generated: '2026-09-17' method: searched source: >- openapi/_original/*.json + https://compliance.workday.com/ + https://www.workday.com/en-us/why-workday/trust/overview.html + https://community.workday.com/sites/default/files/file-hosting/productionapi/Integrations/v47.0/Integrations.wsdl standards: - id: openapi-3.0 conforms: true evidence: >- Both published contracts declare openapi 3.0.1 — developer.workday.com/bundles/rest-directory-ui/public/static/openApiFiles/businessProcess_v1_20260905_oas3.json - id: oauth2 conforms: true evidence: components.securitySchemes.OAuth2 type oauth2 (implicit flow) in businessProcess v1; oAuth2 with read/write scopes in customBusinessProcessConfig v1 - id: oauth2-client-credentials conforms: true evidence: >- Workday documents Client Credentials and Authorization Code flows for API clients — https://developer.workday.com/doc/axp1537909839739.md and .../jzx1537909761291.md - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any Workday host (84 probes, 2026-09-17); see well-known/ - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: auth.api.workday.com/.well-known/oauth-authorization-server returned HTTP 404 - id: rfc9457-problem-details conforms: false evidence: error responses are application/json with a bare `error` string; no application/problem+json media type anywhere in either spec - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header declared in the spec or the docs - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on every Workday host probed - id: idempotency conforms: false evidence: no Idempotency-Key header or equivalent on any of the 11 mutating operations; see conventions/ - id: pagination conforms: true evidence: offset/limit query parameters with a {total, data} envelope on every collection operation - id: soap-1.1-wsdl-1.1 conforms: true evidence: >- wsdl/workday-business-processes-integrations-v47.0.wsdl — WSDL 1.1 with SOAP binding, 34 operations, 8 of them business-process operations - id: ws-security conforms: true evidence: >- Workday Web Services authenticate with WS-Security UsernameToken / X.509 headers — https://developer.workday.com/doc/GUID-4c354bdb-06cd-461d-a632-ea8303beaedb-enHYPHENus.md - id: graphql conforms: true evidence: >- Workday publishes the full Graph API SDL anonymously at https://developer.workday.com/bundles/graphql-changelog/public/static/schema/schema.txt (HTTP 200, 3.5 MB), including businessProcessDefinition, workerBusinessProcess, actionEvent and eventRecord query fields - id: llms-txt conforms: true evidence: >- https://developer.workday.com/llms.txt (HTTP 200, 133 KB) — a real, curated index naming the REST, GraphQL and SOAP specification endpoints, plus a markdown-per-doc convention (GET /doc/{docId}.md). One of the most complete first-party llms.txt files in this catalog. domain_standard: market: enterprise HCM / financial management workflow declared: false note: >- REWARD-ONLY and honestly empty. Nothing in either contract declares a domain standard for its market: no SCIM schema URN, no OData $metadata surface, no HR-XML/HR-Open payloads, no ISO 20022 or X12 message types. Workday's business process model is proprietary (WID identifiers, Workday business process types). The one adjacent signal is the SOAP namespace urn:com.workday/bsvc, which is a vendor namespace, not an industry standard. No conformance is invented to fill the slot. compliance_program: published: true url: https://compliance.workday.com/ verified: '2026-09-17' http_status: 200 certifications: - SOC 1 - SOC 2 - ISO 27001 - ISO 22301 - CSA STAR - FedRAMP - IRAP - HITRUST - HIPAA - GDPR - C5 note: >- Workday runs a dedicated compliance portal at compliance.workday.com naming the certifications above, alongside the trust overview at https://www.workday.com/en-us/why-workday/trust/overview.html (HTTP 200). Both were fetched and keyword-verified on 2026-09-17.