Files
pre-repos/workday_monthly_admin_activities_audit/event_logs.txt
2026-02-04 13:18:15 -05:00

129 lines
39 KiB
Plaintext
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
=== Dennis Cregan ===
[EVT-0001] - On January6,2026 at 6:51AM EST, Workday administrator DennisCregan edited the user account for CaseySpelman. He changed Caseys account expiration date to January6,2026 and configured a large number of usernotification settings for Casey. The new settings enabled email and mobile push notifications for dozens of Workday event categories (e.g., Academic Advising, Accounting Center Job Process, Birthdays, Benefits Notifications, Time Off, etc.). The transaction was completed successfully as part of the “Edit Workday Account” workflow. No other changes were recorded.
[EVT-0002] - On January6,2026 at 9:40AM EST, Workday administrator **Dennis Cregan** edited the record for student **DNUEvaDNUSilvaEwan**. He changed the students **Universal ID** from the old value **“1115670”** to the new value **“DNU1115670.”** The edit was performed as part of an “Edit Universal Id” transaction. No other attributes were altered, and no relationships were removed; the only additions recorded were the new Universal ID value and the transaction label. The action was logged under eventIDEVT0002.
[EVT-0003] - DennisCregan (user 1000054) launched a background job called **“Student Prospect Update Event (Default Definition)”** on January7,2026 at 07:43AM EST. The job was started by the **Integration Administrator** and ran as a batch process that matched student records. During this run, the system added two new **Custom Identifier References** to the prospect record for **FolusoAdeluola**: 1. **PSID** a new internal student ID. 2. **SlateID** an external system identifier. These identifiers were added to the record under the “Custom Identifier Reference.for Custom Identifier” relationship. The job also removed the previous set of identifiers (0306632, 495870520, and 647589765) that had been associated with the prospect. No other userinitiated changes were made; the entire update was performed automatically by the integration process.
[EVT-0004] - On January7,2026 at 07:44AM EST, Workday administrator **Dennis Cregan** (user ID1000054) performed an “Edit Other IDs” transaction for the student **Kyra Dinkins**. During this edit, a new custom identifier reference was added to Kyras record: **CUSTOM_IDENTIFIER_REFERENCE319695**. The log shows that the previous custom identifier reference (CUSTOM_IDENTIFIER_REFERENCE35003) was removed. The transaction also added the students **PSID** (Personal Student ID) to her list of identifiers and removed an earlier “Reconciled” status from the record. The change was part of a background process launch for the “Student Prospect Update Event” batch job that runs student prospect updates. The event was logged as EVT0004 and involved 86 rows of data being processed.
[EVT-0005] - On January7,2026 at 8:08AM EST, Workday administrator Dennis Cregan edited the universal ID for employee SarahLittle. He changed her Student Universal ID from **1117191** to **1117192**, and updated the corresponding entry moment timestamp. The edit was recorded as an “Edit Universal Id” transaction applied to SarahLittle, and the change was logged under event ID EVT0005. No other attributes were modified or removed during this transaction.
[EVT-0006] - On January7,2026 at 8:09AM EST, Workday administrator Dennis Cregan edited the Student ID for Sarah Little. The system changed her Student ID from1117191 to1117192 and updated the associated entry moment timestamp. The edit was recorded as part of the “Edit Student ID” transaction and applied to Sarah Littles record in the ASLConnect program. The change was logged under event IDEVT0006 and involved no attachments or removals.
[EVT-0007] - On January7,2026 at 8:09AM EST, Workday administrator Dennis Cregan (user ID1000054) edited the Workday account for employee Sarah Little. The edit created a new usernotification configuration (new value1117192) that added 21 notification settings for Sarah Little. These settings enabled both email and mobilepush notifications for a wide range of Workday events—including academic advising, accounting center jobs, activity comments, benefits notifications, birthdays, bonus and compensation reviews, businessprocess general alerts, inventory updates, learning campaigns, onboarding plans, open enrollment for benefits, timeoff requests, and many others. The change was part of the “Edit Workday Account” transaction and was successfully completed by Dennis Cregan.
