UKG Developer Policy
1. Purpose and Scope
This Developer Policy governs the access and use of any UKG-provided and UKG-approved technical interfaces for accessing, receiving, transmitting or exchanging data, including without limitation:
- REST and SOAP APIs (UKG Pro, UKG WFM/Dimensions, UKG Ready)
- Software development kits (SDK’s)
- Webhooks (event-driven data delivery)
- Customer Data Warehouse / People Fabric Data Platform (BYOBI, GraphQL)
- MCP Gateway (AI agent tool access)
- Other datafeeds, databases, data lakes
This Policy form is incorporated by reference into the applicable Master License Agreement (MLA) and/or Master Service Agreement (MSA). In the event of conflict, the MLA/MSA controls.
2. Published Data Interfaces Only
Developers may only access UKG Data Interfaces that are provisioned and approved by UKG. Developers must register their access with UKG using an active, approved credential prior to accessing the UKG Data Interface.
A complete list of UKG Data Interfaces is available in UKG’s Developer Portal or People Fabric API catalog and include, but may not be limited to:
| Tier | Description | Access Path |
|---|---|---|
| Production APIs | Fully supported, versioned, SLA-backed | Partner Portal credential + Customer consent |
| Beta / Preview APIs | Available under a separate Beta Agreement | Beta enrollment required |
| Data Warehouse (BYOBI) | Exposed curated data marts | Separate Data Access Agreement required |
Developers must not access, submit, receive, query, transmit, or exchange data or functionality with or through a UKG solution without using a UKG Data Interface. UKG may remove access to its solutions by non-approved connection methods without notice and assumes no liability for any resulting breakage.
3. Authentication and Credential Management
3.1 Required Authentication
All UKG Data Interface access must use supported authentication methods published in the Developer Hub.
3.2 Credential Issuance
All credentials are issued through the UKG Partner Portal or Developer Console, and subject to the following levels of access control:
| Access Control | Description |
|---|---|
| Generic Credentials | Access UKG data interfaces not scoped to a specific customer(s) tenant. |
| Customer-Specific Credentials | Access UKG data interfaces scoped to a specific Customer's data; requires explicit customer consent (via a UKG-approved method) before issuance |
| Multiple-Customer Credentials | Access UKG data interfaces scoped to multiple Customers’ data; requires explicit consent from all customers (via a UKG-approved method) before issuance |
3.3 Credential Use
While in use, Developers must:
- Store all credentials securely (credentials must not be stored in source code, logs, or public repositories)
- Rotate credentials according to the following schedule:
- Tenant-Specific Credentials (access to Customer PII): once at least every 90 days
- Generic Credentials and Multiple-Customer Credentials: once at least every 12 months
- All credential types: immediately upon suspected compromise
- Never share credentials across organizations or unrelated applications
- Treat client secrets as shown only once at issuance; UKG will not re-display them
3.4 Credential Revocation
Credentials may be revoked by UKG, its customer, or the Developer at any time with or without notice. Developers who believe that their credentials have been compromised must revoke their credentials immediately.
A Customer may withdraw consent for a specific Developer’s access by contacting UKG via the UKG Partner Portal or UKG Support. Upon withdrawal, the Developer must immediately cease usage of the credentials related to such Partner Integration and all data processing related to that Customer.
Revocation takes effect immediately. The affected party will be notified by email. Revoked credentials cannot be reinstated; a new credential must be requested.
After revocation of credentials, Developer must comply with the data deletion requirements described in Section [8].
