All writing
5 December 20257 min read

Zero Trust WFM: WFM's New Frontier, The Cybersecurity Crossover

WFM is becoming part of an organisation's broader technology and risk landscape. Never automatically trust. Always verify.

When most people hear Workforce Management, they usually think about forecasting, scheduling, capacity planning, adherence and service levels.

When they hear cybersecurity, they think about firewalls, encryption, identity management, threat detection and security operations.

For a long time, these looked like completely separate worlds.

I do not think they are anymore.

The modern WFM environment has access to sensitive information, interacts with multiple systems, influences employee access and increasingly relies on cloud platforms, integrations, APIs and AI.

That means WFM is becoming part of an organisation's broader technology and risk landscape.

And that leads to an idea I find increasingly relevant:

Zero Trust WFM.

WFM is becoming a technology ecosystem

WFM is no longer simply a standalone planning function.

A typical WFM environment can interact with HR systems, payroll, scheduling platforms, attendance systems, authentication systems, CRM platforms, reporting tools, collaboration applications and increasingly AI-enabled technologies.

Every integration creates another connection.

Every connection creates another potential point of risk.

The question therefore cannot simply be:

Does the WFM system work?

We also need to ask:

Who has access to it, what can they access, why do they need that access, and what happens when that access is no longer required?

That is where cybersecurity thinking starts becoming relevant to WFM.

The traditional approach to access is no longer enough

Historically, organisations often relied on perimeter-based security.

You are inside the company network, so you are trusted.

You are an employee, so you have access.

You are part of the WFM team, so you can see certain information.

But modern work does not fit neatly inside those boundaries.

People work remotely.

Systems are cloud-based.

Vendors connect to platforms.

Employees change roles.

Contractors require temporary access.

Automation increasingly interacts with production systems.

AI agents may eventually perform tasks on behalf of people.

The old concept of:

You are inside, therefore you are trusted

becomes increasingly difficult to defend.

Zero Trust takes a different approach.

Never automatically trust. Always verify.

What would Zero Trust WFM look like?

I think the concept can be applied surprisingly well to Workforce Management.

At its core, Zero Trust means that access should be based on the specific user, device, application, context and action rather than simply on someone's organisational position.

For WFM, that could mean thinking carefully about every layer of access.

A planner may need access to forecasting data.

That does not automatically mean they need access to payroll information.

A supervisor may need to view adherence.

That does not necessarily mean they should be able to change workforce rules.

A vendor may require temporary access to troubleshoot an issue.

That does not mean they should have permanent administrative privileges.

An AI agent may need to read specific operational data.

That does not mean it should automatically have permission to modify schedules.

This is the essence of the Zero Trust mindset:

Access should be intentional, limited and continuously evaluated.

Least privilege becomes especially important

One of the most important Zero Trust principles is least privilege.

Give a user or system only the level of access required to perform its function.

Nothing more.

This sounds straightforward, but it becomes more difficult in complex WFM environments.

WFM teams often interact with sensitive information.

Employee schedules.

Attendance.

Absence.

Productivity.

Performance.

Skills.

Availability.

Potentially compensation-related information.

The broader the access, the greater the potential impact of a compromised account.

Reducing unnecessary access is therefore not simply an IT security exercise.

It can reduce operational risk as well.

The AI angle makes this even more important

This is where I think things become particularly interesting.

We are increasingly talking about AI copilots and Agentic AI within WFM.

Imagine an AI system that can:

Analyse forecast data.

Recommend staffing changes.

Identify adherence issues.

Create schedules.

Initiate communications.

Request overtime.

Potentially even make controlled operational changes.

The benefits could be significant.

But we now have a new question:

What should an AI agent be allowed to do?

An AI system should not automatically inherit the full permissions of the human or account through which it operates.

Its access should be deliberately designed.

It should only have the permissions required for its role.

Actions should be auditable.

Sensitive actions should have stronger controls.

And certain decisions may require human approval.

In other words:

AI needs Zero Trust too.

Identity becomes part of WFM governance

Once we start thinking about WFM through a cybersecurity lens, identity becomes much more important.

Who is this user?

How are they authenticated?

What role do they have?

What permissions are associated with that role?

Is their access still appropriate?

Are they using an approved device?

Is the activity unusual?

Should the action require additional verification?