[EVT-0008] - DennisCregan edited the security segment for two integration systems in Workday. On January7,2026 at 1:03PM EST he applied the “Edit Integration System Security Segment” action to the integration systems named **ISSS Financial Aid Integrations**, **SINT100 Slate Financial Aid Packages Outbound**, and **SINT100b Slate Financial Aid Packages FSFSA Outbound**. The change was recorded in the audit log under eventEVT0008, showing that the integration system security segment was updated for those three integrations.
[EVT-0009] - On January8,2026 at 3:25PM EST, Dennis Cregan created a new universal identifier for the employee Phillip Hight. The system generated the ID “1117202” and recorded it as Phillip Hights Student Universal ID. The action was performed through the “Create Universal Id” transaction, and the new identifier was added to Phillip Hights record. No previous value existed for this field, and no relationships were removed. The event was logged as EVT0009 with seven audit rows capturing the details of the creation.
[EVT-0010] - On January8,2026 at 3:26PM EST, Workday administrator DennisCregan edited the account for employee PhillipHight. He changed Phillips Workday user ID to **1117202** and set the account creation date to midnight on that day. During the same transaction, Dennis configured a large number of usernotification settings for Phillip, adding email and mobile push notifications for dozens of Workday categories (e.g., Gigs, Academic Advising, Accounting Center Job Process, Birthdays, Benefits, TimeOff, etc.). The transaction was completed successfully and logged as “Edit Workday Account.”
[EVT-0011] - On January8,2026 at 3:26PM EST, Workday administrator Dennis Cregan edited the Student ID for Phillip Hight. The system replaced Phillips temporary student identifier “TEMP_STUDENT_0002670” with the new ID “1117202”. The change was made as part of an “Edit Student ID” transaction that updated the students financial period record and entry moment. The audit shows Dennis Cregan as the user who performed the edit, affecting Phillip Hights record.
[EVT-0012] - On January8,2026 at 3:47PM EST, user DennisCregan (ID1000054) performed an “Edit Permissions” transaction in Workday. He removed the SelfService: Dining Dollar (diningDollar_wspzsl) permission from the “Student as Self” role and removed the associated “View Only” and “View Only for SelfService: Dining Dollar (diningDollar_wspzsl)” permissions. He then added the “Edit Permissions” permission to that same SelfService role, effectively granting students the ability to edit their Dining Dollar account. The change was applied to the “Student as Self” security group, and the transaction updated several domainsecurity policy relationships accordingly. The event was logged as EVT0012 and recorded 7 related relationship changes.
[EVT-0013] - On January8,2026 at 12:47PM (Pacific Time), Workday administrator **Dennis Cregan** approved a pending securitypolicy change. The approval activated the “Activate Pending Security Policy Changes” transaction, which in turn published a new security timestamp for the **SelfService: Dining Dollar (diningDollar_wspzsl)** domain. As part of this change, the **StudentasSelf** security group was removed from that domain, temporarily revoking students access to the Dining Dollar application until the new version is promoted to production (change requestCHG0037158). The transaction also updated the tenants security timestamps and recorded the approval action in the audit log.
[EVT-0014] - On January8,2026 at 4:00PM (EST) DennisCregan activated a pending securitypolicy change. The action removed the “Student as Self” security group from the **SelfService: Dining Dollar (diningDollar_wspzsl)** domain, effectively revoking students access to the Dining Dollar application until a new version is promoted to production (CHG0037158). The change was processed under the “Activate Pending Security Policy Changes” transaction and logged as a securitytimestamp event for the tenant. The removal was recorded at 12:46PM, and the activation took place at 12:59PM. No other users or objects were affected.
[EVT-0015] - On January9,2026 at 12:48PM EST, Workday administrator Dennis Cregan created a new Universal Identifier for the student “Jr.Kang.” The system recorded that the person now has a Universal Identifier (Person.has Universal Identifier) and linked this identifier to the students record in the “Kang” instance. The new Universal ID value was **1117211**, and it was added to the students profile under “Universal Identifier.for Person.” The transaction, labeled **Create Universal Id**, was executed as part of the “Create Universal Id” task behavior. No values were removed, and the change was logged under event IDEVT0015 with a total of 28 rows affected.
