Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

DIY vs Workday Agent System of Record: an in-house build or a Workday system of record for AI agents

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

DIY is not a product: you build agent connections and controls yourself, on protocols like MCP and A2A that leave authorization logic to the implementer.⁠Source 1, Source 2 Workday Agent System of Record (ASOR) is part of your Workday tenant: it registers agents built by Workday, partners, or you, with permissions set by Workday security policies and groups.⁠Source 3, Source 4, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both cover registering agents and controlling access: ASOR inside Workday, DIY through a registry service and authorization logic you build.⁠Source 1, Source 3, Source 4, Source 5, Source 6
Where they differ
ASOR is set up in each Workday tenant; self-hosting is not publicly documented.⁠Source 3 DIY runs where you put it, assembled from parts such as Istio and LangGraph.⁠Source 7, Source 8
Running both
Workday’s docs say ASOR manages self-built agents, and agents built outside Workday register only through its API, which records the platform each runs on, or OTHER.⁠Source 4, Source 9, Source 10
Public sources · checked 2 October 2026
  • Offered
  • You build it
  • Not publicly documented

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 11
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 8
  • Identity and access: You build itYour own identity provider⁠Source 12
  • Registry and governance: You build itYour own agent registry⁠Source 6
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 13
  • Agents across organizations: You build itA2A with API management⁠Source 14

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 15
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 4
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 16
  • Agents across organizations: Not publicly documented

At a glance

TopicDIYWorkday Agent System of Record
What it isAn in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which the A2A specification calls complementary.⁠Source 1A functional area you enable in each Workday tenant to find, add, register, configure, monitor, and manage AI agents.⁠Source 3, Source 4
Agents it coversWhatever you connect: A2A gives agents built with different frameworks or languages, or by different vendors, a common language.⁠Source 1Workday-built, partner-built, and self-built agents.⁠Source 4 Workday says some agents, including those for HiredScore and Evisort, are not part of ASOR.⁠Source 4
Agent identityYours to set up: in A2A, identity is established at the HTTP layer; MCP makes authorization optional.⁠Source 14, Source 17Each agent has a unique Workday identity, using Agent System User accounts, governed by Workday security policies and groups.⁠Source 5, Source 15
MaturityVaries by component: the latest MCP specification revision is 2026-07-28, and the official MCP Registry is in preview.⁠Source 2, Source 18Announced on 11 February 2025, while in development.⁠Source 19 Workday says it has been generally available since February 2026.⁠Source 20
PricingThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 21 Build and running costs are not publicly documented.ASOR needs no additional specific SKU.⁠Source 4 Workday-built agents in production need the Workday Flex Credits and Platform Entitlement Policy.⁠Source 4 Testing in non-production is free.⁠Source 22 Credit prices are not publicly documented.

What each one is

Build it yourself (DIY)

DIY means connecting and governing agents without buying an agent platform: protocols such as MCP and A2A wired together in-house, existing infrastructure stretched, an in-house platform, self-hosted open source, or no central approach; Pinterest, for one, runs its own MCP servers and a central registry.⁠Source 23

Workday Agent System of Record

Workday calls ASOR the single source of truth for a company’s AI agents, whether Workday, the customer, or a partner built them.⁠Source 20 Workday describes their lifecycle in ASOR as register, configure, activate, and deactivate.⁠Source 24 Each agent has a unique Workday identity.⁠Source 15

The differences that matter

  1. Agent registry

    DIY

    You build one: the current A2A specification prescribes no standard API for curated registries; Pinterest runs a central registry of MCP servers.⁠Source 6, Source 23

    Workday Agent System of Record

    Its Agent Registry lists registered agents with their status; external agents can currently be registered only through the ASOR API.⁠Source 4, Source 9

    The official MCP Registry is in preview and does not support private servers; its docs recommend hosting your own private registry for those.⁠Source 18

  2. Agent identity and access

    DIY

    In A2A, identity is established at the HTTP layer and authorization logic is implementation-specific; MCP makes authorization optional.⁠Source 1, Source 14, Source 17

