Workday
What Paperbeam reads from Workday, the read-only access it asks for and why, filters, and the beats it feeds.

People
Read-only API key
Hires, departures (count only), anniversaries, job changes and headcount by organization from Workday HCM, via the REST API or a RaaS report. Never pay, reasons or personal data.
What we read
- Hires, work anniversaries and promotions
- Metric values
- Events
- Pages and documents you share
Only the reporting window of each edition is read. Paperbeam stores derived facts and short excerpts, not copies of your Workday data, and keeps raw evidence only for your retention period.
Access we ask for, and why
| Scope | Why |
|---|---|
API client scope: Staffing | Read workers (name, business title, supervisory organization) and business title changes |
API client scope: Organizations and Roles | List supervisory organizations for headcount and filters |
RaaS report shared with the integration system user | Read only the columns you put in the report (hire, termination and service dates, title, organization) |
All access is read-only. You can revoke it from Workday at any time, or disconnect the source in Paperbeam.
Connect Workday
- Go to Sources and choose Workday.
- Create a workday api client or raas report. Fill the REST fields (API client registered in your tenant), the RaaS fields (report + integration system user), or both. With both, dates come from the report and title changes from the REST API. Open Workday settings.
- Fill in REST: Workday services host (optional), REST: Tenant (optional), REST: Client ID (optional), REST: Client secret (optional), REST: Refresh token (optional), RaaS: Report URL (optional), RaaS: Integration system user (optional) and RaaS: ISU password (optional), then click Test connection. Paperbeam makes one read-only call and shows the account it reached, or exactly what went wrong.
- Click Connect. The credential is encrypted before it is stored and never shown again. Use Sync now on the source’s page to see what it collects from the last 24 hours, and set filters there.
You need the admin or owner role in Paperbeam, and enough permission in Workday to grant read access to the data listed above.
Filters
Set on the source’s page at Sources›Workday. Filtered-out data is never collected.
| Filter | Effect |
|---|---|
| Name column | Optional. Report column with the worker's name; auto-detects Worker, Employee, Legal_Name, Preferred_Name. |
| Worker ID column | Optional. Stable worker id column; auto-detects Employee_ID, Worker_ID. |
| Hire date column | Optional. Auto-detects Hire_Date, Most_Recent_Hire_Date, Original_Hire_Date. |
| Service date column | Optional. Date anniversaries count from; auto-detects Continuous_Service_Date, Original_Hire_Date, then the hire date. |
| Termination date column | Optional. Departures are counted only (no names, no reasons). Auto-detects Termination_Date. |
| Title column | Optional. Auto-detects Business_Title, Job_Title, Job_Profile. |
| Organization column | Optional. Auto-detects Supervisory_Organization, Department, Cost_Center. |
| Job change date column | Optional. For promotions and title changes from the report; auto-detects Job_Change_Date, Promotion_Date. |
| Work email column | Optional. Auto-detects Work_Email, Primary_Work_Email. |
To keep specific people, channels or topics out of the paper across all sources, use exclusion rules and the never-mention list in House style.
Beats
Workday is a source for:
Stories land in whichever of your sections fits them best.