This is a complete guide for setting up your Stablecoin Payroll in Workday.
Toku Integration Setup
These steps are required to establish the initial connection to Toku
**1. Create Integrated System User and Integrated System Security Group**
Create your Integrated System User and Integrated System Security Group
- Create an integrated system user by searching for “Create Integrated System User” task in the search box

- Set an appropriate username and password to create the account (To be shared with us)

- Create a security group of type “Integration System Security Group (Unconstrained)” by searching for “Create security group” task

- On the next page about security group details, add “TOKU_USER” in the Integrated System Users field

- After creating the group, click on “Maintain Domain Permissions for Security Group”

- On the “Maintain Domain Permissions” page, add the following permissions along with any other permissions needed for the custom report generation in the following steps

- Final step - After creating and setting up the security group, search for “Activate Pending Security Policy Changes” task and confirm the changes.

**2. Create RAAS Reports (contains example of RAAS report for employee sync)**
Creating Custom Reports with RAAS enabled
Follow the steps below to create RAAS reports within Workday. This will enable you to push the required information needed to onboard employees onto the platform.
- Search for the “Create Custom Report” task and fill in the details as below. Ensure that the report type is “Advanced” and the “Enable as Web Service” is checked. Select the appropriate data source

- Provide report name as: “TOKU_EMPLOYEE_DEMOGRAPHICS”

- Finally, choose the Data source as “All Active and Terminated Workers” and click on “OK”

- You will be greeted with a screen (shared below) and now you can setup the fields in the custom report from the fields table

- Complete fields list 1. Field list needed

1. Table of fields needed. Required fields are marked with a *.
| Field | Column Heading Override (XML Alias) |
|---|---|
| Employee ID* | employeeID |
| Email - Work* | |
| Compensation Range - Currency* | currency |
| All Home Addresses - Full with Country* | address |
| Total Pay Annualized - Amount* | totalSalary |
| Pay Group - Country* | country |
| Full Legal Name* | fullName |
| Cost Center - Name | department |
| Position ID* | positionID |
| Active Status with Date* | status |
| Terminated* | terminated |
| Worker Active* | worker_active |
| Total Pay - Frequency* | freq |
| Pay Group | payGroup |
- Click on “OK”, once all the fields are added
- Add your integrated system user to the Authorized Users of the Share section (For eg. if your integrated system user is TOKU_USER)
Note the “Report Owned by” field here, which will be required to be added when we add the credentials on the Toku platform here - RAAS Report owner . For the following screenshot, it is
nwilliams.

- Your custom report is ready!

**3. Setup credentials on the Toku Platform**
Add your information to your Toku Account Navigate to the credentials setup on the Toku platform using - Add credentials to Toku
From step 1.3 , grab the username and password of the integrated system user that was created -
UsernamePasswordSearch for “View API Clients”

In the “View API Clients” find the tenant id (blue) and the Tenant endpoint URL (red) .
Note - For Tenant endpoint URL , you just need to enter the part after the https:// and before the /ccx./….

Tenant IDTenant endpoint URL
From step 2.7 , grab the Report Owned by field for -
RAAS Report owner
Sample Data:

💡 If Workday is your source of truth for employee sync only, your setup is now complete. Some organizations use Workday to sync employee data but rely on a different provider for payroll. If this describes your setup, you're done here.
If Workday also handles your payroll data, continue with the steps below.
**4. SOAP API Setup (Post Data)**
Create a new integrated system user and a new security group
Create a new integrated system user - search for “Create integrated system user”

Choose a username and password (To be shared with us for the SOAP setup by the client)


Create a Security group - search “Create security group”

Select “Integration system security group (unconstrained)

Choose any name for your Security group and click on “OK”

Assign your integrated system user to this security group and click on “OK”

Add all required policies to the created Security group and integrated system user for automated deductions
Search for “View security group”

Choose your group and click on “OK”

Click on the 3 dots and go to security group option

A) We need to add two types of policies:
- Domain Security Policies permitting Modify access
- Reports: Payroll Input
- Worker Data: Payroll (Payroll Input Workbooks)
- Worker Data: Payroll Interface (Payroll Input by Batch ID)
- Worker Data: Payroll Public API (Payroll Input)

- Domain Security Policies permitting Put access
- Audit: Payroll Interface
- Custom Report Creation
- Integration Event
- Integration Process
- Payroll Interface
- Reports: Payroll Input
- Set Up: Payroll
- Set Up: Payroll (Calculations - Payroll Specific)
- Set Up: Payroll Interface
- Set Up: Payroll Interface (Update Pay Period Status)
- Worker Data: Compensation
- Worker Data: Payees
- Worker Data: Payroll
- Worker Data: Payroll (Payroll Input Workbooks)
- Worker Data: Payroll Interface
- Worker Data: Payroll Interface (Additional Payroll Data)
- Worker Data: Payroll Interface (Payroll Input by Batch ID)
- Worker Data: Payroll Public API (Payroll Input)
- Worklet: Payroll

B) We need to add the group to the business process of “Payroll Interface Data”


You’ll be greeted with this screen:

Scroll to Business process > Add your security group > Click on “OK”

C) Go to “Manage authentication policies”

Add authentication rule for your Security group:

D) Add Import payroll input wsdl service to your integrated system user and click on “Save”


E) Activate all your policies

Add your comment and click on “OK”

Setup is done!
One-Time Set Up
These steps are required to ensure the Stablecoin Deduction is properly configured in Workday and to have a manual way to post deductions as a failsafe.
**5. How to create a Stablecoin Deduction**



**6. How to create an EIB to import deductions manually**







**7. How to add your deduction to a run category**





Note: Add your deduction codes to the “Deductions” under Subtract from pay accumulation section
Reoccurring Payroll Process (No SOAP API setup)
These EIB steps are only needed when manually posting deductions. Running payroll calculation is required for both manually posting and automatic posting of deductions.
**8. Export Your Deductions**



Your export will look something like this. Save for later!
**9. Launch your EIB**







Add your deduction export from Toku



You can hit refresh until the “Status” changes to “Complete”
**10. Run Pay Calculation***

Select the pay period matching the Toku payroll you exported your deductions from

Verification: Go to the worker > Pay > Input

Automated deductions (SOAP API setup required)
These steps are required to post deductions from the Toku platform to workday (via API and not the manual way)
**11. Update workday integration setup on our platform**
Use the SOAP username and SOAP password created on this step

Post deductions from the platform

Success message

You will need to trigger “Run Pay Calculation” explicitly from workday as a final step
CONFIDENTIALITY NOTICE: resource and any attachments are only for the use of the intended recipient and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient, any disclosure, distribution or other use of this resource or attachments is prohibited. If you have received this resource in error, please delete and notify the sender immediately. Thank you.
