Skip to content

Connect Workday to Black Cat SSPM

Version française

Connect your Workday tenant so Black Cat can review workers, security groups, authentication policies, integration users and audit settings.

≈ 20 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
Integration System User (ISU) assigned to an Integration System Security GroupLets Black Cat sign in as a dedicated read-only Workday account rather than as one of your people.Required
Domain Security Policy (Get access): Worker Data: Public Worker ReportsLets Black Cat see workers, their account status, manager and termination date.Required
Domain Security Policy (Get access): Security ConfigurationLets Black Cat review security groups, their membership and the domains they reach.Required
Domain Security Policy (Get access): Integration BuildLets Black Cat review integration systems and the scope they carry.Required
Domain Security Policy (Get access): System AuditingLets Black Cat check that audit logging is switched on for the tenant.Required
Register API Client for Integrations (OAuth 2.0 refresh-token grant)Lets Black Cat connect as the integration user without holding a password.Required
OAuth client functional-area scopes (Report as a Service, System, Staffing, Tenant Non-Configurable)Lets Black Cat read the custom reports you have shared with it and the tenant settings behind them.Required

What you'll need

  • Service base URL Required — The Workday web services address for your tenant, shown in your integration setup.
  • Workday tenant name Required — The short name of your Workday tenant, as it appears in your Workday address.
  • Authentication method Required — Whether the integration user signs in with a refresh token or with a username and password.
  • Client identifier Required — Shown when you register the read-only integration client in Workday.
  • Client secret Required — Issued with the client identifier when you register the integration client.
  • Refresh token Required — Issued to the integration system user when you authorise the client.
  • Token request URL Required — Where the integration client exchanges its refresh token, shown with the client registration.
  • Integration username — Optional — the integration system user's name when it signs in with a password.
  • Integration password — Optional — the integration system user's password when you are not using a refresh token.
  • Workers report URL Required — The address of the custom report that lists your workers.
  • Security groups report URL Required — The address of the custom report that lists security groups and their members.
  • Authentication policies report URL Required — The address of the custom report that lists your authentication and password policies.
  • Integrations report URL Required — The address of the custom report that lists integration systems and their scope.
  • Delegated authentication report URL Required — The address of the custom report that lists delegated authentication settings and certificates.
  • Tenant configuration report URL Required — The address of the custom report that lists tenant-wide security settings.

Where to create it

What we check on Workday →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan