The Workday integration offers a single sign-on integration, as well as user data syncing directly from your workday environment to Simpplr, meaning no need to waste time with duplication. With the data updating every night, your intranet will always stay current. A sample of the report format that should be used with Simpplr is specified at the end of this article.
Note: You must be a Workday admin user to properly configure this integration.
Simpplr allows you to connect with Workday using SAML 2.0. With this connection:
Users are given the ability to login and authenticate into Simpplr using their Workday credentials
Workday users will be added immediately (Just In Time provisioning) if not already onboarded while logging in to the system
Users can log in via the employee ID/number or email stored in Workday (alternate login SSO)
To get started, as the Workday admin user:
Log in into your Workday dashboard.
From the Applications menu, go to SSO.
Create a SAML application by following the instructions on screen.
Copy the SAML 2.0 Endpoint (HTTP) url. Paste the link in a place you'll have easy access to later. We will paste it again in Simpplr momentarily.
From the SAML Signature Algorithm dropdown, choose SHA-256.
In the X.509 Certificate section, click View Details, then download the PEM file.
Add the following mappings to your Workday integrated Simpplr SAML app:
Field Name (Simpplr) | Value (Workday) |
first_name | First Name |
last_name | Last Name |
Email* | |
employee_number | Employee ID* |
* At-least one mapping (email or employee_number) is mandatory, but both would work as well.
Back in Simpplr:
As the App manager, navigate to Manage > Application > Security > External IdP (SSO).
Select Workday.
Enter the Workday link retrieved from your Workday portal. This is the SAML 2.0 Endpoint (HTTP) url we copied in the above steps.
Upload the PEM certificate file to Simpplr in the Certificate section.
Select at least one Login identifier that users will be able to use from their Workday credentials.
Select Save.
Create a JSON report. See Appendix A in this article for a sample. The field labels should be exactly the same as the ones in Appendix A. Field labels are case sensitive. Once you have the report generated, from Simpplr, click on your avatar at the upper right hand corner, go to Manage > Application > Integrations > People Data. Check the box next to Workday and enter your Workday username, password and endpoint url to access the report. Click Save when done.
Note: “Workday endpoint URL” is the location of your Workday JSON report. You must find this by navigating to your JSON report that contains your user list within Workday. Copy and paste that JSON endpoint URL into the box in Simpplr. Only Admins of Workday can perform this.
Go to Manage > Application > People > Provision & sync users. Select Workday from the Syncing source dropdown menu and select the fields that you want to sync with Workday. Note that EmployeeID and PrimaryWorkEmail are the required fields. Click Save when you are done. Note you're able to select Show mapping key to list the names of the fields you need to sync with your JSON file.
Back in the Manage > Application > Integrations > People Data menu, click Run now to pull through the Workday user information immediately. Here you can also choose what time every day for the scheduler to run and update. The timezone is CMT.
If you'd like to display open jobs from your ATS, time-off balances, or messages from your Workday inbox on a Simpplr intranet tile, you'll need to configure a few additional data points in the Workday setup. For more on App tiles, check out this article.
To get started:
Click Additional details (optional) from the Workday setup page in Manage > Application > Integrations > People data.
Enter the Workday WSDL URL and Workday Tenant Id.
Next, create an API Client to obtain the Client ID, Client Secret, and Refresh Token.
To ensure the Workday app tile functions correctly, the following security permissions must be granted to the Integration System User (ISU) or the security group it belongs to.
Access Level | Domain Security Policy | Functional Area |
|---|---|---|
Get Only | Reports: Pay Calculation Results for Worker | Core Payroll |
Get Only | Worker Data: Current Staffing Information | Staffing |
View Only | Worker Data: Time Off (Time Off Balances) | Time Off and Leave |
View and Modify | Worker Data: Leave of Absence | Time Off and Leave |
View and Modify | Worker Data: Time Off (Time Off) | Time Off and Leave |
View and Modify | Worker Data: Public Worker Reports | Staffing |
View and Modify | Set Up: Time Off (Calculations - Absence Specific) | Time Off and Leave |
View and Modify | Worker Data: Time Off | Time Off and Leave |
View and Modify | Set Up: Leave of Absence | Time Off and Leave |
View Only | Set Up: Time Off | Time Off and Leave |
Get Only | Job Postings | Recruiting |
Get Only | Set Up: Learning Catalog | Learning Core |
Get Only | Reports: Learning Record | Learning Core |
Get Only | Worker Data: Payroll | Core Payroll |
Get Only | Manage: Learning Content | Learning Core |
Get Only | Process: Business Assets | Business Asset Tracking |
Get Only | Business Process Reporting | System |
Get Only | Business Process Administration | System |
To configure Business Process permissions required for tile visibility and functionality, search: Edit Business Process Security Policy
Permission | Business Process Type | Functional Area |
|---|---|---|
Initiate (Enter Time Off (Web Service)) | Request Time Off | Time Off and Leave |
Initiate (Change Personal Information (Web Service)) | Change Personal Information | Personal Data |
View All | Distribute Documents or Tasks | System |
Add your security group to the relevant policies and actions listed above.
