Salesforce + Workday integration

Hires, transfers and leavers in Workday HCM become correct Salesforce users, roles and territory assignments the same day, and won opportunities reach Workday Financials or your PSA without a spreadsheet in between.

California-based leadership · Serving US and international teams

Salesforce
AIONDATAsync · MCP · rules
Workday
Workers → Salesforce usersTerminations and contract ends → deactivationSupervisory organizations and managers → role hierarchyPositions, locations and regions → territoriesCost centers, companies and projects → reference dataWorker profile → Employee object or PSA resourceClosed-won opportunities → Workday customers, opportunities, contracts or projects
Illustrative integration flow

Your integration, scoped before we build

  • Object and field mapping for your workflows
  • Sync timing, error handling and reconciliation
  • Written scope, timeline and support options

Ready to connect Salesforce and Workday?

Share your objects, volumes, and timing needs — we'll come back with a written scope.

Please share the systems and workflow—not credentials or customer records. We’ll confirm API access, scope and next steps.

NVIDIA Inception

NVIDIA Inception member

Part of NVIDIA’s program for startups building with AI and accelerated computing.

About the program
Pravin BansalSravan Modugula

Bay Area roots. Enterprise experience.

Pravin’s experience includes Google and SmartBear. Sravan previously held leadership roles at JPMorgan Chase and First Republic Bank.

Meet the founders

San Francisco Bay Area, California

9110 Alcosta Blvd Ste H345, San Ramon, CA 94583

US-led delivery, with engineering in India. Supporting US and international organizations.
Prefer email? info@aiondata.io

Let’s scope your integration.

Just your name and email to get started. Your details are handled under our Privacy Policy.

How Salesforce and Workday work together

A Salesforce Workday integration is mostly about people: every seller, manager and consultant hired, moved or terminated in Workday needs a matching Salesforce user, role and territory, and a new owner for their records when they leave. Workday is the system of record for workers, positions, supervisory organizations and cost centers; Salesforce is where that structure shows up as users, the role hierarchy, territories and PSA resources. The reverse flow matters to finance: won opportunities, customers and projects can be created in Workday Financials, or stay in Certinia PS Cloud on the Salesforce platform with Workday supplying the people and cost data. AIONDATA, an independent consultancy and not a partner of either vendor, builds this on Workday Web Services, Reports as a Service and the Salesforce REST, Bulk and SCIM APIs, or configures Workday’s own Salesforce connectors and MuleSoft where they fit.

Plan your Salesforce + Workday implementation

These decisions shape the scope, cost and acceptance tests. The flows below describe possible implementation behavior, not a preinstalled connector or a guarantee for every product edition.

Which Workday workers become Salesforce users

Decide by job profile, supervisory organization, company and worker type who gets a user and which license and profile they get. Get_Workers returns employees and contingent workers alike, so the rule must be explicit and should live in a mapping table that HR and RevOps can edit.

Identity provider in the loop, or direct

If Microsoft Entra ID or Okta already provisions accounts from Workday, Salesforce can be one more SCIM 2.0 target of the identity provider, and the integration adds only what SCIM does not carry: role hierarchy, territories, manager and record reassignment. Without one, the integration creates and deactivates users itself. Either way, one owner per User field.

Role hierarchy and territories from Workday organizations

Supervisory organizations and managers can drive the Salesforce role hierarchy and forecast rollups; positions, locations and regions can drive territory membership. Agree how a Workday reorganization maps to UserRole changes and what happens to open opportunities when a rep changes territory.

Event-driven or scheduled, by data type

Hire, Change Job and Termination business processes can include an Integration step that launches an Integration Process Event, so provisioning starts when HR completes the transaction. Organizations, cost centers and projects change less often and suit a scheduled Reports as a Service or EIB pull. Salesforce-originated triggers use Change Data Capture.

What goes back to Workday, and who owns the customer

Choose whether a closed-won opportunity creates a customer, customer opportunity, customer contract or project in Workday, and which system owns billing address and payment terms afterwards. On Certinia PS Cloud, projects and resources stay on the Salesforce platform and Workday supplies workers and cost centers.

