Workday
Configuring the integration for Workday
Why use the integration for Workday
Workday is the system of record for your people, teams, and reporting relationships. However, that organizational structure often lives separately from the tools your engineers use day to day. The integration for Workday bridges that gap by syncing your Workday ownership data directly into Cortex, automatically importing employees, teams, and hierarchies so that ownership in your software catalog stays aligned with how your organization is actually structured.
Instead of manually maintaining team rosters and reporting lines in two places, you can rely on Workday as the source of truth and let Cortex handle the rest: connecting people to the services, resources, and entities they own, enforcing accountability through Scorecards, and ensuring that as teams reorganize or employees change roles, your ownership model evolves with them. This is especially valuable for organizations that want to drive operational excellence at scale, where knowing who owns what—and being able to trust that information—is foundational to incident response, compliance, and engineering productivity.
Configuring Workday
Prerequisites
Users with the
Configure Integrationspermissions can configure Workday.
Step 1: Generating an ownership report in Workday
In Workday, generate an ownership report. Depending on how you want to manage teams and the corresponding hierarchy, you can choose one of the following options:
Manage teams based on Workday supervisory organizations
Manage teams based on Workday teams
Note that the required fields in the report differ depending on which option you choose. See the table below.
email
Email address for employee. Use the same address that employees will use to access Cortex.
employeeId
Unique employee ID.
firstName
Employee first name (displayed in Cortex).
lastName
Employee last name (displayed in Cortex).
employeeRole
Employee role (displayed in Cortex).
optional
optional
employeeSupervisoryOrgId
Supervisory org ID for employee. Cortex uses this field to group employees. Any changes to this field results in the creation of a new team as this is how Cortex identifies teams.
teamName
Team name for employee. This field is used to group employees into teams in Cortex. Any changes to this field results in the creation of a new team as this is how Cortex identifies teams.
teamDisplayName
Display name for team. This is used for the title and tag for any teams imported from Workday. If not included, teamName is used instead. This should be the same for all employees on the same team.
optional
teamEmployeeManages
The team this employee manages. Include this field if your report identifies a team's manager on the team record. If you omit it, Cortex treats the person in managerEmail as the manager.
optional
optional
managerEmail
Email address for employee's manager. Cortex uses this field to create team hierarchies. If Cortex detects an employee with the same email as the managerEmail, that employee is added to the team with a Manager role.
Omit this field if you do not want to auto-import teams and the corresponding hierarchy from Workday.
teamSupervisoryOrgId
Supervisory org ID for the employee's team. This org becomes the parent of employeeSupervisoryOrgId in the team hierarchy.
teamListKey
Key for the list of teams associated with a given user. This field is for a single employee on multiple teams.
Step 2: Configuring the Workday integration
From the main sidebar in Cortex, expand Integrations, then select Configurations.
Locate Workday, then click Install. The Workday side panel opens.
In the Workday side panel, do the following:
From the Category dropdown, select at least one category that applies to the integration (required). Team is the default category.
Under Username, enter the username associated with the Workday account used to generate the ownership report (required).
Under Password, enter the password associated with the Workday username (required).
Under Ownership report URL, enter the URL for the ownership report you generated (required).
Provide the base report URL. Do not include query parameters in the URL. If necessary, Cortex appends
?format=jsonwhen making requests.
Click Test connection. A successful connection means your integration is configured correctly.
Click Save.
Step 3: Configuring the report mappings in Cortex
After saving the configuration, you can configure how you want the fields to map to different elements in Cortex. The options available in each drop-down menu mirror the fields included when generating the ownership report.
Note on field mapping availability
When you first add or update a Workday report URL, Cortex runs a background sync job to fetch and cache the report's column structure. The field mapping dropdowns on the configuration page are populated from this cache.
If you open the configuration page immediately after adding or rotating credentials, the dropdowns may appear empty or validation errors like Employee Id is required may surface before the sync completes. If this occurs, wait a few minutes and refresh the page—the column options populate once the background sync has finished.
