Workday Human Capital Management
Use selected Workday HCM workforce records in Pomerium policy through a customer-owned external data source.
Overview
Workday Human Capital Management is a workforce and human resources system. Its APIs and report interfaces can expose selected worker records. A customer-owned adapter can map approved fields to Pomerium Enterprise external data.
Selected Workday HCM data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected Workday HCM records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
Create a Workday integration user and security group with access only to the required worker fields. Use the supported SOAP, REST, GraphQL, or approved report interface for the selected tenant.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
An adapter maps an active Workday worker record to a stable work email or user ID. A Pomerium policy requires the imported employment state. Workday changes reach Pomerium on the adapter polling schedule.
Considerations
- Workday security controls which workers and fields an integration can read. Request only the required data sections.
- Large Get_Workers requests can have variable performance. The adapter must handle paging and missing fields.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A workforce record does not prove that the current requester is the person named by that record. Match it through a supported user key.
