Your tenant changed on a Saturday

The Workday 2026R2 release has been available in production since September 19, 2026, according to a release analysis from the consultancy SQORUS published the same day. Opkey, Zeneesha, Commit Consulting and Howard University ETS give the same production date. SQORUS describes several hundred enhancements across HCM, Finance, Payroll, Integration and Talent, a count that is the consultancy's characterization rather than a figure Workday published.

We found no Workday-issued press release marking the release, so what the market has to work from is consultancy reporting and customer-side change lists. The date matters more than that gap. September 19 was a Saturday, so a large release arrived in customer tenants over a weekend and was waiting on Monday for people who had read nothing about it.

For an admin the headline feature list is the least useful part. The changes are in the tenant already. What decides your week is which of them arrived without a switch and which ones wait for somebody to turn them on.

The automatic and optional split is the number to go find

Howard University's enterprise technology services group published its own 2026R2 change list and counted 243 automatic changes and 144 optional ones at that institution. Read that as an illustration of the shape and nothing more. The split at any given customer depends on which modules are licensed, how much configuration sits on top, and which optional features from earlier releases were already adopted.

Roughly two thirds of what changed at that institution needed no decision from anyone. Automatic changes can alter a report, a business process step, or a field an integration reads, with no project, no test plan and no go-live date attached. They are also the ones nobody assigned to a person.

Pull your own change list and separate the two before you read a word about the optional features. Then check the automatic items against the integrations and custom reports you maintain, because a quiet field change is what turns into a Tuesday incident with no obvious cause.

Mass Job Change is a permission decision before it is a feature

The HCM item most people will notice is Mass Job Change, which SQORUS says allows management of up to 5,000 changes within a single interface with real-time validation. For anyone who has pushed a reorganization through repeated business process transactions, that saves real hours.

It is also a large amount of write capability gathered in one place. Five thousand job changes run by one person in one session carries a different risk profile from five thousand transactions that each pass through normal routing. Decide which security groups can reach it, and confirm the business process definitions behind it still apply their condition rules at that volume.

Our guide on what happens when Workday security groups multiply covers the usual failure, where a group picked up a domain permission years ago and nobody has reviewed the membership since. A feature that writes 5,000 records at once makes an old membership list expensive.

Agent Passport puts Workday's name on somebody else's agent

The platform item that deserves more attention is Agent Passport. SQORUS describes it as a certification introduced in 2026R2 that ensures an AI agent, whether internal or third party, meets the Workday platform's security and compliance standards. Workday also added a Developer Agent in Workday Build and Agent-Ready Tools with MCP access controls.

Read that claim slowly. A certification stating that an outside agent meets the platform's security and compliance standards is Workday asserting a trust boundary on the customer's behalf. It tells you the agent passed whatever tests Workday runs. It says nothing about what that agent may do inside your tenant, and those two facts get merged in a demo.

We first wrote about Agent Passport when it appeared in Workday's second-quarter release, described then as testing and verifying agents before they reach production. The 2026R2 description extends it to third-party agents, and that changes the conversation. A customer now holds a vendor statement about software the vendor did not write.

What a customer can actually inspect

The questions for an account team are narrow ones. Does certification cover the agent's code and model, or only the interfaces it uses to reach Workday data? Can a customer read the test results, or only see that a pass was issued? Does certification lapse when the third party ships an update, and who gets told?

Then ask the one that decides budget. If a certified third-party agent writes something unwanted into your tenant, who carries it? Our read is that the customer does, because the agent runs under a security configuration the customer granted, and a vendor certification is not an indemnity. None of the reporting addresses it.

Until those answers exist in writing, Passport belongs in your review as one input and not a replacement for it. What decides an agent's reach in your tenant is still the security group it runs under and the business process definitions governing the objects it writes.

Every platform is now deciding how far outside agents reach

Workday is not alone. ServiceNow put MCP actions behind its own governance layer rather than letting an external client call whatever it wanted, which we covered in how ServiceNow governs MCP actions. Salesforce hit the same question once a third-party model started acting inside customer orgs, and we wrote about where that trust boundary actually sits.

Each platform wants outside agents to be useful and each one wants a control point it owns. Certification is the lightest version, because it happens once, before the agent runs, and it makes a claim about the agent rather than about the actions the agent takes. The MCP access controls shipped alongside Passport are the heavier version, and the ones we would spend review time on.

So list every agent with reach into your tenant, mark the Workday-built ones and the third-party ones, and write down what each can write. If Agent Passport is the only thing standing behind a third-party agent on that list, you are holding a vendor's word where you need your own configuration. Our coverage of agent governance tracks how the other platforms answer this. Ask your account team for the Passport test report by name, and see how far that request gets.