7.3 User-Based, Job-Based, Segment-Based & Workday-Assigned Security Groups

Key Takeaways

  • User-Based Security Groups (UBSG) are manually assigned directly to Workday Accounts, are permanently unconstrained, and never automatically adjust when a worker changes positions.
  • Job-Based Security Groups (JBSG) dynamically calculate membership at runtime based on worker job attributes including Job Profile, Job Family, Management Level, and Exempt Status.
  • Segment-Based Security Groups (SBSG) enforce row- and field-level partitioning within a domain to restrict access to sensitive slices of data, such as executive compensation plans.
  • Integration System Security Groups (ISSG) provide least-privilege access containers designed exclusively for non-human Integration System Users (ISUs) executing web service operations.
  • Workday-assigned security groups (self-service such as Employee As Self, public such as All Employees, and context-resolved such as Initiator and Manager's Manager) are delivered and populated by Workday; administrators can change their policy permissions but never their membership.
Last updated: September 2026

7.3 User-Based, Job-Based, Segment-Based & Workday-Assigned Security Groups

Quick Answer: Beyond Role-Based Security Groups, Workday provides specialized security group types to solve distinct governance needs. User-Based Security Groups (UBSG) are assigned manually directly to a worker's user account, grant tenant-wide (unconstrained) access, and never change automatically when a worker transfers jobs—making them ideal for IT administrators (e.g., Security Administrator) but dangerous for operational HR. Job-Based Security Groups (JBSG) evaluate membership dynamically based on job attributes (Job Profile, Job Family, Management Level), automatically granting or revoking access as workers move across jobs. Segment-Based Security Groups (SBSG) introduce row- and field-level data filtering within a securable domain, allowing organizations to restrict sensitive data slices (e.g., executive pay components or restricted compensation grades). Finally, Integration System Security Groups (ISSG) govern non-human service accounts for automated web service integrations.


User-Based Security Groups (UBSG)

A User-Based Security Group (UBSG) is the simplest and most direct security group type in Workday. However, because of its static nature and tenant-wide power, it is also the most tightly audited under IT general controls (ITGC) and Sarbanes-Oxley (SOX) frameworks.

Core Characteristics of UBSGs

  1. Direct Account Assignment: Membership is manually assigned directly to a user's Workday Account via the Assign User-Based Security Groups task.
  2. Permanently Unconstrained: User-based security groups are always unconstrained. They cannot be restricted by supervisory organization, company, or cost center. A user holding a UBSG exercises its permissions across the entire enterprise tenant.
  3. Static Membership (No Dynamic Lifecycle): Membership does not change when a worker changes positions, transfers between departments, or relocates geographically. If an employee in Marketing is granted a UBSG and later transfers to Accounting, they retain that UBSG until an administrator manually executes a task to revoke it.
  4. Primary Use Cases: Designed strictly for system administrators, IT support specialists, and compliance auditors who require tenant-wide privileges that transcend organizational boundaries.

Delivered User-Based Security Groups

Workday delivers foundational administrative user-based groups, including:

  • Security Administrator: Configures security policies, assigns user security, activates pending security changes.
  • System Auditor: Read-only access to audit trails, policy configurations, and event logs across the entire tenant.
  • Report Administrator: Manages report categories, schedules enterprise reports, and monitors report performance.
  • Integration Administrator: Monitors integration enterprise interface builders (EIBs), Studio integrations, and document delivery.

Exam Trap Alert: Assigning a User-Based Security Group to an operational HR role (such as an HR Generalist or Payroll Specialist) is a severe architectural antipattern. Because UBSGs are unconstrained and static, doing so grants the worker tenant-wide visibility into sensitive records and creates severe privilege creep when the worker changes jobs. Operational roles must always be implemented using Role-Based or Job-Based security groups.


Job-Based Security Groups (JBSG)

A Job-Based Security Group (JBSG) provides dynamic, automated membership calculation based on the attributes of the position and job currently occupied by a worker.

