Workday · Workday AI

Self-Service Agent

Workday documents Self-Service Agent as a Workday-built conversational AI agent, registered and configured through Agent System of Record, that answers employee and manager self-service questions from Workday data and tenant policy documents and takes configured actions through named tools, including submitting time-off requests, correcting or cancelling approved time off, entering and submitting time, changing personal information and home contact details, creating support cases and, for managers, initiating job changes and payroll input requests. The actions available are determined entirely by which skills and tools an administrator enables and which security groups are permitted to use them.

Recorded characteristics

Function
Workday states that "The Self-Service Agent is a conversational AI agent that you can configure to take action on common worker and manager requests, such as submitting support requests and viewing absence information", and that "The actions the Self-Service Agent can take are determined by which skills you enable for the agent." Workday's About topic describes it as an agent that "retrieves and summarizes broad self-service data and takes action on common interactions, such as: Updating personal information and requesting time off. Managing organizational goals and viewing team learning statuses. Viewing organization policy information from knowledge articles stored in Workday." Structurally, Workday defines skills as "specific actions or tasks that an agent can take" and tools as "Workday APIs agents use when executing skills", with ESS skills for employees, MSS skills for managers, Base for simple action skills and Advanced for complex action skills. The Guide skill must be active for the agent to run and provides "intelligent navigational direction, ensuring task completion by directing users to the specific Workday report or task required"; the Policy Intelligence skill resolves "questions about company rules by searching authorized documentation". Question answering and retrieval authority is documented through Base skills and view tools: time-off balances as of an effective date including carryover, eligible time-off types, the user's own time-off events with status Approved, Submitted, Not Submitted or Sent Back, entered and submitted time, company holidays, scheduling, worker profile, compensation and benefits details, dependents, healthcare elections, bonus and payment history, tax forms, coworker information subject to the user's security access, team and organization information, learning and goal data, internal job listings, expense history and purchase requisition/order status. Established write authority is per tool. Time off: the request_time_off tool "Initiates a time off request, such as vacation and sick leave, using the Request Time Off business process"; cancel_time_off and edit_time_off initiate the Correct Time Off business process to cancel, delete or edit an approved entry, and cancel_time_off also supports cancelling in-progress requests and correction events. Time entry: enter_time_block creates time entries, submit_time "Submits a user's timesheet for review and approval for a single date", shift_check_in and shift_check_out clock a user in and out, and update_time_block_comment edits a time-block comment. Personal data: change_personal_info "initiates the Change Personal Information business process as a conversational alternative to the UI task" for citizenship status, gender, gender identity, marital status, nationality, pronoun, religion or sexual orientation; change_name updates legal and/or preferred name; change_home_contact_info updates home address and personal phone numbers; change_marital_status "Guides a user through updating their marital status in three sequential steps: initiation, draft creation, and submission"; add_dependent, change_dependent and delete_dependent initiate dependent events. Other established actions: create_a_case submits formal support requests, request_reference_letter initiates an employment verification or reference letter request, and Advanced Talent skills support submitting performance reviews and creating referrals. For managers, MSS Advanced skills cover initiating job changes and organizational updates, approving, sending back or denying submitted time entries, and MSS - Payroll - Advanced, which "Calls the existing Request Payroll Inputs business process" and blocks requests for workers not on Workday Payroll. Expenses: despite Workday's product-page phrasing that the agent handles "time-off requests, expenses, and profile updates, end-to-end", the only expense authority established in Workday's skill and tool documentation is retrieval. The ESS - Financial Management - Base skill "Provides employees with the ability to retrieve financial information, including expense history", and the tools view_expenses and view_orders retrieve and display expense report and expense item details and requisition, purchase order and invoice details. No tool establishing expense creation, receipt attachment, expense-report submission, approval or reimbursement by Self-Service Agent was found, and those functions are documented for the separate Travel & Expense