AI for CFOs · Independent decision intelligenceSource-backed reporting · No paid editorial rankings
CFO AI Ledger

An independent finance-leadership publication that examines where AI changes planning, close, cash, control, disclosure, and capital decisions—and what evidence a CFO must require before relying on it.

CFO briefings

Workday audit-agent access needs two-layer approval

Workday’s Financial Audit Agent guide says administrators assign access to each agent skill through an Available To security group and that runtime also checks the user’s access to the APIs used as tools. For a CFO, activation is therefore an audit-data authorization decision, not merely a feature switch. Approve the precise sample-retrieval purpose, authorized roles, underlying finance permissions, evidence custody, and revocation test before an agent handles audit requests.

Answer capsule

Workday’s Financial Audit Agent guide says administrators assign access to each agent skill through an Available To security group and that runtime also checks the user’s access to the APIs used as tools. For a CFO, activation is therefore an audit-data authorization decision, not merely a feature switch. Approve the precise sample-retrieval purpose, authorized roles, underlying finance permissions, evidence custody, and revocation test before an agent handles audit requests.

What the source establishes

  • Workday says the Financial Audit Agent can identify and retrieve audit samples for audit requests.
  • The guide states that a Workday-built agent requires a UMSA subscription agreement for non-production and production tenants; organizations on an MSA must opt in to UMSA.
  • Administrators populate Available To security groups separately for each enabled skill, and Workday checks both agent access and tool API access at runtime.
  • The guide points administrators to a View Security for Agent Skill report and describes registration, configuration, activation, deactivation, and reactivation.

Approve the audit question before activating a skill

Name the audit request, legal entity, ledger or subledger, period, population, sampling purpose, requester, data owner, and reviewer. Decide whether the agent may locate candidate samples, retrieve records, draft a support package, or transmit anything outside finance. Those are different authorities. The Workday guide describes a capability to identify and retrieve samples; it does not say a generated selection satisfies an auditor’s sampling method, evidence standard, or independence requirement. Preserve the original request and the exact population definition so a reviewer can reproduce why these records were returned. If the request concerns restricted payroll, supplier, customer, or transaction data, document the narrower access decision and the approved channel for sharing.

Reconcile skill groups with underlying finance permissions

Create two maps for every enabled skill: who can interact with the agent, and which records and API operations those people can reach through its tools. Workday explicitly describes both checks, but it leaves each buyer’s group membership and security policy to configuration. Test allowed and denied users, changed roles, terminated accounts, delegated access, cross-entity records, closed periods, and an audit request that asks for more than the user can see in the ordinary interface. Record the agent, skill, tool, role, security group, source domain, test result, and owner. A successful prompt is not evidence that the access design is correct; a denied prompt is not proof every indirect path is closed.

Keep sample evidence separate from the accounting conclusion

For a representative request, retain the population extract or reproducible query, selection rule, sample IDs, source-system links, retrieval time, financial period, record version, exceptions, human reviewer, and any evidence package delivered to an auditor. Compare returned records with the underlying ledger and approved audit request. Test missing attachments, reversals, amended transactions, duplicate IDs, entity changes, inaccessible documents, and mismatches between display and export. Decide who can redact personal or commercially sensitive material and who certifies completeness. The agent may reduce retrieval effort, but the controller and audit team still own accuracy, scope, confidentiality, and any conclusion drawn from the sample.

Release through a bounded finance control

Start in a non-production tenant only after confirming the applicable agreement, Agent System of Record setup, relevant domains, and expected credit treatment. Use synthetic or approved non-sensitive cases first, then a small real population with a named reviewer. Record configuration, group membership, tool permissions, test cases, accepted and rejected outputs, reviewer time, corrections, and total operating cost. Define who can activate, suspend, and reactivate the agent; rehearse a permissions change and a deactivation while an audit request is open. Move to a wider use only after the evidence package can be reconstructed and unauthorized requests are consistently denied. Reopen approval when a skill, API, agreement, group, finance process, source system, or audit requirement changes.

Turn this source into a reviewable decision

For AI for CFOs, use this briefing as a dated decision record rather than a substitute for the source. Preserve Workday Administrator Guide: Set Up Financial Audit Agent, the exact URL, the September 21, 2026 review date, the supported facts above, the editorial interpretation, the limitations, and any buyer-specific evidence. Link that record to the decisions most directly affected: Internal control and audit evidence; Close, reconciliation, and variance investigation; Management reporting and external disclosure support; Finance policy and self-service. State whether the source changes the scope, evidence requirement, control, sequence, or only the language used to describe the decision.

Before action, name the accountable owner, affected population and workflow, exact offering or configuration, source data and rights, human decision point, exception and appeal path, complete cost, expected benefit, failure and stop conditions, retained evidence, and next review date. Keep official facts, provider statements, buyer observations, representative tests, measured outcomes, editorial inferences, and unknowns visibly separate. Reopen the record when the source, offer, model, integration, data, policy, population, responsible person, or measured result changes.

Limitations and unknowns

Workday is the product and documentation source. Its undated current guide, reviewed September 21, 2026, establishes stated setup and runtime checks; it does not prove a buyer’s subscription status, tenant configuration, actual API permissions, audit population, sampling validity, control effectiveness, complete logging, data security, fees, or accounting and audit outcome. Current agreements, tenant reports, finance records, test evidence, and qualified finance, audit, security, privacy, procurement, and legal review control. No attributable post-cutoff change is established.

Decision test

Ask whether the source changes the decision itself, the evidence required, the implementation sequence, or only the language used to describe an existing capability. Record which claims are directly supported, which are provider statements, which require an independent test, and which remain unknown. A source-linked review should make uncertainty easier to see, not bury it inside a blended score.

Questions to take into review

  • Is the AI itself in scope for change and access controls?
  • Can evidence provenance survive export and retention?
  • What evidence links a suggestion to the subledger and general ledger?
  • Who can accept a proposed match or explanation?
  • Which source supports each number and assertion?
  • How is materiality assessed outside the model?
  • Which documents are authoritative and effective today?
  • What topics always require a person?
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.