Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Workday Agent System of Record vs Zenity

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

Workday Agent System of Record (ASOR) registers and manages AI agents in each Workday tenant; Zenity is a security platform that, it says, finds agents across platforms.⁠Source 1, Source 2, Source 3, Source 4 ASOR gives each agent a unique Workday identity; Zenity says it can block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
ASOR keeps an inventory of agents, records their activity, and can deactivate one; Zenity says it inventories agents, logs activity, and can block actions or shut agents down.⁠Source 1, Source 4, Source 7, Source 8
Where they differ
Each ASOR agent gets a unique Workday identity; for agents working with Workday, tools are Workday APIs.⁠Source 1, Source 5 Zenity says it blocks inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6
Running both
Workday’s docs say ASOR registers outside agents through its API; Zenity says it catalogs agents it finds by scanning.⁠Source 4, Source 9 Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 5
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 1
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 10
  • Agents across organizations: Not publicly documented

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 4
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 11
  • Agents across organizations: Not publicly documented

At a glance

TopicWorkday Agent System of RecordZenity
What it isA functional area you enable in each Workday tenant to find, add, register, configure, monitor, and manage AI agents.⁠Source 1, Source 2A SaaS security and governance platform for AI agents, which Zenity aims at security teams.⁠Source 3, Source 12
Who it’s forIT and business leaders who want visibility into, and accountability for, agents in the workforce, per Workday.⁠Source 13Security teams that need to discover and inventory agents, enforce policies, and reduce unmanaged risk, per Zenity.⁠Source 12
Where it runsInside each Workday tenant, set up separately; there is no current way to migrate ASOR configuration between tenants.⁠Source 2 A self-hosted option is not publicly documented.Software as a service, shown on AWS Marketplace as deployed on AWS.⁠Source 3 Self-hosting isn’t in Zenity’s public docs; its product docs require a login.⁠Source 14
Agent identityA unique Workday identity per agent, using Agent System User accounts governed by Workday security policies and groups.⁠Source 5, Source 15Zenity says Boundaries rules can use Okta attributes such as active status and role.⁠Source 8 Issuing agent identities isn’t in Zenity’s public docs.
Pricing modelNo additional specific SKU for ASOR.⁠Source 1 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 1 A credit’s price is not publicly documented.Custom pricing on its main AWS Marketplace listing; a Security Hub Extended listing shows usage prices per resource and per million tokens.⁠Source 3, Source 16

What each one is

Workday Agent System of Record

Workday Agent System of Record (ASOR) is a functional area of a Workday tenant for finding, registering, configuring, monitoring, and managing AI agents.⁠Source 1, Source 2 Workday calls it the single source of truth for a company’s agents, whether Workday, the customer, or a partner built them.⁠Source 17

Zenity AI Agent Security & Governance Platform

Zenity is a security and governance platform for AI agents, spanning SaaS, homegrown cloud platforms, and end-user devices.⁠Source 3 Zenity says AI Observability catalogs agents and Runtime Boundaries can check agent actions against your rules.⁠Source 4, Source 8 It is delivered as software as a service.⁠Source 3

The differences that matter

  1. How agents are added

    Workday Agent System of Record

    You register agents: eligible Workday-built agents, and external agents through the ASOR API with the URL where each is hosted.⁠Source 1, Source 9, Source 18

    Zenity

    Zenity says it discovers agents: AI Observability scans your environment and flags agents operating outside sanctioned deployment channels.⁠Source 4

    ASOR shows each agent’s status and who built it; Zenity says it lists each agent with its configuration, permissions, and tool access.⁠Source 1, Source 4, Source 9

  2. Identity and access

    Workday Agent System of Record

    Each agent has a unique Workday identity; acting for a user, it gets only what both the user’s permissions and its allowed skills permit.⁠Source 5

    Zenity

    Zenity says its Boundaries rules can reference Okta attributes, such as active status and role, so policy reflects who is behind an action.⁠Source 8

    Whether Zenity issues agent identities or credentials isn’t in its public docs.

  3. Stopping an agent

    Workday Agent System of Record

    Admins can deactivate an agent, which hides it from users; if you suspect compromise, Workday says to disable the affected OAuth client.⁠Source 1, Source 7

    Zenity

    Runtime Boundaries can check agent actions in real time; Zenity says it can block actions only on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 8

    Generated ASOR agent accounts and their OAuth clients stay disabled until the agent is activated.⁠Source 15 Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 8

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicWorkday Agent System of RecordZenity
Network exposureThird-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 10 Inbound endpoint needs: not publicly documented.Delivered as SaaS on AWS, per its AWS Marketplace listing.⁠Source 3 Monitored agents’ network needs aren’t in Zenity’s public docs.
IdentityUnique identity per agent.⁠Source 5 External agents use OAuth 2.0 or signed JWTs; tokens for third-party (self-built) agents last 4 hours.⁠Source 1, Source 5, Source 19Zenity says rules can reference Okta attributes such as role.⁠Source 8 Issuing agent identities isn’t in Zenity’s public docs.
Access changes and revocationDeactivating an agent hides it from users; the change may take up to a minute to reach Agent Gateway.⁠Source 1, Source 10Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 8 It says rules can shut agents down.⁠Source 8
Audit trailAn audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 5, Source 7 SIEM export: not publicly documented.Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 4, Source 20
ComplianceWorkday says its SOC 2 report covers Workday Enterprise Products; ASOR isn’t named.⁠Source 21 ISO 42001 covers Workday Platform.⁠Source 21Zenity says it has SOC 2 Type II, is ISO 27001 compliant, and announced FedRAMP “In Process” in March 2026.⁠Source 22, Source 23