Data flows

What moves between Salesforce and Workday

  1. 01Workers → Salesforce usersWorkday SalesforceHires and rehires create or reactivate the User with profile, role, license and Federation ID set by rule; the Workday worker ID sits on the User as an external ID.
  2. 02Terminations and contract ends → deactivationWorkday SalesforceTermination and End Contingent Worker Contract events deactivate the user on the termination date, free the license and reassign owned accounts, opportunities and cases by rule.
  3. 03Supervisory organizations and managers → role hierarchyWorkday SalesforceManager changes update ManagerId and UserRoleId so forecast rollups follow the real reporting line after a reorganization.
  4. 04Positions, locations and regions → territoriesWorkday SalesforcePosition, location and region data create UserTerritory2Association rows in the active territory model, with a role in territory of Sales Rep, Owner or Administrator.
  5. 05Cost centers, companies and projects → reference dataWorkday SalesforceWorkday cost centers, companies and projects land in custom objects or picklists so services records carry the right worktags when they go back to Workday.
  6. 06Worker profile → Employee object or PSA resourceWorkday SalesforceJob profile, location, time type and cost center feed an Employee-type custom object, or the resource record in Certinia PS Cloud, for staffing and utilization.
  7. 07Closed-won opportunities → Workday customers, opportunities, contracts or projectsSalesforce WorkdayA Change Data Capture event on Opportunity calls Submit_Customer, Submit_Opportunity or Submit_Customer_Contract, or creates a project through Resource_Management, with the Salesforce record ID stored as the reference.

Field mapping

Salesforce and Workday field mapping

The records, match keys and triggers most implementations start from. Your scope confirms each row against your editions, custom fields and business rules.

Salesforce and Workday field mapping
SourceTargetMatch keyDirectionTriggerNotes
Worker (Get_Workers: worker ID, legal name, work email, job profile, time type, hire date)User (Username, Email, FirstName, LastName, Alias, FederationIdentifier, EmployeeNumber, ProfileId, IsActive)Workday worker ID in an external ID field on User; upsert by external IDWorkday → SalesforceIntegration step on the Hire business process (Integration Process Event), plus a nightly RaaS reconciliation pullOnly workers in the provisioning table. Username must be in email form and unique across all Salesforce orgs.
Termination (Terminate_Employee) or contract end (End_Contingent_Worker_Contract)User.IsActive = false; owned Accounts, Opportunities and Cases reassignedWorkday worker ID on UserWorkday → SalesforceIntegration step on the Termination business process, effective on the termination dateSalesforce users cannot be deleted; deactivation frees the license. Reassignment rule: manager from Workday, territory owner or a holding user.
Worker’s manager (from Get_Workers)User.ManagerIdManager’s worker ID → User external IDWorkday → SalesforceChange Job business process event, plus the nightly pullA manager without a Salesforce user leaves ManagerId empty and raises an exception for review.
Supervisory Organization hierarchy (Get_Organizations, type Supervisory)UserRole hierarchy and User.UserRoleIdSupervisory organization reference ID → UserRole in a mapping tableWorkday → SalesforceNightly EIB or RaaS pull; reorganizations rehearsed in the sandbox firstThe table collapses small teams into their parent role. Role changes affect sharing and forecast rollups immediately.
Position (Get_Positions), Location (Get_Locations) and Region (Get_Regions)UserTerritory2Association (Territory2Id, RoleInTerritory2)Position or location → Territory2 in the active territory modelWorkday → SalesforceChange Job or Assign_Organization event, plus the nightly pullRole in territory is Sales Rep by default and Owner for managers. Account assignment stays with Salesforce assignment rules.
Job Profile (Get_Job_Profiles)Profile, permission set group and license mapping table; User.TitleJob profile reference IDWorkday → SalesforceSet up once; reviewed when HR adds job profilesUnmapped job profiles are reported, never guessed. Changing a user’s profile changes the license, so the table lists the license too.
Cost Center (Get_Cost_Centers) and Company (Get_Workday_Companies)Cost Center and Company custom objects, or picklists on User and PSA recordsWorkday reference ID in an external ID fieldWorkday → SalesforceScheduled RaaS or EIB pull, typically nightlyRead-only in Salesforce; reused as worktags when records go back to Workday Financials.
Worker profile fields for services (job profile, location, time type, cost center)Employee-type custom object, or the resource record in Certinia PS CloudWorkday worker ID external IDWorkday → SalesforceHire and Change Job events, plus the nightly pullOnly the fields the PSA needs; compensation and personal data stay in Workday.
Project Resource Assignments and Project Worker Roles (Get_Project_Resource_Assignments, Get_Project_Worker_Roles)PSA assignment or a custom Project Role objectWorkday project and worker reference IDsWorkday → SalesforceScheduled pull, typically nightlyOnly when Workday Projects is the resourcing system; otherwise the PSA owns assignments and Workday receives cost and revenue summaries.
Closed-won Opportunity with Account and primary ContactWorkday Customer (Submit_Customer) and Customer Opportunity (Submit_Opportunity)Salesforce Opportunity and Account IDs stored as Workday reference IDs; existing-customer check before createSalesforce → WorkdayChange Data Capture event on Opportunity when StageName becomes Closed WonCustomer created only when no reference ID or tax ID matches; the Workday customer reference is written back to the Account.
Won services OpportunityWorkday Customer Contract (Submit_Customer_Contract) or Project (Resource_Management)Salesforce Opportunity ID as the Workday reference IDSalesforce → WorkdaySame Change Data Capture event, gated by record type or a services flagOptional; contract or project is chosen per business unit. Project status can flow back to the Opportunity on a schedule.
Salesforce Username and work email (after provisioning)Worker work contact information or Workday accountWorkday worker IDSalesforce → WorkdayAfter the User is createdOptional write-back, the pattern identity providers use for email and username; needs Put access on those domains in the ISSG.

