Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
DIY vs Workday Agent System of Record: an in-house build or a Workday system of record for AI agents
Build it yourself (DIY)
Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Short answer
DIY is not a product: you build agent connections and controls yourself, on protocols like MCP and A2A that leave authorization logic to the implementer.Source 1, Source 2 Workday Agent System of Record (ASOR) is part of your Workday tenant: it registers agents built by Workday, partners, or you, with permissions set by Workday security policies and groups.Source 3, Source 4, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
DIY
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Build it yourself (DIY)
DIY means connecting and governing agents without buying an agent platform: protocols such as MCP and A2A wired together in-house, existing infrastructure stretched, an in-house platform, self-hosted open source, or no central approach; Pinterest, for one, runs its own MCP servers and a central registry.Source 23
Workday Agent System of Record
Workday calls ASOR the single source of truth for a company’s AI agents, whether Workday, the customer, or a partner built them.Source 20 Workday describes their lifecycle in ASOR as register, configure, activate, and deactivate.Source 24 Each agent has a unique Workday identity.Source 15
The differences that matter
Agent registry
DIYYou build one: the current A2A specification prescribes no standard API for curated registries; Pinterest runs a central registry of MCP servers.Source 6, Source 23
Workday Agent System of RecordIts Agent Registry lists registered agents with their status; external agents can currently be registered only through the ASOR API.Source 4, Source 9
The official MCP Registry is in preview and does not support private servers; its docs recommend hosting your own private registry for those.Source 18
Agent identity and access
DIYIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific; MCP makes authorization optional.Source 1, Source 14, Source 17
Workday Agent System of RecordEach agent has a unique Workday identity; Workday security policies and groups control its access to secured items such as tools and APIs.Source 5, Source 15, Source 25
In ASOR’s delegate mode, where an agent acts for a user, access is the intersection of the user’s permissions and the agent’s allowed skills.Source 15
Agents at other companies
DIYA2A enables agents built by different companies, on separate servers, to communicate, and each server authorizes requests under its own policies.Source 1, Source 26
Workday Agent System of RecordWorkday supports partner-built agents, and says ASOR’s accountability and governance apply to them, not just to Workday-delivered agents.Source 4, Source 20
For ASOR, access controls held by the partner company, rather than by you, are not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| DIY | Workday Agent System of Record | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | An in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which the A2A specification calls complementary.Source 1 | A functional area of the Workday tenant to find, add, register, configure, monitor, and manage AI agents.Source 3, Source 4 |
| Maturity | Varies by component: MCP’s latest specification revision is 2026-07-28.Source 2 The official MCP Registry is in preview; breaking changes may occur.Source 18 | Announced on 11 February 2025, while in development.Source 19 Workday says it has been generally available since February 2026.Source 20 |
| Control | ||
| Agent registry and discovery | Build your own: the current A2A spec sets no standard API for curated registries; the official MCP Registry, in preview, doesn’t support private servers.Source 6, Source 18 | The Agent Management Hub’s Agent Registry lists registered agents and their status.Source 4 External agents can currently register only through the ASOR API.Source 9 |
| Identity and access control | In A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.Source 1, Source 14 MCP authorization is optional.Source 17 | Each agent has a unique Workday identity, governed by Workday security policies and groups.Source 5, Source 15 An Agent Interaction Policy sets who may invoke delegate skills.Source 32 |
| Ownership, policy, and revocation | MCP says implementers should build consent and authorization flows.Source 2 Uber starts every MCP server and tool disabled until its owning team reviews and enables it.Source 13 | Agent accounts and OAuth clients stay off until activation; deactivation hides an agent.Source 4, Source 5 Workday says changes can take up to a minute to reach Agent Gateway.Source 16 |
| Audit log and observability | A2A docs advise auditing significant events and tracing, for example with OpenTelemetry.Source 14 Pinterest’s MCP servers log inputs, outputs, and invocation counts.Source 23 | An audit trail report covers agent transactions; delegated actions name the agent and the user.Source 15, Source 30 Per-agent analytics reports: Workday-built agents only.Source 4 |
| Connection | ||
| How agents connect | MCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.Source 1, Source 27 AWS PrivateLink privately connects a VPC to services.Source 33 | Third-party (self-built) agents reach Workday APIs through Agent Gateway, a single regional endpoint.Source 4, Source 16 Private networking is not publicly documented. |
| Agents across organizations | A2A enables agents built by different companies on separate servers to communicate.Source 26 Each server authorizes requests under its own policies.Source 1 | Partner-built agents are supported, and Workday says its governance covers them too.Source 4, Source 20 Access controls held by the partner are not publicly documented. |
| Protocol support | MCP defines stdio and Streamable HTTP transports.Source 34 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.Source 1 | API registration is based on the A2A Agent Card.Source 10 Outside assistants can call the Self-Service Agent over A2A; tool search can filter by SOAP, REST, or MCP.Source 35, Source 36 |
| Frameworks, models, and clouds supported | A2A gives agents from different frameworks, languages, or vendors a common language.Source 1 Google’s ADK says it is model-agnostic and deployment-agnostic.Source 11 | Registration records the platform an agent runs on, or OTHER.Source 10 Outside assistants, such as Google Gemini Enterprise, can call Workday’s Self-Service Agent.Source 35 |
| Operations | ||
| Deployment options and data residency | Wherever you run it: Pinterest optimized for MCP servers in its internal cloud.Source 23 A2A docs say to protect stored data under your own policies.Source 14 | Set up in each Workday tenant.Source 3 Agent Gateway has endpoints in eight regions, including the US, EU, and UK.Source 16 A self-hosted option is not publicly documented. |