4. Prohibited Use
Uses which are strictly prohibited regardless of technical feasibility include:
| Prohibition | Description |
|---|---|
| Competitive Intelligence | Using UKG data to benchmark, analyze, or inform products that compete with UKG offerings. |
| Competitive Product or Service | Creating a competitive product or service to UKG’s offerings. |
| Cross-Tenant Data Aggregation | Aggregating or comparing data across multiple Customer tenants without a signed Data Sharing Agreement and consent from all involved tenants. This includes anonymized or aggregated benchmarking data derived from multiple tenants unless explicitly authorized under a Data Sharing Agreement. |
| Data Redistribution or Resyndication | Sharing, distributing or syndicating of Customer Data or UKG platform data without prior written UKG authorization. |
| Data Resale or Monetization | Selling, licensing, or commercializing Customer Data or UKG platform data to any third party, whether for monetary value or otherwise, without written UKG authorization. |
| Training AI/ML Models on Customer Data | Using Customer Data to train, fine-tune, or evaluate AI or machine learning models without explicit Customer and UKG written consent. |
| Profiling or Re-identification | Attempting to re-identify anonymized or aggregated data, or linking UKG data with external datasets to identify individuals |
| Storing PII Beyond Purpose | Retaining Personally Identifiable Information accessed through UKG data interfaces beyond what is necessary for the declared integration purpose. |
| Scraping and Bulk Extraction | Using automated tools to extract data beyond the intended UKG data interface’s scope, including agentic loops, screen scraping, session replay, or unpublished endpoint enumeration. |
| Reverse Engineering | Decompiling, disassembling, or otherwise attempting to derive source code, data models, or internal logic from UKG data interfaces. |
| Circumventing Access or Rate Limits | Attempting to circumvent any permitted or provisions access or rate limits on UKG data interfaces, including through the use of multiple credentials, IP addresses, or tenants. |
| Unapproved AI Agents | Deploying semi-autonomous or generative AI systems that plan, select, or execute sequences of UKG API calls without MCP Gateway registration or explicit UKG authorization. |
| Credential Sharing | Deploying semi-autonomous or generative AI systems that plan, select, or execute sequences of UKG API calls without MCP Gateway registration or explicit UKG authorization. |
| Direct Database Access | Connecting directly to UKG databases, internal services, or infrastructure. |
| Bypassing Consent Flows | Accessing Customer tenant data without the Customer's documented consent, including circumventing the Partner Portal consent flow |
The above list does not constitute an exhaustive list of use cases for which Developer access and use are prohibited.
5. Data Interface Specific Policies
All Developers accessing UKG Data Interfaces must:
| Policy | Description |
|---|---|
| Process data only for authorized purposes | Access and process data only for the limited and specific purpose provided at the time the Developer requests and receives approval of access by UKG. |
| Apply least-privilege principles for access requests | Request only the OAuth scopes, data fields, and access time period strictly necessary for the requested purpose. |
| Protect Customer Data in transit | All data transmitted over public networks must use TLS 1.3 (preferred) or TLS 1.2 at minimum or other prevailing industry standard encryption methodology at the time. Developers should plan to migrate to TLS 1.3-usage only by the date communicated in the UKG Developer Portal. |
| Protect Customer Data at rest | Customer Data stored and at rest in Developer systems must be encrypted using AES-256 or an equivalent standard recognized by NIST (e.g., ChaCha20-Poly1305). Developers must be able to demonstrate compliance with FIPS 140-2 or FIPS 140-3 validated cryptographic modules upon request. |
| Restrict data access | Limit access to the data and UKG Data Interface within the Developer's organization only to personnel who require it for the stated and UKG-authorized purpose. |
| Comply with data residency requirements | Developers must process and store Customer Data only in the geographic jurisdictions authorized in credential issuance or as specified in the applicable Data Processing Agreement. Where cross-border data transfers are necessary, and approved by the Customer, Developers must implement appropriate safeguards to protect such transfers and do so in compliance with applicable laws. |
| Delete Customer Data upon request | Developer must immediately and permanently delete and purge all Customer Data and any copies in its possession and control, including from shared environments, backups, archives, and derivative datasets, except to the extent required by applicable law, if: - The engagement between Developer and Customer is terminated; - Developer’s credentials are revoked; or - Developer receives a deletion request from Customer or UKG. UKG may request, and Developer shall provide, written confirmation such Customer Data has been permanently deleted in accordance with this section. |
| Report security incidents | Any suspected or confirmed unauthorized access or export of Customer Data or a breach of any security or privacy controls on any ecosystem hosting Customer Data must be reported to UKG Security Operations within twenty-four (24) hours of discovery, or sooner if required by applicable law. Reports must be submitted to [email protected] or through the UKG Partner Portal Security Incident form. The initial report must include: date and time of discovery, nature of the incident (data types affected, estimated scope), containment measures taken or planned, and Developer point of contact for incident coordination. |
| Sub-processor management | Developers must obtain prior written authorization from UKG prior to engaging their own sub-processors to process Customer Data must, ensure sub-processors are bound by data protection obligations no less protective than those in this Policy, maintain a current list of sub-processors and make it available to UKG and the Customer upon request, and remain fully liable for the acts and omissions of their sub-processors. No rights to Customer Data are transferred to Developers through use of UKG data interfaces. |
| Published Requirements | Developers must comply with any documentation that specifies additional requirements. |
6. Rate Limits and Quotas
UKG applies rate limits and quotas to all data interface types to ensure equitable access and protect platform health. Developers may request quota or rate limit increases via the UKG Partner Portal and Developer Portal.