[EVT-0016] - On January9,2026 at 12:49PM EST, Workday administrator DennisCregan edited the account of user Jr.Kang (user ID1117211). During that edit, Dennis configured a large number of notification preferences for Jr.Kang, enabling both email and mobilepush notifications for dozens of Workday event categories (such as “Gigs,” “Academic Advising,” “Accounting Center Job Process,” “Benefits Notifications,” “Time Off,” “Workbook Access Additions,” etc.). The changes were made as part of the “Edit Workday Account” transaction and were recorded under event IDEVT0016. No notifications were removed; only new notification settings were added for Jr.Kangs account.
[EVT-0017] - On January9,2026 at 12:49PM EST, Workday administrator **Dennis Cregan** performed an “Edit Student ID” transaction for the student **Jr.Kang** (applying to “Kang”). The system changed Jr.Kangs student identifier from the temporary value **TEMP_STUDENT_0002621** to the new permanent ID **1117211**. The audit records show that this edit was recorded in the “Student ID” attribute and that the transaction was logged under eventEVT0017. No other attributes were altered, and no attachments or removals occurred during this action.
[EVT-0018] - On January16,2026 at 5:40AM EST, Workday administrator DennisCregan edited the user account for DaleShepard. During that transaction, he added a large set of notification preferences to Dales account—configuring email and mobilepush alerts for dozens of Workday events (such as “Anniversaries,” “Benefits Notifications,” “Time Off,” “Student Records,” etc.). The changes were recorded under the “Edit Workday Account” workflow and completed successfully. No items were removed; only new notification settings were added to Dales profile.
[EVT-0019] - On January17,2026 at 6:18AM EST (UTC08:00), Dennis Cregan added the “Edit Permissions” permission to the SelfService role **Dining Dollar (diningDollar_wspzsl)** for the user group **Student as Self**. This change granted students who are acting on their own account the ability to edit permissions for the Dining Dollar selfservice application, while also giving them viewonly access to that same application. The action was recorded as an “Edit Permissions” transaction in the Workday audit log.
[EVT-0020] - Dennis Cregan updated the “ISSG Dining Dollar Extend” security group on January17,2026 at 6:19AM EST. He added several permissions to the group: * Granted the “View Only” permission for the “Reports: Student Financial Account” report. * Added the “Maintain Permissions for Security Group” task behavior to the group, allowing it to manage other security groups. * Assigned the “View Only for Reports: Student Financial Account” permission, giving readonly access to that specific report. These changes were recorded under the event IDEVT-0020 and involved updating domain security policy permissions for the group. No items were removed, and no attachments were added.
[EVT-0021] - On January17,2026 at 6:21AM EST, Workday administrator Dennis Cregan activated pending security policy changes for the Gallaudet tenant. The activation added two new domainlevel permissions: 1. **Reports: Student Financial Account** the “ISSG Dining Dollar Extend” security group was granted viewonly access. 2. **SelfService: Dining Dollar (diningDollar_wspzsl)** the “Student as Self” role was granted viewonly access. These changes were recorded in the audit log with a comment referencing change request CHG0037161. The activation replaced an earlier processing instance dated January8,2026 and updated the tenants security timestamp. No other objects were modified.
[EVT-0022] - DennisCregan (user ID1000054) edited the Workday account for employee **Kelby Brick** on January17,2026 at 06:45AM EST. During that transaction he updated Kelbys usernotification settings, adding a long list of notification categories (e.g., “Gigs,” “Academic Advising,” “Accounting Center Job Process,” “Birthdays,” “Benefits Notifications,” “Time Off,” etc.) and specifying that each of those notifications should be sent via **Email** and, for many categories, also via **Mobile Push Notification**. The change was recorded as part of the “Edit Workday Account” transaction and completed successfully. No other attributes were changed or removed.
[EVT-0023] - On January17,2026 at 6:56AM EST, Workday administrator Dennis Cregan (user ID1000054) edited Gabrielle Vidmars Universal ID. The change replaced the old Student Universal ID “1117251” with a new value of “1117249”. The edit was performed as part of the “Edit Universal Id” transaction. No other attributes were altered, and no attachments were added or removed. The event was logged as EVT0023.
