security group:
1
In your Workday account search bar, search for and select the View Security Group task.
2
Enter the security group name you have created.
3
Verify that the created Integration Security Group has assigned operation for the specified domain.
Connect Workday HCM to Make
You can establish two types of connection between Workday HCM and Make: with user credentials or OAuth2.
The System Administrators must thoroughly understand and review their organization's authentication policy and design the integration user based on it.
To obtain a Host URL from your Workday HCM account:
1
Log in to your Workday HCM account as an admin.
2
Go to View API Clients.
3
Copy a Token Endpoint and store it in a safe place.
You've now obtained your Host URL. You'll use the domain part of this value in the Host URL field in Make.
Establish the connection with Workday HCM in Make (User Credentials)
To establish a connection with user credentials:
1
Log in to your Make account, add a Workday HCM module to your scenario, and click Create a connection.
2
In the Connection type dropdown, select Workday HCM.
3
Enter your Host URL Address that you copied above without a trailing slash. For example, https://wd3-services1.myworkday.com for your production instance and https://wd3-impl-services1.workday.com for your sandbox instance.
4
Enter your Tenant ID. This can be located in your account URL address as follows: https://HostName.workday.com/TenantID/d/home/html.
5
In the Username and Password fields, enter the Workday HCM login credentials with API access. For more information, see the Getting Started Getting Started section.
6
Click Save.
You have successfully established the connection. You can now edit and add more Workday HCM modules. If your connection requires reauthorization, follow the connection renewal steps herehere.
Establish the connection with Workday HCM in Make (OAuth2)
Before establishing an OAuth2 connection, your Workday system administrator must complete the steps in the Set Up Workday HCM for OAuth2 Connections section to generate client credentials and refresh tokens.
1
Log in to your Make account, add a Workday HCM module to your scenario, and click Create a connection.
2
In the Connection type dropdown, select Workday HCM OAuth2.
3
Enter your Host URL Address that you copied above without a trailing slash. For example, https://wd3-services1.myworkday.com for your production instance and https://wd3-impl-services1.workday.com for your sandbox instance.
4
Enter your Tenant ID. This can be located in your account URL address as follows: https://HostName.workday.com/TenantID/d/home/html.
5
In the Client ID and Client Secret fields, enter your client credentials.
6
Enter the Refresh Token for the connection, provided by your Workday system administrator. Each connection should have its own refresh token as sharing tokens may result in connections being broken.
7
Workday system administrators can generate tokens in Workday > View API Clients > Manage Refresh Tokens for integrations.
8
Set the Access Token Expiry in Seconds, provided by your Workday system administrator. This value must be the same as the token expiry settings in Workday.
9
Click Save.
You have successfully established the connection. You can now edit and add more Workday HCM modules. If your connection requires reauthorization, follow the connection renewal steps herehere.
Set up Workday HCM for OAuth2 connections
Follow these steps in Workday to retrieve the client credentials and refresh tokens necessary to establish an OAuth2 connection.
To generate Client Credentials:
1
In your Workday account search bar, search for and select the Register API Client for Integrations task.
2
Fill in the Client Name field.
3
Check the Non-Expiring Refresh Tokens box. This is important to minimize risk of integration down-time. If it is not selected, a new refresh token must be manually created and entered into Make after each expiration.
4
Add the following Scopes (Functional Areas): System for WQL functionality and Tenant Non-Configurable for RAAS functionality.
5
Click OK.
6
Copy the Client ID and Client Secret values and store them in a safe place. This is important as you will not be able to view the Client Secret again after leaving this page and you will be required to generate new credentials.
You have successfully created the Client ID and Client Secret to be used when creating the OAuth2 connection in Make.
Configure Refresh Tokens
1
In your Workday account, go to View API Clients.
2
Find the relevant API Client and click on ... > API Client > Manage Refresh Tokens for Integrations.
3
Note: This is also where you can edit API Client scopes, generate new client secrets, and find new refresh tokens if an expiration date was set.
4
In the Manage Refresh Tokens for Integrations window, enter the Workday Account to be assigned to the API Client. This account must have access to the reports you would like to work with. WQL, RAAS, and SOAP API security is tied to the Workday account.