These questions are increasingly relevant as WFM platforms become more integrated and more intelligent.

Identity is no longer just an IT concern.

It becomes part of operational governance.

Think beyond people

Another important aspect of Zero Trust is that not every identity is human.

Modern technology environments contain:

Human users.

Applications.

APIs.

Service accounts.

Bots.

Automation workflows.

AI agents.

Each one can potentially access information or perform actions.

That changes the security conversation dramatically.

A WFM platform connected to an AI agent could potentially involve multiple automated identities interacting with multiple systems.

So we need to know:

Who or what initiated the action?

What permissions were used?

What information was accessed?

What decision was made?

What action was taken?

Can we trace it back?

That level of visibility becomes increasingly important as automation grows.

The biggest challenge may be convenience

Security and operations often have a complicated relationship.

Operations wants things to be fast and easy.

Security wants things to be controlled and verified.

In WFM, speed matters.

A planner working on an intraday issue cannot wait hours for access approvals.

Managers need information quickly.

Schedules need to change quickly.

Business conditions change quickly.

That can create pressure to give people broad access simply because it is easier.

But convenience today can create significant risk tomorrow.

The goal of Zero Trust should not be to make WFM painful.

It should be to make access smart, contextual and appropriately controlled.

Cybersecurity is not just an IT responsibility anymore

This is probably the biggest mindset change I would encourage.

WFM professionals do not need to become cybersecurity experts.

But they should understand that many of their decisions have security implications.

For example:

Who has access to WFM reports?

Who can change a schedule?

Who can modify forecasting parameters?

Who can export employee data?

Who can administer the platform?

How long should former employees retain access?

What happens when someone changes roles?

Can vendors access the environment remotely?

How are automated actions logged?

These are operational questions with cybersecurity consequences.

What could a Zero Trust WFM framework include?

I think a practical approach could be built around a few simple principles.

Verify every access request

Do not assume trust based only on role, location or network.

Apply least privilege

Give users and systems only the permissions they actually need.

Separate duties

The person who creates a rule should not necessarily be the person who approves or implements it.

Monitor continuously

Access should not be treated as a one-time decision. Behaviour and context matter.

Make everything auditable

Critical actions should leave a clear trail.

Secure AI agents

AI should have explicit permissions, defined boundaries and appropriate escalation mechanisms.

Remove access quickly

Role changes and employee departures should automatically trigger access reviews or removal.

These may sound like standard security principles.

But bringing them directly into WFM is where the opportunity lies.

Zero Trust can actually improve WFM

There is an interesting upside here.

Cybersecurity is often presented as a restriction.

But good access governance can actually improve operational discipline.

When permissions are clear, ownership becomes clearer.

When actions are logged, accountability improves.

When systems are integrated with proper identity controls, manual access administration can decrease.

When AI agents have defined permissions, their behaviour becomes easier to govern.

Security and efficiency do not always have to be opposites.

Done properly, security can become an enabler of scalable WFM automation.

The future WFM leader needs a risk mindset

As WFM becomes more technology-driven, leadership expectations will also change.

The future WFM leader may need to understand more than forecasting and scheduling.

They will increasingly need to understand:

Data governance.

Technology risk.

Identity and access.

AI governance.

Automation controls.

Third-party risk.

Business continuity.

Cyber resilience.

Not because WFM leaders need to replace the cybersecurity team.

They do not.

But they need to understand how their function fits into the organisation's overall risk environment.

My take

For years, WFM has focused on answering:

Do we have the right people, in the right place, at the right time?

I think the next generation of WFM needs to ask another set of questions:

Do we have the right data?

Does the right person have the right access?

Can we trust the systems making decisions?

Can we explain what happened?

Can we control what AI is allowed to do?

Can we recover when something goes wrong?

That is where cybersecurity and WFM start to converge.

The future of WFM will not simply be about becoming more automated.

It will be about becoming securely automated.

And as AI agents become increasingly capable of accessing data, making recommendations and taking action, that distinction will become even more important.

Because the objective is not simply to build an intelligent WFM environment.

It is to build one that is intelligent, resilient and trusted.

That, to me, is the real frontier of Zero Trust WFM.

Share this on LinkedIn

Copies a caption, then opens the composer. Paste with ⌘V and post.

Workforce ManagementCybersecurityZero TrustAI Governance

Adapted and expanded from my post on LinkedIn.