[EVT-0024] - On January17,2026 at 6:57AM EST, Workday administrator Dennis Cregan edited the Student ID for Gabrielle Vidmar. The students ID was changed from 1117251 to 1117249. This change was recorded as part of the “Edit Student ID” transaction and applied to Gabrielle Vidmars record for the Fall2026 term (and related program entries). The audit shows that the transaction was processed and executed, with no other relationships added or removed. No attachments were added. The event (EVT0024) logged 12 rows of data related to the edit.
[EVT-0025] - On January17,2026 at 6:58AM EST, Workday administrator Dennis Cregan edited the account for user Gabrielle Vidmar. During that transaction, he configured a large number of notification settings for Gabrielles user profile—adding email and mobilepush notifications for dozens of Workday event categories (such as “Academic Advising,” “Benefits Notifications,” “Time Off,” “Student Recruiting Marketing,” etc.). The edit was performed as part of the standard “Edit Workday Account” workflow, and the changes were applied to Gabrielle Vidmars account. No items were removed; only new notification configurations were added.
[EVT-0026] - On January21,2026 at 12:18PM (EST) the integration administrator **Dennis Cregan** launched a background process that updated student prospect records. The process started the “Student Prospect Update Event (Default Definition)” workflow for the prospect **JayC. Sink** and ran the batch job “Match Students.” During that workflow a new custom identifier was created for JayC. Sink: the system added the reference **CUSTOM_IDENTIFIER_REFERENCE321093** to his record. The identifier was added as a “Custom Identifier Reference” for the custom ID type “SlateID.” The audit shows that the event moved through several steps—initiation, approval by the integration administrator, batch/job execution, and completion. The process logged that it was “In Progress” and later marked the job as “Successfully Completed.” No attachments were added, and no other fields were changed except the creation of this custom identifier. The event is recorded under event ID **EVT0026** and involved 68 rows of data.
[EVT-0027] - On January23,2026 at 8:25AM EST, Workday administrator Dennis Cregan edited the account for employee EmilyWolski. During that transaction he configured a large number of usernotification settings for her, adding email and mobilepush notifications for dozens of event categories (such as Gigs, Academic Advising, Accounting Center Job Process, Activity Comments, Comp Process additions, Admissions, Anniversaries, Background Error Notifications, Benefits, Birthdays, Bonus/Comp reviews, Business Process General notifications, CheckIns, Consignment Usage Requisitions, Customer Central, Drive Access changes, E&G Committee invitations, Evidence of Insurance, Extended Enterprise Campaigns, Financial Aid disbursements and packages, General notifications, Give Feedback, Goal Notes, Integrations, Interview Schedule communications, Inventory alerts, Learning campaigns and expirations, Marketplace promotions, Metric reviews, Onboarding plan notifications, Open Enrollment for benefits, Par usage alerts, Passive enrollment events, Prism data acquisition, Remote Form I9 notifications, Repository documents, Request for Quote alerts, Supplier synchronization errors, Scheduled processes and reports, Schedule distribution requests, Share career development opportunities, Student engagement monitoring, Student financials and records, Supplier contract expirations and renewals, Surveys, System monitor alerts, Talent pool notifications, Time Off, Upcoming shift, Voluntary selfidentification of disability, Workbook access changes, workbook comments and conversations, import failures/successes, live data updates, function notifications, and worker communications. All of these were added to EmilyWolskis notification preferences during that edit transaction.
[EVT-0028] - On January23,2026 at 10:59AM EST, user **Dennis Cregan** (ID1000054) created a new security group in the Gallaudet and Clerc HR UBSG tenant. The group was given the name **“USERBASED_SECURITY_GROUP3237”** and its creation was recorded as a “Create Security Group” transaction. The event was logged in English (United States) language and the groups entry moment timestamp is 2026012307:59:56.5710800. No prior values existed, and no relationships were removed; the only changes recorded are the addition of the new group.