How JBSGs Evaluate Membership

Instead of manual account assignment or organizational role assignment, a JBSG evaluates eligibility rules based on job data stored in the worker's active job record:

  • Job Profile: (e.g., Software Development Engineer II, Regional Sales Director)
  • Job Family & Job Family Group: (e.g., Information Technology > Software Engineering)
  • Management Level: (e.g., Executive, Director, Manager, Individual Contributor)
  • Exempt Status: (e.g., FLSA Exempt vs. Non-Exempt)

Automated Lifecycle Management

JBSGs eliminate administrative maintenance through real-time in-memory evaluation:

  • Automatic Grant: The moment a worker is hired or transferred into a position with a qualifying job profile (e.g., Vice President), the in-memory engine instantly includes them in the JBSG.
  • Automatic Revocation: The moment a worker transfers to an individual contributor role or separates from the enterprise, their membership in the JBSG is immediately terminated in memory.

Constrained vs. Unconstrained JBSGs

Unlike user-based groups, Job-Based Security Groups can be configured as either:

  • Constrained JBSG: Restricts the user's access to workers within their own supervisory organization hierarchy.
  • Unconstrained JBSG: Grants the qualifying job holders tenant-wide visibility across all workers.

Common JBSG Enterprise Scenarios

  • "All People Managers": A JBSG configured for all workers holding a management level of Manager or higher, granting access to managerial dashboards and performance calibration tools.
  • "Executive Leadership": A JBSG based on the Executive management level, granting access to corporate organizational modeling and enterprise succession planning.
  • "IT Support Specialists": A JBSG based on the Help Desk Support job family, granting read-only access to basic worker contact information tenant-wide.

Segment-Based Security Groups (SBSG): Data Partitioning

In many global enterprises, standard Domain Security Policies are insufficient to meet data privacy mandates. For example, an organization might want local HR Partners to view base pay and standard allowances for their workforce, but completely block them from viewing executive equity grants, severance packages, or retention bonuses—even though all of these pay components reside within the exact same domain: Worker Data: Compensation.

Workday solves this complex security challenge through Segment-Based Security Groups (SBSG), which enforce row-level and field-level data segmentation within a domain.

+---------------------------------------------------------------------------------------------------+
|                         SEGMENT-BASED SECURITY ARCHITECTURE                                      |
+---------------------------------------------------------------------------------------------------+
|                                 DOMAIN: Worker Data: Compensation                                 |
|                                                |                                                  |
|                 +------------------------------+------------------------------+                   |
|                 |                                                             |                   |
|                 v (Segment 1)                                                 v (Segment 2)       |
|       STANDARD PAY COMPONENTS                                       RESTRICTED PAY COMPONENTS     |
|       - Base Salary Plan                                            - Executive Equity / Stock    |
|       - Hourly Wage Plan                                            - Retention Bonus             |
|       - Standard Car Allowance                                      - Severance Agreement         |
|                 |                                                             |                   |
|                 v                                                             v                   |
|       Standard HR Partner Group                                     Executive Comp Security Group |
|       (Can view Base & Hourly only)                                 (Can view Executive Equity)   |
+---------------------------------------------------------------------------------------------------+

How Segment-Based Security Works

  1. Identify Securable Segment Type: Workday delivers specific segmentable business categories, including:
    • Compensation Pay Components: Base pay, bonus plans, merit plans, stock plans.
    • Compensation Grades & Grade Profiles: Standard pay bands vs. executive bands.
    • Worker Segments: Segmenting workers by country, company, or contingent worker type.
    • Custom Organizations: Slicing access by strategic business initiatives.
    • Expense Items: Standard travel expenses vs. confidential executive reimbursements.
  2. Define the Security Segment: The administrator executes Create Security Segment (e.g., Restricted Executive Pay Components) and adds the sensitive items to the segment.
  3. Enable Domain Segmentation: The administrator edits the governing Domain Security Policy (e.g., Worker Data: Compensation) and flags it to require segmentation.
  4. Create the Segment-Based Security Group: Using Create Security Group, the administrator creates an SBSG, specifies the permitted security segments, and assigns the group to authorized users or positions.
  5. Runtime Enforcement: When an unauthorized HR Partner views an executive's compensation tab, the base salary appears normally, but the executive stock and retention bonuses are completely suppressed from the screen.

Integration System Security Groups (ISSG)

Automated integrations between Workday and external systems (such as third-party payroll engines, benefit carriers, applicant tracking systems, and active directory) do not log in as human employees. They authenticate programmatically using Integration System Users (ISU).

Integration System Users (ISU)

An ISU is an artificial, non-human service account created via the Create Integration System User task. Key characteristics:

  • Has no worker record, no personal bio data, and no position.
  • Does not consume an employee software license.
  • Has no Workday Inbox and cannot initiate interactive self-service tasks.
  • Configured with non-expiring passwords or, ideally, X.509 public certificates or OAuth 2.0 API credentials.

