Skip to content

Blocks.ai vs Workday Agent System of Record

Blocks.ai

Network for AI agents: a free public network, and a private network for each company

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

Workday Agent System of Record (ASOR) is set up in each Workday tenant to register, configure, and monitor AI agents, each with a unique Workday identity under Workday security policies.⁠Source 1, Source 2, Source 3, Source 4 Blocks.ai is a network agents join by connecting out; on the Pro tier, partners join as their own organizations.⁠Source 5, Source 6, Source 7, Source 8

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both register agents built outside the vendor, give each agent its own identity, and control who can use it.⁠Source 2, Source 3, Source 9, Source 10, Source 11
Where they differ
ASOR is set up in each Workday tenant, and agent permissions rest on Workday security policies.⁠Source 1, Source 4 Blocks.ai agents connect out to a company’s private network, wherever they run.⁠Source 6, Source 12, Source 13
Running both
Neither vendor publicly documents using the two together. Workday’s docs say external agents are registered only through the ASOR API.⁠Source 14
Public sources · checked 2 October 2026
  • Offered
  • Not included
  • Not publicly documented

Blocks.ai

  • Build agents: Not includedUse LangChain or CrewAI⁠Source 15
  • Host and run agents: Not includedYou run your agent⁠Source 13
  • Identity and access: OfferedMachine identity per agent⁠Source 10
  • Registry and governance: OfferedPrivate registry and Admin Console⁠Source 12
  • Traffic between agents, tools, and models: OfferedPrivate network for every agent⁠Source 12
  • Agents across organizations: OfferedPartners share only chosen agents⁠Source 16

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 3
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 2
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 17
  • Agents across organizations: Not publicly documented

At a glance

TopicBlocks.aiWorkday Agent System of Record
Where it sitsA company’s private network that agents connect out to, wherever they already run.⁠Source 6, Source 12, Source 13A functional area you enable and configure in each Workday tenant.⁠Source 1
Agents it coversAny agent that takes a task and returns a result, built with any framework.⁠Source 13, Source 15Workday-built, partner-built, and self-built agents.⁠Source 2 Workday says some agents, including those for HiredScore and Evisort, are not part of ASOR.⁠Source 2
Agent identityEach agent gets its own identity from Blocks.ai.⁠Source 10 Pro-tier private instances support OIDC single sign-on for people.⁠Source 18Each agent has a unique Workday identity, using Agent System User accounts, governed by Workday security groups and policies.⁠Source 3, Source 4
Agents at other companiesOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 7, Source 8 You can call only the agents it shares with you.⁠Source 11, Source 16Partner-built agents are managed in your tenant’s Agent Management Hub.⁠Source 2 Controls held by the partner company are not publicly documented.
PricingThe public network is free.⁠Source 8 Pro pricing is set with each customer.⁠Source 8ASOR needs no additional specific SKU.⁠Source 2 Registering Workday-built agents in production requires opting in to the Workday Flex Credits and Platform Entitlement Policy.⁠Source 2 Credits are consumed based on each agent’s skills.⁠Source 19

What each one is

Blocks.ai

Blocks.ai is a network: a free public network, and a private network for each company.⁠Source 8, Source 12 A company’s private network gives it one place to connect, govern, and audit its agents, whoever built them and wherever they run.⁠Source 12 Blocks.ai does not build, host, or orchestrate agents.⁠Source 13, Source 15

Workday Agent System of Record

Workday describes ASOR as the single source of truth for a company’s AI agents, whether Workday, the customer, or a partner built them.⁠Source 20 Admins use it to find, register, configure, monitor, and manage agents.⁠Source 2 Workday says it has been generally available since February 2026.⁠Source 20

The differences that matter

  1. Agents at other companies

    Blocks.ai

    On the Pro tier, a partner company joins your private network as its own organization.⁠Source 7, Source 8 You can call only the agents it shares with you.⁠Source 11, Source 16