[EVT-0029] - On January23,2026 at 11:02AM EST (08:02AM PST), Dennis Cregan edited the “Gallaudet and Clerc HR UBSG” security group. He added a comment that the group will be used by intersection security groups to exclude Gallaudet and Clerc HR employees who hold specific roles such as Manager or UI. The edit was performed through the “Edit User-Based Security Group” transaction, and Dennis Cregan is listed as both the user who performed the action and the administrator. No items were removed, and no attachments were added. The event is recorded as EVT0029.
[EVT-0030] - DennisCregan added seven employees to the “Gallaudet and Clerc HR UBSG” userbased security group on January23,2026 at 11:04AM EST. The users added were: * BeckyWhittington * AnthonyBalogh * ChristinaShenAustin (appears as “Christina Shen” in the applied list) * RachelParker * YunheBai * OloladeOlasanoye * KellyFournier * StephanieBettencourt The action was recorded as a “Assign Users to UserBased Security Group” transaction, and the event log shows that the group membership was updated for each of those users. No users were removed, and the change was performed by DennisCregan (user ID1000054).
[EVT-0031] - On January23,2026 at 11:04AM Eastern Standard Time, DennisCregan created a new security group called **“NonHR Manager ISG.”** The action was performed through the Workday “Create Security Group” transaction. The groups internal ID is **INTERSECTION_SECURITY_GROUP321** and the entry moment recorded was 2026012308:04:33.2190800 (UTC8). No other changes were made to the group at that time.
[EVT-0032] - On January23,2026 at 11:05AM EST, user Dennis Cregan (ID1000054) edited the “Intersection Security Group” named **Gallaudet and Clerc HR UBSG**. He added the role **Manager** to this group and set it to exclude all employees who are both in the Gallaudet and Clerc HR tenant and have the Manager role. The change was recorded as part of the “Edit Intersection Security Group” transaction, and a comment noting that this intersection security group is used to exclude all Gallaudet and HR employees with the Manager role was added. No items were removed, and no attachments were added. The event ID for this action is EVT0032.
[EVT-0033] - On January23,2026 at 11:05AM Eastern Standard Time, user DennisCregan (ID1000054) created a new security group in Workday. The group was given the internal IDINTERSECTION_SECURITY_GROUP322 and the display name “NonHR Unit Initiator ISG.” The creation transaction was recorded as a “Create Security Group” event (EVT0033). No other attributes were changed, and the action was performed in the default English (United States) language setting. No attachments were added, and no relationships were removed. The audit shows the transaction was processed successfully for the task behavior and associated with the users language setting.
[EVT-0034] - On January23,2026 at 11:06AM (EST) DennisCregan edited the “Intersection Security Group” that is used to exclude employees from certain security permissions. In that edit he added three items to the group: “Gallaudet and Clerc HR UBSG”, “NonHR Unit Initiator ISG”, and the role “Unit Initiator”. The change was recorded as part of the transaction “Edit Intersection Security Group” and is intended to prevent all Gallaudet and HR employees who hold the Unit Initiator role from receiving the permissions granted by this security group.
[EVT-0035] - On January26,2026 at 6:35AM EST, DennisCregan (user ID1000054) edited the UniversalID for employee AndrewGreenman. The change updated Andrews UniversalID from **1117188** to **1108237**. The edit was recorded as the “Edit UniversalId” transaction and applied to AndrewGreenmans record. The audit shows the entry moment timestamp, the new UniversalID value, and notes that XML file contents were excluded from the audit. No other attributes or relationships were altered.
[EVT-0036] - On January26,2026 at 06:36AM EST, Workday administrator DennisCregan edited the Workday account for employee AndrewGreenman. During that “Edit Workday Account” transaction, Dennis configured Andrews usernotification settings. The change added a long list of notification categories for Andrew, enabling both email and mobilepush alerts for each category (for example, Gigs, Academic Advising, Accounting Center Job Process, Activity Comments, Benefits Notifications, Birthdays, Bonus/Comp review, Business Process General notifications, CheckIns, Student Recruiting Marketing, Time Off, Upcoming Shift, and many others). The transaction completed successfully with no removals or attachments added.
