In enterprise SaaS, orchestrating ML models on sensitive workforce data requires zero compromise on data privacy and multi-tenant isolation. Workday’s Scheduling & Labor Optimization product uses Airflow to power predictive workforce forecasts across thousands of customer tenants—where each customer strictly owns their data and model artifacts. This session demonstrates how Workday leverages Airflow for multi-tenant ML pipeline orchestration.
We cover how Airflow dynamically materializes isolated ML DAGs per tenant, enforces strict execution boundaries via TENANT_KEY metadata, and automates lifecycle operations for customer opt-in and opt-out workflows, including mandatory 14-day data/model purges.
Key Problems Solved:
- Strict Data & Model Privacy: Isolating tenant data and training models exclusively on tenant-owned datasets.
- Lifecycle Compliance: Triggering DAG creation on opt-in and managing grace periods with enforced 14-day purges on opt-out. 3. Operational Efficiency: Scaling thousands of dynamic DAGs using VPA/Scaleops autoscaling without scheduler overhead.
Session Outline :
- Overview & Challenge
- Multi-tenant ML privacy in SaaS.
- Dynamic DAG Architecture
- Event-driven materialization and TENANT_KEY isolation.
- Lifecycle Compliance
- Dynamic enrollment and automated 14-day deletion pipelines. Scaling & Infrastructure
- Resource optimization with ScaleOps/VPA
Takeaways:
- Design patterns for dynamic per-tenant DAG generation.
- Enforcing tenant isolation, security boundaries, and model governance in Airflow.
- Building compliance workflows for dynamic opt-in/opt-out retention policies.
Serjesh Sharma
Workday,Manager, Software Development Engineering-AI Platform
John Macmillan
Workday, DevOps