# Work reports

Read and manage work reports using the timeman scope. Personal keys use the incoming webhook owner’s rights; OAuth app keys use the calling user’s token. Reading other employees’ reports is not audited. Reports may contain personal data. Each GET route has a configured rate limit of 30 requests per minute per key and user; the effective limit is returned in x-ratelimit-limit and divided across backend replicas.

There is no delete operation. **Submitting without reportId creates and sends a new report.** files input is not supported. Absent and null PATCH fields are preserved. reject is neutral; disapprove is negative. Subordinate pagination counts users with default limit 5.

## Operations

| Operation | Endpoint |
|---|---|
| [List work reports](/docs/workday/work-reports/list) | GET /v1/workday/work-reports |
| [Subordinate work reports](/docs/workday/work-reports/subordinates) | GET /v1/workday/work-reports/subordinates |
| [Read a work report](/docs/workday/work-reports/get) | GET /v1/workday/work-reports/:id |
| [Create a work report](/docs/workday/work-reports/create) | POST /v1/workday/work-reports |
| [Update a work report](/docs/workday/work-reports/update) | PATCH /v1/workday/work-reports/:id |
| [Send a work report](/docs/workday/work-reports/send) | POST /v1/workday/work-reports/:id/send |
| [Submit a work report](/docs/workday/work-reports/submit) | POST /v1/workday/work-reports/submit |
| [Approve a work report](/docs/workday/work-reports/approve) | POST /v1/workday/work-reports/:id/approve |
| [Reject a work report](/docs/workday/work-reports/reject) | POST /v1/workday/work-reports/:id/reject |
| [Disapprove a work report](/docs/workday/work-reports/disapprove) | POST /v1/workday/work-reports/:id/disapprove |

[Fields](/docs/workday/work-reports/fields)