Download this mapping as a CSV worksheet · no email required

Editions and APIs

Salesforce and Workday: editions, hosting and APIs

The edition, hosting model and API on each side decide what the integration can do and how it is built.

Editions, hosting and APIs
Workday HCM and Financial ManagementOne tenant per customer, with implementation tenants for testing. The Workday Web Services directory is at v47.0 (2026R2): Human_Resources covers employees, contingent workers and organizations; Staffing covers positions, hires, job changes and terminations; Financial_Management covers cost centers, companies, regions and business units; Revenue_Management covers customers, opportunities, contracts and invoices; Resource_Management covers projects and project resources. Workday asks you to specify a version in each request and recommends the most recent one.
Workday REST, Reports as a Service and toolingREST services sit behind the API gateway by service and version at https://api.workday.com/{service}/{version}/{resource}, secured with OAuth 2.0; the REST directory lists staffing (up to v7), person (v4), projects, revenue and customerAccounts among others. Reports as a Service exposes an advanced or search custom report as CSV, JSON, RSS or XML. Enterprise Interface Builder handles no-code inbound and outbound integrations launched or scheduled from the Workday UI, Workday Studio is the Eclipse-based environment for sophisticated ones, and business-process Integration steps launch an Integration Process Event. Workday describes the platform as a native part of Workday at no additional cost; confirm which connectors your subscription includes.
Workday security and AI agentsIntegration System Users in Integration System Security Groups, constrained or unconstrained, with Get and Put domain permissions and business process security where an integration starts a process. OAuth API clients are registered per integration with scopes by functional area. Agent-Ready Tools over MCP are in early access through Workday Extend Professional, with general availability projected for the second half of 2026.
Salesforce editions and API allocationsREST API access is on by default in Enterprise, Unlimited, Performance and Developer Edition and is an add-on for Professional. Daily allocation: 100,000 calls plus 1,000 per Salesforce license in Enterprise and Professional with API, 5,000 per license in Unlimited and Performance, 15,000 in Developer Edition, and 25 concurrent requests running 20 seconds or longer in production. Bulk API 2.0 allows 150,000,000 records per rolling 24 hours, 150 MB per job and 15,000 batches shared across Bulk API versions. Change Data Capture allows 5 selected objects without an add-on and 25,000 delivered events per day in Enterprise, retained for 72 hours.
Salesforce objects, SCIM and AI agentsUser (cannot be deleted, only deactivated; ProfileId required and tied to the license; FederationIdentifier for SAML single sign-on; ManagerId and UserRoleId lookups), UserRole, Contact, Account and custom objects for employees, cost centers and projects. Enterprise Territory Management (Territory2, Territory2Model, UserTerritory2Association) is included in Performance and Developer Editions and in Enterprise and Unlimited with Sales Cloud. SCIM 2.0 provisioning is available in all editions. Salesforce Hosted MCP Servers have been generally available since April 29, 2026 for Enterprise Edition and above, intended for Flex Credits customers.