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Workday Agent System of Record and Zenity compared on 18 criteria
Workday Agent System of RecordZenity
What it is
What it is and who it’s forSet up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.⁠Source 1, Source 2A SaaS security and governance platform for AI agents spanning SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.⁠Source 3, Source 12
MaturityAnnounced in February 2025; generally available since February 2026.⁠Source 17, Source 24 Agent Gateway was announced in June 2025.⁠Source 25Zenity announced Azure Marketplace (now Microsoft Marketplace) availability in March 2025 and AWS in January 2026.⁠Source 26, Source 27, Source 28
Control
Agent registry and discoveryThe Agent Management Hub lists registered Workday-built, partner-built, and self-built agents with their status.⁠Source 1 HiredScore and Evisort agents are not in ASOR.⁠Source 1Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and on laptops, with their permissions and tool access.⁠Source 4
Identity and access controlEach agent has a unique Workday identity, governed by security policies and groups.⁠Source 5, Source 15 An Agent Interaction Policy sets which users may use delegate-mode skills.⁠Source 29Zenity says Boundaries rules can reference Okta attributes such as active status, role, and department.⁠Source 8 Issuing agent identities isn’t in Zenity’s public docs.
Ownership, policy, and revocationAdmins set each agent’s skills and who can use it, and activate or deactivate it.⁠Source 1, Source 13 A deactivated agent is hidden from users and can be reactivated.⁠Source 1Zenity says rules can allow an action, block it, or shut the agent down, but it blocks inline only on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 8
Audit log and observabilityAn audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 5, Source 7 Per-agent analytics reports cover Workday-built agents only.⁠Source 1Zenity says it logs agent messages, tool calls, retrievals, and handoffs.⁠Source 4 It says its audit log events can stream to Splunk or Microsoft Sentinel.⁠Source 20
Connection
How agents connectThird-party agents must route Workday API traffic through Agent Gateway, a single regional endpoint.⁠Source 10 Outbound-only use is not publicly documented.Zenity says agents emitting OpenTelemetry or gen_ai spans can connect, with an Evaluate API for inline enforcement.⁠Source 20 Network needs: not in Zenity’s public docs.
Agents across organizationsPartner-built agents are supported, and Workday says its governance covers them too.⁠Source 1, Source 17 Partner-held access controls are not publicly documented.Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 14
Protocol supportAPI registration is based on the A2A Agent Card.⁠Source 18 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.⁠Source 30, Source 31Zenity says custom agents can connect by emitting OpenTelemetry or gen_ai spans.⁠Source 20 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedAPI registration records each agent’s platform, or OTHER.⁠Source 18 Workday names Google Gemini Enterprise as an outside assistant able to call its Self-Service Agent.⁠Source 30Zenity says it blocks inline on Copilot Studio, Microsoft Foundry, and coding agents; elsewhere, such as Agentforce, it offers detection and posture only.⁠Source 6
Operations
Deployment options and data residencySet up in each Workday tenant.⁠Source 2 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.⁠Source 10 Self-hosting: not publicly documented.Software as a service, shown on AWS Marketplace as deployed on AWS.⁠Source 3 Regions, data residency, and self-hosting aren’t in Zenity’s public docs.
Compliance attestationsWorkday says its SOC 2 report covers Workday Enterprise Products.⁠Source 21 Its ISO 42001 certificate covers named products including Workday Platform; ASOR isn’t named.⁠Source 21Zenity says the company holds SOC 2 Type II certification and is ISO 27001 compliant.⁠Source 22 It announced FedRAMP “In Process” status in March 2026.⁠Source 23
Support and SLAWorkday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 32 An ASOR uptime SLA is not publicly documented.Zenity’s terms commit to at least 99.9% monthly uptime, with commercially reasonable efforts.⁠Source 33 Support requests go through Zendesk in business hours.⁠Source 33
Time and effort to get runningEnable the ASOR functional area and set its security policies.⁠Source 2 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 9Zenity says it has custom-agent guides for Cribl, LiteLLM, and Kong, and a Cursor plugin.⁠Source 20, Source 34 Prerequisites aren’t in Zenity’s public docs.
Pricing model and public pricesNo additional specific SKU for ASOR.⁠Source 1 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 1 A credit’s price is not publicly documented.Main AWS listing: custom pricing.⁠Source 3 Security Hub Extended listing: Observability $130 per resource a month, Runtime Protection $16 per million tokens a month.⁠Source 16
Building
Agent building toolsYou provide an external agent’s definition through an API.⁠Source 1 Workday announced the low-code Flowise Agent Builder for Workday’s separate Workday Build in 2025.⁠Source 35Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 14
Model accessWorkday’s AI agents use large language models.⁠Source 1 Which models ASOR supports or includes is not publicly documented.Zenity says its threat detection combines rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.⁠Source 36 The models used aren’t in Zenity’s public docs.
Integrations and ecosystemIn February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 17 Workday says partner agents reached its Marketplace in June 2025.⁠Source 25Zenity says its signals can show in Microsoft Agent 365 and findings in AWS Security Hub Extended; it is on the Cursor Marketplace.⁠Source 34, Source 37, Source 38

