Agent Operating Guide
/bridge-workday-provision
Provision and deprovision Canvas users from Workday, turning HR joins, transfers, and leaves into proposed user and role changes for an admin to approve.
Turn Workday HR events into Canvas user changes. When an employee joins, transfers, or leaves, the skill detects the event and proposes the matching Canvas change, a new user with default roles, a role and team reassignment, or a deactivation, as a suggestion via suggest_change. Even provisioning goes through approval, so an admin sees the batch before anything is written to your tenant.
When to use
Section titled “When to use”When you want the Canvas user roster and role assignments to track Workday without manual onboarding and offboarding. Run it on a schedule once HR events are flowing so the roster stays current.
Inputs
Section titled “Inputs”| Flag | Required | Notes |
|---|---|---|
--since <ISO> |
No | Sync HR events since this timestamp. Defaults to the last sync. |
--dry-run |
No | Report the event counts and ask before submitting anything. |
Example
Section titled “Example”/bridge-workday-provision --since 2026-07-01 queries Workday for HR events
since that date. For each it builds the Canvas action, a new hire becomes a
user with the department’s default roles, a transfer updates team and role
assignments, a termination marks the user inactive and removes their
assignments, and submits them as one suggest_change batch for an admin to
approve. With --dry-run it reports the counts and asks first.
Good to know
Section titled “Good to know”- Terminations are never auto-approved: the batch is drafted for an admin to review, which catches HR-feed lags and false positives before anyone loses access.
- Transfers and terminations reuse /coach-bulk-user-change to reassign or remove the subject’s existing item assignments.
- Check when the Workday bridge last ran with /bridge-sync-status.
Related
Section titled “Related”- /coach-bulk-user-change: the bulk reassign/remove used for transfers and terminations.
- /bridge-sync-status: last-sync time and health for the Workday bridge.
- Permissions: the roles and assignments provisioning writes.
- Builds on suggest_change: every user change is proposed here.