W
Setup Guide

Connect Workday to Clarity

4 steps About 20 minutes to complete your portion

You will create secure integration access in Workday, assign the data permissions Clarity needs, and then use your secure Clarity connection link to finish setup.

BEFORE YOU BEGIN
You will need Workday administrator access with permission to create integration users, security groups, authentication policies, and security permissions.
1

Create Your Integration User

Open the secure Clarity connection link and select Allow and Continue. Then sign in to Workday.

Create the Integration System User (ISU)

  • Search for Create Integration System User. Create a dedicated username and password for the Clarity connection.
  • Do not select Generate Random Password.
  • Leave the remaining settings unchanged, then select OK and Done.

Prevent the password from expiring

Search for Maintain Password Rules. Under System Users exempt from password expiration, add the ISU you just created, then select OK and Done.

2

Create Secure Integration Access

Next, place the ISU in a dedicated security group and allow that group to authenticate with credentials.

Create the security group

Search for Create Security Group. For Type of Tenanted Security Group, choose Integration System Security Group (Unconstrained). Name the group and add your new ISU as the Integration System User.

Update the authentication policy

  • Search for Manage Authentication Policies and edit your current policy.
  • Create a new rule for the security group you just created.
  • Authentication Condition Name: credentials
  • Leave the remaining rule settings unchanged.
  • Select OK and Done.

Activate the authentication policy

Select Activate All Authentication Policies, add a comment, and confirm the change.

IMPORTANT
The authentication-policy changes must be activated before the integration can connect.
3

Give Clarity Access to the Required Data

Search for Maintain Permissions for Security Group and select the security group you created. Add the permissions below based on the data you want Clarity to sync.

FOR A STANDARD READ-ONLY CONNECTION
Choose Get Only for each permission. Use Get and Put only if your specific integration requires read/write access.
DataDomain Security Policies
OrganizationManage: Organization Integration
Employee ProfileWorker Data: Public Worker Reports; Person Data: Name; Person Data: Personal Data; Person Data: Home Contact Information; Person Data: Work Contact Information; Worker Data: Workers
EmploymentWorker Data: All Positions; Worker Data: Current Staffing Information; Worker Data: Employment Data; Worker Data: Organization Information; Worker Data: All Worker’s Positions Past and Present
CompensationWorker Data: Compensation; Worker Data: Compensation by Organization
PayrollReports: Pay Calculation Results for Worker (Results); Worker Data: Payroll
Payroll CodesIntegration Build
Bank InformationWorker Data: Payroll (Payment Elections)
Time OffWorker Data: Time Off; Worker Data: Time Off (Accrual and Time Off Adjustments/Overrides by Batch ID)
BenefitsSet Up: Benefits; Worker Data: Benefit Elections; Worker Data: Beneficiaries and Dependents
TimesheetsProcess: Export Time Blocks

Finish the Workday Security Setup

When all required permissions are selected, choose OK and Done.

Activate your security changes

Search for Activate Pending Security Policy Changes. Add a comment, confirm the changes, and complete the activation.

WORKDAY CONFIGURATIONS CAN VARY
If an expected field is unavailable after the standard permissions are enabled, your Workday administrator may need to review related domains or subdomains in your tenant.

Only if data is missing

The original Workday instructions identify these additional areas to review when a standard domain is not available or does not expose the expected data:

  • Personal Data: citizenship, disabilities, IDs, marital status, date of birth, gender, government IDs, personal information and photo
  • Home Contact Information: home address, email, instant messenger, phone and web address
  • Work Contact Information: work address, email, private/public work email integration, instant messenger, phone and web address
  • Time Off: time off, balances, manager views and accrual/adjustment domains
  • Worker position, payroll payment-election and compensation domains

These are troubleshooting options, not additional steps for every connection.

4

Connect Workday to Clarity

Once the Workday security setup is active, return to your secure Clarity connection link.

Enter the ISU credentials

Enter the Integration System User ID and password you created earlier, then select Next.

Find your Workday Web Services endpoint

In Workday, search for Public Web Services. Open Benefit Administration > Web Service > View WSDL. Scroll to the bottom and copy the URL up to, but not including, /service.

Enter the endpoint and tenant name

Paste the endpoint into the Clarity connection screen and select Next. Then enter your Workday tenant name, which is the portion of your Workday dashboard URL after workday.com.

Optional: Workday Custom Fields

Skip this section unless you want to use Workday Custom Fields with the integration.

Find the Integration System ID

  • If you already have the required Integration System, search for View Integration System, open it, select the applicable Integration System, and copy its System ID.
  • If you do not already have an Integration System for custom/calculated fields, one must be created before you can provide this ID.
You’re Set!
Select Connect. Once the connection is successful, Clarity can begin using the authorized Workday data for your integration.
KEEP THESE CREDENTIALS SECURE
The ISU username and password provide access to your Workday integration. Store them securely and limit access to authorized administrators.

Quick Check Before You Finish

  • ISU created with a non-expiring password
  • ISU added to an unconstrained Integration System Security Group
  • Authentication rule created and activated
  • Required data permissions assigned and security changes activated
  • Web Services endpoint and tenant name entered in Clarity