workday-fetch-processor — Design (DEFERRED)

Status: DEFERRED. Workday’s vulnerability disclosure happens behind the Workday Community auth wall (customer-only). Public footprint is marketing + status redirects + one-off corporate blog posts (Log4j 2021, social-engineering breach 2025). No public PSIRT, no advisory feed, no GHSAs.

1. Overview

  • Tier: Tier-3 SaaS (Phase 5)
  • Verdict: DEFERRED
  • Reason in one sentence: Workday’s security posture is enterprise-gated; vulnerability disclosures only reach authenticated customers via Workday Community.

2. Source contract (Phase 0 recon — 2026-05-09)

Recon-protocol grid:

StepCheckFinding
1–6All advisory-feed pathsNone public
7CVE alias presenceOnly via Workday’s one-off blog posts (Log4j 2021, 2025 social-engineering); no canonical feed
8Anti-bot / auth wallAuth wall — Workday Community is customer-only

URLs checked:

  • https://www.workday.com/en-us/why-workday/trust.html — 200; navigation hub only
  • https://www.workday.com/en-us/why-workday/trust/overview.html — marketing
  • https://status.workday.com — 301 redirects to gated/regional status pages; per-tenant only
  • https://trust.workday.com — 301 into corporate site; no advisory listing
  • https://workday-community.workday.com — auth wall (customer-only)
  • https://blog.workday.com/en-us/workday-response-on-log4j.html — one-off post; same pattern for 2025 social-engineering breach
  • github.com/workday — no notable OSS / GHSA presence

11. Deferral rationale + unblock conditions

What we’d accept to flip this:

  1. Workday launches a public PSIRT page (analogous to SAP / Oracle / Salesforce — vendors that already ship their own processors in tree).
  2. Workday adopts a public Trust Center with disclosed advisories.

Related work:

  • Workday-affecting CVEs (when assigned) land in NVD/MITRE. That’s the only signal vdb-manager will have until the customer-portal disclosures become public.

Why not retarget as commentary enricher:

  • Corporate blog volume is too low (one-off incident-response posts, not CVE-tagged commentary). Below the Vultr §15.8 ROI floor.

Recheck cadence: every 12 months. Next 2027-05-09.

S3 Persistence

Not used. This processor does not currently archive payloads or quarantine failures to S3. Per the S3 Persistence Contract this is non-compliant — see the compliance matrix for the implementation roadmap.

⚠ Not in the compliance matrix — status needs verification.

Expected paths when implemented:

  • Archive: workday/files/{sha256}/{filename}
  • Quarantine: failed-feeds/workday-fetch-processor/{YYYY-MM-DD}/{reason}/{filename}
  • Likely reasons: (none documented)