← All products
Approved Marketplace Solution · Security Plus

Security governance for Workday, run inside Workday.

Assign. Review. Prove.

Workday holds your salaries, merit, feedback and financial results. Roles and security groups are all that stands in front of them, and in most organizations those assignments are still requested by e-mail, tracked in spreadsheets and reviewed when an audit forces it. Security Plus puts every security assignment under a Workday business process, expires temporary access by itself, runs scheduled reviews and crucial-role certifications, detects conflicts, anomalies and cross-tenant drift, and produces audit evidence as a by-product of normal operation. No export, no sync, no second identity store.

Built by people who have owned Workday security for global tenants. Runs on your existing security groups and business process framework. App security domains map to your existing Workday security groups, so there is no new access model to build or audit.

  • Workday security domains
  • EU-resident data
  • AI Fact Sheet with every contract
  • Regression tested against both biannual releases
Read our trust and security posture →

01Why we built this

Why we built this

Workday security assignments protect your most sensitive data, but they are governed outside any process. Requests arrive by e-mail or ticket. Temporary access is revoked by memory, if at all. Access reviews are periodic clean-ups, not a process. Evidence for auditors is assembled by hand, after the fact. The risk is concrete: one role assigned to the wrong person, one temporary access that never expired, one critical role that differs between IMPL and Production, one audit question with no evidence behind it. Verizon's DBIR 2025 found 60% of breaches involved the human element, with credential abuse the leading initial access vector.

The alternatives are not better. External monitoring tools observe your tenant and report findings, but the workflow that grants, expires, freezes and revokes access still has to live somewhere else. Enterprise IGA platforms treat Workday as one connector among many: shallow on Workday's group-and-domain model, deployed in quarters, priced in the hundreds of thousands. And native Workday tooling gives you point-in-time reports without an engine: no request workflow with justification, no auto-expiry, no attestation records, no health score.

So we built one. Every assignment a business process. Every review an attestation. Every change evidence. Governance that runs on your existing security groups and business process framework, designed by people who have owned Workday security for global tenants.

Source: Verizon's 2025 Data Breach Investigations Report: Alarming surge in cyberattacks through third-parties

02What it is

What does Security Plus do?

Every assignment under a business process

Request, approve, justify, done. Add, change and remove roles and security group memberships through configurable business processes with mandatory business justification and full history. Revocation runs through the same governance, so the record is complete in both directions.

Temporary access that expires by itself

Flag an assignment as temporary and set Assign Until. When the date passes, access is removed without anyone remembering to do it. A temporary security freeze suspends an assignment, or a person's entire security, for a defined window during leave, an investigation or an audit, and restores it automatically.

Reviews and crucial-role certification

Scheduled access reviews route to the right owner as Workday inbox tasks and record the attestation on the event. Crucial roles go further: quarterly or annual certification campaigns driven by a four-level criticality scale you configure, closed with a named certifier's sign-off. Flagged items feed straight into revocation, so reviews end in cleanup, not in a spreadsheet.

Segregation of duties, before and after

A rule library defines conflicting combinations of security groups and domain permissions, with a starter set for common HCM, Payroll and Financials conflicts. Every new request is checked before approval. The whole tenant is scanned on a schedule. Exceptions exist only as documented, time-boxed waivers that reopen when they expire.

Detection: anomalies, drift, and one score

Dormant access, privilege outliers against peers in the same job profile, roles granted outside the governed process, unusual sign-on patterns on critical accounts, and critical-role drift across any set of tenants you configure: Sandbox, IMPL, Production. One Security Check score aggregates it all, so posture is trackable quarter over quarter.

Answer "why do I have access?" in a minute

Compare two workers' security side by side. Ask why anyone has access to any report, task or domain, and get the exact granting chain: the domain security policy, the permitting security groups, and the full membership path.

03Versus standard Workday

How is it different from standard Workday?

CapabilityStandard WorkdayIncubane Security Plus
Security request workflowE-mail and tickets, outside WorkdayConfigurable business process with mandatory justification
Temporary accessRevoked by memoryAuto-expiry on a date, plus temporary security freeze
Access reviewsManual clean-ups, evidence by handScheduled, routed, attested in the Workday inbox
Crucial-role certificationNot supportedQuarterly or annual campaigns with named sign-off
Criticality classificationNot nativeFour-level scale, fully configurable per customer
Segregation of dutiesPoint-in-time delivered reportsRule library, preventive checks at request, scheduled scans, waivers
Anomaly detectionNoneAssignment and sign-on signals, ungoverned-change alerts
Tenant comparisonManual, tenant by tenantMulti-tenant comparison for critical roles, drift as findings
"Why do I have access?"Expert investigationAccess Explainer traces the exact granting chain
Audit evidenceAssembled by hand, every auditEvery event carries actor, timestamp, justification, approval chain

Standard Workday covers the basics. Our app covers what Audit and IT teams actually ask for.

