Microsoft Copilot security directory
Workday HCM
Published by Microsoft
Medium risk
Workday HCM contains operations that expose Workday Human Capital Management Business Services data, including Employee, Contingent Worker and Organization information.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 10 tools or capabilities.
- Add or Update Address Information
- Add or Update Email Address Information
- Add or Update Instant Messenger Information
- Add or Update Phone Information
- Add or Update Web Address Information
- Get Employee Employment Info
- Get Employee Identity Info
- Get Employee Personal Info
- Get Employee Qualification Info
- SOAP Operation
The interactive security report will load automatically.