The dropdowns include fields that appear on only some rows of your report, as well as fields nested inside a team list, so every employee record doesn't need to carry every field.
To configure report mappings:
From the main sidebar, expand Integrations, then select Configurations.
Locate Workday, then click Settings.

From the Integrations settings tab, do the following:
In the Employee attributes section, map report fields that pertain to employees:
From the Employee ID dropdown, select a report field for the unique employee identifier (required).
From the Email dropdown, select a report field for the employee's email address (required). This is what Cortex matches against a user's login.
From the First Name dropdown, select a report field for the given name shown in Cortex.
From the Last Name dropdown, select a report field for the surname shown in Cortex.
From the Role dropdown, select a report field for the employee's role, displayed as a badge next to their name on the team's Members tab.
From the Manager Email dropdown, select a report field for the manager's email. This is used to identify a team's manager.
Click Save.
In the Team attributes section, map report fields that pertain to employees' teams.
From the Team type dropdown, select the shape of the report:
One Employee-Multiple Teams - Select this option if your report includes employees who belong to multiple teams.
From the Team List Key dropdown, select a report field that contains the teams you want imported into Cortex for a given employee entry (required). This requires the
teamListKeyfield in the Workday report. TheteamListKeyshould be a list of objects, where each object has at leastteamNameandteamIdproperties:From the Team ID dropdown, select a report field for the team ID. New teams are imported based on this ID (required). If the identifier changes, Cortex creates a new team.
From the Team ID-Fallback dropdown, enter a fallback team for a user who does not have an associated
teamListKey.From the Team Name dropdown, select a report field for the team name. Cortex updates this name if changes are detected in Workday.
From the Team Name-Fallback dropdown, enter a fallback team name for the fallback team ID defined above.
From the Team Employee Manages dropdown, select a report field that names the team an employee manages. If you set this, Cortex assigns managers based on this field. If you leave it empty, Cortex uses the person in Manager Email as the team's manager.
Click Save.
One Employee - Multiple Teams (Multiple Fields) -
Click Add team.
Configure the team:
From the Team ID dropdown, select a report field for the team ID. New teams are imported based on this ID (required). If the identifier changes, Cortex creates a new team.
From the Team Name dropdown, select a report field for the team name. Cortex updates this name if changes are detected in Workday.
From the Parent Team ID Field, select a report field that identifies the parent team.
Click Save.
One Employee - One Team -Select this option if your report includes employees who belong to a single team. This is best if you are configuring the integration based on supervisory orgs and/or if users manage teams they belong to.
From the Team ID dropdown, select a report field for the team ID. New teams are imported based on this ID (required). If the identifier changes, Cortex creates a new team.
From the Team Name dropdown, select a report field for the team name. Cortex updates this name if changes are detected in Workday.
Click Save.
In the Hierarchy fields section, configure the hierarchy fields mappings. This is only required if you want to automatically import Workday teams. Note that you must enable the option to auto-import Workday teams in order for new teams to be created automatically. Hierarchy relationships are written for existing teams on manual import and whenever hierarchy field mappings are updated, regardless of whether auto-import is enabled.
From the Field on parent team dropdown, select a report field whose value identifies a team as a parent (required).
Optionally, toggle on Is List when the parent field holds a list rather than a single value, so one entry can be the parent of several teams.
From the Field on parent team-Fallback dropdown, select an alternate field for the parent identifier.
Optionally, toggle on Is List-Fallback so Cortex reads the fallback field when the primary field is missing from a record, which is useful when your report doesn't populate every field on every row.
From the Field on child team dropdown, select a report field on a team's record whose value points at that team's parent (required).
From the Field on child team-Fallback dropdown, select an alternate field for the parent pointer.
From the Root Team IDs dropdown, select the ID for the team you expect to be at the top of the hierarchy. If set, Cortex uses this to break cycles that may be in the hierarchy.
Click Save.
Last updated
Was this helpful?