Capabilities
Specifically, the connector syncs Clock Device Groups, Document Security Groups, and Pay Adjust Groups.
The Dayforce connector supports automatic account provisioning by hiring a new employee, and grants and revokes security-role assignments on existing employees.
This connector does not support account deprovisioning. Dayforce employee records are persistent, so C1 disables access by revoking role grants rather than deleting accounts.
Same-day role revokes take effect at end of day. Dayforce ends a role assignment at 23:59 of the day it was granted, so revoking a role on the same day it was granted leaves it active until midnight. The role appears as granted in C1 until the first sync after midnight. For immediate access cut-off, disable the user in the Dayforce IAM admin UI.
Gather Dayforce credentials
Configuring the connector requires you to pass in credentials for Dayforce. Gather these credentials before you move on. Here’s the set of credentials you’ll need when setting up the connector:- Username and password for your account or for a service account
- Dayforce tenant URL
- Dayforce client namespace
Permissions required for the Dayforce account
Set the following roles and permissions on the account or service account you use for the integration:1
Navigate to System Admin > Roles.
2
On the Features tab, enable the Read Data subfeature under HCM Anywhere > Web Services.
3
On the Web Services Field-Level Access tab, enable XRefCode (and relevant child nodes for Employee) under RESTful Services > Human Resources > Employee.
4
On the Authorizations tab, set the following:
- Can Read for Employee Status Information
- Can Read for Employee Contact Information - Personal and/or Employee Contact Information - Business
- Can Read for Employee Profile - Security Settings - Roles
- Can Read for Employee Profile - Security Settings - User Document Security
- Can Read for Employee Profile - Security Settings - Pay Code Groups
5
Permissions for provisioning: To use account provisioning (hire new employees) and role provisioning (grant/revoke security roles), also enable:
- Can Add and Can Edit for New Hire / Employee records
- Can Edit for Employee Profile - Security Settings - Roles
6
Finally, set location access for the user:
- Navigate to System Admin > User and select the user.
- Click Location Access > Add Location and select the appropriate location.
Configure the Dayforce connector
- Cloud-hosted
- Self-hosted
Follow these instructions to use a built-in, no-code connector hosted by C1.Done. Your Dayforce connector is now pulling access data into C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Dayforce and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
In the Username and Password fields, enter your Dayforce credentials, or those for a service account you’ve created for this integration.
9
Use the Environment dropdown to select the correct environment: Production, Testing, or Configuration.
10
Enter the full URL of your Dayforce tenant in the Dayforce URL field.
11
Enter the Dayforce client namespace in the Client Namespace field.
12
Click Save.
13
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.