UKG reserves the right to throttle, suspend, or terminate access for any Developer at any time upon notice. The reasons for which UKG may do so include, but are not limited to:
- Consistently exceeds published rate limits
- Generating API traffic that degrades performance for other customers
- Exhibiting patterns consistent with bulk scraping or unauthorized data extraction
7. AI Agents
All AI agents accessing the MCP Gateway must maintain a complete audit log of every tool invocation, including:
- Timestamp
- Tool/API invoked
- Input parameters (with PII redacted or masked in logs)
- Response status code
- The identity of the human operator (for human-supervised agents), or the agent session identifier (for autonomous agents)
Audit logs must be retained for the duration of Developers’ access to UKG data interfaces and use or storage of UKG data and a minimum of twelve (12) months following cessation of such access and use.
Developers deploying AI agents that access UKG data interfaces must comply with all applicable AI governance laws and regulations in the jurisdictions where the agent operates.
The Developer that registers as an AI agent in the MCP Gateway is responsible for all actions taken by that agent, including unauthorized data access, data mutations, and policy violations. Where a customer deploys a developer agent within their tenant, the Developer remains liable for agent behavior. UKG monitors MCP Gateway usage for anomalous agent behavior.
8. IP Restrictions and Security Controls
UKG may require IP allowlisting for access to certain data and/or specific use cases. In addition, UKG monitors API usage continuously for anomalies and, upon detection of an anomaly, may:
- Throttle the affected credential automatically
- Notify the Developer and/or Customer
- Suspend access
9. Change Management
UKG will communicate changes to the developer policy through supported channels (such as the Developer Hub). Developers are solely responsible for monitoring deprecation notices and updating integrations accordingly.
10. Enforcement and Remedies
UKG may throttle, suspend, or revoke Developer’s access to UKG Data Interface(s) upon a violation of this Policy, as determined by UKG in its sole discretion.
11. Audit Rights
UKG reserves the right to audit Developer compliance with this Policy. Developers must retain logs of UKG data interface and data access. The scope of UKG’s audit may include, but is not limited to:
- API + MCP Gateway or server access logs and credential usage records
- Data storage and encryption practices
- AI agent design specifications and audit logs (for MCP Gateway users, per Section 7.4)
- Sub-processor arrangements and data processing records
- Documentation related to Developers’ compliance with applicable law
In the event an audit reveals non-compliance, UKG reserves the right to immediately terminate or suspend Developer’s access, unless a remediation plan acceptable to UKG is agreed upon.
12. Policy Updates
UKG reserves the right to update this Policy. Developers will be notified of material changes via posting the updated version to the UKG Developer Portal. Continued use of UKG data interfaces after the effective date of a change constitutes acceptance of the revised Policy.
Revision History
| Version | Date | Summary of Changes |
|---|---|---|
| 1.0 | [--] | Creation of Developer Policy |
Appendix A: Glossary
| Term | Definition |
|---|---|
| AI Integration Agreement | A supplemental agreement between UKG and a Developer governing the deployment of autonomous AI agents that access UKG data interfaces via the MCP Gateway |
| Customer Data | All data submitted to or generated within UKG services by or on behalf of a Customer |
| Data Access Agreement | A supplemental agreement governing Developer access to the UKG People Fabric Data Platform / Data Warehouse, specifying permitted datasets, retention, and usage restrictions |
| Data Processing Agreement (DPA) | A contract between UKG and a Developer (acting as Sub-Processor) establishing data protection obligations in compliance with applicable privacy law |
| Data Interfaces | UKG-provided and UKG-approved technical interfaces for accessing, sending, receiving, transmitting, or exchanging data, including without limitation API’s, software development kits (SDK’s), Webhooks, MCP Gateways or servers, data feeds, databases, data hubs, data lakes, data warehouses, and endpoints. |
| Data Sharing Agreement | A supplemental agreement signed by multiple Customers authorizing cross-tenant data aggregation or comparison for specified purposes |
| Developer Console | UKG's self-service UI for API credential creation, available to Customers and authorized Partners |
| MCP Gateway | UKG's Model Context Protocol Gateway; enables AI agents to invoke UKG tools via a governed interface |
| Partner Portal | UKG's governed platform for partner onboarding, credential management, and customer consent |
| People Fabric Data Platform | UKG's unified data platform, including the Data Warehouse exposed via BYOBI and GraphQL |
| Published API | An API listed in the UKG Developer Portal or official product documentation |
| Sub-Processor | Any person (including any third party) appointed by or on behalf of Developer to process Customer Data on behalf of a Customer |
| Tenant-Specific Credential | An API credential scoped to a specific Customer's data environment, requiring Customer consent |
Updated 1 day ago