A service account lapses tonight. Lapsed already knows which integrations stop.
Lapsed reads three read-only reports out of your own Workday tenant and maps every integration system to the account it runs as. When an account's password lapses, you get the integrations that go down with it, by name, before anyone raises a ticket.
Read only. Certificates, non-human accounts and integration system owners. No worker records, no payroll, no personal data.
- INT2001 Paycrest Payroll Outbound
- INT2002 Paycrest Quarterly Tax Outbound
- INT2003 Paycrest Periodic Tax Outbound
- INT2004 GL Journal Export
- INT2005 Payroll Costing Allocation Outbound
Exposure map
Every integration system matched to the Workday account it runs as. 23 systems across 216 non-human accounts.
Certificate inventory
All 21 certificates with days remaining, including the 4 that Workday holds no expiry date for at all.
Your own threshold
Workday is fixed at 30, 15 and 7 days. Set yours to 90, 60 or 45 and get the list that far ahead.
Honest unknowns
Where Workday reports nothing, Lapsed says so and tells you to verify by hand. It never invents a countdown to fill the gap.
Workday warns you at 30 days, and you cannot move the line.
One email at 30 days, one at 15, one at 7. No report, no list, no dashboard, and no setting that widens the window.
Those three emails are the whole of Workday's built-in certificate warning. There is nowhere in the tenant to see what is expiring next month, nowhere to see what expired last month, and no way to ask for more notice.
They also only send if someone switched them on. The tenant setting that enables them is the same one that sends security notices to every user in the tenant, so plenty of customers turn it off deliberately and never think about it again.
Meanwhile a service account password lapsing sends nothing at all, and Workday does not report the date the next rotation falls due.
Enable Security Emails in tenant setup. On, and every user gets security notices. Off, and nobody gets the certificate warning either. There is no middle position.
What the audit actually looks like.
The real components from the Lapsed dashboard, filled with sample data from a fictional tenant.
Integration exposure by account
Sorted by blast radius| Account | Password state | Exempt | Stops | Integrations taken down |
|---|---|---|---|---|
| ISU_PAYROLL_OUT | Unknown | No | 5 | INT2001 Paycrest Payroll Outbound INT2002 Paycrest Quarterly Tax Outbound INT2003 Paycrest Periodic Tax Outbound INT2004 GL Journal Export INT2005 Payroll Costing Allocation Outbound |
| ISU_BANK_SETTLE | Unknown | No | 3 | INT2010 Halewood Bank Settlement Outbound INT2011 Halewood Positive Pay INT2012 Halewood Statement Reconciliation Inbound |
| ISU_BENEFITS_OUT | Unknown | No | 3 | INT2020 Everline Medical and Dental Outbound INT2021 Cavendish Retirement Contributions Outbound INT2022 Everline Life and Disability Outbound |
| ISU_IDENTITY_SYNC | Unknown | No | 2 | INT2030 Keyhold Worker Provisioning Outbound INT2031 Keyhold Deprovisioning Outbound |
| ISU_EXPENSE_SYNC | Unknown | No | 2 | INT2050 Ledgerly Expense Outbound INT2051 Ledgerly Cost Centre Inbound |
| ISU_TIME_CLOCK | Unknown | No | 2 | INT2090 Shiftline Time Clock Inbound INT2091 Shiftline Schedule Outbound |
Certificate inventory
21 certificates, grouped by stateExpired
- Paycrest_PGP_Key_2024412 days ago
- Vetterly_x509_Legacy203 days ago
- INT2012_Halewood_PGPKey_OLD58 days ago
Expiring inside 60 days
- SAMLCert_Prod_90421178305149 d
- Keyhold_SAML_Signing17 d
- Cavendish_Retirement_PGPKey23 d
- Halewood_Settlement_Lockbox31 d
- Everline_Benefits_PGPKey44 d
- Ledgerly_Expense_x50952 d
- Sourcewise_Supplier_PGPKey58 d
No expiry date held by Workday
- PGP key-Halewood SettlementUnknown
- Vendor PGP Public Key (Everline)Unknown
- Vendor PGP Public Key (Cavendish)Unknown
- Legacy Key Pair (no metadata)Unknown
What Lapsed does not claim
Lapsed maps accounts to integrations, because that is the relationship Workday actually exposes. It does not tell you which integrations use a given certificate: Workday holds no such link, and any tool that draws one is guessing. Certificates are tracked as their own inventory, with real dates where Workday has them and a plain unknown where it does not.
Five states, and one of them is honesty.
Everything Lapsed shows you resolves to one of these. Four are facts. The fifth is an admission, and it is the one worth reading twice.
expired
The date has already passed. The certificate is dead or the account password has lapsed. This is not a warning, it is a report of something that has happened.
expiring
Inside the threshold you set. At 60 days that includes the four certificates Workday's 30 day email would never have mentioned.
ok
A real date exists and it is beyond your threshold. Nothing to do today, and Lapsed will move it as the date approaches.
not applicable
The account is exempt from password expiration, so there is no date to know. Fine by design, worth reviewing on purpose.
unknown
Workday genuinely does not report it: a certificate with no expiry date set, or an account whose next rotation date Workday never exposes. Not an error, and never safe. Verify this one manually.
Find out what is already expired.
The first audit takes three read-only reports and about an hour of setup. Most tenants turn up something nobody knew about.