Options, cost and timeline

Ways to deliver Salesforce and Workday integration

A prebuilt connector is sometimes enough. This comparison shows when each route fits, what it typically costs and how long it takes.

Delivery options, cost and timeline
ApproachTypical costTypical timeFits whenWatch for
Workday connectors (Salesforce Worker Connector, Salesforce Financial Management Connector)Licensed through your Workday subscription; Workday publishes no price and the Marketplace listings need a sign-inWeeks to configure, map and test in an implementation tenantAccount provisioning by user profile, department and division, and opportunity-to-customer or project creation that matches the connector’s rulesRole hierarchy, territories, PSA resource data, contingent-worker rules and record reassignment sit outside those rules; confirm what the current connector version does before planning around it
iPaaS (MuleSoft Anypoint Connector for Workday, or your existing platform)Platform subscription quoted by the vendor; MuleSoft publishes no list priceWeeks for standard flows once the platform and connectors are in placeTeams already running MuleSoft or another iPaaS with Workday and Salesforce connectors and an integration team to own the flowsConnector 16.7.1 targets Workday API v46.0, so plan version upgrades; the mapping and rule logic still has to be designed, built and tested
Identity provider plus a thin custom layerYour Microsoft Entra ID or Okta licenses, plus a smaller custom build quoted after discoveryUsually a few weeks, since the identity provider already creates and deactivates usersCompanies that already provision from Workday through an identity provider and need Salesforce-specific role, territory and reassignment logic on topTwo systems writing to the Salesforce User need one owner per field; SCIM carries profiles, permission sets and roles, but not territories or manager-based reassignment
Custom integration (AIONDATA)Quoted after a short discovery; hosting and support priced separatelyUsually a few weeks for provisioning, deactivation and role hierarchy; territories, PSA data and the reverse flow extend the scopeRules that vary by job profile, organization or country, services firms with PSA data, several Workday companies, the reverse flow to Workday Financials, or a requirement to own the codeNeeds an owner for monitoring and for retesting on the Workday and Salesforce release calendars, or a support agreement

Vendor prices are list prices from their public pages on the date shown; confirm current pricing with each vendor.

Workday and Salesforce APIs, authentication and versions

Workday exposes the same data three ways. Workday Web Services are SOAP services with a WSDL per service; the directory is at v47.0 (2026R2), and Workday tells you to specify a version in each request so the request and response model stays stable, while recommending the most recent one. Older versions stay callable for years: Microsoft’s Entra connector still defaults to v21.1 of Get_Workers unless you put a newer version in the URL. Reports as a Service turns an advanced or search custom report into a CSV, JSON, RSS or XML feed, the cheapest way to get exactly the worker and organization fields you want in one call. Workday REST APIs sit behind the API gateway at https://api.workday.com/{service}/{version}/{resource}, use OAuth 2.0 and Workday’s configurable security, and Workday positions them for smaller real-time transactions rather than bulk work.

On the Salesforce side the integration uses the REST API with OAuth for record-level work, Bulk API 2.0 for anything above about 2,000 records such as the initial load, and Change Data Capture for events that originate in Salesforce. Every write uses upsert by external ID, so a retry cannot create a duplicate and a double match stops the record instead of guessing.