Which to choose

Choose Workday Agent System of Record if

  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.⁠Source 1, Source 2
  • You want each agent to have a unique Workday identity, governed by the security policies and groups you already use.⁠Source 5, Source 15
  • You want an agent acting for a user limited to what both may do, with audit entries naming both.⁠Source 5
  • You want outside assistants, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A for authorized users.⁠Source 30

Choose Zenity if

  • Your security team needs one inventory of agents across platforms such as Copilot Studio and Agentforce, which Zenity says it builds.⁠Source 4, Source 12
  • You want what Zenity says it offers: agents found by scanning, with flags for agents outside sanctioned deployment channels.⁠Source 4
  • You want the rule checks Zenity says it runs on agent actions, blocking inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 8
  • You want what Zenity says it offers: audit log events in Splunk or Microsoft Sentinel, or findings in AWS Security Hub Extended.⁠Source 20, Source 38

Questions buyers ask

Can Workday Agent System of Record manage agents built outside Workday?

Yes. You define and register an external agent in one step through the ASOR API, and the Agent Management Hub manages self-built and partner-built agents.⁠Source 1, Source 9 Per-agent analytics reports cover Workday-built agents only.⁠Source 1

Which agents can Zenity cover?

Zenity says AI Observability inventories agents inside platforms such as Copilot Studio, ChatGPT Enterprise, and Agentforce, and homegrown agents on frameworks such as Azure AI Foundry and AWS Bedrock.⁠Source 4 On Amazon Bedrock AgentCore, Zenity says security teams can instrument agent code to enforce inline controls.⁠Source 39

Do they support A2A and MCP?

ASOR’s registration API is based on the A2A Agent Card, outside assistants can call Workday’s Self-Service Agent over A2A, and tool search can filter by MCP.⁠Source 18, Source 30, Source 31 Whether Zenity supports A2A isn’t publicly documented. Zenity says its agent hooks can block coding agents’ dangerous tool calls.⁠Source 11

How is each one priced?

ASOR needs no additional specific SKU.⁠Source 1 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 1 A credit’s price is not publicly documented. Zenity’s main AWS Marketplace listing has custom pricing.⁠Source 3 Its Security Hub Extended listing shows usage prices per resource and per million tokens.⁠Source 16

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

44 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz272829

  2. Source 2: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcdefgh

  3. Source 3: AWS Marketplace: Zenity Zenity · checked Back:abcdefghijk

  4. Source 4: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijklm

  5. Source 5: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijkl

  6. Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abcdef

  7. Source 7: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abcd

  8. Source 8: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefghijkl

  9. Source 9: Register External Agents (Workday Administrator Guide) Workday · checked Back:abcde

  10. Source 10: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcde

  11. Source 11: Coding and Personal Agents | Zenity Zenity · checked Back:ab

  12. Source 12: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abcd

  13. Source 13: Workday Agent System of Record | Workday US Workday · checked Back:ab

  14. Source 14: Zenity Documentation (login) Zenity · checked Back:abc

  15. Source 15: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcd

  16. Source 16: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  17. Source 17: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abcd

  18. Source 18: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcd

  19. Source 19: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  20. Source 20: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdef

  21. Source 21: Workday Compliance | Workday US Workday · checked Back:abcd

  22. Source 22: Zenity Trust Center Zenity · checked Back:ab

  23. Source 23: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  24. Source 24: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back to text

  25. Source 25: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back:ab

  26. Source 26: Zenity Now Available in the Microsoft Azure Marketplace Zenity · checked Back to text

  27. Source 27: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Zenity · checked Back to text

  28. Source 28: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back to text

  29. Source 29: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  30. Source 30: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abcd

  31. Source 31: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  32. Source 32: Workday Support | Workday US Workday · checked Back to text

  33. Source 33: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  34. Source 34: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back:ab

  35. Source 35: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back to text

  36. Source 36: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back to text

  37. Source 37: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back to text

  38. Source 38: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back:ab

  39. Source 39: Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore Zenity · checked Back to text

  40. Source 40: Your company's private network Blocks.ai · checked Back to text

  41. Source 41: Network requirements Blocks.ai · checked Back to text

  42. Source 42: Solutions: Agent sprawl Blocks.ai · checked Back to text

  43. Source 43: Solutions: Partner networks Blocks.ai · checked Back to text

  44. Source 44: Pricing Blocks.ai · checked Back to text