    Workday Agent System of Record

    Each agent has a unique Workday identity; Workday security policies and groups control its access to secured items such as tools and APIs.⁠Source 5, Source 15, Source 25

    In ASOR’s delegate mode, where an agent acts for a user, access is the intersection of the user’s permissions and the agent’s allowed skills.⁠Source 15

  3. Agents at other companies

    DIY

    A2A enables agents built by different companies, on separate servers, to communicate, and each server authorizes requests under its own policies.⁠Source 1, Source 26

    Workday Agent System of Record

    Workday supports partner-built agents, and says ASOR’s accountability and governance apply to them, not just to Workday-delivered agents.⁠Source 4, Source 20

    For ASOR, access controls held by the partner company, rather than by you, are not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicDIYWorkday Agent System of Record
Network exposureMCP servers on Streamable HTTP expose an HTTP endpoint, and A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 27Third-party (self-built) agents call Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 4, Source 16 Delegate skills need a Redirect URI callback.⁠Source 28
IdentityIn A2A, identity is established at the HTTP layer, with credentials obtained out of band.⁠Source 1, Source 14 MCP authorization is optional.⁠Source 17Unique identity per agent.⁠Source 15 External agents use OAuth 2.0 or signed JWTs; third-party (self-built) agents’ tokens last 4 hours.⁠Source 15, Source 29
Access changes and revocationUp to your build: each A2A server authorizes requests under its own policies, in logic the specification calls implementation-specific.⁠Source 1Deactivating hides an agent from users.⁠Source 4 Workday says that can take up to a minute to reach Agent Gateway requests.⁠Source 16
Audit trailA2A docs advise auditing task creation, critical state changes, and agent actions, and tracing, for example with OpenTelemetry.⁠Source 14An audit trail report covers agent transactions and activity; delegated actions record both the agent and the user.⁠Source 15, Source 30
ComplianceSits with the implementer: A2A docs say to ensure compliance with privacy regulations such as GDPR, CCPA, and HIPAA.⁠Source 14Workday says its SOC 2 report covers Workday Enterprise Products and ISO 42001 covers Workday Platform; ASOR isn’t named.⁠Source 31

