ANALYSIS |
Customers | Alin Hunter, Snezana Popovic, UW-IT – The customers of the groups described in this design template represent the owners of Legacy HR/P Archive reports. |
Application Use | TBD. BI Portal – The groups will be used for controlling access to the Legacy HR/P Archive reports available in the BI Portal (https://biportal.uw.edu) and/or EDW (https://edw.washington.edu). TBD. Email – The groups will be used for emailing notices about the Legacy HR/P Archive reports using UW Mailman or Marketo. |
Membership (Business Definition) | The business definition of the group memberships is individuals assigned to each Workday security role or group. For example, someone with the "Academic_Partner" role will be a member of the related UW group. See https://isc.uw.edu/admin-corner/security-roles/assignable-roles/ See https://isc.uw.edu/support-resources/how-to-get-workday-help/named-support-contacts/ |
Business Process | Workday security role or group management |
System of Record | Workday |
Subject Area | Master Data |
Business Domain | Master Data – Services & Resources – HR/P – Access permissions and restrictions
|
DESIGN |
Type | Group/Role |
Home Group | uw_isc |
Group IDs | The following table describes mappings from Workday security groups and roles to UW group attributes. Each UW Group ID will be of the format "uw_isc_security_<identifier>" where the <identifier> is replaced with the reference ID of the Workday security role or group. In order to conform to the UW group syntax, the reference ID will be lowercased and underscores converted to hyphens. Each UW Group Display Name will be of the format "Workday Security - <name>" where the <name> is replaced with the Workday security role or group name, without any changes to the data.
| Workday Security Role/Group Reference ID | Workday Security Role/Group Name | UW Group Display Name | UW Group ID |
---|
1 | Absence_Office_Partner | Absence Office Partner | Workday Security - Absence_Office_Partner | uw_isc_security-group_absence-office-partner | 2 | Academic_Partner | Academic Partner | Workday Security - Academic_Partner | uw_isc_security_academic-partner | 3 | Academic_Personnel_Office_Partner | Academic Personnel Office Partner | Workday Security - Academic_Personnel_Office_Partner | uw_isc_security_academic-personnel-office-partner | 4 | CBU_Benefits_Office_Partner | CBU - Benefits Office Partner | Workday Security - CBU_Benefits_Office_Partner | uw_isc_security_cbu-benefits-office-partner | 5 | Costing_Allocations_Coordinator | Costing Allocations Coordinator | Workday Security - Costing Allocations Coordinator | uw_isc_security_costing-allocations-coordinator | 6 | HCM_Initiate_2 | HCM Initiate 2 | Workday Security - HCM_Initiate_2 | uw_isc_security_hcm-initiate-2 | 7 | HR_Auditor | HR Auditor | Workday Security - Workday Security Group - HR_Auditor | uw_isc_security_hr-auditor | 8 | HR_Office_Partner | HR Office Partner | Workday Security - HR_Office_Partner | uw_isc_security_hr-office-partner | 9 | HR_Partner | HR Partner | Workday Security - HR_Partner | uw_isc_security_hr-partner | 10 | ISC_Compensation_Office_Partner | ISC - Compensation Office Partner | Workday Security - ISC_Compensation_Office_Partner | uw_isc_security_isc-compensation-office-partner | 11 | ISC_Payroll_Office_Partner | ISC - Payroll Office Partner | Workday Security - ISC_Payroll_Office_Partner | uw_isc_security_isc-payroll-office-partner | 12 | ISC_Retiree_Office_Partner | ISC - Retiree Office Partner | Workday Security - ISC_Retiree_Office_Partner | uw_isc_security_isc-retiree-office-partner | 13 | Labor_Relations_Union_Office_Partner | Labor Relations / Union Office Partner | Workday Security - Labor_Relations_Union_Office_Partner | uw_isc_security_labor-relations-union-office-partner | 14 | Payroll_Auditor | Payroll Auditor | Workday Security - Payroll_Auditor | uw_isc_security_payroll-auditor | 15 | VO_Medical_Centers_Payroll_Partner | VO-Medical Centers Payroll Partner (RBC) | Workday Security - VO_Medical_Centers_Payroll_Partner | uw_isc_security_vo-medical-centers-payroll-partner | 16 | VO_Medical_Centers_Absence_for_Leave_Specialist | VO-Medical Centers Absence for Leave Specialist | Workday Security - VO_Medical_Centers_Absence_for_Leave_Specialist | uw_isc_security_vo-medical-centers-absence-for-leave-specialist | 17 | VO_STAFF_COMP_COST | VO-STAFF-COMP-COST | Workday Security - VO_STAFF_COMP_COST | uw_isc_security_vo-staff-comp-cost | 18 | VO_Academic_Personnel_Office_Partner | VO-Academic Personnel Office Partner | Workday Security - VO_Academic_Personnel_Office_Partner | uw_isc_security_vo-academic-personnel-office-partner |
|
Display Name | Group display names will be populated with data from Workday. See table above. |
Lifecycle Policy (Creation) | Groups will be created only for approved uses related to Legacy HR/P Archive reports. |
Lifecycle Policy (Deletion) | Groups will be deleted when data custodians request and plan for their deletion. |
Membership (Direct) | Direct membership of each group include the UW NetIDs of individuals assigned to the specific Workday security role or group. |
Membership (Exceptions) | No exceptions for additions or deletions to memberships. All updates to the memberships must be made in Workday. |