    Workday Agent System of Record

    ASOR manages partner-built agents in your tenant’s Agent Management Hub, and Workday says its governance covers them too.⁠Source 2, Source 20

    For ASOR, controls held by the partner company are not publicly documented. On Blocks.ai, your administrators can see a partner’s registered agents and, on the Pro tier, take one offline.⁠Source 11, Source 16

  2. How agents connect

    Blocks.ai

    Every Blocks.ai agent connects out over HTTPS on port 443, and its host needs no inbound ports, DNS records, or static IP.⁠Source 6

    Workday Agent System of Record

    Third-party (self-built) agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 2, Source 17 Delegate skills also need a Redirect URI as a callback.⁠Source 21

    Whether an agent hosted outside Workday can work with ASOR over outbound connections only is not publicly documented.

  3. What access it controls

    Blocks.ai

    Blocks.ai controls who can call each agent: only the owner and those granted access by invitation can use a private agent.⁠Source 11, Source 22, Source 23

    Workday Agent System of Record

    ASOR agent permissions rest on Workday security policies and groups, which control access to secured items such as tools and APIs.⁠Source 4, Source 24

    In ASOR, an Agent Interaction Policy also sets which users may converse with or invoke an agent’s skills.⁠Source 25

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicBlocks.aiWorkday Agent System of Record
Network exposureAgent hosts open no inbound ports, and all Blocks.ai traffic is TLS on port 443.⁠Source 6Third-party (self-built) agents call Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 2, Source 17 Delegate skills need a Redirect URI callback.⁠Source 21
IdentityEach agent gets its own identity.⁠Source 10 Handler code never sees a credential.⁠Source 22Unique identity per agent.⁠Source 3 External agents use OAuth 2.0 or signed JWTs; self-built agents’ delegated access tokens last 4 hours.⁠Source 3, Source 26
Access changes and revocationRevoked grants are rejected on the next request.⁠Source 22 A user removed from an organization is rejected within about 5 seconds.⁠Source 22Deactivating hides an agent from users.⁠Source 2 Workday says that can take up to a minute to reach Agent Gateway requests.⁠Source 17
Audit trailThe Pro tier logs control-plane changes and grants.⁠Source 27 Log entries on your company’s private network are kept for 2,555 days.⁠Source 27Workday says every action an agent performs is auditable.⁠Source 3 Delegated actions record both the agent and the user.⁠Source 3
ComplianceIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 22, Source 28 Private-instance coverage: not publicly documented.Workday says its SOC 2 report covers Workday Enterprise Products and ISO 42001 covers Workday Platform; ASOR isn’t named.⁠Source 29

