workday-fetch-processor — Design (DEFERRED)
Status: DEFERRED. Workday’s vulnerability disclosure happens behind the Workday Community auth wall (customer-only). Public footprint is marketing + status redirects + one-off corporate blog posts (Log4j 2021, social-engineering breach 2025). No public PSIRT, no advisory feed, no GHSAs.
1. Overview
- Tier: Tier-3 SaaS (Phase 5)
- Verdict: DEFERRED
- Reason in one sentence: Workday’s security posture is enterprise-gated; vulnerability disclosures only reach authenticated customers via Workday Community.
2. Source contract (Phase 0 recon — 2026-05-09)
Recon-protocol grid:
| Step | Check | Finding |
|---|---|---|
| 1–6 | All advisory-feed paths | None public |
| 7 | CVE alias presence | Only via Workday’s one-off blog posts (Log4j 2021, 2025 social-engineering); no canonical feed |
| 8 | Anti-bot / auth wall | Auth wall — Workday Community is customer-only |
URLs checked:
https://www.workday.com/en-us/why-workday/trust.html— 200; navigation hub onlyhttps://www.workday.com/en-us/why-workday/trust/overview.html— marketinghttps://status.workday.com— 301 redirects to gated/regional status pages; per-tenant onlyhttps://trust.workday.com— 301 into corporate site; no advisory listinghttps://workday-community.workday.com— auth wall (customer-only)https://blog.workday.com/en-us/workday-response-on-log4j.html— one-off post; same pattern for 2025 social-engineering breachgithub.com/workday— no notable OSS / GHSA presence
11. Deferral rationale + unblock conditions
What we’d accept to flip this:
- Workday launches a public PSIRT page (analogous to SAP / Oracle / Salesforce — vendors that already ship their own processors in tree).
- Workday adopts a public Trust Center with disclosed advisories.
Related work:
- Workday-affecting CVEs (when assigned) land in NVD/MITRE. That’s the only signal vdb-manager will have until the customer-portal disclosures become public.
Why not retarget as commentary enricher:
- Corporate blog volume is too low (one-off incident-response posts, not CVE-tagged commentary). Below the Vultr §15.8 ROI floor.
Recheck cadence: every 12 months. Next 2027-05-09.
S3 Persistence
Not used. This processor does not currently archive payloads or quarantine failures to S3. Per the S3 Persistence Contract this is non-compliant — see the compliance matrix for the implementation roadmap.
⚠ Not in the compliance matrix — status needs verification.
Expected paths when implemented:
- Archive:
workday/files/{sha256}/{filename} - Quarantine:
failed-feeds/workday-fetch-processor/{YYYY-MM-DD}/{reason}/{filename} - Likely reasons: (none documented)