Reminder: After updating these security policies, be sure to activate the pending changes in Workday.
Activate security policy changes
In the search bar, type "Activate pending security policy changes" to view a summary of the changes in the security policy that needs to be approved.
Add any relevant comments on the window that pops up.
Confirm the changes in order to accept the changes that are being made and hit OK.
Search for "View Security for Securable Item".
Enter "All Business Process Transactions Of Type Awaiting Person".
Expand "Data Sources".
Find "All Business Process Transactions of Type Awaiting Person".
Click on "View Security".
Click on "Related Actions (...)" for Business Process Reporting > Domain Security Policy > Edit Permissions.
Under Report/Task Permissions > Add Row > In Security Group select a Group which has All Employees or the group of employees for whom the App tile will be visible.
Click on "Ok" > "Done".
Lastly, to Activate changes, search for "Activate pending security policy changes".
Click on "OK" > Confirm > "OK".
If you get the error: Enter a valid report field. This field is invalid: cf_ApprovalChainNextApprover.
Go to Create Calculated Fields.
Enter Field Name as "Approval Chain Next Approver".
Enter Business object as "Event".
Enter Function as "Extract Single Instance".
Enter the rest of the details:
Source Field - Workers Possibly Assigned next
Condition - Is True
Sort Field - Management Level
Go to Additional Info > Advanced > Make sure the WQL Alias is cf_ApprovalChainNextApprover.
Click on OK > Done.
Employee number We use the Employee number stored in Workday to find the corresponding user in Simpplr. If the Employee number field is selected to sync with Simpplr, we will add an Employee number for those users who do not have one already set. The user's email address is matched to the corresponding user in Simpplr. If multiple users have the same email address, all of the user's records will be updated with the Employee number. The user's email address must be written in all lowercase.
Synced fields All fields that are selected for sync will be updated with the corresponding values received from Workday. If a field is selected to sync with Workday then it cannot be edited from Simpplr.
Birthday day and month The birthday field has two inputs in Simpplr; one for the day and one for the month. These must be separated values, both numerical in your JSON report in order for the sync to occur correctly.
Country code If you're in the United States, the Country code field must be input with "United States", not "US". The country code is the phone code id. For example, the US is (+1). The United Kingdom is (+44).
Locale For the Locale field, you must input the full name of the country. See the list below for the corresponding values based on locale. The exact value shown must be entered in the field.
Locale value (this is what must be input into the JSON): en-US, en-GB, fr-FR, fr-CA, es-ES, de-DE, it-IT, ja-JP, pt-BR, zh-CN, nl-NL, ro-RO, hy-AM, bg-BG, da-DA, ms-MY, th-TH
Language Input the applicable language exactly as written below.
English (US), English (UK), French, French (Canadian), Spanish, German, Italian, Japanese, Portuguese, Chinese (simplified), Dutch, Romanian, Armenian, Bulgarian, Danish, Malay, Thai
Sample JSON response accepted by Simpplr:
json
{
"Report_Entry": [
{
"EmployeeID": "100",
"FirstName": "Ryan",
"LastName": "Taylor",
"Role": "CEO",
"HireDate": "2011-06-06",
"AboutMe": "Nice bio coming soon.",
"BirthDate": "1978-08-12",
"BusinessTitle": "CEO",
"PayCurrency": "CAD",
"ManagerID": "",
"Manager": "",
"Department": "Corporate",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+ryan.taylor@gmail.com",
"PublicWorkPhones": "9565550401",
"PublicWorkMobilePhones": "9565550501",
"NickName": "rtaylor",
"CompanyName": "GoodCo Inc.",
"Extension": "101",
"Fax": "8765550700"
},
{
"EmployeeID": "105",
"FirstName": "Jennifer",
"LastName": "Whitman",
"Role": "Director",
"HireDate": "2012-07-07",
"AboutMe": "Nice bio for Jennifer Whitman coming soon.",
"BirthDate": "1980-06-10",
"BusinessTitle": "Director, Human Resources",
"PayCurrency": "CAD",
"ManagerID": "100",
"Manager": "Ryan Taylor",
"Department": "Human Resources",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+jennifer.whitman@gmail.com",
"PublicWorkPhones": "9565550402",
"PublicWorkMobilePhones": "9565550502",
"NickName": "jwhitman",
