Separate Customer Central roles from tenant security

Object Transporter access has two layers. Customer Central accounts and tenant access establish who can reach the relevant environment. Tenant-side security establishes what that person can migrate or use once they are there.

Workday’s access guidance calls for active Customer Central user and administrator roles, access to the tenants involved, and Object Transporter security permissions. Each part is required for a complete setup.

Create the Migration Administrator group

In every source and target tenant used with Object Transporter, Workday directs administrators to create a user-based security group named Migration Administrator. Add the Customer Central users who need Object Transporter to that group.

Workday’s current security guidance identifies the Special OX Web Services and OX for Non-implementers domain security policies. The Migration Administrator group needs View and Modify plus Get and Put permissions for both policies, followed by activation of pending security policy changes.

Grant extra tooling access only when the job requires it

Some capabilities are separate from baseline migration access. Workday documents controls in Maintain Access to Customer Central Tooling for items such as security configuration package migration, configuration extracts, tenant comparison, and full Object Transporter coverage for Configuration Change Tracker work.

Assign those capabilities based on the person’s actual role. This keeps normal migration access distinct from higher-impact tools and makes it easier to review who can perform each type of deployment activity.

For the current product guidance, see Workday’s Object Transporter security guidance.