Book a walkthrough
Workday tenant audit

A service account lapses tonight. Lapsed already knows which integrations stop.

Lapsed reads three read-only reports out of your own Workday tenant and maps every integration system to the account it runs as. When an account's password lapses, you get the integrations that go down with it, by name, before anyone raises a ticket.

Read only. Certificates, non-human accounts and integration system owners. No worker records, no payroll, no personal data.

Northwind Logistics Last audit today
ISU_PAYROLL_OUT Unknown
Password expiresNot reported
Exempt from expiryNo
Already expiredNo
5integrations stop if this account lapses
  • INT2001 Paycrest Payroll Outbound
  • INT2002 Paycrest Quarterly Tax Outbound
  • INT2003 Paycrest Periodic Tax Outbound
  • INT2004 GL Journal Export
  • INT2005 Payroll Costing Allocation Outbound

Exposure map

Every integration system matched to the Workday account it runs as. 23 systems across 216 non-human accounts.

Certificate inventory

All 21 certificates with days remaining, including the 4 that Workday holds no expiry date for at all.

Your own threshold

Workday is fixed at 30, 15 and 7 days. Set yours to 90, 60 or 45 and get the list that far ahead.

Honest unknowns

Where Workday reports nothing, Lapsed says so and tells you to verify by hand. It never invents a countdown to fill the gap.

Why the emails are not enough

Workday warns you at 30 days, and you cannot move the line.

One email at 30 days, one at 15, one at 7. No report, no list, no dashboard, and no setting that widens the window.

Those three emails are the whole of Workday's built-in certificate warning. There is nowhere in the tenant to see what is expiring next month, nowhere to see what expired last month, and no way to ask for more notice.

They also only send if someone switched them on. The tenant setting that enables them is the same one that sends security notices to every user in the tenant, so plenty of customers turn it off deliberately and never think about it again.

Meanwhile a service account password lapsing sends nothing at all, and Workday does not report the date the next rotation falls due.

The setting in question is Enable Security Emails in tenant setup. On, and every user gets security notices. Off, and nobody gets the certificate warning either. There is no middle position.
Certificates expiring in Northwind Logistics 7 certificates, days remaining
Workday will email you No Workday email at any point
Workday's 30 day limit
SAMLCert_Prod_90421178305149 days
Keyhold_SAML_Signing17 days
Cavendish_Retirement_PGPKey23 days
Halewood_Settlement_Lockbox31 days
Everline_Benefits_PGPKey44 days
Ledgerly_Expense_x50952 days
Sourcewise_Supplier_PGPKey58 days
0 15 30 45 60
Four of those seven fall at 31, 44, 52 and 58 days. Every one of them sits past the 30 day limit, so on the day Lapsed found them, nobody at Northwind had been emailed about a single one. There is no tenant setting that would have changed that. A 60 day threshold in Lapsed catches all four on the first run.

Inside the product

What the audit actually looks like.

The real components from the Lapsed dashboard, filled with sample data from a fictional tenant.

Tenant audit northwind_logistics / prod
6
Integration accounts that will expire
on a date Workday does not report
17
Integrations that stop when they do
named, not estimated
216
Non-human accounts in the tenant
integration and system users
23
Integration systems
mapped to their accounts
21
Certificates tracked
3 expired / 7 in 60 days / 4 unknown

Integration exposure by account

Sorted by blast radius
Account Password state Exempt Stops Integrations taken down
ISU_PAYROLL_OUT Unknown No 5 INT2001 Paycrest Payroll Outbound
INT2002 Paycrest Quarterly Tax Outbound
INT2003 Paycrest Periodic Tax Outbound
INT2004 GL Journal Export
INT2005 Payroll Costing Allocation Outbound
ISU_BANK_SETTLE Unknown No 3 INT2010 Halewood Bank Settlement Outbound
INT2011 Halewood Positive Pay
INT2012 Halewood Statement Reconciliation Inbound
ISU_BENEFITS_OUT Unknown No 3 INT2020 Everline Medical and Dental Outbound
INT2021 Cavendish Retirement Contributions Outbound
INT2022 Everline Life and Disability Outbound
ISU_IDENTITY_SYNC Unknown No 2 INT2030 Keyhold Worker Provisioning Outbound
INT2031 Keyhold Deprovisioning Outbound
ISU_EXPENSE_SYNC Unknown No 2 INT2050 Ledgerly Expense Outbound
INT2051 Ledgerly Cost Centre Inbound
ISU_TIME_CLOCK Unknown No 2 INT2090 Shiftline Time Clock Inbound
INT2091 Shiftline Schedule Outbound
6 accounts that are not exempt from password expiration, carrying 17 integrations between them. Password state reads Unknown because Workday reports no next rotation date.

Certificate inventory

21 certificates, grouped by state

Expired

  • Paycrest_PGP_Key_2024412 days ago
  • Vetterly_x509_Legacy203 days ago
  • INT2012_Halewood_PGPKey_OLD58 days ago

Expiring inside 60 days

  • SAMLCert_Prod_90421178305149 d
  • Keyhold_SAML_Signing17 d
  • Cavendish_Retirement_PGPKey23 d
  • Halewood_Settlement_Lockbox31 d
  • Everline_Benefits_PGPKey44 d
  • Ledgerly_Expense_x50952 d
  • Sourcewise_Supplier_PGPKey58 d

No expiry date held by Workday

  • PGP key-Halewood SettlementUnknown
  • Vendor PGP Public Key (Everline)Unknown
  • Vendor PGP Public Key (Cavendish)Unknown
  • Legacy Key Pair (no metadata)Unknown

What Lapsed does not claim

Lapsed maps accounts to integrations, because that is the relationship Workday actually exposes. It does not tell you which integrations use a given certificate: Workday holds no such link, and any tool that draws one is guessing. Certificates are tracked as their own inventory, with real dates where Workday has them and a plain unknown where it does not.


The five states

Five states, and one of them is honesty.

Everything Lapsed shows you resolves to one of these. Four are facts. The fifth is an admission, and it is the one worth reading twice.

expired

The date has already passed. The certificate is dead or the account password has lapsed. This is not a warning, it is a report of something that has happened.

expiring

Inside the threshold you set. At 60 days that includes the four certificates Workday's 30 day email would never have mentioned.

ok

A real date exists and it is beyond your threshold. Nothing to do today, and Lapsed will move it as the date approaches.

not applicable

The account is exempt from password expiration, so there is no date to know. Fine by design, worth reviewing on purpose.

unknown

Workday genuinely does not report it: a certificate with no expiry date set, or an account whose next rotation date Workday never exposes. Not an error, and never safe. Verify this one manually.

Find out what is already expired.

The first audit takes three read-only reports and about an hour of setup. Most tenants turn up something nobody knew about.