Security governance for Workday, run inside Workday.
Assign. Review. Prove.
Workday holds your salaries, merit, feedback and financial results. Roles and security groups are all that stands in front of them, and in most organizations those assignments are still requested by e-mail, tracked in spreadsheets and reviewed when an audit forces it. Security Plus puts every security assignment under a Workday business process, expires temporary access by itself, runs scheduled reviews and crucial-role certifications, detects conflicts, anomalies and cross-tenant drift, and produces audit evidence as a by-product of normal operation. No export, no sync, no second identity store.
Built by people who have owned Workday security for global tenants. Runs on your existing security groups and business process framework. App security domains map to your existing Workday security groups, so there is no new access model to build or audit.
Workday security assignments protect your most sensitive data, but they are governed outside any process. Requests arrive by e-mail or ticket. Temporary access is revoked by memory, if at all. Access reviews are periodic clean-ups, not a process. Evidence for auditors is assembled by hand, after the fact. The risk is concrete: one role assigned to the wrong person, one temporary access that never expired, one critical role that differs between IMPL and Production, one audit question with no evidence behind it. Verizon's DBIR 2025 found 60% of breaches involved the human element, with credential abuse the leading initial access vector.
The alternatives are not better. External monitoring tools observe your tenant and report findings, but the workflow that grants, expires, freezes and revokes access still has to live somewhere else. Enterprise IGA platforms treat Workday as one connector among many: shallow on Workday's group-and-domain model, deployed in quarters, priced in the hundreds of thousands. And native Workday tooling gives you point-in-time reports without an engine: no request workflow with justification, no auto-expiry, no attestation records, no health score.
So we built one. Every assignment a business process. Every review an attestation. Every change evidence. Governance that runs on your existing security groups and business process framework, designed by people who have owned Workday security for global tenants.
Request, approve, justify, done. Add, change and remove roles and security group memberships through configurable business processes with mandatory business justification and full history. Revocation runs through the same governance, so the record is complete in both directions.
Temporary access that expires by itself
Flag an assignment as temporary and set Assign Until. When the date passes, access is removed without anyone remembering to do it. A temporary security freeze suspends an assignment, or a person's entire security, for a defined window during leave, an investigation or an audit, and restores it automatically.
Reviews and crucial-role certification
Scheduled access reviews route to the right owner as Workday inbox tasks and record the attestation on the event. Crucial roles go further: quarterly or annual certification campaigns driven by a four-level criticality scale you configure, closed with a named certifier's sign-off. Flagged items feed straight into revocation, so reviews end in cleanup, not in a spreadsheet.
Segregation of duties, before and after
A rule library defines conflicting combinations of security groups and domain permissions, with a starter set for common HCM, Payroll and Financials conflicts. Every new request is checked before approval. The whole tenant is scanned on a schedule. Exceptions exist only as documented, time-boxed waivers that reopen when they expire.
Detection: anomalies, drift, and one score
Dormant access, privilege outliers against peers in the same job profile, roles granted outside the governed process, unusual sign-on patterns on critical accounts, and critical-role drift across any set of tenants you configure: Sandbox, IMPL, Production. One Security Check score aggregates it all, so posture is trackable quarter over quarter.
Answer "why do I have access?" in a minute
Compare two workers' security side by side. Ask why anyone has access to any report, task or domain, and get the exact granting chain: the domain security policy, the permitting security groups, and the full membership path.
03Versus standard Workday
How is it different from standard Workday?
CapabilityStandard WorkdayIncubane Security Plus
Security request workflowE-mail and tickets, outside Workday✓Configurable business process with mandatory justification
Temporary accessRevoked by memory✓Auto-expiry on a date, plus temporary security freeze
Access reviewsManual clean-ups, evidence by hand✓Scheduled, routed, attested in the Workday inbox
Crucial-role certificationNot supported✓Quarterly or annual campaigns with named sign-off
Criticality classificationNot native✓Four-level scale, fully configurable per customer
Segregation of dutiesPoint-in-time delivered reports✓Rule library, preventive checks at request, scheduled scans, waivers
Anomaly detectionNone✓Assignment and sign-on signals, ungoverned-change alerts
Tenant comparisonManual, tenant by tenant✓Multi-tenant comparison for critical roles, drift as findings
"Why do I have access?"Expert investigation✓Access Explainer traces the exact granting chain
Audit evidenceAssembled by hand, every audit✓Every event carries actor, timestamp, justification, approval chain
Standard Workday covers the basics. Our app covers what Audit and IT teams actually ask for.
04For your IT and Security team
How does it work inside Workday?
✓
One system of record
Assignments, reviews, findings and evidence live in your Workday tenant as Extend business objects. Worker, org and manager data are read live. No integration to build, no data to duplicate, no second identity store. This is what external monitoring tools cannot match without rebuilding their product.
✓
Your security model, governed, not replaced
Security Plus runs on your existing security groups and business process framework. App security domains map to your Workday security groups, so there is no new access model to build or audit. It passes review as Workday configuration, not as a new vendor platform. And because it is a security product, it holds itself to its own standard: every administrative act inside Security Plus is itself a recorded event.
✓
AI on your terms
You connect the language model you control. Prompts are configurable, AI is off by default, and the agent is strictly human-in-the-loop: it explains and drafts, a person decides. Nothing is sent to Incubane. An AI Fact Sheet ships with the contract, ready for your EU AI Act governance.
✓
Stable across every Workday release
We regression-test the app against both biannual Workday releases before they reach you, and feature updates are included in the license. No version-lag risk, no surprise breakage.
05Use cases
What do teams use it for?
