The Platform
One system of record for every control, finding, and risk in your Workday tenant
Argeye is the full-suite Governance, Risk, and Compliance (GRC) platform built for Workday. This is what it actually looks like, module by module.
Scans
Continuous monitoring, tuned to your tenant
Automated scans continuously evaluate and monitor changes across five areas of your Workday tenant. Every control can also be scoped independently across Production, Sandbox, and Implementation.
System Access
Who can get into the system — external account creation, authentication policy changes, and more.
User Access
Once inside, who can reach configurable sensitive or privileged items — security group edits, assignable role edits, and more.
Segregation of Duties
SoD conflicts, fully configurable across Domains and Business Processes.
User Activity
Configurable rules that monitor specific actions, including activity performed against peers or managers, and activity performed while in proxy.
Business Process Changes
Configuration changes made to Workflows, tracked as they happen.
What makes Argeye different
Controls that stay honest
With Argeye, your controls and previously-accepted Findings are constantly evaluated against underlying configuration changes. The SOD conflict you Accepted 3 months ago may not be valid anymore due to configuration changes. With Configuration Aware, your Findings and monitoring rules are evaluated, and flagged, against any configuration changes.
Monitoring Rules impacted flagged for review
The configured rule used to monitor a Business Process is flagged for review when changes have been made to that Business Process, ensuring your rules are up-to-date with configuration.
Every Finding tied to it reopens on its own
A Finding accepted six months ago, because compensating approval steps made the risk acceptable, gets flagged "Requires Reevaluation" the moment those steps disappear. Nobody has to remember to go check.
No configuration change goes unchecked against a decision you already made.
It goes beyond just edits made to the Business Process. Any edits made to entry conditions, or calculated fields nested in those entry conditions, are monitored and flagged for changes. Most tools don't check this at all.
Findings, Issues & Risks
What gets tracked, and what it rolls up to
Findings and Issues are how you track and resolve what your Scans, Activities, and Audits turn up. Risks are the separate, higher-level register everything maps back to.
What was observed, tracked to resolution
Every Scan, Activity, and Audit produces Findings, the record of what was observed. A Finding can be accepted, mitigated, or escalated into an Issue.
Issues are remediation objects. Every Issue links to at least one Finding, and a single Issue can group multiple related Findings together, so you can apply one decision in bulk or track remediation that spans more than one observation.
One register for what actually matters
Both Findings and Issues link back to your Risks register: your organization's catalog of the risks that actually matter. That gives you one holistic view of what controls are in place for what risk, drawn from Scans, Activities, and Audits alike.
Activities & Audits
Manual work gets a full module too
Automation only goes so far. Scans run continuously across your Production and Non-Production Workday environments, but some compliance work will always need a person. That work still has to be scheduled, evidenced, and defensible.
Recurring work that can’t be automated
- Monthly review of all manual Payroll Inputs
- Bi-annual password reset for external vendors
Scheduled, tracked to completion, evidenced for audit.
Formal engagements, start to finish
- IT General Controls
- SOX Compliance
Scope, timeline, findings, and evidence in one record.
How it all connects
Scans, Activities, and Audits all tag back to your Risk register. Findings & Issues let you see where risk has propagated, and what needs actioning.
Scans
Automatic detection
RisksActivities
Manual reviews
RisksAudits
Formal engagements
RisksFinding
What was observed
Contains all evidence
RisksIssue
Decision or remediation
References Finding evidence
RisksRisksEvery object links back to your Risk register — so coverage, and the gaps in it, are visible in one place.