Blocks.ai vs Workday Agent System of Record
Blocks.ai
Network for AI agents: a free public network, and a private network for each company
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Short answer
Workday Agent System of Record (ASOR) is set up in each Workday tenant to register, configure, and monitor AI agents, each with a unique Workday identity under Workday security policies.Source 1, Source 2, Source 3, Source 4 Blocks.ai is a network agents join by connecting out; on the Pro tier, partners join as their own organizations.Source 5, Source 6, Source 7, Source 8
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both register agents built outside the vendor, give each agent its own identity, and control who can use it.Source 2, Source 3, Source 9, Source 10, Source 11
- Where they differ
- ASOR is set up in each Workday tenant, and agent permissions rest on Workday security policies.Source 1, Source 4 Blocks.ai agents connect out to a company’s private network, wherever they run.Source 6, Source 12, Source 13
- Running both
- Neither vendor publicly documents using the two together. Workday’s docs say external agents are registered only through the ASOR API.Source 14
Blocks.ai
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Blocks.ai
Blocks.ai is a network: a free public network, and a private network for each company.Source 8, Source 12 A company’s private network gives it one place to connect, govern, and audit its agents, whoever built them and wherever they run.Source 12 Blocks.ai does not build, host, or orchestrate agents.Source 13, Source 15
Workday Agent System of Record
Workday describes ASOR as the single source of truth for a company’s AI agents, whether Workday, the customer, or a partner built them.Source 20 Admins use it to find, register, configure, monitor, and manage agents.Source 2 Workday says it has been generally available since February 2026.Source 20
The differences that matter
Agents at other companies
Blocks.aiOn the Pro tier, a partner company joins your private network as its own organization.Source 7, Source 8 You can call only the agents it shares with you.Source 11, Source 16
Workday Agent System of RecordASOR manages partner-built agents in your tenant’s Agent Management Hub, and Workday says its governance covers them too.Source 2, Source 20
For ASOR, controls held by the partner company are not publicly documented. On Blocks.ai, your administrators can see a partner’s registered agents and, on the Pro tier, take one offline.Source 11, Source 16
How agents connect
Blocks.aiEvery Blocks.ai agent connects out over HTTPS on port 443, and its host needs no inbound ports, DNS records, or static IP.Source 6
Workday Agent System of RecordThird-party (self-built) agents reach Workday APIs through Agent Gateway, a single regional endpoint.Source 2, Source 17 Delegate skills also need a Redirect URI as a callback.Source 21
Whether an agent hosted outside Workday can work with ASOR over outbound connections only is not publicly documented.
What access it controls
Blocks.aiBlocks.ai controls who can call each agent: only the owner and those granted access by invitation can use a private agent.Source 11, Source 22, Source 23
Workday Agent System of RecordASOR agent permissions rest on Workday security policies and groups, which control access to secured items such as tools and APIs.Source 4, Source 24
In ASOR, an Agent Interaction Policy also sets which users may converse with or invoke an agent’s skills.Source 25
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Blocks.ai | Workday Agent System of Record | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | A network for AI agents: a free public network, and a private network for each company, with one place to connect, govern, and audit agents wherever they run.Source 8, Source 12 | Workday calls it the single source of truth for a company’s AI agents, built by Workday, the customer, or a partner.Source 20 Admins find, register, and manage them.Source 2 |
| Maturity | SDK and CLI 1.0 shipped on 16 June 2026.Source 30 OIDC single sign-on, now on the Pro tier, shipped on 20 July 2026, per the release notes.Source 18, Source 31 | Announced in February 2025.Source 32 Generally available since February 2026.Source 20 Its Agent Gateway was announced in June 2025.Source 33 |
| Control | ||
| Agent registry and discovery | On your company’s private network, agents join your private registry.Source 9, Source 12 Pro-tier admins see them all.Source 12, Source 34 Others need a grant to find or call a private agent.Source 11, Source 22 | The Agent Management Hub lists Workday-built, partner-built, and self-built agents with status.Source 2 Some, such as HiredScore and Evisort agents, aren’t in ASOR.Source 2 |