04For your IT and Security team

How does it work inside Workday?

  • One system of record

    Assignments, reviews, findings and evidence live in your Workday tenant as Extend business objects. Worker, org and manager data are read live. No integration to build, no data to duplicate, no second identity store. This is what external monitoring tools cannot match without rebuilding their product.

  • Your security model, governed, not replaced

    Security Plus runs on your existing security groups and business process framework. App security domains map to your Workday security groups, so there is no new access model to build or audit. It passes review as Workday configuration, not as a new vendor platform. And because it is a security product, it holds itself to its own standard: every administrative act inside Security Plus is itself a recorded event.

  • AI on your terms

    You connect the language model you control. Prompts are configurable, AI is off by default, and the agent is strictly human-in-the-loop: it explains and drafts, a person decides. Nothing is sent to Incubane. An AI Fact Sheet ships with the contract, ready for your EU AI Act governance.

  • Stable across every Workday release

    We regression-test the app against both biannual Workday releases before they reach you, and feature updates are included in the license. No version-lag risk, no surprise breakage.

05Use cases

What do teams use it for?

01

SOX and ISO audit readiness

Walk into fieldwork with evidence instead of a war room. Every assignment, review, certification and exception already carries actor, timestamp, justification and approval chain, reportable through Workday reporting. Access-control expectations from ISO 27001 A.5.18 and NIST AC-2 map to running processes, not policy documents.

02

Crucial-role certification programs

Classify your security groups on a four-level criticality scale, then certify the holders of the top levels quarterly with a named sign-off. Uncertified items escalate and surface as findings. The control does not just exist; it demonstrably operates.

03

Joiners, movers, leavers without residue

Access follows people through role changes instead of accumulating. Privilege outliers against job-profile peers, dormant access signals and delta reviews keep standing privilege shrinking over time, and the manager's team view makes who-holds-what a routine glance instead of a request to IT.

04

IMPL drift and consultant access

Implementation tenants accumulate elevated access that quietly diverges from Production. Multi-tenant comparison for critical roles turns that drift into findings with owners, and time-boxed temporary assignments mean consultant access ends when the project does, by itself.

06The Workday security check

Can you answer these three in under a minute?

01

How do you assign Workday roles today?

With Security Plus: one business process. Request, approve, justify, done. Full history, no e-mail chains.

02

How do you know nothing unusual sits in your IMPL tenant?

With Security Plus: critical roles compared across tenants. Drift shows up before your auditor finds it.

03

How do you make sure access is removed when people change roles?

With Security Plus: scheduled reviews land with the right owner. Temporary access expires by itself.

If any answer involves a spreadsheet, let's talk.

07What's included

Core and Platinum.

CorePlatinum
Full application, all features included
Regression tested every Workday release
Service level agreementStandardEnhanced, negotiable
Product roadmap input1 vote3 votes
Quarterly business reviewGroup session1-1 with a Managing Partner
Implementation teamDelivery teamDelivery team plus senior product team
Post go-live configuration supportOn requestUp to 40 hours per quarter
Security Agent·

Every subscription includes the full application for your whole workforce. Platinum is an optional upgrade for organizations that want enhanced SLAs, senior delivery attention, and direct roadmap influence.

08Questions

The things we get asked first.

Workday stores your security model and offers point-in-time reports on it, including delivered segregation-of-duties reports for specific scenarios. What it does not give you is an engine: a request workflow with mandatory justification, temporary access that expires by itself, scheduled reviews with attestation records, certification campaigns for crucial roles, a conflict rule library with preventive checks, anomaly and drift detection, or a health score. Security Plus adds the engine on top of the model you already have.

Works together

Workday Plus Bundle

Use them individually or together. Governed security and clean data are the two halves of a tenant your auditors stop asking about.

Ready to see it in your Workday?

A 30-minute demo with one of our solution principals. Live tenant, real flows, no slide warm-up.

Incubane Security Plus