> For the complete documentation index, see [llms.txt](https://www.cakewalk.security/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.cakewalk.security/docs/platform-overview/connections-and-integrations/identity-sources/workday.md).

# Workday

Workday connects to Cakewalk with an API client backed by a dedicated integration system user (ISU). Expect about 30 minutes of setup in the Workday console; for the shared flow, see [Connecting an HRIS](/docs/platform-overview/connections-and-integrations/connecting-an-hris.md).

### ✅ Before You Start

* You need to be an admin of your company's Workday account.
* To check: log in to Workday and search for "View API Clients". If the menu item does not appear, ask your Workday admin to grant your account sufficient permissions or to take over the setup.

### 🛠 Connect

1. In Cakewalk, go to **Settings → Data Sources → Users** and select Workday.
2. Find your service URL: search for "View API Clients", open the task and copy the **Workday REST API Endpoint** (it follows `https://{domain}/ccx/api/v1/{tenant}`).
3. Create the integration user: search for "Create Integration System User", enter a username and a secure password. Workday recommends checking **Do Not Allow UI Sessions**.
4. Create a security group for it: search for "Create Security Group", pick the type **Integration System Security Group (Unconstrained)**, name it after the integration user and add that user to **Integration System Users**.
5. Grant the group its permissions: search for "Maintain Permission for Security Group", select **Maintain**, pick your group and add the permissions under **Domain Security Policy Permissions**. The connection flow shows the exact list to enter.
6. Activate the changes: search for "Activate Pending Security Policy Changes", add a comment, check **Confirm** and select OK. Without this task, none of the permission changes take effect.
7. Create the API client: search for "Register API Client for Integrations", enter a client name, turn on **Non-Expiring Refresh Tokens** and enter the **Scope (Functional Areas)** values the connection flow shows.
8. Copy the **Client ID** and **Client Secret**, then, still on the same page, open **API Client → Manage Refresh Tokens for Integrations**, enter your integration user, check **Generate New Refresh Token** and copy the refresh token.
9. Enter the service URL, Client ID, Client Secret and refresh token in the connection flow and finish.

The first sync starts immediately. Sync details and cadence: [Connecting an HRIS](/docs/platform-overview/connections-and-integrations/connecting-an-hris.md).

### 📚 Related

* [HRIS and IdP](/docs/platform-overview/connections-and-integrations/hris-and-idp.md)
* [Connecting an HRIS](/docs/platform-overview/connections-and-integrations/connecting-an-hris.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.cakewalk.security/docs/platform-overview/connections-and-integrations/identity-sources/workday.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