| Compliance attestations | Sits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA; MCP leaves access controls and data protection to implementers.Source 2, Source 14 | Workday says its SOC 2 report covers Workday Enterprise Products.Source 31 Its ISO 42001 certificate covers products including Workday Platform; ASOR isn’t named.Source 31 |
| Support and SLA | Depends on the component: MCP SDKs are tiered partly by maintenance commitments.Source 37 The official MCP Registry, in preview, gives no uptime guarantees.Source 38 | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 39 An ASOR uptime SLA is not publicly documented. |
| Time and effort to get running | A curated A2A registry is a service you deploy and maintain.Source 6 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.Source 23 | Enable the ASOR functional area and set its domain security policies.Source 3 Registering an external agent needs the Workday IDs of its APIs, from a custom report.Source 9 |
| Pricing model and public prices | The A2A and MCP specifications are openly licensed, A2A under Apache 2.0.Source 1, Source 21 Build and running costs are not publicly documented. | ASOR needs no additional specific SKU.Source 4 Workday-built agents in production need a Flex Credits policy opt-in.Source 4 Credit prices are not publicly documented. |
| Building | ||
| Agent building tools | Frameworks such as LangGraph and Google’s open-source Agent Development Kit build and deploy agents.Source 8, Source 11 A2A has SDKs in six languages.Source 40 | ASOR takes external agent definitions through an API.Source 4 Workday announced a low-code Flowise Agent Builder in its separate Workday Build.Source 41 |
| Model access | Chosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.Source 11 | Workday AI agents use large language models.Source 4 Which models ASOR includes or supports is not publicly documented. |
| Integrations and ecosystem | The official MCP Registry, in preview, offers a REST API for MCP clients and aggregators to discover servers.Source 18 | In February 2026, Workday said over 65 partners were connecting agents to ASOR.Source 20 Workday announced partner agents on Workday Marketplace in June 2025.Source 42 |
Which to choose
Choose DIY if
- You already run a service mesh or internal access-control system and want it to check MCP calls, as Uber and Pinterest do.Source 13, Source 23
- You want your own review rules: Uber starts every MCP server and tool disabled until reviewed; Pinterest reviews all but one-off experiments.Source 13, Source 23
- Your agents call agents at other companies, and each company’s server should authorize requests under its own policies, as in A2A.Source 1, Source 26
- You want no agent platform contract: the A2A and MCP specifications are openly licensed, A2A under Apache 2.0.Source 1, Source 21
Choose Workday Agent System of Record if
- You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.Source 3, Source 4
- You want each agent to have a unique Workday identity, governed by the security policies and groups you already use.Source 5, Source 15
- You want delegated agents limited to the intersection of the user’s permissions and the agent’s allowed skills, with audit records naming both.Source 15
- You want Workday-built, partner-built, and self-built agents managed in one hub, each with a Built By field naming its provider.Source 4, Source 9
Questions buyers ask
Is Workday Agent System of Record an alternative to building it yourself?
Can Workday Agent System of Record manage agents I build myself?
Does Workday Agent System of Record support A2A and MCP?
API registration is based on the A2A Agent Card, and assistants outside Workday, such as Google Gemini Enterprise, can call Workday’s Self-Service Agent over A2A.Source 10, Source 35 Its resource search API can filter tools by type, including MCP.Source 36 Protocol versions are not publicly documented.
How do the costs compare?
Workday says ASOR needs no additional specific SKU.Source 4 Workday-built agents in production need a Flex Credits policy opt-in.Source 4 Credit prices are not publicly documented. For DIY, the A2A and MCP specifications are openly licensed; build and running costs are not publicly documented.Source 1, Source 21
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
46 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Agent2Agent (A2A) Protocol Specification Back:abcdefghijklmnopqrst
Source 2: Specification - Model Context Protocol 2026-07-28 Back:abcde
Source 3: Set Up Agent System of Record (Workday Administrator Guide) Back:abcdefgh
Source 4: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz272829303132
Source 5: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcdefgh
Source 9: Register External Agents (Workday Administrator Guide) Back:abcdefg
Source 10: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcde
Source 12: Integrating with Model Context Protocol (MCP) - Keycloak Back to text
Source 13: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog Back:abcd
Source 14: Enterprise Features - A2A Protocol Back:abcdefghij
Source 15: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijklm
Source 16: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcdef
Source 17: Authorization - Model Context Protocol specification 2026-07-28 Back:abcd
Source 18: The MCP Registry - Model Context Protocol Back:abcde
Source 19: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back:ab
Source 20: The Workday Agent System of Record Is Now Generally Available Back:abcdef
Source 21: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) Back:abcd
Source 23: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog Back:abcdefg
Source 24: Workday Agent System of Record | Workday US Back to text
Source 25: Configure Security Policies for Agent Skills (Workday Administrator Guide) Back to text
Source 27: Streamable HTTP - Model Context Protocol specification 2026-07-28 Back:ab
Source 28: Configure External Agents (Workday Administrator Guide) Back to text
Source 29: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 30: FAQ: Agent Security (Workday Administrator Guide) Back:abc
Source 32: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 33: What is AWS PrivateLink? - Amazon Virtual Private Cloud Back to text
Source 34: Transports - Model Context Protocol specification 2026-07-28 Back to text
Source 35: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abcd
Source 36: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back:ab
Source 38: MCP Registry Aggregators - Model Context Protocol Back to text
Source 41: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Back to text
Source 42: Workday Announces New AI Agent Partner Network and Agent Gateway Back to text