"CompanyName": "GoodCo Inc.",
"Extension": "102",
"Fax": "8765550701"
},
{
"EmployeeID": "110",
"FirstName": "Troy",
"LastName": "Miller",
"Role": "Employee Communications Manager",
"HireDate": "2013-08-08",
"AboutMe": "The master of all things sales, marketing, HR and ops at Goodco. Interests: Boating, cats",
"BirthDate": "1984-03-04",
"BusinessTitle": "Employee Communications Manager",
"PayCurrency": "CAD",
"ManagerID": "105",
"Manager": "Jennifer Whitman",
"Department": "Human Resources",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+troy.miller@gmail.com",
"PublicWorkPhones": "9565550403",
"PublicWorkMobilePhones": "9565550503",
"NickName": "tmiller",
"CompanyName": "GoodCo Inc.",
"Extension": "103",
"Fax": "8765550702"
},
{
"EmployeeID": "112",
"FirstName": "Nicole",
"LastName": "Kramer",
"Role": "Senior HR Manager",
"HireDate": "2013-08-08",
"AboutMe": "Nice bio about Nicole Kramer coming soon.",
"BirthDate": "1981-11-21",
"BusinessTitle": "Senior HR Manager",
"PayCurrency": "CAD",
"ManagerID": "105",
"Manager": "Jennifer Whitman",
"Department": "Human Resources",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+nicole.kramer@gmail.com",
"PublicWorkPhones": "9565550404",
"PublicWorkMobilePhones": "9565550504",
"NickName": "nkramer",
"CompanyName": "GoodCo Inc.",
"Extension": "104",
"Fax": "8765550703"
},
{
"EmployeeID": "114",
"FirstName": "Erika",
"LastName": "Kane",
"Role": "VP",
"HireDate": "2014-03-01",
"AboutMe": "Nice bio for Jennifer Whitman coming soon.",
"BirthDate": "1980-02-09",
"BusinessTitle": "VP, Customer Success",
"ManagerID": "100",
"Manager": "Ryan Taylor",
"Department": "Customer Success",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+eikra.kane@gmail.com",
"PublicWorkPhones": "9565550405",
"PublicWorkMobilePhones": "9565550505",
"NickName": "ekane",
"CompanyName": "GoodCo Inc.",
"Extension": "105",
"Fax": "8765550704"
},
{
"EmployeeID": "115",
"FirstName": "Sydnee",
"LastName": "Walker",
"Role": "Manager",
"HireDate": "2012-07-17",
"AboutMe": "Nice bio for Sydnee Walker coming soon.",
"BirthDate": "1980-02-09",
"BusinessTitle": "Manager, Customer Success",
"PayCurrency": "CAD",
"ManagerID": "114",
"Manager": "Erika Kane",
"Department": "Customer Success",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+sydnee.walker@gmail.com",
"PublicWorkPhones": "9565550406",
"PublicWorkMobilePhones": "9565550506",
"NickName": "swalker",
"CompanyName": "GoodCo Inc.",
"Extension": "106",
"Fax": "8765550705"
},
{
"EmployeeID": "116",
"FirstName": "Robert",
"LastName": "Hawkins",
"Role": "Manager",
"HireDate": "2012-05-07",
"AboutMe": "Nice bio for Robert Hawkins coming soon.",
"BirthDate": "1983-12-19",
"BusinessTitle": "Tech Support Specialist",
"ManagerID": "115",
"Manager": "Sydnee Walker",
"Department": "Customer Success",
"Division": "Corporate",
"WorkAddressFormattedLine1": "1650 Castro Street",
"WorkAddressFormattedLine2": "Suite 221",
"WorkAddressCity": "Mountain View",
"WorkAddressStateProvince": "California",
"WorkAddressPostalCode": "94041",
"WorkAddressCountry": "United States of America",
"PrimaryWorkEmail": "simpplr.dev+robert.hawkins@gmail.com",
"PublicWorkPhones": "9565550407",
"PublicWorkMobilePhones": "9565550507",
"NickName": "swalker",
"CompanyName": "GoodCo Inc.",
"Extension": "107",
"Fax": "8765550706"
}
]
}Follow the steps below to register an API client in Workday.
Navigate to Register API Client in Workday.
Provide the following values:
Client Grant Type: Authorization Code Grant
Access Token Type: Bearer
Redirection URI: As provided by Simpplr
Enable the following scopes:
Adaptive Planning for Financial Plans
Adaptive Planning for the Workforce
Organizations and Roles
Tenant Non-Configurable
Time Off and Leave
Leave all other fields unchanged.
Time off Requests - Allow users to view pending time off requests and approve or deny them
It displays:
Created on date
Name of the user who has applied for time off
Type of leave
Start date
End date
No of hours
Interactions:
Clickable Type of leave: redirects to the time off details page in Workday.
Select tick button to approve time off request
Select X button to deny time off request. On clicking the “deny” button, a popup opens which requires a comment to deny time off request.
Prerequisites & Setup:
An OAuth 2.0 Authorization Code configuration is required. An OAuth application must be created by a Workday Admin to obtain the Client ID and Client Secret.