Agent, whose authority is not attributed here. High-stakes guidance is distinct from execution. Workday's product page positions promotions and job changes as "step-by-step guidance in high-stakes moments", with an example in which the agent "lays out the eligibility rules and effective dates to help make the case". That is recorded as guidance and generation authority, not execution. The one execution exception is the documented MSS - Human Capital Management - Advanced skill, which "Enables managers to take action on workforce lifecycle transactions for their direct reports, including initiating job changes and executing key organizational updates"; initiation of the business process is the established boundary, and the Workday business process and its human approvers remain responsible for the outcome. The agent is not documented as approving anything on its own behalf; the only approval action documented is a manager using the agent to approve, send back or deny submitted time entries, which is the manager's decision executed through the agent.
Data access
Workday documents the agent using live Workday data plus tenant policy documents. The product page states the agent gives "instant, plain-language answers based on live Workday data" and that it "uses your live Workday data and company policies". The Policy Intelligence skill "retrieves specific details from policy documents and procedural guides"; Workday warns of a 14-day waiting period "for Self-Service Agent to ingest your policy documents" unless the tenant opts in to the People Experience Help service beforehand. Data categories established through skills and tools include absence and time-off balances and events, scheduling and time tracking, worker profile and personal information, dependents, healthcare and retirement elections, compensation, payment history and tax forms, goals, feedback, learning and internal job listings, team and organization structures, expense history and procurement documents, and knowledge articles stored in Workday. Workday states the fields returned depend on the user's security access, giving the example that home email may be withheld. The agent cannot read document attachments on help articles, and has no documented visibility into My Tasks.
Actions
Can take actions
External actions
Unknown
Human confirmation
Conditional
Permission basis
Mixed
Administrative control
Administration runs through the Agent System of Record and the Agent Management Hub. An administrator registers Self-Service Agent from the Unregistered Workday Agent tab, configures the agent, enables each relevant skill in the Status column, selects the security groups permitted to access each skill in the Available To prompt, and clicks Activate. Skills can be set active or inactive individually; individual tools inside a skill can be disabled without disabling the skill, and Workday notes that tools inherit the skill's security groups and cannot be assigned their own. A custom global fallback message can be configured. Skill and tool configuration changes can take up to 10 minutes to take effect for skills and up to 5 minutes for tools in new conversations. Workday states that it "evaluates both user access to the agent and to the APIs the agent is executing as tools at runtime" and recommends aligning the Available To security groups with the groups holding permissions for the underlying tools; the View Security for Agent Skill report shows the required and recommended security policies per tool. The Agent Interaction Policy in Agent System of Record "explicitly defines which users are authorized to converse with or invoke specific agent skills" and functions as an opt-in mechanism, so a user outside a skill's security group cannot use that skill even with the underlying domain access. Workday also documents agent audit and usage reports, including View AI Agent User Audit Trail. Activating the agent with at least one skill displays the Workday Chat icon in global navigation and hides the Workday Assistant chat bubble. Where tenant access restrictions such as multi-factor authentication apply, Workday directs administrators to configure the same restrictions for the security groups assigned to the skill or tool.
Default state
Disabled
Availability
Workday documents Self-Service Agent as a Workday-built agent available through Agent System of Record and describes it in current administrator documentation rather than as a preview. Availability depends on the subscription agreement: under the Universal Main Service Agreement the feature "is automatically available", while Main Service Agreement customers "must opt in to UMSA and enable this feature through Innovation Services". UMSA is required for both non-production and production tenants for Workday-built agents. Workday states the agent is "optimized and validated for all level 1 and level 2 languages" and that while the underlying LLM can communicate in over 30 additional languages, Workday does not support the same verified accuracy for those. Through Workday Everywhere the agent is available in Chinese (simplified and traditional), Dutch, English, French, French-Canadian, German, Italian, Japanese and Portuguese, defaulting to English. Access channels documented are Workday itself plus Slack, Microsoft Teams, Microsoft 365 Copilot and Gemini Enterprise. No explicit General Availability, Early Adopter or region list specific to Self-Service Agent was established in the documentation reviewed.
