Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Workday Agent System of Record vs Zenity
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Zenity AI Agent Security & Governance Platform
Security and governance platform for AI agents, aimed at security teams
Short answer
Workday Agent System of Record (ASOR) registers and manages AI agents in each Workday tenant; Zenity is a security platform that, it says, finds agents across platforms.Source 1, Source 2, Source 3, Source 4 ASOR gives each agent a unique Workday identity; Zenity says it can block actions on Copilot Studio, Microsoft Foundry, and coding agents.Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Zenity
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Identity and access: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Workday Agent System of Record
Workday Agent System of Record (ASOR) is a functional area of a Workday tenant for finding, registering, configuring, monitoring, and managing AI agents.Source 1, Source 2 Workday calls it the single source of truth for a company’s agents, whether Workday, the customer, or a partner built them.Source 17
Zenity AI Agent Security & Governance Platform
Zenity is a security and governance platform for AI agents, spanning SaaS, homegrown cloud platforms, and end-user devices.Source 3 Zenity says AI Observability catalogs agents and Runtime Boundaries can check agent actions against your rules.Source 4, Source 8 It is delivered as software as a service.Source 3
The differences that matter
How agents are added
Workday Agent System of RecordYou register agents: eligible Workday-built agents, and external agents through the ASOR API with the URL where each is hosted.Source 1, Source 9, Source 18
ZenityZenity says it discovers agents: AI Observability scans your environment and flags agents operating outside sanctioned deployment channels.Source 4
ASOR shows each agent’s status and who built it; Zenity says it lists each agent with its configuration, permissions, and tool access.Source 1, Source 4, Source 9
Identity and access
Workday Agent System of RecordEach agent has a unique Workday identity; acting for a user, it gets only what both the user’s permissions and its allowed skills permit.Source 5
ZenityZenity says its Boundaries rules can reference Okta attributes, such as active status and role, so policy reflects who is behind an action.Source 8
Whether Zenity issues agent identities or credentials isn’t in its public docs.
Stopping an agent
Workday Agent System of RecordAdmins can deactivate an agent, which hides it from users; if you suspect compromise, Workday says to disable the affected OAuth client.Source 1, Source 7
ZenityRuntime Boundaries can check agent actions in real time; Zenity says it can block actions only on Copilot Studio, Microsoft Foundry, and coding agents.Source 6, Source 8
Generated ASOR agent accounts and their OAuth clients stay disabled until the agent is activated.Source 15 Zenity says its kill switch immediately disables an agent’s tool and data access.Source 8
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Workday Agent System of Record | Zenity | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Set up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.Source 1, Source 2 | A SaaS security and governance platform for AI agents spanning SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.Source 3, Source 12 |
| Maturity | Announced in February 2025; generally available since February 2026.Source 17, Source 24 Agent Gateway was announced in June 2025.Source 25 | Zenity announced Azure Marketplace (now Microsoft Marketplace) availability in March 2025 and AWS in January 2026.Source 26, Source 27, Source 28 |
| Control | ||
| Agent registry and discovery | The Agent Management Hub lists registered Workday-built, partner-built, and self-built agents with their status.Source 1 HiredScore and Evisort agents are not in ASOR.Source 1 | Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and on laptops, with their permissions and tool access.Source 4 |
| Identity and access control | Each agent has a unique Workday identity, governed by security policies and groups.Source 5, Source 15 An Agent Interaction Policy sets which users may use delegate-mode skills.Source 29 | Zenity says Boundaries rules can reference Okta attributes such as active status, role, and department.Source 8 Issuing agent identities isn’t in Zenity’s public docs. |
| Ownership, policy, and revocation | Admins set each agent’s skills and who can use it, and activate or deactivate it.Source 1, Source 13 A deactivated agent is hidden from users and can be reactivated.Source 1 | Zenity says rules can allow an action, block it, or shut the agent down, but it blocks inline only on Copilot Studio, Microsoft Foundry, and coding agents.Source 6, Source 8 |
| Audit log and observability | An audit trail report covers agent transactions; delegated actions record the agent and the user.Source 5, Source 7 Per-agent analytics reports cover Workday-built agents only.Source 1 | Zenity says it logs agent messages, tool calls, retrievals, and handoffs.Source 4 It says its audit log events can stream to Splunk or Microsoft Sentinel.Source 20 |
| Connection | ||
| How agents connect | Third-party agents must route Workday API traffic through Agent Gateway, a single regional endpoint.Source 10 Outbound-only use is not publicly documented. | Zenity says agents emitting OpenTelemetry or gen_ai spans can connect, with an Evaluate API for inline enforcement.Source 20 Network needs: not in Zenity’s public docs. |
| Agents across organizations | Partner-built agents are supported, and Workday says its governance covers them too.Source 1, Source 17 Partner-held access controls are not publicly documented. | Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)Source 14 |
| Protocol support | API registration is based on the A2A Agent Card.Source 18 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.Source 30, Source 31 | Zenity says custom agents can connect by emitting OpenTelemetry or gen_ai spans.Source 20 Whether Zenity supports A2A isn’t publicly documented. |
| Frameworks, models, and clouds supported | API registration records each agent’s platform, or OTHER.Source 18 Workday names Google Gemini Enterprise as an outside assistant able to call its Self-Service Agent.Source 30 | Zenity says it blocks inline on Copilot Studio, Microsoft Foundry, and coding agents; elsewhere, such as Agentforce, it offers detection and posture only.Source 6 |
| Operations | ||
| Deployment options and data residency | Set up in each Workday tenant.Source 2 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.Source 10 Self-hosting: not publicly documented. | Software as a service, shown on AWS Marketplace as deployed on AWS.Source 3 Regions, data residency, and self-hosting aren’t in Zenity’s public docs. |