  • Workday: one Integration System User in its own Integration System Security Group, Get on the HR domains it reads, Put only where it writes back.
  • Workday REST and Reports as a Service over OAuth: Register API Client, authorization code grant, scopes by functional area, non-expiring refresh token for the ISU.
  • Salesforce: a dedicated API-only integration user with a least-privilege permission set and the Manage Internal Users permission, never a person’s login.
  • Pin the Workday Web Services version per request and the Salesforce API version per endpoint; retest on both release calendars.

Provisioning rules: who gets a user, which profile, which role

The hard part is not the API, it is the table. Get_Workers returns employees and contingent workers across every Workday company, so the integration needs an explicit list of which job profiles, supervisory organizations, companies and worker types get a Salesforce user, and which license and profile each gets; Salesforce ties the license to the profile, so the table lists both. The User carries more than a login: FederationIdentifier holds the SAML subject for single sign-on, EmployeeNumber holds the Workday worker ID, ManagerId links to the manager’s user, UserRoleId places the user in the role hierarchy, and Department, Division and Title come straight from Workday. Territories are UserTerritory2Association rows, and only the active territory model is visible to users; account assignment stays with Salesforce assignment rules.

Many Workday customers already provision accounts through an identity provider. Microsoft Entra ID’s Workday inbound provisioning reads Get_Workers with an Integration System User, creates users in Active Directory and Entra ID, and can write email and username back to Workday; Salesforce then becomes a SCIM 2.0 target at /services/scim/v2/ for users, groups, profiles, permission sets and roles. In that design our integration does not create users; it sets what SCIM does not carry, and the rule that matters is one owner per User field so the two never overwrite each other.

Won deals, customers and projects back to Workday

When Workday Financials is the ledger, a closed-won opportunity should create or update the customer and, where you use them, the customer opportunity, customer contract or project. Revenue_Management provides Submit_Customer, Submit_Opportunity, Submit_Customer_Contract and Submit_Customer_Invoice, and Resource_Management provides the project operations; a project can then be used as a worktag across Financial Management and HCM. Workday’s own Financial Management for Salesforce connector follows the same pattern: an opportunity created in Salesforce is created in Workday against a prospective customer, and a closed opportunity creates the customer if required.

The trigger is a Change Data Capture event on Opportunity when the stage becomes Closed Won, gated by record type or a services flag. The Salesforce record ID is stored as the Workday reference ID and checked before every create, and the Workday customer reference is written back to the Account. Decide early which system owns the customer master after the first invoice; we recommend Workday Financials for billing address and payment terms and Salesforce for the relationship fields. Services firms on Certinia PS Cloud, which unifies resource planning and project delivery on Salesforce, usually keep projects and resources there, so the integration brings workers, cost centers and job profiles into Certinia and sends cost or revenue summaries to Workday at period end.

Failure and reconciliation playbook

HR data arrives in bursts: a reorganization changes hundreds of managers at once, a Workday release weekend pauses integrations, and a Change Data Capture subscriber that disconnects has 72 hours to catch up before events expire. The integration stores every event, processes it once, and keeps failures visible until a named owner in HR or RevOps clears them.

  • Duplicate worker event: absorbed by the upsert on the Workday worker ID; a multiple-match 300 error stops the record and alerts, because two users already claim one worker.
  • No free license or unmapped job profile: the user is held with the reason; the owner adds a license or a mapping row and replays.
  • Manager without a Salesforce user: ManagerId left empty, role set from the organization table, exception listed for review.
  • Workday tenant unavailable or an integration event delayed: retries with backoff, then an alert; the nightly Reports as a Service reconciliation pull catches anything missed.
  • Salesforce API allocation running low: bulk reads pause and resume; provisioning and deactivation keep priority.
  • Daily check: active Workday workers in scope without an active Salesforce user, and active Salesforce users without an active worker.
  • Weekly check: UserRole and territory membership against supervisory organizations and positions, and won opportunities without a Workday customer reference.

