Use the setup sequence Workday documents
Workday’s published access sequence is direct: create Customer Central accounts, enable Customer Central to access other tenants, set up production access and a session only when production migration is required, then configure Object Transporter security permissions.
This order matters because Object Transporter relies on Customer Central access to the tenants involved. A person can have a valid Customer Central account and still be unable to select or work with a tenant that has not been enabled and made available.
Enable nonproduction access before migration work
For an implementation or sandbox tenant, enable Customer Central access in the tenant’s system setup, then add that tenant to Customer Central’s Current Tenants list. Enabling the setting does not add the tenant by itself. The add step is what makes communication possible.
After the tenant is connected, use Customer Central’s access controls to give the right users access to that specific tenant. The access list should reflect the work a user is responsible for, not simply their general project involvement.
Treat production as a separate path
Production access is optional in the initial setup because it is only needed for loading or migration to or from production. When it is needed, Workday requires production access to be enabled and the individual user to create a production tenant session for authentication.
Finally, configure Object Transporter permissions. Workday’s guide separates customer central access from the domain security required in each source and target tenant, so both layers must be reviewed before a migration is attempted.
For the current product guidance, see Workday’s Object Transporter access setup steps.