Integration System Security Groups (ISSG)

An Integration System Security Group (ISSG) is a specialized security group designed exclusively to hold Integration System Users:

  • Least Privilege Architecture: An ISSG must be configured with the absolute minimum set of Get (read) and Put (write) operations required for the integration's specific interface contract.
  • Constrained vs. Unconstrained: ISSGs can be constrained by organization (e.g., an integration that only extracts payroll data for the UK legal entity) or unconstrained (e.g., an enterprise active directory sync that updates phone numbers globally).

Workday-Assigned Security Groups: The Non-Configurable Baseline

Every worker in the tenant already belongs to several security groups before an administrator assigns anything. Workday-assigned security groups are defined, delivered, and populated by Workday itself. Administrators cannot create, edit, rename, or delete them, and cannot change their membership criteria — Workday determines who is a member. What administrators can do is grant those groups permissions on domain and business process security policies.

This is the third leg of the distinction the certification exam tests most often: user-based (a human assigns the member), role-based (membership is derived from a role assignment on an organization or position), and Workday-assigned (Workday populates membership automatically from the worker's own record and context).

The Three Families of Workday-Assigned Groups

FamilyWhat Workday EvaluatesDelivered ExamplesTypical Permission Use
Self-ServiceIs this user acting on their own record?Employee As Self, Contingent Worker As SelfWorker Profile edits, own address/contact changes, own time off requests
PublicDoes this user hold this worker type at all?All Employees, All Contingent Workers, All RetireesCompany directory, published policies, announcements, org chart visibility
Other Workday-AssignedIs this user in a specific system or process context?Implementers, Initiator, Manager's ManagerImplementation-tenant access, initiator-only step routing, skip-level approvals

Why the Self-Service Constraint Is Structural, Not Configured

Employee As Self is automatically and permanently constrained to the single worker who is signed in. There is no organization context to widen and no "unconstrained" variant to create. This matters on the exam because candidates frequently try to solve a requirement such as "let employees update their own emergency contacts" by building a new constrained role-based group. The delivered answer is to grant Employee As Self permission on the relevant domain — no new group is needed, and no role has to be assigned to 40,000 workers.

Initiator and Manager's Manager in Business Process Routing

Two Workday-assigned groups exist specifically to make business process definitions portable across the whole tenant:

  • Initiator resolves at runtime to whichever user actually started the event. A To-Do step routed to Initiator reaches the recruiter on a requisition they launched and the HR Partner on one they launched — from a single step configuration.
  • Manager's Manager resolves by walking one additional level up the supervisory hierarchy from the event subject's manager. It delivers skip-level approval on compensation and termination processes without hard-coding named approvers.

Because Workday owns the membership logic, these groups keep resolving correctly through reorganizations, manager changes, and terminations with zero maintenance.

Permission Grants Still Follow Normal Rules

A Workday-assigned group being non-configurable does not mean its access is fixed. Adding All Employees to the view column of a sensitive domain security policy exposes that data to the entire workforce the moment the change is activated. Workday-assigned groups are the most dangerous place to make a careless policy grant precisely because their membership is enormous and automatic.

Exam Tip: If a question asks how to change who belongs to Employee As Self, All Employees, or Manager's Manager, the correct answer is that you cannot — Workday maintains the membership. If it asks how to change what those members can do, the answer is to edit the domain or business process security policy and then run Activate Pending Security Policy Changes.


Comprehensive Security Group Typology Matrix

Understanding the precise mechanics, assignment methods, and scopes of each security group type is essential for the HCM certification exam:

