Connect Workday to Black Cat SSPM
Connect your Workday tenant so Black Cat can review workers, security groups, authentication policies, integration users and audit settings.
≈ 20 min · audit access · no write-capable permission
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
Integration System User (ISU) assigned to an Integration System Security Group | Lets Black Cat sign in as a dedicated read-only Workday account rather than as one of your people. | Required |
Domain Security Policy (Get access): Worker Data: Public Worker Reports | Lets Black Cat see workers, their account status, manager and termination date. | Required |
Domain Security Policy (Get access): Security Configuration | Lets Black Cat review security groups, their membership and the domains they reach. | Required |
Domain Security Policy (Get access): Integration Build | Lets Black Cat review integration systems and the scope they carry. | Required |
Domain Security Policy (Get access): System Auditing | Lets Black Cat check that audit logging is switched on for the tenant. | Required |
Register API Client for Integrations (OAuth 2.0 refresh-token grant) | Lets Black Cat connect as the integration user without holding a password. | Required |
OAuth client functional-area scopes (Report as a Service, System, Staffing, Tenant Non-Configurable) | Lets Black Cat read the custom reports you have shared with it and the tenant settings behind them. | Required |
What you'll need
- Service base URL Required — The Workday web services address for your tenant, shown in your integration setup.
- Workday tenant name Required — The short name of your Workday tenant, as it appears in your Workday address.
- Authentication method Required — Whether the integration user signs in with a refresh token or with a username and password.
- Client identifier Required — Shown when you register the read-only integration client in Workday.
- Client secret Required — Issued with the client identifier when you register the integration client.
- Refresh token Required — Issued to the integration system user when you authorise the client.
- Token request URL Required — Where the integration client exchanges its refresh token, shown with the client registration.
- Integration username — Optional — the integration system user's name when it signs in with a password.
- Integration password — Optional — the integration system user's password when you are not using a refresh token.
- Workers report URL Required — The address of the custom report that lists your workers.
- Security groups report URL Required — The address of the custom report that lists security groups and their members.
- Authentication policies report URL Required — The address of the custom report that lists your authentication and password policies.
- Integrations report URL Required — The address of the custom report that lists integration systems and their scope.
- Delegated authentication report URL Required — The address of the custom report that lists delegated authentication settings and certificates.
- Tenant configuration report URL Required — The address of the custom report that lists tenant-wide security settings.