App admin must have enabled and configured the Workday integration from: Manage > Application > Integration > Custom Apps
Navigate to Add New App > Add Prebuilt App, then select and add the Workday (User Auth) app.
Once added, configure the app using the generated Client ID and Client Secret.
Enter the Auth URL (Authorization Endpoint) and Token URL (Token Endpoint) given in Workday (API Clients section).
For the Base URL (Workday REST API Endpoint), use the pre-filled format and ensure that ::process:: is appended after /ccx/api/.
Example:
If your Workday REST API endpoint is
https://{your-workday-domain}.myworkday.com/ccx/api/v1/{your-tenant}
then the Base URL to enter is:
https://{your-workday-domain}.myworkday.com/ccx/::process::/v1/{your-tenant}
After completing the configuration, enable the app.
Once enabled, the app will be available under the Add Tile option on the home or site dashboard.
Users must authenticate using their Workday accounts.
Do I need to be a Workday admin to set up this integration? Yes. You must be a Workday admin user to configure SSO, generate the user data report, and register API clients. Only Workday admins can retrieve the JSON endpoint URL and grant the necessary domain security permissions.
What SAML version does Simpplr support for Workday SSO? Simpplr connects to Workday using SAML 2.0, with SHA-256 as the signature algorithm.
Which field mappings are required for SSO to work? At least one of email or employee_number must be mapped between Simpplr and Workday. Both can be mapped together, but one is the minimum requirement.
How often does the user data sync run? By default, the sync runs nightly. You can choose a specific time for the scheduler to run each day from Manage > Application > Integrations > People Data. The timezone used is CMT. You can also trigger an immediate sync using the Run now option.
What are the required fields for user syncing? EmployeeID and PrimaryWorkEmail are required fields when configuring Provision & sync users.
Can I edit a field in Simpplr if it's set to sync with Workday? No. Any field selected for sync will be overwritten by the value from Workday and cannot be manually edited in Simpplr.
Why isn't my Employee Number updating for a user? Simpplr matches users to Workday records using email address. If multiple users share the same email address, all matching records will be updated with the same Employee number. Make sure email addresses in the JSON report are written in all lowercase.
Why is my Birthday field not syncing correctly? The Birthday field requires separate numerical values for day and month in the JSON report. If they aren't split out this way, the sync won't populate correctly.
What value should I use for Country code and Locale? Country code should be the full country name (e.g., "United States", not "US"). Locale requires the exact locale code from the supported list (e.g., en-US, fr-FR, ja-JP) — partial or reformatted values won't be accepted.
What do I need to set up App tiles like time-off balances or job postings? In addition to the standard people data sync, you'll need to enter the Workday WSDL URL and Workday Tenant ID, then create an API Client to obtain a Client ID, Client Secret, and Refresh Token.
Who needs the Domain Security Policy permissions — every Workday user or just one account? These permissions need to be granted to the Integration System User (ISU) used for the integration, or to the security group that ISU belongs to — not to individual end users.
I updated the security policies in Workday but the tile still isn't working. What am I missing? Security policy changes in Workday don't take effect until they're activated. Search for "Activate pending security policy changes," review and confirm the summary, and hit OK to push the changes live.
I'm getting the error "Enter a valid report field. This field is invalid: cf_ApprovalChainNextApprover." How do I fix it? This means the calculated field doesn't exist yet in your tenant. Create it via Create Calculated Fields with Field Name "Approval Chain Next Approver," Business object "Event," and Function "Extract Single Instance," then set the Source Field to Workers Possibly Assigned next, Condition to Is True, and Sort Field to Management Level. Finally, confirm the WQL Alias is set to cf_ApprovalChainNextApprover under Additional Info > Advanced.
Which security group controls who can see the Workday User Auth app tile? Under Report/Task Permissions on the relevant Domain Security Policy, add the Security Group that should have visibility — this can be an All Employees group or a more limited group, depending on who should see the tile.
What's the difference between the Workday (User Auth) app and the standard People Data integration? People Data handles the core user sync and SSO. The Workday (User Auth) app is a separate prebuilt app used specifically for interactive tiles (like Time Off Requests) and requires its own OAuth 2.0 Authorization Code setup with a Client ID, Client Secret, Auth URL, and Token URL.
How do I format the Base URL for the Workday (User Auth) app? Take your standard Workday REST API endpoint and replace /api/ with /::process::/. For example, https://{domain}.myworkday.com/ccx/api/v1/{tenant} becomes https://{domain}.myworkday.com/ccx/::process::/v1/{tenant}.
Can users approve or deny time off requests directly from the Simpplr tile? Yes, once the Workday (User Auth) app is configured, the Time Off Requests tile lets users approve requests with a tick button or deny them with an X button. Denying a request requires entering a comment in the popup that appears.