Security, permissions and data residency

Workday’s model was built for this. An Integration System User is not a person, needs no UI access and lives in its own Integration System Security Group, constrained to specific organizations where you want it. Domain security policies grant Get for reading and Put for writing, and business process security applies only when the integration starts a process such as a hire. OAuth API clients are registered per integration with scopes by functional area such as Staffing and Personal Data.

The integration carries only the fields in the mapping workbook: names, work contact details, job profile, organization, manager and dates. Compensation, personal identifiers and benefits never leave Workday, and we leave them out of the Reports as a Service reports rather than filtering them later. On the Salesforce side a dedicated integration user with a least-privilege permission set performs the writes, and field-level security hides HR-sourced fields from users who do not need them. We host the integration in the region you choose, including an existing cloud account of yours.

Timeline, environments and acceptance tests

A provisioning, deactivation and role-hierarchy scope usually takes a few weeks, including a Workday implementation tenant, a Salesforce sandbox and the security review on both sides; territories, PSA data and the reverse flow extend that. AIONDATA scopes the work in a short discovery of your Workday configuration, Salesforce customizations and identity setup, then delivers under ISO 9001:2015 and CMMI Level 3 processes from Noida with leadership in San Ramon. We run these tests with HR, RevOps and IT before go-live and repeat the short list after each Workday and Salesforce release.

  • A hire with a mapped job profile creates one Salesforce user with the right license, profile, role, manager, territory and Federation ID within the agreed time after the Hire process completes.
  • The same hire event delivered twice creates one user.
  • A hire with an unmapped job profile is held with a readable reason and provisions after the mapping row is added.
  • A job change into another supervisory organization updates the role and territory, and open opportunities follow the reassignment rule.
  • A termination deactivates the user on the termination date, frees the license and reassigns owned accounts, opportunities and cases; a rehire reactivates the same user.
  • A contingent worker contract end deactivates that user without touching employees.
  • A closed-won opportunity creates one Workday customer and opportunity, the Workday reference appears on the Account, and a second save does not create a second customer.
  • The nightly reconciliation report shows zero mismatches on a quiet day and exactly the seeded ones on a test day.

AI agent access through MCP

Salesforce Hosted MCP Servers have been generally available since April 29, 2026 for Enterprise Edition and above; every call runs as the signed-in user with OAuth and PKCE, and Salesforce says they are intended for Flex Credits customers. Workday’s Agent-Ready Tools over MCP are in early access through Workday Extend Professional, with general availability projected for the second half of 2026. For Salesforce-only questions, start with the hosted servers.

Cross-system questions need a custom MCP server: “who covers this territory, and are they an active worker”, “which Salesforce users are not active employees”, or “draft the reassignment plan for this leaver”. We build those read-only first, with the Workday side on an ISU scoped to Get, and put every write, such as a territory change, behind a confirmation step so a person approves it. Tool calls into Salesforce count against the daily API allocation, and HR fields are limited to the mapping list.

Technical details last reviewed September 30, 2026. Product capabilities and prices change; confirm them for your edition.