Licensing
Workday links agent usage to Flex Credits, stating "For information about how using agents impacts your Flex Credits, see: Workday Flex Credits Community page", and requires the Universal Main Subscription Agreement for Workday-built agents in non-production and production tenants. No Flex Credit quantity, pricing formula or product SKU specific to Self-Service Agent was established in the documentation reviewed. Workday separately documents SKU and Flex Credit requirements for Sana Core and Sana Enterprise, which are not attributed to Self-Service Agent here.
External model or provider
Not established
Limitations and uncertainty
Model and provider are not established: Workday refers only to "the underlying LLM" in the language-support note and does not name a model, model family or provider for Self-Service Agent. Human confirmation is recorded as conditional rather than required: Workday's product-page example states the agent "checks the PTO balance, confirms the dates, and submits the request", and change_marital_status is documented as three sequential steps of initiation, draft creation and submission, but no Workday page reviewed establishes a universal review-and-approve step before every write, and the agent's responses through Workday Chat support UI elements such as tables and buttons without a documented mandatory confirmation gate. Workday's phrase "performs the approved action" is not defined on that page; the mechanisms actually documented are the two-step security evaluation (Agent Interaction Policy plus domain and business process security) and the ordinary Workday business processes the tools initiate, and no evidence establishes that the agent itself grants approval. Permission basis is recorded as mixed on affirmative evidence rather than as user permissions alone: Workday's delegate mode uses a "Combination of user and agent ASU" identity with OAuth 2.0 On-Behalf-Of authentication, and authorization logic evaluates "the intersection of the user's permissions and the agent's allowed skills"; Agent System of Record automatically creates a dedicated Agent Security User with its own OAuth client and key pair when skills are enabled. The audit log in delegate mode "Records the transaction as performed by the agent as By User and the user as On Behalf Of User"; that comparison table is documented for Workday agents generally rather than named for Self-Service Agent, so it is recorded as the applicable framework rather than as a Self-Service Agent-specific enumeration. External action capability is recorded as unknown: Slack, Microsoft Teams, Microsoft 365 Copilot and Gemini Enterprise are documented as conversational surfaces from which workers invoke the agent to perform Workday tasks, and the Gemini path is an external assistant calling Self-Service Agent as a tool through A2A, which is inbound rather than outbound; no Workday evidence reviewed establishes that the agent writes records into, or posts messages to, those external systems, and Workday Everywhere notifications in Microsoft Teams are configured Workday Everywhere behaviour rather than an established agent action. Expense authority beyond retrieval is not established and is explicitly not inherited from Travel & Expense Agent; payroll processing authority is not inherited from Payroll Agent; and HR Service, Talent Acquisition, Talent Management, Workforce Management and Total Rewards agent authorities are not attributed here. Retention is split: Workday states "Chats are deleted after 30 days" while "the permanent log is securely maintained within your standard Workday audit trail", and Workday separately states it does not delete agent usage analytics data, with usage analytics reports covering the past 30 days; the exact audit fields recorded for a Self-Service Agent action beyond the By User and On Behalf Of User distinction are not enumerated. Documented limitations are that Self-Service Agent does not support contingent workers, hiding or requiring fields through Configure Optional Fields, additional jobs or multi-position workers, implementer and proxy accounts, delegated actions (Workday states delegate-initiated actions "won't create actual events or requests in the system" and the agent states the action cannot be performed when a user specifies they are acting on behalf of someone else), data extractions from articles in Sandbox, reading document attachments on help articles, tokenization in agent, skill and tool descriptions, and visibility into My Tasks. Workday also states that responses are non-deterministic and updated continuously, which may produce differing interactions over time. Tool-level limitations include no worktag support for time-off requests or time blocks, no correction of time-off type, position or worktags, no removal of a marital status, no support for social or former name components, no file uploads for home contact information, and managers being unable to update home contact information or request reference letters for direct reports.

Evidence