[EVT-0037] - On January28,2026 at 10:15AM EST, Workday administrator DennisCregan (user ID1000054) performed an “Edit Other IDs” transaction for the student prospect **MarkKillian**. During this transaction, a new custom identifier reference was added to Marks record: **CUSTOM_IDENTIFIER_REFERENCE321213**. This identifier was created as part of the “Student Prospect Update Event (Default Definition)” background process that launched a batch job called **Match Students**. The event was initiated by the Integration Administrator and progressed through approval, batch processing, and completion stages. No other identifiers were removed or changed; the only removal noted was a prior identifier “376542395681374436” that had been reconciled earlier. The transaction logged 69 rows of audit data and was recorded under event IDEVT0037.
[EVT-0038] - On January28,2026 at 2:06PM EST, Workday administrator **Dennis Cregan** edited the Workday account of user **StephanieBaran**. During that edit, Dennis changed several attributes on Stephanies account: * Set the **Account Expiration Date** to 20260128. * Updated various workflow and transaction timestamps (e.g., “Completed Date,” “Creation Date,” “Due Date,” etc.). * Configured a large number of **User Notification Settings** for Stephanie, enabling both email and mobilepush notifications across dozens of Workday categories (e.g., Academic Advising, Accounting Center Job Process, Birthdays, Benefits Notifications, Time Off, Student Recruiting, etc.). * Selected **English (United States)** as Stephanies preferred user language. The action was performed under the “Edit Workday Account” transaction, and it completed successfully on that same day.
=== Joseph DeSiervi ===
[EVT-0040] - On January8,2026 at 3:46PM EST, JosephDeSiervi (user ID1003153) edited a Workday businessprocess security policy. In that edit he added the “Approve” permission to the policy, linked it to the “Edit Business Process Security Policy” task behavior, and assigned that permission to the “ProcurementDataEntrySpecialist” security group. The change was recorded as a new entry moment and the XML contents of the policy were updated (the file contents themselves are not shown in the audit). No items were removed. The event was logged under event IDEVT0040.
[EVT-0041] - On January8,2026 at 3:48PM (EST) JosephDeSiervi activated a pending securitypolicy change. The activation added the “Procurement Data Entry Specialist” role with permission to approve any BP purchaseorder change orders (INC0164817/CHG0037156). The policy activation was logged as part of the “Activate Pending Security Policy Changes” transaction, and it updated the tenants security timestamps. The change was made by JosephDeSiervi (user ID1003153) and recorded under eventEVT0041.
=== Julie Longson ===
[EVT-0057] - On January6,2026 at 4:11p.m. (EST) Julie Longson performed an “Assign Roles” transaction in Workday. She added several role assignments to the user **Shelby Bean (P004080)**, giving her: * Unofficial Student Transcript Viewer RBSGC and RBSGU * Financial Aid Specialist RBSGC (effective 01/06/2026) * Financial Aid Student Assistant LevelI RBSGC (effective 01/06/2026) * Financial Aid Student Assistant LevelII RBSGC (effective 01/06/2026) * Financial Aid Student Assistant SFS Access RBSGU (effective 01/06/2026) The transaction also updated the role assignment snapshot for Shelby Bean and affected membership of the corresponding tenanted security groups. No roles were removed; only additions were recorded. The event was logged under IDEVT0057 and involved 147 rows of audit data.
[EVT-0058] - Julie Longson, a Workday administrator, performed an “Assign Roles” transaction on January62026. She added the role **Financial Aid Specialist (View Only) Gallaudet University** to employee **JohnDavis**. The role assignment became effective on January62026, and the event was automatically completed at 13:12:23 on that day. The transaction created a roleassignment event and snapshot, recorded in the system as “Assign Roles for P001809 Director, Outreach effective 01/06/2026.” No roles were removed. The action was logged under event IDEVT0058 and completed successfully.
[EVT-0059] - On January6,2026 at 4:15PM EST, Julie Longson (user ID1004645) assigned JohnDavis (user ID1102491) to the “Financial Aid Specialist UBSG U” userbased security group. The action was recorded as a “UserBased Group Change Event Lite Type” and the transaction was logged under the task “Assign Users to UserBased Security Group.” No users were removed, and the change was completed successfully.