| Compliance attestations | Workday says its SOC 2 report covers Workday Enterprise Products.Source 21 Its ISO 42001 certificate covers named products including Workday Platform; ASOR isn’t named.Source 21 | Zenity says the company holds SOC 2 Type II certification and is ISO 27001 compliant.Source 22 It announced FedRAMP “In Process” status in March 2026.Source 23 |
| Support and SLA | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 32 An ASOR uptime SLA is not publicly documented. | Zenity’s terms commit to at least 99.9% monthly uptime, with commercially reasonable efforts.Source 33 Support requests go through Zendesk in business hours.Source 33 |
| Time and effort to get running | Enable the ASOR functional area and set its security policies.Source 2 Registering an external agent includes finding the IDs of the Workday APIs it will use.Source 9 | Zenity says it has custom-agent guides for Cribl, LiteLLM, and Kong, and a Cursor plugin.Source 20, Source 34 Prerequisites aren’t in Zenity’s public docs. |
| Pricing model and public prices | No additional specific SKU for ASOR.Source 1 Workday-built agents in production need a Flex Credits policy opt-in.Source 1 A credit’s price is not publicly documented. | Main AWS listing: custom pricing.Source 3 Security Hub Extended listing: Observability $130 per resource a month, Runtime Protection $16 per million tokens a month.Source 16 |
| Building | ||
| Agent building tools | You provide an external agent’s definition through an API.Source 1 Workday announced the low-code Flowise Agent Builder for Workday’s separate Workday Build in 2025.Source 35 | Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)Source 14 |
| Model access | Workday’s AI agents use large language models.Source 1 Which models ASOR supports or includes is not publicly documented. | Zenity says its threat detection combines rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.Source 36 The models used aren’t in Zenity’s public docs. |
| Integrations and ecosystem | In February 2026, Workday said more than 65 partners were connecting agents to ASOR.Source 17 Workday says partner agents reached its Marketplace in June 2025.Source 25 | Zenity says its signals can show in Microsoft Agent 365 and findings in AWS Security Hub Extended; it is on the Cursor Marketplace.Source 34, Source 37, Source 38 |
Which to choose
Choose Workday Agent System of Record if
- You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.Source 1, Source 2
- You want each agent to have a unique Workday identity, governed by the security policies and groups you already use.Source 5, Source 15
- You want an agent acting for a user limited to what both may do, with audit entries naming both.Source 5
- You want outside assistants, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A for authorized users.Source 30
Choose Zenity if
- Your security team needs one inventory of agents across platforms such as Copilot Studio and Agentforce, which Zenity says it builds.Source 4, Source 12
- You want what Zenity says it offers: agents found by scanning, with flags for agents outside sanctioned deployment channels.Source 4
- You want the rule checks Zenity says it runs on agent actions, blocking inline on Copilot Studio, Microsoft Foundry, and coding agents.Source 6, Source 8
- You want what Zenity says it offers: audit log events in Splunk or Microsoft Sentinel, or findings in AWS Security Hub Extended.Source 20, Source 38
Questions buyers ask
Can Workday Agent System of Record manage agents built outside Workday?
Which agents can Zenity cover?
Zenity says AI Observability inventories agents inside platforms such as Copilot Studio, ChatGPT Enterprise, and Agentforce, and homegrown agents on frameworks such as Azure AI Foundry and AWS Bedrock.Source 4 On Amazon Bedrock AgentCore, Zenity says security teams can instrument agent code to enforce inline controls.Source 39
Do they support A2A and MCP?
ASOR’s registration API is based on the A2A Agent Card, outside assistants can call Workday’s Self-Service Agent over A2A, and tool search can filter by MCP.Source 18, Source 30, Source 31 Whether Zenity supports A2A isn’t publicly documented. Zenity says its agent hooks can block coding agents’ dangerous tool calls.Source 11
How is each one priced?
ASOR needs no additional specific SKU.Source 1 Workday-built agents in production need a Flex Credits policy opt-in.Source 1 A credit’s price is not publicly documented. Zenity’s main AWS Marketplace listing has custom pricing.Source 3 Its Security Hub Extended listing shows usage prices per resource and per million tokens.Source 16
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
44 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz272829
Source 2: Set Up Agent System of Record (Workday Administrator Guide) Back:abcdefgh
Source 4: AI Observability | See Every Agent, Know What it Touches | Zenity Back:abcdefghijklm
Source 5: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijkl
Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Back:abcdef
Source 7: FAQ: Agent Security (Workday Administrator Guide) Back:abcd
Source 8: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Back:abcdefghijkl
Source 9: Register External Agents (Workday Administrator Guide) Back:abcde
Source 10: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcde
Source 12: Platform | AI Agent Security & Governance Platform | Zenity Back:abcd
Source 13: Workday Agent System of Record | Workday US Back:ab
Source 15: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcd
Source 16: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Back:abc
Source 17: The Workday Agent System of Record Is Now Generally Available Back:abcd
Source 18: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcd
Source 19: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 20: From Triage to Full Coverage: The Shift AI Agent Security Took in August Back:abcdef
Source 23: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Back:ab
Source 24: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back to text
Source 25: Workday Announces New AI Agent Partner Network and Agent Gateway Back:ab
Source 26: Zenity Now Available in the Microsoft Azure Marketplace Back to text
Source 27: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Back to text
Source 28: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Back to text
Source 29: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 30: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abcd
Source 31: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back:ab
Source 33: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Back:ab
Source 34: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Back:ab
Source 35: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Back to text
Source 36: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Back to text
Source 37: Zenity Now Integrates with Microsoft Agent 365 Back to text
Source 38: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Back:ab
Source 39: Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore Back to text