Which Workday APIs does a Salesforce integration use?+
Usually three together. Workday Web Services (SOAP) are the bulk workhorse: Human_Resources exposes employee, contingent worker and organization data through operations such as Get_Workers and Get_Organizations, and Staffing covers positions, hires, job changes and terminations; the directory is at v47.0 (2026R2). Reports as a Service turns an advanced custom report into a JSON or CSV feed with exactly the worker fields you need. Workday REST APIs on the api.workday.com gateway, secured with OAuth 2.0, suit smaller real-time calls; Workday positions REST as a complement to SOAP, not a replacement for bulk work.
How is the Salesforce side connected, and do API limits matter?+
Through the REST API with OAuth, Bulk API 2.0 for loads above about 2,000 records, and Change Data Capture for triggers that start in Salesforce. API access is on by default in Enterprise, Unlimited, Performance and Developer Edition and is an add-on for Professional. The daily allocation is 100,000 calls plus 1,000 per Salesforce license in Enterprise, and 5,000 per license in Unlimited and Performance; a provisioning sync uses a small share. Bulk API 2.0 allows 150,000,000 records per rolling 24 hours, so the first load of every worker is not a limits problem.
How do you match Workday workers to Salesforce users without duplicates?+
The Workday worker ID is stored in an external ID field on the User, and every write uses upsert by external ID: no match creates the user, one match updates it, and more than one match returns a 300 error and writes nothing, which is the duplicate guard you want. A rehire therefore reactivates the existing user. Username must be in email form and unique across all Salesforce orgs, so we agree the pattern with IT before the first load.
Does the integration need an identity provider?+
No, but it should work with yours. Microsoft Entra ID provisions users from Workday’s Get_Workers operation with an Integration System User and can write email and username back to Workday, and Salesforce accepts SCIM 2.0 provisioning at /services/scim/v2/ for Users, Groups, Entitlements (profiles and permission sets) and Roles in all editions. Then the identity provider creates and deactivates the user, and our integration adds manager, role hierarchy, territory membership, cost center and record reassignment. Without an identity provider, the integration does both.
Is the Salesforce Workday sync real-time or scheduled?+
Both, by data type. Workday business processes such as Hire, Change Job and Termination can include an Integration step that launches an Integration Process Event, so provisioning starts minutes after HR completes the transaction. Organization, cost center and project data run on a schedule, often an hourly Reports as a Service pull or a nightly EIB. In Salesforce, Change Data Capture delivers Opportunity changes within seconds; the default allocation is 25,000 delivered events per day in Enterprise and 50,000 in Unlimited and Performance, with 5 objects selectable without an add-on.
What happens to a leaver’s accounts and opportunities?+
Salesforce users can’t be deleted in the UI or the API, only deactivated, so the integration deactivates the user on the Workday termination date and reassigns owned records by a rule you choose: to the manager from Workday, to a territory owner, or to a holding user for review. The rule is a table, not code, so RevOps can change it without a release.
Can Workday supervisory organizations drive the Salesforce role hierarchy and territories?+
Yes. Get_Organizations returns supervisory, cost center, company and region organizations and their hierarchies, and each worker’s manager comes with the worker. We map supervisory organizations to UserRole records and set ManagerId, and map positions, locations or regions to territories in Enterprise Territory Management, which Salesforce includes in Performance and Developer Editions and in Enterprise and Unlimited with Sales Cloud. Membership is a UserTerritory2Association row with a role in territory of Owner, Administrator or Sales Rep. Rehearse a reorganization in the sandbox, because role changes affect sharing and forecast visibility at once.
Should Workday’s own Salesforce connectors or MuleSoft do this instead?+
Sometimes. Workday’s datasheets describe a Salesforce.com Worker Sync that provisions Salesforce and Chatter accounts with rules for user profile, department and division, and a Financial Management for Salesforce connector that creates Workday opportunities, customers and projects from Salesforce triggers; Workday Marketplace lists both behind a sign-in. MuleSoft’s Anypoint Connector for Workday 16.7.1 supports Workday API v46.0 with basic, OAuth or X.509 authentication and suits teams already on Anypoint. If your rules fit, use them and we will configure and test them. Role hierarchy, territories, PSA data, contingent-worker rules and record reassignment are where a connector usually runs out of room.
What do the Salesforce Workday partnership and zero-copy announcements mean here?+
Less than the headlines suggest. The July 24, 2024 announcement described a planned AI employee service agent and a shared data foundation through Salesforce Data Cloud, with the usual note that unreleased features may not be delivered. What has shipped is a Data Cloud Workday connector (batch ingestion generally available, zero-copy query federation in beta); Workday said in September 2025 that Workday Data Cloud would reach early adopters in the first half of 2026 and general availability later that year. Those feed analytics and AI. They do not provision users, set territories or write won deals into Workday Financials.
Which Workday security setup does the integration need?+
An Integration System User that is not a person, in its own Integration System Security Group, with domain security policies granting Get on the HR domains it reads and Put only where it writes back; Workday notes that most outbound integrations need only Get. For REST and Reports as a Service over OAuth, an admin runs Register API Client, picks the authorization code grant and the scopes by functional area, and can issue a non-expiring refresh token. Every call is attributable to that ISU.
Can AI agents use Salesforce and Workday together?+
Yes, with each vendor’s current state in mind. Salesforce Hosted MCP Servers have been generally available since April 29, 2026 for Enterprise Edition and above, with every call made as the signed-in user. Workday’s Agent-Ready Tools over MCP, announced June 2, 2026, are in early access through Workday Extend Professional with general availability projected for the second half of 2026. For a cross-system question such as “who covers this territory now, and are they still an active worker”, we build a custom MCP server that reads both systems with least-privilege credentials and prepares provisioning changes for a person to approve.
What drives the cost and timeline, and who maintains it?+
The number of flows and how much logic sits in the rules. Provisioning, deactivation and role hierarchy usually take a few weeks including implementation-tenant testing and the security review; territories, PSA resource data, several Workday companies and the reverse flow into Workday Financials add to that. Ongoing cost is hosting, monitoring and the support plan; a Workday connector or MuleSoft subscription is priced by the vendor. After go-live we hand over the code, mapping workbook, runbook and alerts, or support it under an agreed plan.