Web Services Role
User roles control which features users can access in Dayforce, and they play an important part in the security
of Dayforce. User
roles are assigned to user names.
In Dayforce: To access this infromation navigate to System Admin > Roles.
General
Name: Provide a unique name and avoid spaces and special characters.
Password Policy: Ensure this is the password policy you either created earlier or aligns with best practices described in Web Services Password Policy.
Reference Code: Provide a unique name and avoid spaces and special characters.
Note: Do not change the name of the Role once it is used in the integration. Doing so might cause problems with the integration.
Features
This is a very important part of ensuring user security.
Only select the Web Services features required for the integration to function. Providing access to more than necessary is a security risk.
At an absolute minimum we recommend checking off:
Home
Home > Actions
Home > Events
This provides the ability of a landing page when logging into Dayforce using the Web Services user, for example, if you wanted to confirm user name / password is set up correctly.
HCM Anywhere
HCM Anywhere > Web Services
Beyond these, it somes down to what methods you require, read/get, post/insert, patch/update or delete. For POST/PATCH there will be many individual endpoint topics.
Authorizations
Role authorizations define what access rights a role has to different types of information in Dayforce.
Only select authorizations required by the integration. We recommend scrutinizing this area and not selecting everything just to ensure any errors are not returned.
You can assign four types of authorizations:
- Can Create: The role can add new items of the associated information.
- Can Read: The role can read items of the associated information.
- Can Update: The role can edit the details of existing items of the associated information.
- Can Delete: The role can delete items of the associated information.
Web Services Field-Level Access
From a GET / read perspective, Field-level access must be configured to control the specific data elements that are populated when that consumer requests data.
Only select the fields required for the integration. We strongly recommend avoiding selecting all fields under an endpoint as this is a security risk.