Sources: Workday Web Services (WWS) Directory v47.0 · Workday Web Services: Human_Resources v47.0 · Workday Web Services: Staffing v47.0 · Workday Web Services: Financial_Management v47.0 · Workday Web Services: Revenue_Management v47.0 · Workday Web Services: Resource_Management v47.0 · Workday Education: Using Workday Web Services · Workday REST Directory · Workday Education: Web Services and API Integrations · Workday Administrator Guide: Reports as a Service (RaaS) · Workday datasheet: Workday Integration Cloud · Workday datasheet: Integration Cloud Connectors for HCM · Workday datasheet: Integration Cloud Connect · Workday Administrator Guide: Setup Considerations: Business Processes · Workday Education: Workday Configurable Security (integrations) · Workday Education: Security for Administrators, Integrations · Workday documentation: Connect to Workday Using OAuth (Register API Client) · Workday newsroom (June 2, 2026): New tools for developers to build, connect and verify AI agents · Workday newsroom (Sept 16, 2025): Workday Introduces Workday Data Cloud · Salesforce press release (July 24, 2024): Salesforce and Workday form strategic partnership · Salesforce Developers: Data Cloud Workday Connector · Salesforce REST API Developer Guide: Supported editions · Salesforce Developers: API request limits and allocations · Salesforce Developers: Bulk API and Bulk API 2.0 limits and allocations · Salesforce Change Data Capture Developer Guide: Allocations · Salesforce REST API Developer Guide: Upsert a record using an external ID · Salesforce Object Reference: User · Salesforce Object Reference: Territory2 · Salesforce Object Reference: UserTerritory2Association · Salesforce Help: Enterprise Territory Management · Salesforce Help: Understand the SCIM implementation · Salesforce Developers blog: Hosted MCP Servers are now generally available · Salesforce Developers: Hosted MCP Servers, get started · MuleSoft: Workday Connector 16.7 reference · MuleSoft: Workday Connector release notes (Mule 4) · Microsoft Learn: Configure Workday for automatic user provisioning with Microsoft Entra ID · Certinia: Professional Services Cloud

Outcomes

Why teams connect Salesforce and Workday

  • New sellers and consultants log in to Salesforce with the right role and territory on their first day, without a ticket to IT.
  • Leavers lose Salesforce access on their termination date, their license is freed and their pipeline has a new owner the same day.
  • Forecast hierarchies and territories follow Workday reorganizations instead of drifting until someone notices at quarter end.
  • Finance sees won deals and new customers in Workday without re-keying, and RevOps stops reconciling user lists against headcount.

Salesforce Workday Integration FAQs

Which Workday APIs does a Salesforce integration use?

Usually three together. Workday Web Services (SOAP) are the bulk workhorse: Human_Resources exposes employee, contingent worker and organization data through operations such as Get_Workers and Get_Organizations, and Staffing covers positions, hires, job changes and terminations; the directory is at v47.0 (2026R2). Reports as a Service turns an advanced custom report into a JSON or CSV feed with exactly the worker fields you need. Workday REST APIs on the api.workday.com gateway, secured with OAuth 2.0, suit smaller real-time calls; Workday positions REST as a complement to SOAP, not a replacement for bulk work.

How is the Salesforce side connected, and do API limits matter?

Through the REST API with OAuth, Bulk API 2.0 for loads above about 2,000 records, and Change Data Capture for triggers that start in Salesforce. API access is on by default in Enterprise, Unlimited, Performance and Developer Edition and is an add-on for Professional. The daily allocation is 100,000 calls plus 1,000 per Salesforce license in Enterprise, and 5,000 per license in Unlimited and Performance; a provisioning sync uses a small share. Bulk API 2.0 allows 150,000,000 records per rolling 24 hours, so the first load of every worker is not a limits problem.

How do you match Workday workers to Salesforce users without duplicates?

The Workday worker ID is stored in an external ID field on the User, and every write uses upsert by external ID: no match creates the user, one match updates it, and more than one match returns a 300 error and writes nothing, which is the duplicate guard you want. A rehire therefore reactivates the existing user. Username must be in email form and unique across all Salesforce orgs, so we agree the pattern with IT before the first load.

Does the integration need an identity provider?

No, but it should work with yours. Microsoft Entra ID provisions users from Workday’s Get_Workers operation with an Integration System User and can write email and username back to Workday, and Salesforce accepts SCIM 2.0 provisioning at /services/scim/v2/ for Users, Groups, Entitlements (profiles and permission sets) and Roles in all editions. Then the identity provider creates and deactivates the user, and our integration adds manager, role hierarchy, territory membership, cost center and record reassignment. Without an identity provider, the integration does both.

Is the Salesforce Workday sync real-time or scheduled?

Both, by data type. Workday business processes such as Hire, Change Job and Termination can include an Integration step that launches an Integration Process Event, so provisioning starts minutes after HR completes the transaction. Organization, cost center and project data run on a schedule, often an hourly Reports as a Service pull or a nightly EIB. In Salesforce, Change Data Capture delivers Opportunity changes within seconds; the default allocation is 25,000 delivered events per day in Enterprise and 50,000 in Unlimited and Performance, with 5 objects selectable without an add-on.