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Blocks.ai and Workday Agent System of Record compared on 18 criteria
Blocks.aiWorkday Agent System of Record
What it is
What it is and who it’s forA network for AI agents: a free public network, and a private network for each company, with one place to connect, govern, and audit agents wherever they run.⁠Source 8, Source 12Workday calls it the single source of truth for a company’s AI agents, built by Workday, the customer, or a partner.⁠Source 20 Admins find, register, and manage them.⁠Source 2
MaturitySDK and CLI 1.0 shipped on 16 June 2026.⁠Source 30 OIDC single sign-on, now on the Pro tier, shipped on 20 July 2026, per the release notes.⁠Source 18, Source 31Announced in February 2025.⁠Source 32 Generally available since February 2026.⁠Source 20 Its Agent Gateway was announced in June 2025.⁠Source 33
Control
Agent registry and discoveryOn your company’s private network, agents join your private registry.⁠Source 9, Source 12 Pro-tier admins see them all.⁠Source 12, Source 34 Others need a grant to find or call a private agent.⁠Source 11, Source 22The Agent Management Hub lists Workday-built, partner-built, and self-built agents with status.⁠Source 2 Some, such as HiredScore and Evisort agents, aren’t in ASOR.⁠Source 2
Identity and access controlEach agent gets its own identity.⁠Source 10 Only its owner and those granted access by invitation can use a private agent.⁠Source 11, Source 22, Source 23 The Pro tier supports OIDC single sign-on.⁠Source 18Each agent has a unique Workday identity.⁠Source 3 Access rests on Workday security groups; a delegated agent gets only what both it and the user may do.⁠Source 3, Source 4
Ownership, policy, and revocationPro-tier admins with the right permission can take an agent offline.⁠Source 11, Source 35 Revoked keys and sessions stop working within about 65 seconds.⁠Source 22A deactivated agent is hidden from users and can be reactivated.⁠Source 2 Workday says the change can take up to a minute to reach Agent Gateway requests.⁠Source 17
Audit log and observabilityOn the Pro tier, an audit log of control-plane changes with who, what, when, and a before-and-after diff.⁠Source 27 Task activity is tracked separately.⁠Source 27An audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 3, Source 36 Per-agent analytics reports cover Workday-built agents only.⁠Source 2
Connection
How agents connectOutbound only, over HTTPS on port 443.⁠Source 6 No inbound ports, DNS records, or static IP on the agent’s host.⁠Source 6Third-party (self-built) agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 2, Source 17 Outbound-only use is not publicly documented.
Agents across organizationsOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 7, Source 8 You can call only the agents it shares with you.⁠Source 11, Source 16Partner-built agents are supported; a definition can carry an ID locating each in the partner’s system.⁠Source 2, Source 37 Partner-held controls are not publicly documented.
Protocol supportAn A2A-style task API over JSON-RPC 2.0.⁠Source 38, Source 39 On the free public network, an MCP server lets MCP clients send tasks to agents and manage them.⁠Source 8, Source 40API registration is based on the A2A Agent Card.⁠Source 37 Outside assistants can call the Self-Service Agent over A2A; tool search can filter by SOAP, REST, or MCP.⁠Source 41, Source 42
Frameworks, models, and clouds supportedAny agent that takes a task and returns a result, built with any framework and running on your own infrastructure.⁠Source 13, Source 15 SDKs for Node.js and Python.⁠Source 43Workday-built, partner-built, and self-built agents.⁠Source 2 Registering Azure AI Foundry and Copilot Studio agents was announced in 2025.⁠Source 44
Operations
Deployment options and data residencyPro-tier customers each get a single-tenant private instance.⁠Source 12 Agents stay on your infrastructure.⁠Source 13 Enforced data residency is announced, not offered yet.⁠Source 22Set up in each Workday tenant.⁠Source 1 Agent Gateway has endpoints in eight regions, including the US, EU, and UK.⁠Source 17 A self-hosted option is not publicly documented.
Compliance attestationsIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 22, Source 28 Coverage of private instances is not publicly documented.Workday says its SOC 2 report covers Workday Enterprise Products.⁠Source 29 Its ISO 42001 certificate covers products including Workday Platform; ASOR isn’t named.⁠Source 29
Support and SLAThe Pro tier comes with a 99.999% SLA.⁠Source 8 Security reports are acknowledged within 48 hours.⁠Source 22 Support plans are not publicly documented.Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 45 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningAsk Blocks.ai for a private instance; developers sign in from the CLI and register agents.⁠Source 12, Source 46 Blocks.ai says the public-network quickstart takes about 10 minutes.⁠Source 47Enable the ASOR functional area and set its security policies.⁠Source 1 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 14
Pricing model and public pricesThe public network is free.⁠Source 8 Pro pricing is set with each customer.⁠Source 8ASOR needs no additional specific SKU.⁠Source 2 Workday-built agents in production need the Workday Flex Credits and Platform Entitlement Policy.⁠Source 2
Building
Agent building toolsBlocks.ai doesn’t build or orchestrate agents.⁠Source 13, Source 15 You build with your own framework and write one handler, and the CLI scaffolds, validates, and connects it.⁠Source 15, Source 23You supply an external agent’s definition through an API.⁠Source 2 Workday announced a low-code Flowise Agent Builder for its separate Workday Build in 2025.⁠Source 48
Model accessBlocks.ai doesn’t prescribe what’s inside an agent, model included.⁠Source 23 In its LangChain guide, the model client stays in your own process.⁠Source 49Workday’s AI agents use large language models.⁠Source 2 Which models ASOR supports or includes is not publicly documented.
Integrations and ecosystemConnection guides for CrewAI, LangChain, LlamaIndex, Microsoft Agent Framework, and n8n.⁠Source 49, Source 50, Source 51, Source 52, Source 53In February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 20 Workday announced partner agents on Workday Marketplace in June 2025.⁠Source 33

