Sourced open data and public reuse context
Source records, publishing, and corrections: Workday Security
Open Data BR provides City-Parish data for public analysis, web visualizations, applications, department coordination, and resident access. Translate the operating setting into security groups, domain permissions, business-process policies, organization constraints, and sensitive fields. Ask how users complete work under least privilege. A public-data service needs named owners for source records, publication rules, refresh timing, metadata, legal review, corrections, and downstream applications that the publishing team does not control.
Evidence to request: Use an access-design exercise with worker groups, domains, business processes, sensitive fields, and organization constraints. Identify each source system, dataset owner, publication test, refresh schedule, restricted field, correction route, consumer, and support handoff connected to the role.
Sourced enterprise applications and infrastructure context
Shared services across departments: Workday Security
Baton Rouge Information Services lists application development, server administration, network management, and consolidation of department technology among its responsibilities. Define joiner, mover, leaver, service-account, and integration access across Workday and identity systems. Require evidence from provisioning, authentication, access reviews, and exception handling. A shared service may support departments with separate case records, approvals, retention rules, operating hours, budgets, and legacy systems while one central team owns infrastructure and support.
Evidence to request: Review a provisioning or integration-security defect with identity, scope, logs, correction, retest, and user impact. Name the departments, user groups, service owner, application and hosting boundary, approval path, maintenance window, legacy connections, and acceptance evidence.
Sourced cybersecurity and geographic data context
Identity, location, and disclosure boundaries: Workday Security
The Information Services department identifies cybersecurity and geographic information systems as City-Parish functions and describes work on maps, data, and applications. Set audit and release ownership. Candidates should explain how they analyze access, resolve conflicts, migrate changes, test populations, retain evidence, and verify permissions after an organization or process change. Constituent and location records can cross identity, field access, map layers, integrations, operational use, audit logs, and public-disclosure rules that require separate review owners.
Evidence to request: Ask for an audit finding or tenant release the consultant handled, including analysis, configuration, population testing, evidence, and follow-up review. Define the identity authority, protected records, geographic layers, access groups, public boundary, retained logs, incident route, and review required after a system change.