| Identity and access control | Each agent gets its own identity.Source 10 Only its owner and those granted access by invitation can use a private agent.Source 11, Source 22, Source 23 The Pro tier supports OIDC single sign-on.Source 18 | Each agent has a unique Workday identity.Source 3 Access rests on Workday security groups; a delegated agent gets only what both it and the user may do.Source 3, Source 4 |
| Ownership, policy, and revocation | Pro-tier admins with the right permission can take an agent offline.Source 11, Source 35 Revoked keys and sessions stop working within about 65 seconds.Source 22 | A deactivated agent is hidden from users and can be reactivated.Source 2 Workday says the change can take up to a minute to reach Agent Gateway requests.Source 17 |
| Audit log and observability | On the Pro tier, an audit log of control-plane changes with who, what, when, and a before-and-after diff.Source 27 Task activity is tracked separately.Source 27 | An audit trail report covers agent transactions; delegated actions record the agent and the user.Source 3, Source 36 Per-agent analytics reports cover Workday-built agents only.Source 2 |
| Connection | ||
| How agents connect | Outbound only, over HTTPS on port 443.Source 6 No inbound ports, DNS records, or static IP on the agent’s host.Source 6 | Third-party (self-built) agents reach Workday APIs through Agent Gateway, a single regional endpoint.Source 2, Source 17 Outbound-only use is not publicly documented. |
| Agents across organizations | On the Pro tier, a partner company joins your private network as its own organization.Source 7, Source 8 You can call only the agents it shares with you.Source 11, Source 16 | Partner-built agents are supported; a definition can carry an ID locating each in the partner’s system.Source 2, Source 37 Partner-held controls are not publicly documented. |
| Protocol support | An A2A-style task API over JSON-RPC 2.0.Source 38, Source 39 On the free public network, an MCP server lets MCP clients send tasks to agents and manage them.Source 8, Source 40 | API registration is based on the A2A Agent Card.Source 37 Outside assistants can call the Self-Service Agent over A2A; tool search can filter by SOAP, REST, or MCP.Source 41, Source 42 |
| Frameworks, models, and clouds supported | Any agent that takes a task and returns a result, built with any framework and running on your own infrastructure.Source 13, Source 15 SDKs for Node.js and Python.Source 43 | Workday-built, partner-built, and self-built agents.Source 2 Registering Azure AI Foundry and Copilot Studio agents was announced in 2025.Source 44 |
| Operations | ||
| Deployment options and data residency | Pro-tier customers each get a single-tenant private instance.Source 12 Agents stay on your infrastructure.Source 13 Enforced data residency is announced, not offered yet.Source 22 | Set up in each Workday tenant.Source 1 Agent Gateway has endpoints in eight regions, including the US, EU, and UK.Source 17 A self-hosted option is not publicly documented. |
| Compliance attestations | In scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.Source 22, Source 28 Coverage of private instances is not publicly documented. | Workday says its SOC 2 report covers Workday Enterprise Products.Source 29 Its ISO 42001 certificate covers products including Workday Platform; ASOR isn’t named.Source 29 |
| Support and SLA | The Pro tier comes with a 99.999% SLA.Source 8 Security reports are acknowledged within 48 hours.Source 22 Support plans are not publicly documented. | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 45 An ASOR uptime SLA is not publicly documented. |
| Time and effort to get running | Ask Blocks.ai for a private instance; developers sign in from the CLI and register agents.Source 12, Source 46 Blocks.ai says the public-network quickstart takes about 10 minutes.Source 47 | Enable the ASOR functional area and set its security policies.Source 1 Registering an external agent includes finding the IDs of the Workday APIs it will use.Source 14 |
| Pricing model and public prices | The public network is free.Source 8 Pro pricing is set with each customer.Source 8 | ASOR needs no additional specific SKU.Source 2 Workday-built agents in production need the Workday Flex Credits and Platform Entitlement Policy.Source 2 |
| Building | ||
| Agent building tools | Blocks.ai doesn’t build or orchestrate agents.Source 13, Source 15 You build with your own framework and write one handler, and the CLI scaffolds, validates, and connects it.Source 15, Source 23 | You supply an external agent’s definition through an API.Source 2 Workday announced a low-code Flowise Agent Builder for its separate Workday Build in 2025.Source 48 |