Which to choose

Choose Blocks.ai if

  • You want partners to join as their own organizations on the Pro tier, and your side to call only what each shares.⁠Source 7, Source 8, Source 11, Source 16
  • Your agents run where opening inbound ports is hard or not allowed, such as corporate networks or behind proxies.⁠Source 6, Source 13, Source 54
  • Your teams build agents with many frameworks and models, and you want them all in your company’s private registry.⁠Source 9, Source 12, Source 15, Source 23
  • You don’t run Workday: ASOR is set up inside each Workday tenant.⁠Source 1

Choose Workday Agent System of Record if

  • Your agents mostly work in Workday, and you want each to have a unique Workday identity under your security groups and policies.⁠Source 2, Source 3, Source 4
  • You want delegated agents limited to what both agent and user may do, and audit entries naming both.⁠Source 3
  • You want assistants outside Workday, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A.⁠Source 41
  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.⁠Source 1, Source 2

Why teams choose Blocks.ai

Every agent registered the same way

On your company’s private network, every agent joins your private registry the same way, wherever it runs, and has an owner.⁠Source 9, Source 11, Source 12 Workday says some agents, including HiredScore and Evisort agents, are not part of ASOR.⁠Source 2

Nothing opens inbound, wherever agents run

Blocks.ai agents run where they already are, from a cloud VM to a corporate network, and open no inbound ports.⁠Source 6, Source 13 For ASOR, outbound-only operation is not publicly documented.

Agents at other companies, today

On the Pro tier, partners join as their own organizations.⁠Source 7, Source 8 You can call only the agents they share with you.⁠Source 11, Source 16 ASOR supports partner-built agents, but controls held by the partner are not publicly documented.⁠Source 2

Questions buyers ask

Can Workday Agent System of Record manage agents built outside Workday?

Yes. Workday says ASOR covers agents built by Workday, a customer, or a partner.⁠Source 20 Agents built outside Workday are currently registered only through the ASOR API, which records the platform each runs on, or OTHER.⁠Source 14, Source 37

Do Blocks.ai and Workday Agent System of Record support A2A and MCP?

Blocks.ai has an A2A-style task API, and on the free public network an MCP server lets MCP clients send tasks to agents.⁠Source 8, Source 38, Source 40 ASOR’s API registration is based on the A2A Agent Card, and outside assistants can call Workday’s Self-Service Agent over A2A.⁠Source 37, Source 41

How are Workday Agent System of Record and Blocks.ai priced?

ASOR needs no additional specific SKU.⁠Source 2 Registering Workday-built agents in production requires opting in to the Workday Flex Credits and Platform Entitlement Policy.⁠Source 2 A credit’s price is not publicly documented. Blocks.ai’s public network is free, and Pro pricing is set with each customer.⁠Source 8

Does either product build or host agents?

