Workday Integration Setup | Provisioning a HyperAdmin User

Workday | Provisioning a Hypercard Admin User for Integration Setup

Workday | Provisioning a Hyper Admin User for Integration Setup

This article explains how a Workday Administrator can provision a temporary, login-capable admin user for Hyper. This user allows Hyper to log into the Workday UI and complete initial integration setup tasks, including:

  • Creating an Integration System User (ISU)
  • Creating and configuring Integration Security Groups
  • Registering an API Client for Integrations (OAuth)
  • Generating OAuth refresh tokens

Important: This user is intended for initial integration setup only and can be disabled or deactivated after credentials are created.


When This Is Needed

This approach is recommended when:

  • The customer wants Hyper to self-manage Workday integration setup
  • The customer prefers to avoid back-and-forth during OAuth and ISU provisioning
  • The integration timeline is tight and requires hands-on configuration by Hyper

If the customer prefers to provision all credentials themselves, this step can be skipped.


Overview of the User Being Created

This is a human Workday user, not an Integration System User.

Capabilities of this user:

  • Can log into the Workday UI
  • Can run Workday admin tasks
  • Can create ISUs and API clients

Limitations:

  • Should not be used for day-to-day operations
  • Should not be granted payroll or compensation access unless explicitly required

Step 1: Create a Workday User for Hyper

  1. Log into Workday as a Workday Administrator
  2. In the search bar, type Create Worker or Create User (tenant-dependent)
  3. Create a user with the following details:
    • Name: Hyper Integration Admin
    • Email: (provided by Hyper)
    • User Name: Hyper.admin (or customer naming standard)
  4. Complete the task and ensure the user is able to log in

Step 2: Assign Required Administrative Roles

Assign the following roles to the Hyper admin user.

Exact role names may vary slightly by tenant.

Required Roles (Minimum)

RolePurpose
Integration AdministratorCreate ISUs, security groups, API clients
Security AdministratorAssign domain permissions

Optional (If Required by Tenant)

RolePurpose
Workday AdministratorFull access if roles above are insufficient

Best practice: Start with Integration + Security Administrator and only expand if Workday blocks a required task.


Step 3: Enable UI Authentication

  1. Search for Manage Authentication Policies
  2. Ensure the Hyper admin user is included in a policy that allows:
    • User Name / Password authentication
  3. Confirm the user is not restricted to SAML-only authentication
  4. Activate any pending authentication policy changes

Step 4: Hyper Performs Integration Setup

Once the user is provisioned, Hyper will log in and perform the following:

  1. Create an Integration System User (ISU)
  2. Create an Integration Security Group
  3. Assign required Domain Security Policy Permissions
  4. Register an API Client for Integrations
  5. Generate a non-expiring OAuth refresh token

No additional customer action is required during this phase.


After setup is complete, the customer may:

  • Disable the Hyper admin user
  • Remove elevated roles
  • Restrict authentication policies

The integration will continue to function using the ISU and OAuth credentials.


Security & Audit Notes

  • Hyper does not access employee payroll, compensation, or time-off data
  • All API access occurs through the ISU after setup
  • Admin access is used only for provisioning and can be revoked

Summary

By creating a temporary Hyper admin user, customers can:

  • Accelerate Workday integration setup
  • Reduce configuration errors
  • Maintain control over long-term access

For questions or role validation, Hyper can provide a tenant-specific checklist on request.


    • Related Articles

    • Workday | Integration System User (ISU) Authentication

      Workday | Integration System User (ISU) Authentication This article explains how to authenticate an Integration System User (ISU) for a direct Hyper ↔ Workday integration, scoped specifically for expense creation, accounting, and ad-hoc employee ...
    • Setting Up User Groups as an Admin

      As an admin, you can set up user groups in Hyper, assign members to each group, and create subgroups to better organize your team. Accessing User Groups Log in to your Hyper dashboard. Click on Settings at the bottom right. From the left navigation ...
    • Managing Integrations as an Admin

      As an admin, you can easily manage integrations that enhance how your team uses Hyper. These include: Calendar Integrations Messaging Platform Integrations These integrations help streamline the expense submission process by allowing TARS to ...
    • Establishing an SFTP Feed for Corporate Card Transactions to Hyper

      Hyper can receive corporate card transaction data via a secure SFTP feed directly from your issuing bank. Overview The SFTP feed delivers transaction-level data from your bank to Hyper on a scheduled basis, typically nightly. This enables near ...
    • Setting Up Users as an Admin

      As an admin in Hyper, you have full control over managing your company’s users. This includes inviting new employees, assigning roles, and updating user details. Accessing the Users Section Click on the Users icon in the left navigation column. This ...