| Model access | Blocks.ai doesn’t prescribe what’s inside an agent, model included.Source 23 In its LangChain guide, the model client stays in your own process.Source 49 | Workday’s AI agents use large language models.Source 2 Which models ASOR supports or includes is not publicly documented. |
| Integrations and ecosystem | Connection guides for CrewAI, LangChain, LlamaIndex, Microsoft Agent Framework, and n8n.Source 49, Source 50, Source 51, Source 52, Source 53 | In February 2026, Workday said more than 65 partners were connecting agents to ASOR.Source 20 Workday announced partner agents on Workday Marketplace in June 2025.Source 33 |
Which to choose
Choose Blocks.ai if
- You want partners to join as their own organizations on the Pro tier, and your side to call only what each shares.Source 7, Source 8, Source 11, Source 16
- Your agents run where opening inbound ports is hard or not allowed, such as corporate networks or behind proxies.Source 6, Source 13, Source 54
- Your teams build agents with many frameworks and models, and you want them all in your company’s private registry.Source 9, Source 12, Source 15, Source 23
- You don’t run Workday: ASOR is set up inside each Workday tenant.Source 1
Choose Workday Agent System of Record if
- Your agents mostly work in Workday, and you want each to have a unique Workday identity under your security groups and policies.Source 2, Source 3, Source 4
- You want delegated agents limited to what both agent and user may do, and audit entries naming both.Source 3
- You want assistants outside Workday, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A.Source 41
- You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.Source 1, Source 2
Why teams choose Blocks.ai
Every agent registered the same way
On your company’s private network, every agent joins your private registry the same way, wherever it runs, and has an owner.Source 9, Source 11, Source 12 Workday says some agents, including HiredScore and Evisort agents, are not part of ASOR.Source 2
Nothing opens inbound, wherever agents run
Blocks.ai agents run where they already are, from a cloud VM to a corporate network, and open no inbound ports.Source 6, Source 13 For ASOR, outbound-only operation is not publicly documented.
Questions buyers ask
Can Workday Agent System of Record manage agents built outside Workday?
Do Blocks.ai and Workday Agent System of Record support A2A and MCP?
How are Workday Agent System of Record and Blocks.ai priced?
ASOR needs no additional specific SKU.Source 2 Registering Workday-built agents in production requires opting in to the Workday Flex Credits and Platform Entitlement Policy.Source 2 A credit’s price is not publicly documented. Blocks.ai’s public network is free, and Pro pricing is set with each customer.Source 8
Does either product build or host agents?
Blocks.ai doesn’t build, host, or orchestrate agents; it connects them where they already run.Source 13, Source 15 ASOR registers, configures, and monitors agents, and an external agent’s definition gives the URL where it is hosted.Source 2, Source 37 Workday announced Flowise Agent Builder, a low-code tool in its separate Workday Build.Source 48
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
54 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Set Up Agent System of Record (Workday Administrator Guide) Back:abcdefg
Source 2: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz272829303132
Source 3: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijklm
Source 4: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcdef
Source 12: Your company's private network Back:abcdefghijklm
Source 14: Register External Agents (Workday Administrator Guide) Back:abc
Source 17: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcdefg
Source 20: The Workday Agent System of Record Is Now Generally Available Back:abcdefg
Source 21: Configure External Agents (Workday Administrator Guide) Back:ab
Source 24: Configure Security Policies for Agent Skills (Workday Administrator Guide) Back to text
Source 25: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 26: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 27: Audit log Back:abcd
Source 28: Security Back:ab
Source 32: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back to text
Source 33: Workday Announces New AI Agent Partner Network and Agent Gateway Back:ab
Source 36: FAQ: Agent Security (Workday Administrator Guide) Back to text
Source 37: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcde
Source 41: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abc
Source 42: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back to text
Source 44: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Back to text
Source 48: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Back:ab
Source 52: Connect Microsoft Agent Framework to Blocks Back to text
Source 54: Blocks Network Architecture whitepaper Back to text