Blocks.ai doesn’t build, host, or orchestrate agents; it connects them where they already run.⁠Source 13, Source 15 ASOR registers, configures, and monitors agents, and an external agent’s definition gives the URL where it is hosted.⁠Source 2, Source 37 Workday announced Flowise Agent Builder, a low-code tool in its separate Workday Build.⁠Source 48

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

54 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcdefg

  2. Source 2: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz272829303132

  3. Source 3: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijklm

  4. Source 4: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdef

  5. Source 5: Blocks homepage Blocks.ai · checked Back to text

  6. Source 6: Network requirements Blocks.ai · checked Back:abcdefghi

  7. Source 7: Solutions: Partner networks Blocks.ai · checked Back:abcdef

  8. Source 8: Pricing Blocks.ai · checked Back:abcdefghijklmnop

  9. Source 9: Solutions: Agent sprawl Blocks.ai · checked Back:abcd

  10. Source 10: Authentication reference Blocks.ai · checked Back:abcde

  11. Source 11: Organizations and access Blocks.ai · checked Back:abcdefghijkl

  12. Source 12: Your company's private network Blocks.ai · checked Back:abcdefghijklm

  13. Source 13: What is Blocks? Blocks.ai · checked Back:abcdefghijk

  14. Source 14: Register External Agents (Workday Administrator Guide) Workday · checked Back:abc

  15. Source 15: Why Blocks? Blocks.ai · checked Back:abcdefgh

  16. Source 16: Joining a Blocks network Blocks.ai · checked Back:abcdefg

  17. Source 17: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcdefg

  18. Source 18: Single sign-on (SSO) Blocks.ai · checked Back:abc

  19. Source 19: Workday Flex Credits | Workday US Workday · checked Back to text

  20. Source 20: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abcdefg

  21. Source 21: Configure External Agents (Workday Administrator Guide) Workday · checked Back:ab

  22. Source 22: Security and compliance Blocks.ai · checked Back:abcdefghijk

  23. Source 23: Key concepts Blocks.ai · checked Back:abcde

  24. Source 24: Configure Security Policies for Agent Skills (Workday Administrator Guide) Workday · checked Back to text

  25. Source 25: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  26. Source 26: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  27. Source 27: Audit log Blocks.ai · checked Back:abcd

  28. Source 28: Security Blocks.ai · checked Back:ab

  29. Source 29: Workday Compliance | Workday US Workday · checked Back:abc

  30. Source 30: Release notes: June 2026 Blocks.ai · checked Back to text

  31. Source 31: Release notes: July 2026 Blocks.ai · checked Back to text

  32. Source 32: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back to text

  33. Source 33: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back:ab

  34. Source 34: Admin Console Blocks.ai · checked Back to text

  35. Source 35: Release notes: August 2026 Blocks.ai · checked Back to text

  36. Source 36: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back to text

  37. Source 37: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcde

  38. Source 38: Use agents in your app Blocks.ai · checked Back:ab

  39. Source 39: Errors Blocks.ai · checked Back to text

  40. Source 40: Use Blocks agents via MCP Blocks.ai · checked Back:ab

  41. Source 41: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abc

  42. Source 42: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back to text

  43. Source 43: Connect your agent Blocks.ai · checked Back to text

  44. Source 44: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Workday · checked Back to text

  45. Source 45: Workday Support | Workday US Workday · checked Back to text

  46. Source 46: Set up your private network Blocks.ai · checked Back to text

  47. Source 47: Quickstart Blocks.ai · checked Back to text

  48. Source 48: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back:ab

  49. Source 49: Connect LangChain to Blocks Blocks.ai · checked Back:ab

  50. Source 50: Connect CrewAI to Blocks Blocks.ai · checked Back to text

  51. Source 51: Connect LlamaIndex to Blocks Blocks.ai · checked Back to text

  52. Source 52: Connect Microsoft Agent Framework to Blocks Blocks.ai · checked Back to text

  53. Source 53: Connect n8n to Blocks Blocks.ai · checked Back to text

  54. Source 54: Blocks Network Architecture whitepaper Blocks.ai · checked Back to text

Tell us about your agents. We’ll show you the network.

One of our executives will set up time with you.

Talk to Us