5
Click OK.
6
In the Delete or Regenerate Refresh Token task, click the Generate New Refresh Token box.
7
Copy the Refresh Token and store it in a safe place.
8
Note: Each Workday account will have its own refresh token, but can have the same Client ID and Client Secret as other accounts linked to the API client.
You have successfully created the Refresh Token to be used when creating the OAuth2 connection in Make.
Workday Human Capital Management modules
After connecting to the Workday Human Capital Management app, you can choose from a list of available modules to build your scenarios.
Creates a new dependent record.
Updates the status of a worker who was previously terminated, marking them as retired in the system.
Adds stock grants to an employee by initiating the request stock option grant business process.
Creates a new job position entry for an employee who is already in the system.
Initiates the hiring process to add a new employee to your system.
Creates new search configurations or modifies existing ones in Workday to customize how search results are displayed and filtered.
Creates a new job family or updates the details of an existing job family.
Creates a new job family group or updates the details of an existing job family group.
Creates a new job profile or updates an existing one with the provided details.
Creates a new location or updates the details of an existing location.
Creates a new pre-hire applicant record or updates an existing applicant’s information.
Creates a new worker record or updates an existing worker's information in the database.
Reactivates an employee by removing their retired status, allowing them to return to active employment.
Terminates the contract of a specified contingent worker.
Enrolls learners into specific learning content using the "Enroll in Content" business process.
Retrieves detailed information about a contingent worker, including their contract details and personal data.
Fetches a specific RaaS (Reporting as a Service) report using its report URL. Requires an OAuth2 connection for access.
Fetches detailed information from a worker's document.
Fetches a list of all event records linked to a specific worker, filtered by event type and date criteria.
Fetches specific details about a worker, including their employment or contract status, personal information, and compensation data.
Retrieves detailed information about an employee, including their employment status, personal details, and compensation data.
Converts a new or existing applicant into an official employee by assigning them to a specific position, headcount, or job role.
Fetches a list of academic rank titles from the system.
Fetches a list of all certification issuers that have been set up in the system.
Allows you to retrieve a list of all company vehicles or filter to access specific vehicles.
Fetches a complete list of all available competency categories from your account.
Fetches detailed competency snapshot data to support translation integration processes.
Fetches a list of contact types based on the provided request references or search criteria.
Retrieves a list of all currencies currently available within a specific tenant account.
Fetches detailed information about job requisitions and includes a reference to the associated job position.
Fetches detailed Canadian employment history information for a specified Record of Employment (ROE).
Fetches up-to-date time off balances for each worker, organized by their specific time off plans.
Retrieve Workday account details for one or multiple specified users.
Retrieves detailed public and private data for the selected workers.
Fetches a list of pre-hires (job applicants) or retrieves details of a specific pre-hire using their email address.
Executes a custom REST API request to the connected service using OAuth2 authentication.
Executes a custom SOAP API request using your authorized credentials.
Executes a custom SOAP API request using your authorized credentials.
Creates a new probation period for a worker or updates an existing probation period assigned to them.
Transfers workers from one organization to another.
Transfers a job requisition from its current job management organization to a different job management organization within your system.
Enables you to initiate a compensation change request for an employee through the compensation change business process.
Submits a new request for a leave of absence.
Generates a new record for an employee returning from a leave of absence request.
Submits a request to adjust an employee's merit, starting the employee merit adjustment workflow.
Executes a WQL (Workday Query Language) query on your Workday account using an OAuth2 connection.
Fetches detailed timesheet records for workers based on the specified criteria.
Removes an employee from the organization's system, ending their employment status.
Updates the information or details of an existing dependent in your system.
Enables you to modify the details of a stock grant that has already been assigned to an employee.
Updates the details of an existing Workday account, such as the username or password, using the provided information.
Triggers when a new worker profile is created in your system.
Templates
You can look for more templates in Make's template gallery, where you'll find thousands of pre-created scenarios.
Workday Human Capital Management resources
You can have access to more resources related to this app on the following links