=== Kristinn Bjarnason ===
[EVT-0042] - On January7,2026 at 12:03PM EST, KristinnBjarnason created a new assignable role called **“Manage Course Offerings.”** The role was given the internal ID **ASSIGNABLE_ROLE3517** and was added to the **Academic Unit Academic Unit Hierarchy**. The role is governed by Workdays security framework: it is **administered by a Tenanted Security Group** and its use is **restricted by RoleUsage metadata.** The transaction that created the role was part of the **Maintain Assignable Roles** task, which is a standard administrative operation. The roles language setting was set to **English (United States)**, and the action was recorded under the event IDEVT0042. No prior values were changed, and no items were removed in this operation.
[EVT-0043] - On January7,2026 at 12:04PM EST, KristinnBjarnason created a new security group in Workday. The group was named “Manage Course Offerings RBSGC” and received the system ID **ROLE-BASED_SECURITY_GROUP__CONSTRAINED_-3-452**. The creation event was logged as transaction “Create Security Group” and the users language setting (English(United States)) was recorded. No prior values existed because this was a new object, and nothing was removed. The audit shows the transaction was processed successfully under the task behavior for creating a security group.
[EVT-0044] - On January7,2026 at 12:04PM Eastern Standard Time, KristinnBjarnason edited a rolebased security group called **“Manage Course Offerings RBSGC.”** During that edit he added the **“Edit RoleBased Security Group (Constrained)”** role to the group, thereby granting members of this group permission to modify other constrained security groups. The change was recorded as eventEVT0044 and involved four attribute updates, all of which were added to the groups membership configuration. No roles or members were removed.
[EVT-0045] - On January7,2026 at 12:05PM EST, KristinnBjarnason (user ID1003966) edited the security settings for a Workday domain. He added a new permission called **“Edit Domain Security Policy Permissions”** to the *Manage Course Offerings RBSGC* domain. The edit granted that permission to the **“Manage: Mass Course Offerings”** group, allowing members of that group to view and modify the domain. The permission also gave access to the *Domain Security Policy* itself, and it enabled the policys members to grant domain access to other members of the *Tenanted Security Group*. In short, Kristinn updated the domain security policy so that users in the “Manage: Mass Course Offerings” group can edit and view course offerings, and he set up the policy to allow those users to further grant access to other members of the same security group. This change was recorded as eventEVT0045 and involved seven individual relationship updates.
[EVT-0046] - On January7,2026 at 12:06PM (EST) KristinnBjarnason activated the pending securitypolicy changes for the “Manage: Mass Course Offerings” domain. During that activation he created a new security group called **RBSGC** so that users in that group could view and modify the “Manage: Mass Course Offerings” domain (this was logged as partof incidentINC0165358/CHG0037144). The activation also removed the earlier securitytimestamp that had been set on December19,2025. The event was recorded under the transaction “Activate Pending Security Policy Changes” and logged with event IDEVT0046.
[EVT-0047] - On January7,2026 at 12:09AM (EST) KristinnBjarnason added the “Associate Dean, Graduate Education” role to user **bethgibbons**. The assignment was made in response to a request from **ErickaBrown** (ticket INC0165358/CHG0037144). The role grants bethgibbons the ability to manage course offerings for two academic units: * Continuing Education Academic Unit * Dean of Faculty Academic Unit / Graduate The change was recorded in the Workday “AssignRoles Add/Remove” transaction and completed automatically. No roles were removed, and the action was logged under event IDEVT0047.
[EVT-0048] - On January7,2026 at 9:10AM (Eastern Time), KristinnBjarnason added the “Assistant Dean, Graduate Education” role to MaryPerrodinSingh. The assignment was made effective on 01/07/2026 and was performed at the request of ErickaBrown (incident INC0165358 / change CHG0037144). The role assignment linked Mary to the “Continuing Education Academic Unit” and the “Dean of Faculty Academic Unit / Graduate” units, which are managed by Associate Dean BethGibbons. The action was recorded in the Workday audit log under event ID EVT0048 and completed automatically.
[EVT-0049] - On January12,2026 at 5:50AM (Eastern Time), Workday administrator **KristinnBjarnason** performed a roleassignment action. He added the **Residence Education Coordinator** role (P007401) to employee **MarlenaDemmon** at Gallaudet University. The assignment became effective immediately on that date. No other roles were removed or changed in this transaction.