01
SOX and ISO audit readiness
Walk into fieldwork with evidence instead of a war room. Every assignment, review, certification and exception already carries actor, timestamp, justification and approval chain, reportable through Workday reporting. Access-control expectations from ISO 27001 A.5.18 and NIST AC-2 map to running processes, not policy documents.
02
Crucial-role certification programs
Classify your security groups on a four-level criticality scale, then certify the holders of the top levels quarterly with a named sign-off. Uncertified items escalate and surface as findings. The control does not just exist; it demonstrably operates.
03
Joiners, movers, leavers without residue
Access follows people through role changes instead of accumulating. Privilege outliers against job-profile peers, dormant access signals and delta reviews keep standing privilege shrinking over time, and the manager's team view makes who-holds-what a routine glance instead of a request to IT.
04
IMPL drift and consultant access
Implementation tenants accumulate elevated access that quietly diverges from Production. Multi-tenant comparison for critical roles turns that drift into findings with owners, and time-boxed temporary assignments mean consultant access ends when the project does, by itself.
06The Workday security check
Can you answer these three in under a minute?
01
How do you assign Workday roles today?
With Security Plus: one business process. Request, approve, justify, done. Full history, no e-mail chains.
02
How do you know nothing unusual sits in your IMPL tenant?
With Security Plus: critical roles compared across tenants. Drift shows up before your auditor finds it.
03
How do you make sure access is removed when people change roles?
With Security Plus: scheduled reviews land with the right owner. Temporary access expires by itself.
Service level agreementStandardEnhanced, negotiable
Product roadmap input1 vote3 votes
Quarterly business reviewGroup session1-1 with a Managing Partner
Implementation teamDelivery teamDelivery team plus senior product team
Post go-live configuration supportOn requestUp to 40 hours per quarter
Security Agent·✓
Every subscription includes the full application for your whole workforce. Platinum is an optional upgrade for organizations that want enhanced SLAs, senior delivery attention, and direct roadmap influence.
Workday stores your security model and offers point-in-time reports on it, including delivered segregation-of-duties reports for specific scenarios. What it does not give you is an engine: a request workflow with mandatory justification, temporary access that expires by itself, scheduled reviews with attestation records, certification campaigns for crucial roles, a conflict rule library with preventive checks, anomaly and drift detection, or a health score. Security Plus adds the engine on top of the model you already have.
Monitoring tools observe your tenant from outside and report findings, and some do that well. But detection is only half the problem: the workflow that grants, expires, freezes, reviews and revokes access still has to live somewhere, and today it lives in e-mail. Security Plus is that workflow, inside your tenant, with detection built on top. One product, one system of record, and evidence generated by the process itself rather than reconstructed by a scanner.
If Workday is the system that matters, IGA is a heavyweight answer: Workday becomes one connector among many, the group-and-domain depth is limited, deployment is measured in quarters and pricing in the hundreds of thousands. Security Plus goes deep on Workday instead of wide across everything, and deploys as Workday configuration. The important distinction is that we built the tool with Workday security experts.
You classify your security groups on a four-level criticality scale, with names and thresholds you define. The top levels get formal certification campaigns, quarterly or annually per level: every holder of an in-scope role is reviewed, and the campaign closes with a named certifier's sign-off recorded as an event. Uncertified items after the deadline escalate and appear as findings. It is the control auditors ask about, running as a process instead of a promise.
Detection is rule-based and runs on scheduled cycles inside your tenant. On the assignment side: dormant access, privilege outliers against peers in the same job profile, and changes to critical groups made outside the governed process. On the sign-on side: activity on accounts that should be dormant and unusual patterns on holders of critical roles, within what Workday sign-on reporting exposes. Every signal creates a finding with an owner and a severity; thresholds and rules are yours to configure.
Yes. The Access Explainer traces the exact granting chain for any worker and any target: the domain security policy, the permitting security groups, and the membership path including role-based, job-based, segment, location and intersection logic. It answers the opposite question too: what is missing when someone cannot see something, with a deep link into the governed request flow. Access questions take a minute instead of an investigation.
The agent answers plain-language questions from Security Plus and Workday data within the asking user's own security scope, explains access, summarizes findings and campaigns, and drafts review scopes, rule proposals and waiver justifications. Every draft requires explicit human submission through the governed flow. It makes the expert faster; it does not replace the approval. Agents are a Platinum feature and run directly in Workday with Developer Agent.
You connect your own language model endpoint: your model, your prompts, your controls. AI is off by default and every AI function degrades gracefully to the non-AI flow. Nothing is sent to Incubane, and no Incubane-hosted model exists. An AI Fact Sheet ships with the contract for your EU AI Act governance.
No. Security Plus deploys into your Workday tenant through Workday Extend and runs on your existing security groups and business process framework. There is no infrastructure, no integration and no separate user store. We regression-test against both biannual Workday releases before they reach you, and updates are included in the license.
Go live in less than 12 weeks. Deployment is configuration, not integration: mapping security domains to your groups, classifying criticality, setting review and certification cadences, and choosing which tenants to compare.
An annual subscription with everything included: the full application, all features, and regression testing every release. We price to the size and complexity of your Workday estate rather than per module, and design partners receive preferred terms. Talk to us and we will give you a number in the first conversation, not after a discovery project.
A 30-minute walkthrough on your tenant setup, your review cycle, your questions. No slideware. Then scoping: which roles and groups are critical, which review cadence, which tenants to compare. Deployment plan and commercial proposal follow on Incubane's standard terms.
Works together
Workday Plus Bundle
Use them individually or together. Governed security and clean data are the two halves of a tenant your auditors stop asking about.