Security Group TypeMembership AssignmentOrganizational ScopeDynamic Lifecycle?Primary Enterprise Use Case
User-Based (UBSG)Manually assigned to Workday AccountPermanently Unconstrained (Tenant-Wide)No (Static; requires manual removal)IT System Admins, Security Admins, Global Auditors
Role-Based (Constrained)Bound to Assignable Role on an Org or PositionConstrained to assigned Org & subordinatesYes (Evaluated dynamically via role incumbent)HR Partners, Department Managers, Cost Center Managers
Role-Based (Unconstrained)Bound to Assignable Role on an Org or PositionUnconstrained (Tenant-Wide)Yes (Evaluated dynamically via role incumbent)Global Benefits Admins, Executive Comp Partners
Job-Based (JBSG)Dynamic rule based on Job Profile / Family / LevelCan be Constrained or UnconstrainedYes (Evaluated dynamically via worker job profile)All People Managers, Director+ Calibrations, Field Techs
Segment-Based (SBSG)Explicitly granted access to defined Data SegmentsConstrained by Segment within DomainDepends on backing group (Role/Job/User)Restricting sensitive pay components, executive grades
Integration System (ISSG)Assigned directly to Integration System UsersCan be Constrained or UnconstrainedNo (Assigned to dedicated API service accounts)Inbound/Outbound EIBs, Workday Studio APIs
Workday-Assigned (Self-Service)Not configurable — Workday assigns automaticallyConstrained to the signed-in worker onlyYes (Follows the worker’s own account)Self-service address, contact, time off and profile tasks
Workday-Assigned (Public)Not configurable — Workday assigns by worker typeUnconstrained (Tenant-Wide)Yes (Membership tracks worker type)Directory, org chart, published policy and announcement access
Workday-Assigned (Other)Not configurable — resolved from event or system contextResolved per event (e.g., initiator, skip-level manager)Yes (Evaluated at runtime per event)Initiator routing, Manager’s Manager skip-level approvals

Certification Pitfalls & Common Exam Traps

  1. The "Build a Group for Self-Service" Trap: A requirement states that employees must be able to maintain their own emergency contacts. Distractors offer creating a constrained role-based group or a job-based group covering all job families. Both are wrong and unmaintainable. Grant the delivered Employee As Self Workday-assigned group permission on the relevant domain — it is already constrained to the signed-in worker and needs no role assignments.
  2. The Editable Membership Trap: Questions ask which task adds a worker to All Employees or removes someone from Manager’s Manager. No such task exists. Workday-assigned groups are not configurable; only their policy permissions can be edited.
  3. The Operational UBSG Trap: An exam scenario features an HR Generalist who is given the HR Administrator user-based security group to help during a busy open enrollment period. Six months later, the generalist transfers to a warehouse supervisor role in a single plant. The exam asks why the supervisor can still see sensitive salary data for executive leadership across the company. The answer: User-based security groups are static and unconstrained; they do not automatically revoke upon transfer.
  4. The Incomplete Segment Security Trap: When configuring Segment-Based Security, administrators frequently create the Security Segment and create the Segment-Based Security Group, but forget to enable segmentation on the Domain Security Policy. If the domain policy is not configured to evaluate segments, the segmentation rules have zero effect in memory.
  5. Confusing Job-Based with Role-Based: Job-based groups evaluate what the worker is (their job profile or management level). Role-based groups evaluate what organizational hat the worker wears (their assignable role on a supervisory org). A worker who is a Manager by job level belongs to a JBSG, but they cannot approve time off for a team until they hold the assignable role of Manager on that team's supervisory organization.
  6. ISU Privilege Escalation: Granting a User-Based Security Group (like System Administrator) to an Integration System User violates SOC-1/SOX compliance and creates massive enterprise vulnerability. Integrations must always use dedicated ISSGs configured for least privilege.
Loading diagram...
Workday Security Group Architecture: Membership Evaluation and Scope Comparison
Test Your Knowledge

A senior benefits analyst is manually assigned to a User-Based Security Group granting tenant-wide compensation administration. Three months later, the analyst transfers into a local facility maintenance role in another country. However, the worker still retains full visibility into executive compensation data. Why did this security privilege fail to revoke automatically?

A
B
C
D
Test Your Knowledge

An organization wants to restrict access to sensitive executive compensation components (such as stock grants and retention bonuses) so that only members of the Executive Compensation team can view them, while allowing standard HR Partners to continue viewing base salary and hourly plans within the same compensation domain. Which security group type must be implemented to partition this data?

A
B
C
D
Test Your Knowledge

An IT team is configuring an automated inbound API integration to load worker historical education and certifications from an external learning management system. In accordance with Workday security best practices and compliance governance, how should this integration be secured?

A
B
C
D
Test Your Knowledge

A tenant requirement states that every employee must be able to update their own emergency contacts, and that HR must not have to assign any role to do it. Which configuration satisfies the requirement with the least ongoing maintenance?

A
B
C
D