Membership (Grace Period) | None |
Membership (Opt-in) | N/A |
Membership (Opt-out) | N/A |
Contact Person | TBD. A contact appropriate for Workday security support, e.g. "ischelp". |
Description | Group descriptions will contain the following information (substituting the specific display name for each group): "Workday Security - Academic_Partner. This group is updated nightly with data sourced from Workday. It is available only for approved business purposes. Authorized users are responsible for enforcing the defined access control policy and may not share the group membership with unauthorized parties without first obtaining authorization to do so. Please contact TBD@uw.edu for questions about using this group." |
More Information | N/A |
Application Settings (Exchange) | Inactive; change to settings will require custodian approval. |
Application Settings (Google) | Inactive; change to settings will require custodian approval. |
ACCESS CONTROL |
Data Custodian | Nancy Jagger, Rachel Gatlin, Margaret Stuart, Cindy Gregovich |
Classification | Confidential. See UW Groups Data Classification Guideline. |
Access Control Policy | The data custodians have classified these UW group memberships as Confidential. This classification forms the basis of the following access control policy and appropriate use guidelines. It is also the basis of the Membership Viewer Control (below) and Description (above). Access Control Policy: Having considered privacy, security, and compliance concerns and acknowledging the business needs for Workday security group memberships, the data custodians have established an access control policy that grants permission to view Workday security group memberships only to authorized users and processes based on business need. Appropriate Use Guidelines: Use of Workday security group memberships is subject to the following appropriate use guidelines. Permission to view Workday security group memberships is granted on the condition that authorized clients use the memberships only for approved business purposes in support of access to Legacy HR data. Authorized users are responsible for enforcing the defined access control policy (above) and may not share group memberships with unauthorized parties without first obtaining authorization to do so. Copying and sharing the membership data with unauthorized users violates the access control policy and is forbidden. |
Membership Viewer Control | TBD. uw_isc_security-group-viewer. This group is used to enforce the defined access control policy (above). TBD. In order to fulfill requests to view the memberships of the Workday groups, appropriate admins and/or member managers should be defined for uw_isc_security-group-viewer. |
Sender Control | N/A |
IMPLEMENTATION |
Data Source | HRPWS |
Membership (Technical) | TBD. Ann Testroet Define the technical definition of the memberships in terms used by the data source (HRPWS) and its data elements, as well as any additional filtering. |
Provisioning | TBD. Ann Testroet Similar to uwhrlocationgroupmaker Define a provisioning model for data integration and reconciliation that ensures the groups are created in accordance with their lifecycle policy and managed in accordance with their data quality standards. |
De-Provisioning | TBD. Ann Testroet Similar to uwhrlocationgroupmaker Define a de-provisioning model that ensures the groups are deleted in accordance with their lifecycle policy. |
Monitoring | TBD. Ann Testroet Similar to uwhrlocationgroupmaker Define a monitoring solution that helps identify incidents and problems, particularly those that impact availability and reliability. |
Data Quality Standards | TBD. Ann Testroet Similar to uwhrlocationgroupmaker Define data quality standards under normal operations, including data validation rules, timeliness of updates, defined error rates, integrity monitoring, and reliability. The standards will depend on the business process, system of record, data source, provisioning and de-provisioning models, monitoring, and operations. |
Internal Documentation | TBD. Ann Testroet Similar to uwhrlocationgroupmaker Define what internal documentation will be developed and where it will be maintained. |
Customer Documentation | TBD. |
Communication Plan | Alin and Snezana will coordinate communications part of the "Legacy HRP System Shutdown and Data Archiving - Implementation" project (PRJ0234400). |
OPERATIONS |
Request Fulfillment | TBD. All requests that cannot be handled self-service by the Customer Documentation, will be directed to the email address defined by the Contact Person (above). Examples of requests include standard requests for information and access to memberships. |
Change Management | TBD. The data custodians and/or ISC and/or Arlene will be responsible for changes to Workday security group reference IDs. Changing an existing reference ID impacts customers of the corresponding UW group, and appropriate change management can reduce the impact to business operations. |
Incident Management | Incidents with the group memberships, with a root cause attributed to UW-IT's systems and processes, will be handled via the UW-IT Incident Management practice. |