The Workday integration with CertnCentric allows your organization to initiate background checks from Workday and receive background check status updates and results from CertnCentric.
The integration works in both directions:
- Workday → CertnCentric: Workday sends the background check order and candidate information to CertnCentric.
- CertnCentric → Workday: CertnCentric returns background check statuses and results to Workday.
Workday uses the Core Connector – Background Check Order Outbound to initiate orders, while CertnCentric uses Workday's Put_Background_Check web service to return status and result information.
This guide is intended for Workday Integration Administrators or Integration SMEs. We recommend configuring and testing the integration in the CertnCentric sandbox environment before setting it up in production.
Before you get started
Make sure you have:
| Requirement | What you need |
|---|---|
| Workday tenant access | Permission to create integrations, security groups, and Background Check business processes |
| CertnCentric account | Integration endpoint and API credentials |
| Network access | HTTPS outbound traffic from Workday to the Certn endpoint |
| OAuth 2.0 connectivity | A verified refresh token exchange between Workday and Certn |
| Package and status alignment | Packages, tests, and statuses in Workday that exactly match the corresponding Certn values |
Step 1: Configure Workday to send background checks to CertnCentric
1. Create an Integration System User
In Workday:
- Search for Create Integration System User.
- Give the Integration System User (ISU) a unique name, such as
ISU_Background_Check_Certn. - Create a password.
- Select Do Not Allow UI Session.
- Select OK.
2. Create an Integration System Security Group
- Search for Create Security Group.
- For Tenanted Security Group Type, select Integration System Security Group (Unconstrained).
- Assign the ISU you created.
- Select OK.
- On the next screen, select your ISU in the Integration System User field.
- Save the configuration.
3. Assign the required domain permissions
- Search for View Security Group for User.
- Select the ISU you created and select OK.
- Go to Security → Maintain Domain Permissions for Security Group.
- Grant View and Modify access according to the Domain Security Permissions Matrix.
Configure the following permissions:
| Operation | Domain security policy | Functional area |
|---|---|---|
| Get and Put | Manage Pre-Hire Process: Manage Pre-Hires | Pre-Hire Process |
| Get and Put | Manage: Evergreen Requisitions | Recruiting |
| Get and Put | Worker Data: Public Worker Reports | Staffing |
| Get and Put | Integration Event | Integration |
| Get and Put | Worker Data: Background Check Status | Personal Data |
| Get and Put | Candidate Data: Background Check History | Recruiting |
| Get and Put | Candidate Data: Job Application | Recruiting |
| Get and Put | Pre-Hire Data: Background Check Status | Pre-Hire Process |
| Get and Put | Job Requisition Data | Pre-Hire Process |
| Get and Put | Pre-Hire: Skills and Experience | Worker Profile and Skills |
| Get and Put | Worker Data: Skills and Experience | Worker Profile and Skills |
4. Link the security group to the Background Check business process
Navigate to:
Background Check (Default Definition) → Business Process Policy → Edit
Then:
- Select View All.
- Go to Security Groups.
- Add the Integration System Security Group you created.
- Save your changes.
- Search for Activate Pending Security Policy Changes.
- Select OK to activate the new permissions.
5. Configure the Background Check business process
Navigate to:
Background Check (Default Definition) → Business Process → Edit Definition
- Locate the Initiation step.
- Add a step immediately after Initiation.
- Set the type to Integration.
- Set Run As User to the ISU you created.
- Select the integration.
- Select Configure.
- Select the integration and select OK.
- Define the Integration Criteria.
For Core Connector: Background Check Outbound Initial Service, configure:
- Background Check ID: Background Check Event
- As of Entry Moment: Current Moment (DateTime)
6. Create the Integration System
In Workday:
- Search for Create Integration System.
- Select Core Connector – Background Check Order Outbound.
- Enable all services.
- From the Integration System landing page, select Configure Integration Attributes.
- Configure:
- Phone Device Type: Mobile
- Email Type: Home
- Phone Type: Home
- Country Code Type: ISO3166-1-Alpha-3
- Address Type: Home
Configure the sequence generator:
- Increment Sequence ID by: 1
- Padding: 0
- Set desired sequence ID format: ie:
BGCHK-[seq]
7. Create the integration business process
From View Integration Systems:
- Open Related Actions.
- Select Integration System → Business Process → Create.
- For Business Process Type, select < none of the above >.
- Select OK.
- Add a step.
- Set Type to Service.
- Select Document Delivery.
- Select OK.
Step 2: Configure CertnCentric to send updates to Workday
The inbound integration allows CertnCentric to update background check statuses, completion results, and adjudication outcomes in Workday using the Put_Background_Check web service.
1. Register an API client
In Workday:
- Search for Register API Client for Integrations.
- Select Create New Client.
- Enter a Client Name, such as CertnCentric API Client.
- Select Non-Expiring Refresh Tokens.
- Add the following scopes:
- Pre-Hire Process
- Recruiting
- Staffing
- Select OK.
Workday generates a Client ID and Client Secret. Save both values for the CertnCentric ATS setup.
2. Generate the refresh token
- Open the API client's Related Actions menu.
- Select API Client → Manage Refresh Tokens for Integration.
- Select the ISU you created earlier.
- Select OK.
- Select Generate New Refresh Token.