What happens to a leaver’s accounts and opportunities?

Salesforce users can’t be deleted in the UI or the API, only deactivated, so the integration deactivates the user on the Workday termination date and reassigns owned records by a rule you choose: to the manager from Workday, to a territory owner, or to a holding user for review. The rule is a table, not code, so RevOps can change it without a release.

Can Workday supervisory organizations drive the Salesforce role hierarchy and territories?

Yes. Get_Organizations returns supervisory, cost center, company and region organizations and their hierarchies, and each worker’s manager comes with the worker. We map supervisory organizations to UserRole records and set ManagerId, and map positions, locations or regions to territories in Enterprise Territory Management, which Salesforce includes in Performance and Developer Editions and in Enterprise and Unlimited with Sales Cloud. Membership is a UserTerritory2Association row with a role in territory of Owner, Administrator or Sales Rep. Rehearse a reorganization in the sandbox, because role changes affect sharing and forecast visibility at once.

Should Workday’s own Salesforce connectors or MuleSoft do this instead?

Sometimes. Workday’s datasheets describe a Salesforce.com Worker Sync that provisions Salesforce and Chatter accounts with rules for user profile, department and division, and a Financial Management for Salesforce connector that creates Workday opportunities, customers and projects from Salesforce triggers; Workday Marketplace lists both behind a sign-in. MuleSoft’s Anypoint Connector for Workday 16.7.1 supports Workday API v46.0 with basic, OAuth or X.509 authentication and suits teams already on Anypoint. If your rules fit, use them and we will configure and test them. Role hierarchy, territories, PSA data, contingent-worker rules and record reassignment are where a connector usually runs out of room.

What do the Salesforce Workday partnership and zero-copy announcements mean here?

Less than the headlines suggest. The July 24, 2024 announcement described a planned AI employee service agent and a shared data foundation through Salesforce Data Cloud, with the usual note that unreleased features may not be delivered. What has shipped is a Data Cloud Workday connector (batch ingestion generally available, zero-copy query federation in beta); Workday said in September 2025 that Workday Data Cloud would reach early adopters in the first half of 2026 and general availability later that year. Those feed analytics and AI. They do not provision users, set territories or write won deals into Workday Financials.

Which Workday security setup does the integration need?

An Integration System User that is not a person, in its own Integration System Security Group, with domain security policies granting Get on the HR domains it reads and Put only where it writes back; Workday notes that most outbound integrations need only Get. For REST and Reports as a Service over OAuth, an admin runs Register API Client, picks the authorization code grant and the scopes by functional area, and can issue a non-expiring refresh token. Every call is attributable to that ISU.

Can AI agents use Salesforce and Workday together?

Yes, with each vendor’s current state in mind. Salesforce Hosted MCP Servers have been generally available since April 29, 2026 for Enterprise Edition and above, with every call made as the signed-in user. Workday’s Agent-Ready Tools over MCP, announced June 2, 2026, are in early access through Workday Extend Professional with general availability projected for the second half of 2026. For a cross-system question such as “who covers this territory now, and are they still an active worker”, we build a custom MCP server that reads both systems with least-privilege credentials and prepares provisioning changes for a person to approve.

What drives the cost and timeline, and who maintains it?

The number of flows and how much logic sits in the rules. Provisioning, deactivation and role hierarchy usually take a few weeks including implementation-tenant testing and the security review; territories, PSA resource data, several Workday companies and the reverse flow into Workday Financials add to that. Ongoing cost is hosting, monitoring and the support plan; a Workday connector or MuleSoft subscription is priced by the vendor. After go-live we hand over the code, mapping workbook, runbook and alerts, or support it under an agreed plan.

Ready to connect Salesforce and Workday?

The enquiry form is at the top of this page. Share your objects, volumes and timing needs and we'll come back with a written scope.

Go to the enquiry form