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

DIY and Workday Agent System of Record compared on 18 criteria
DIYWorkday Agent System of Record
What it is
What it is and who it’s forAn in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which the A2A specification calls complementary.⁠Source 1A functional area of the Workday tenant to find, add, register, configure, monitor, and manage AI agents.⁠Source 3, Source 4
MaturityVaries by component: MCP’s latest specification revision is 2026-07-28.⁠Source 2 The official MCP Registry is in preview; breaking changes may occur.⁠Source 18Announced on 11 February 2025, while in development.⁠Source 19 Workday says it has been generally available since February 2026.⁠Source 20
Control
Agent registry and discoveryBuild your own: the current A2A spec sets no standard API for curated registries; the official MCP Registry, in preview, doesn’t support private servers.⁠Source 6, Source 18The Agent Management Hub’s Agent Registry lists registered agents and their status.⁠Source 4 External agents can currently register only through the ASOR API.⁠Source 9
Identity and access controlIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 1, Source 14 MCP authorization is optional.⁠Source 17Each agent has a unique Workday identity, governed by Workday security policies and groups.⁠Source 5, Source 15 An Agent Interaction Policy sets who may invoke delegate skills.⁠Source 32
Ownership, policy, and revocationMCP says implementers should build consent and authorization flows.⁠Source 2 Uber starts every MCP server and tool disabled until its owning team reviews and enables it.⁠Source 13Agent accounts and OAuth clients stay off until activation; deactivation hides an agent.⁠Source 4, Source 5 Workday says changes can take up to a minute to reach Agent Gateway.⁠Source 16
Audit log and observabilityA2A docs advise auditing significant events and tracing, for example with OpenTelemetry.⁠Source 14 Pinterest’s MCP servers log inputs, outputs, and invocation counts.⁠Source 23An audit trail report covers agent transactions; delegated actions name the agent and the user.⁠Source 15, Source 30 Per-agent analytics reports: Workday-built agents only.⁠Source 4
Connection
How agents connectMCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 27 AWS PrivateLink privately connects a VPC to services.⁠Source 33Third-party (self-built) agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 4, Source 16 Private networking is not publicly documented.
Agents across organizationsA2A enables agents built by different companies on separate servers to communicate.⁠Source 26 Each server authorizes requests under its own policies.⁠Source 1Partner-built agents are supported, and Workday says its governance covers them too.⁠Source 4, Source 20 Access controls held by the partner are not publicly documented.
Protocol supportMCP defines stdio and Streamable HTTP transports.⁠Source 34 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 1API registration is based on the A2A Agent Card.⁠Source 10 Outside assistants can call the Self-Service Agent over A2A; tool search can filter by SOAP, REST, or MCP.⁠Source 35, Source 36
Frameworks, models, and clouds supportedA2A gives agents from different frameworks, languages, or vendors a common language.⁠Source 1 Google’s ADK says it is model-agnostic and deployment-agnostic.⁠Source 11Registration records the platform an agent runs on, or OTHER.⁠Source 10 Outside assistants, such as Google Gemini Enterprise, can call Workday’s Self-Service Agent.⁠Source 35
Operations
Deployment options and data residencyWherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 23 A2A docs say to protect stored data under your own policies.⁠Source 14Set up in each Workday tenant.⁠Source 3 Agent Gateway has endpoints in eight regions, including the US, EU, and UK.⁠Source 16 A self-hosted option is not publicly documented.
Compliance attestationsSits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA; MCP leaves access controls and data protection to implementers.⁠Source 2, Source 14Workday says its SOC 2 report covers Workday Enterprise Products.⁠Source 31 Its ISO 42001 certificate covers products including Workday Platform; ASOR isn’t named.⁠Source 31
Support and SLADepends on the component: MCP SDKs are tiered partly by maintenance commitments.⁠Source 37 The official MCP Registry, in preview, gives no uptime guarantees.⁠Source 38Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 39 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningA curated A2A registry is a service you deploy and maintain.⁠Source 6 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 23Enable the ASOR functional area and set its domain security policies.⁠Source 3 Registering an external agent needs the Workday IDs of its APIs, from a custom report.⁠Source 9
Pricing model and public pricesThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 21 Build and running costs are not publicly documented.ASOR needs no additional specific SKU.⁠Source 4 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 4 Credit prices are not publicly documented.
Building
Agent building toolsFrameworks such as LangGraph and Google’s open-source Agent Development Kit build and deploy agents.⁠Source 8, Source 11 A2A has SDKs in six languages.⁠Source 40ASOR takes external agent definitions through an API.⁠Source 4 Workday announced a low-code Flowise Agent Builder in its separate Workday Build.⁠Source 41
Model accessChosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.⁠Source 11Workday AI agents use large language models.⁠Source 4 Which models ASOR includes or supports is not publicly documented.
Integrations and ecosystemThe official MCP Registry, in preview, offers a REST API for MCP clients and aggregators to discover servers.⁠Source 18In February 2026, Workday said over 65 partners were connecting agents to ASOR.⁠Source 20 Workday announced partner agents on Workday Marketplace in June 2025.⁠Source 42

Which to choose

Choose DIY if

  • You already run a service mesh or internal access-control system and want it to check MCP calls, as Uber and Pinterest do.⁠Source 13, Source 23
  • You want your own review rules: Uber starts every MCP server and tool disabled until reviewed; Pinterest reviews all but one-off experiments.⁠Source 13, Source 23
  • Your agents call agents at other companies, and each company’s server should authorize requests under its own policies, as in A2A.⁠Source 1, Source 26
  • You want no agent platform contract: the A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 21

Choose Workday Agent System of Record if

  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.⁠Source 3, Source 4
  • You want each agent to have a unique Workday identity, governed by the security policies and groups you already use.⁠Source 5, Source 15
  • You want delegated agents limited to the intersection of the user’s permissions and the agent’s allowed skills, with audit records naming both.⁠Source 15
  • You want Workday-built, partner-built, and self-built agents managed in one hub, each with a Built By field naming its provider.⁠Source 4, Source 9

Questions buyers ask

Is Workday Agent System of Record an alternative to building it yourself?

