Workday
A vendor owner who has left the company is the most common reason a review stalls. Urengi reads worker and cost-centre data from Workday, so ownership follows the org chart instead of a spreadsheet somebody maintained until they moved teams.
- Category
- CRM & procurement
- Auth method
- OAuth 2.0 (ISU)
- Direction
- Read-only
- Sync frequency
- Daily
- Scopes requested
- 3
- Available on
- Enterprise
- Maintained by
- Urengi
What the Workday integration does
Three reads that keep ownership true without anyone maintaining it.
Owners follow the org chart
When a vendor owner leaves or changes team, the review reassigns to their successor rather than sitting unanswered in a dead mailbox.
Cost centres come with the vendor
Spend is attributed to the cost centre that actually carries it, which is what makes a tier defensible to the person paying for the tool.
Leavers trigger an access check
A departure reopens the access side of every review that person owned, so offboarding covers third-party tools and not just internal ones.
Exactly what Urengi can see
Three read-only scopes through an integration system user. No compensation or personal data is read.
Urengi reads
- Worker names, work emails and managers
- Cost centre and supervisory organisation names
- Employment status changes
Urengi writes
- Nothing — this connection is read-only
Urengi never touches
- Compensation, benefits or payroll data
- Home addresses or personal identifiers
- Performance, absence or case records
- Anything after you revoke the ISU
Connect it in four steps
One authorisation, one field mapping, and a test sync you run yourself.
01
Authorise the connection
Open Workday from this page and approve the scopes listed above — OAuth in a browser tab, or a scoped API key you paste. An admin approves them once.
02
Choose what syncs
Pick the projects, spaces or accounts Urengi should watch. Narrow is fine to start with; widening it later does not re-authorise anything.
03
Map your fields
Match owners, cost centres and tiers to what Urengi already tracks. Defaults arrive pre-filled from the first sync, so most teams change nothing.
04
Run a test sync
Pull one record and check it landed on the right review. The audit entry confirms the mapping before a real vendor is touched.
Your token, your rules.
Urengi stores the Workday token encrypted at rest under a per-tenant key and never replays it outside the scopes you approved. Revoke the app in Workday and every Urengi write stops within seconds — the audit log keeps the history, the connection simply ends.
Read the security statement- SOC 2 Type II
- audited annually
- Per-tenant keys
- no shared secrets
- Revocable in Workday
- one click, no ticket
- EU or US residency
- chosen at signup