Workhuman Security and Privacy Baseline
Overview
Map customer and Workhuman responsibilities and enforce least privilege, data minimization, financial integrity, and evidence-based incident controls.
Prerequisites
- Tenant products, integrations, data flows, environments, owners, and current agreements
- Workforce-data classification, retention, residency, legal, and incident requirements
- Identity, HCM, payroll, recognition, security, privacy, and vendor contacts
Tool Discipline
Use Read, Glob, and Grep to inspect configurations and flows, WebFetch to verify current first-party commitments, and Write or Edit for threat models, control matrices, and redacted evidence.
Current Contract
Workhuman publicly states support for SSO, fraud detection, granular user privileges and grouping, encryption and monitoring practices, GDPR and CCPA compliance, ISO 27001:2022 and ISO 27701:2019 certification, and defined PCI scope. Confirm scope and customer obligations in current agreements rather than treating marketing statements as the entire control contract.
Authentication
Separate human SSO, administrator roles, managed connectors, and API principals. Enforce least privilege, tenant isolation, rotation, revocation, break-glass controls, and non-exportable secrets.
Instructions
- Diagram identity, worker, recognition, award, redemption, payment-adjacent, reporting, and integration data flows.
- Classify fields and define purpose, authority, access, retention, residency, export, deletion, and incident ownership.
- Review SSO, lifecycle, privileges, groups, delegates, separation of duties, dormant access, and emergency access.
- Threat-model spoofing, cross-tenant access, unsafe messages, approval bypass, award manipulation, fraud, replay, and data exfiltration.
- Verify encryption, secret storage, egress allowlists, audit evidence, anomaly detection, and redacted observability at each customer-controlled boundary.
- Reconcile program spend and sensitive administrative actions with independent evidence and named approvers.
- Test access removal, credential rotation, rejected inputs, duplicate writes, incident containment, and recovery with synthetic fixtures.
- Present gaps with owner, severity, compensating control, due date, verification, and rollback before changing production.
Approval Boundaries
Do not alter SSO, roles, groups, retention, exports, fraud controls, integrations, or financial workflows without security, privacy, and business-owner approval.
Output
Return the responsibility and data-flow maps, access review, threat model, control evidence, gaps, approved changes, test receipts, and residual risks.
Error Handling
| Condition | Response |
|---|---|
| Agreement scope is unavailable | Mark controls unverified and request the current customer documents. |
| Cross-tenant or financial-integrity risk appears | Stop affected processing and activate the approved incident path. |
| Required data has no owner or retention rule | Block the flow until governance is assigned. |
Example
A redacted completion receipt might look like this:
tenant=customer-prod; flows=7; principals=4; high-gaps=0; rotation=tested; spend-reconciliation=exact; residual-risk=accepted
Resources
Next Steps
Schedule access, data-flow, contract-scope, and recovery reviews on the customer's governance cadence.