- Save the generated Refresh Token.
3. Start the Workday setup in CertnCentric
In CertnCentric, go to:
Settings → ATS Integration → Workday
You'll need to provide:
- OAuth Token endpoint
- Recruiting WSDL URL
- Client ID
- Client Secret
- Refresh Token
To find the OAuth Token endpoint in Workday:
- Open View API Clients.
- Copy the displayed Token Endpoint.
To find the Recruiting WSDL URL:
- Go to Public Web Services → Recruiting (Public) → Related Actions.
- Select View WSDL.
- Copy the URL nested under the
<soapbind:address>XML tag.
Enter the required information in CertnCentric and proceed to Step 2 of 3.
4. Configure Document Delivery
In Workday:
- Go to View Integration System.
- Select the Integration System created earlier.
- Go to Business Process Definitions → Steps.
- Select Configure Document Delivery.
- For Document(s), select From this integration process.
Configure:
- Transport Type: HTTP/SSL
- HTTP Address: Enter the address provided by CertnCentric during the Workday integration setup.
- Web Service Invocation Type: OAuth 2.0
In CertnCentric, go to:
ATS Integrations → Workday → Step 2 of 3
Obtain:
- Access Token
- Refresh Token
- Refresh Token URL / REST API Endpoint
- Client ID
- Client Secret
Enter these values into the corresponding Workday fields.
Workday automatically refreshes expired tokens using the stored Client ID, Client Secret, and Refresh Token.
Step 3: Configure packages and statuses
1. Configure background check packages
Proceed to Step 3 of 3 in CertnCentric.
In Workday:
- Search for Maintain Background Check Packages.
- Add each Package Name and Reference ID exactly as they appear in CertnCentric.
- Under Tests, configure:
- Test Name
- Test Reference ID
- Make sure the Test Reference ID matches the Certn format.
2. Configure background check statuses
In Workday, search for:
Maintain Background Check Statuses
Certn sends its status enum values directly to the Workday Put_Background_Check API. These values are used as the Workday Background_Check_Status_ID for Overall Status, Package Status, and individual Test Statuses.
Package-level statuses
| Certn status | Status label | Workday status |
|---|---|---|
CASE_ORDERED | Case Ordered | Overall Status, Package Status |
APPLICANT_INVITED | Applicant Invited | Overall Status, Package Status |
APPLICANT_OPENED | Applicant Opened | Overall Status, Package Status |
APPLICANT_STARTED | Applicant Started | Overall Status, Package Status |
APPLICANT_SUBMITTED | Applicant Submitted | Overall Status, Package Status |
INVITE_UNDELIVERABLE | Invite Undeliverable | Overall Status, Package Status |
APPLICANT_DECLINED | Applicant Declined | Overall Status, Package Status |
APPLICANT_EXPIRED | Applicant Expired | Overall Status, Package Status |
IN_PROGRESS | In Progress | Overall Status, Package Status |
COMPLETE | Completed | Overall Status, Package Status |
Individual check statuses
| Certn status | Status label |
|---|---|
AWAITING_APPLICANT_SUBMISSION | Awaiting Applicant Submission |
PENDING_FULFILLMENT | Pending Fulfillment |
IN_PROGRESS | In Progress |
SUBMITTED_TO_SOURCE | Submitted to Source |
MANUAL_REVIEW_SOURCE | Manual Review with Source |
CLIENT_ACTION_REQUIRED | Client Action Required |
APPLICANT_ACTION_REQUIRED | Applicant Action Required |
PENDING_QUALITY_REVIEW | Pending Quality Review |
IN_QUALITY_REVIEW | In Quality Review |
COMPLETE | Completed |
CANCELLED | Cancelled |
SUPERSEDED | Superseded |
IN_DISPUTE | In Dispute |
Test the Workday integration
Complete an end-to-end test before configuring the integration in production.
Before testing, confirm:
- Core Connector: Background Check Order Outbound is active.
- The CertnCentric endpoint and OAuth configuration have been validated using Test Integration in Workday.
- Background Check (Default Definition) includes the outbound integration as Step 2.
- The ISU has access to Background Check Data, Candidate Data, and Integration Event Data.
- A test candidate has applied to a test job requisition.
1. Confirm the candidate has applied
- Log in to Workday as a Recruiter or Talent Partner.
- Go to Recruiting → Candidates.
- Select the test candidate.
- Confirm the candidate has an Active Job Application for the correct requisition.
2. Initiate the background check
Under Active Job Applications:
- Select Actions → Move Candidate.
- Select Move Forward → Assessment.
- Select Background Check.
This triggers the Background Check business process, where the integration runs as Step 2.
3. Select a background check package
- Start a proxy session as a recruiter for the Job Requisition.
- Go to My Tasks.
- Select Background Check Package (Candidate Name).
- Select the CertnCentric package you want to test.
- Select Submit to trigger the integration.
4. Confirm the results in Workday
Return to the candidate and go to:
Screening → Background Check History
Confirm that:
- Overall Status is updated.
- Package Status is updated.
- The Result URL is available to review the final report.
A successful test confirms that background check information is flowing in both directions:
Workday → CertnCentric → Workday
Once the end-to-end test is successful, repeat the required configuration in your production environment.
Comments
0 comments
Article is closed for comments.