Workday
Sync Workday HR events to trigger intelligent IT provisioning and access management
Workday is an enterprise cloud platform for finance and human resources management. Connecting Workday to Harmony enables automated IT provisioning triggered by HR events, comprehensive employee lifecycle management, and data-driven workforce analytics for IT operations.
What the Workday integration enables
Automated Provisioning
Trigger IT workflows automatically based on Workday HR events
Employee Lifecycle
Manage onboarding, transfers, and offboarding seamlessly
Organizational Sync
Keep employee data and org structure synchronized across IT systems
Lifecycle Automation
Automate IT tasks for role changes, transfers, and promotions
How It Works
Harmony connects to Workday Web Services (SOAP) as an Integration System User (ISU) using WS-Security. The connection requires exactly four values: Username, Password, Tenant ID, and WSDL URL.
Prerequisites
Workday Administrator Access: Admin role with permissions to create Integration System Users (ISUs)
Permissions to configure security groups and policies
Harmony Account: Active Harmony workspace with admin privileges
Connect Workday to Harmony
Step 1: Create Integration System User in Workday
Log in to your Workday tenant
Search for Create Integration System User and fill in:
User Name:
HarmonyIntegrationPassword: Create a strong password (no
&,<, or>characters)Session Timeout Minutes:
0(prevents session expiration)Optionally check Do Not Allow UI Sessions to block interactive logins
Search for Maintain Password Rules and add the ISU to System Users exempt from password expiration
Step 2: Create Security Group
Search for Create Security Group
Select Integration System Security Group (Unconstrained) as the type and name it
Harmony Integration GroupAssign
HarmonyIntegrationto the new security group
Step 3: Grant Domain Security Policies
Search for Maintain Permissions for Security Group and select
Harmony Integration GroupAdd the following domain security policies with Get access:
Worker Data: Public Worker Reports
Person Data: Name
Person Data: Work Contact Information
Worker Data: Current Staffing Information
Worker Data: Organization Information
Worker Data: Workers
Worker Data: Time Off (required for syncing employee time-off and availability)
Search for Activate Pending Security Policy Changes and confirm
For each domain, make sure Get is ticked under Integration Permissions — not only under the report/task view permissions. Integration Permissions are what govern Workday SOAP web services access; granting only view permissions is the usual cause of 403 errors even when all permissions appear to be granted.
Tip: To look up which functional area a given domain belongs to, run the Domain Security Policies for Functional Area report in Workday.
Step 4: Find Your Connection Details
Username / Password: The credentials of the
HarmonyIntegrationISU created in Step 1Tenant ID: The tenant identifier from your Workday URL. For example, if your Workday UI is at
https://impl.workday.com/sample_company/d/home.html, your Tenant ID issample_company. Enter it exactly as it appears in the URL — it is case-sensitiveWSDL URL: Only the Workday web services host — for example
https://wd2-impl-services1.workday.com. To find it, run the Public Web Services report in Workday, select Human Resources (Public) > Web Service > View WSDL, and take just the host part of the WSDL address (everything before/ccx/...)
Do not paste your Workday browser URL or the full /ccx/service/... endpoint into the WSDL URL field. Harmony builds the service path automatically — the field must contain only the host, like https://wd2-impl-services1.workday.com.
Connect your production Workday tenant unless you specifically want sandbox data. URLs containing impl (e.g. impl.workday.com) belong to implementation/sandbox tenants — Harmony will sync whatever tenant the WSDL URL points at.
Step 5: Navigate to Integrations
Log into your Harmony dashboard
Navigate to Settings > Integrations
Find Workday under HRIS and click Connect
Step 6: Enter Credentials
Enter your Username (the ISU created in Step 1)
Enter your Password
Enter your Tenant ID
Enter your WSDL URL
Click Connect
Once connected, Harmony automatically pulls employee data from your Workday instance to keep your team and agent data synchronized with your support platform.
What Harmony Syncs
From Workday:
Employee profiles (name, email, employee ID)
Job information (title, position, job profile)
Department and cost center
Manager relationships and organizational hierarchy
Work location and address
Employment status and type
Employment dates (hire date, termination date)
Time off and availability
New hire, termination, job change, and transfer events
Use Cases
Troubleshooting
Last updated
Was this helpful?
