All connectors

    Workday HCM connector

    Read and update workers, positions, organizations and job changes

    HRProvided by WorkdayOAuth 2.0 (client credentials)

    Authentication

    OAuth 2.0 (client credentials)

    A service application authenticates without a human in the loop. Suited to tenant-wide access managed by IT.

    Requires an administrator to register the application and grant tenant-level permissions.

    Configuration fields

    • Client ID
    • Client secret
    • Tenant or instance ID
    • Requested scopes

    How VeroTX governs the Workday HCM connector

    • Credentials are held in the platform credential vault. Agents never see them.
    • Every call runs as a step in a versioned WorkStream Playbook, so the rules that apply are the rules that were published.
    • Actions that cross a policy threshold stop at a tollgate and wait for the named approver.
    • Each call is written to the Execution Ledger with the inputs, the result and the Playbook version in force.

    What the Execution Ledger records for a Workday HCM call

    1. 1

      Credential resolved

      OAuth 2.0 (client credentials) credential released from the vault to the connector runtime. The step never sees the secret.

    2. 2

      Action called

      A WorkStream step called Workday HCM with the inputs recorded on the step, under the Playbook version in force.

    3. 3

      Policy evaluated

      Thresholds on the step were checked. Anything over the limit stops at a tollgate and waits for the named approver.

    4. 4

      Result written

      The response from Workday HCM, the timing and the Playbook version were written to the Execution Ledger.

    See what gets recorded

    Where this connector is used

    Hiring, onboarding and people data.

    Other hr connectors

    See it run

    Connectors only matter inside a WorkStream. The product tour walks a request from intake through a tollgate to a recorded result.