Inside Workday, it covers the registry, a unique identity for each agent, permissions through Workday security policies, and an audit trail report.⁠Source 4, Source 5, Source 15, Source 30 Self-hosting, private networking, and access controls held by partner companies are not publicly documented.

Can Workday Agent System of Record manage agents I build myself?

Yes. Its Agent Management Hub manages self-built agents alongside Workday-built and partner-built ones.⁠Source 4 Agents built outside Workday are currently registered only through the ASOR API.⁠Source 9 Its per-agent analytics reports are only available for Workday-built agents.⁠Source 4

Does Workday Agent System of Record support A2A and MCP?

API registration is based on the A2A Agent Card, and assistants outside Workday, such as Google Gemini Enterprise, can call Workday’s Self-Service Agent over A2A.⁠Source 10, Source 35 Its resource search API can filter tools by type, including MCP.⁠Source 36 Protocol versions are not publicly documented.

How do the costs compare?

Workday says ASOR needs no additional specific SKU.⁠Source 4 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 4 Credit prices are not publicly documented. For DIY, the A2A and MCP specifications are openly licensed; build and running costs are not publicly documented.⁠Source 1, Source 21

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

46 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopqrst

  2. Source 2: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcde

  3. Source 3: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcdefgh

  4. Source 4: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz272829303132

  5. Source 5: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefgh

  6. Source 6: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcde

  7. Source 7: Security - Istio concepts istio.io · checked Back to text

  8. Source 8: langchain-ai/langgraph README (GitHub) github.com · checked Back:abc

  9. Source 9: Register External Agents (Workday Administrator Guide) Workday · checked Back:abcdefg

  10. Source 10: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcde

  11. Source 11: google/adk-python README (GitHub) github.com · checked Back:abcd

  12. Source 12: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back to text

  13. Source 13: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcd

  14. Source 14: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefghij

  15. Source 15: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijklm

  16. Source 16: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcdef

  17. Source 17: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  18. Source 18: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abcde

  19. Source 19: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back:ab

  20. Source 20: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abcdef

  21. Source 21: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcd

  22. Source 22: Workday Flex Credits | Workday US Workday · checked Back to text

  23. Source 23: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefg

  24. Source 24: Workday Agent System of Record | Workday US Workday · checked Back to text

  25. Source 25: Configure Security Policies for Agent Skills (Workday Administrator Guide) Workday · checked Back to text

  26. Source 26: a2aproject/A2A README (GitHub) github.com · checked Back:abc

  27. Source 27: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  28. Source 28: Configure External Agents (Workday Administrator Guide) Workday · checked Back to text

  29. Source 29: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  30. Source 30: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abc

  31. Source 31: Workday Compliance | Workday US Workday · checked Back:abc

  32. Source 32: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  33. Source 33: What is AWS PrivateLink? - Amazon Virtual Private Cloud docs.aws.amazon.com · checked Back to text

  34. Source 34: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  35. Source 35: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abcd

  36. Source 36: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  37. Source 37: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  38. Source 38: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  39. Source 39: Workday Support | Workday US Workday · checked Back to text

  40. Source 40: A2A protocol roadmap a2a-protocol.org · checked Back to text

  41. Source 41: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back to text

  42. Source 42: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back to text

  43. Source 43: Pricing Blocks.ai · checked Back to text

  44. Source 44: Your company's private network Blocks.ai · checked Back:ab

  45. Source 45: Network requirements Blocks.ai · checked Back to text

  46. Source 46: Solutions: Agent sprawl Blocks.ai · checked Back to text