[EVT-0050] - On January12,2026 at 11:42AM (Pacific Time), KristinnBjarnason added the “Assistant Dean Graduate Education” role to MaryPerrodinSingh. The assignment was made at the request of BethGibbon, as noted in incident INC0165359. The role change became effective on January12,2026 and was completed automatically by the system. No other users or roles were affected in this transaction.
[EVT-0051] - On January14,2026 at 12:16PM EST, Workday administrator KristinnBjarnason edited the account for user VeronicaTovarCervantes. The edit set several account properties: a new account ID of 1004184, an expiration date of January15,2026, a graceperiod login count of 30, and a session timeout of 5minutes. The transaction also updated the users notification settings, configuring a long list of systemwide notifications (e.g., Academic Advising, Accounting Center Job Process, Benefits Notifications, Time Off, etc.) for VeronicaTovarCervantes. The change was performed under the “Edit Workday Account” workflow and completed successfully on that date.
[EVT-0052] - [LLM ERROR] Error code: 400 - {'error': 'The number of tokens to keep from the initial prompt is greater than the context length. Try to load the model with a larger context length, or provide a shorter input'}
[EVT-0053] - On January21,2026 at 5:54AM Eastern Time, KristinnBjarnason processed a Workday workflow that removed TeresaBlankmeyerBurkes “School Director Arts and Humanities School” role. The removal was carried out at the request of Teresa herself, as noted in the comment “Removed School director role per Teresa Blankmeyer Burke's request (INC0166411).” At the same time, the workflow assigned BrianGreenwald to the “Professor P000679” role effective January21,2026. The event was logged as a “Role Assignment Event” and completed automatically with no manual intervention required. Thus, KristinnBjarnason executed a roleremoval for Teresa and a roleassignment for Brian on the same day, completing both actions automatically under the “Assign Roles Add/Remove” transaction.
[EVT-0054] - On January21,2026 at 5:57AM Eastern Time, Workday administrator **Kristinn Bjarnason** (user ID1003966) added a role assignment for **Teresa Blankmeyer Burke**. The action gave Teresa the title of **Professor School Director** in the **Arts and Humanities School**. The assignment was created as part of the “Assign Roles” workflow, which automatically completed at 5:27AM that same day. The change was logged as a “Role Assignment Event” and recorded in the systems event log (event IDEVT0054). The note accompanying the assignment states that Teresa was added because she has returned from her sabbatical (incidentINC0166411). No roles were removed, and the change was fully completed by 5:57AM.
[EVT-0055] - On January22,2026 at 9:19AM EST, KristinnBjarnason (user ID1003966) performed a “Maintain Domain Permissions for Security Group” transaction. He added several permissions and viewonly access rules to the domain security policy for a specific security group. The changes included granting the group access to student transcript and withdrawal/leave data, assigning a “Student Finance Administrator UBSG” role, and adding viewonly permissions for those data sets. No items were removed. The event was logged as EVT0055 and involved 11 rows of permission changes.
[EVT-0056] - KristinnBjarnason (user ID1003966) activated the pending securitypolicy changes for the Gallaudet tenant on January22,2026 at 9:20AM EST. The activation added the Student Data domains “Student Transcript” and “Withdrawal and Leave” to the UBSG security group that manages Student Finance Administrator access. The change was recorded as part of the “Activate Pending Security Policy Changes” transaction, and the new security timestamps for the tenant were updated accordingly.
=== Thad Ferguson ===
[EVT-0039] - On January12,2026 at 2:06PM EST, Workday administrator **Thad Ferguson** (user ID1000998) edited the student record for **Jennifer Ceyanes**. He changed her Student ID from the temporary value **TEMP_STUDENT_0002694** to the new permanent ID **1117210**. The edit was recorded as part of the “Edit Student ID” transaction and applied to Jennifers Fall2026, Fall2027, Fall2028, Spring20262029, and Summer20262028 enrollment records. The change was logged in the “Student Financials Period Record Student ID (Denormalized)” attribute, and the audit captured the entry moment timestamp “20260112110631537-0800”. No other attributes were altered.