Skip to main content

Compliance and Notifications

Identity solution

Keep identity automation accountable: inspect changes, alert responsible owners, and respond before operational conditions become access or service problems.

At a glance

NIM operational controls combine auditing queries, events, scheduled license evaluations, and notifications so administrators can review identity changes and respond to conditions before they interrupt service. Use job-result monitoring for automation outcomes and certificate-expiration notifications for credentials that need replacement.

Verify success: Test each notification with a safe condition, confirm the intended owner receives it, and review auditing-query results against a known identity change before relying on the control in production.

Build the operating controls

Review identity changes
Use auditing queries to investigate changes and provide evidence for operational or compliance review.

Notify on job conditions
Use Job Guard notifications to bring failed or unexpected automation outcomes to the right people.

Prevent certificate outages
Monitor certificate expiration early enough to replace dependent credentials safely.

Also schedule license evaluations and configure events for the conditions your operations team must know about. For daily monitoring and troubleshooting, use Administration & operations.

Design a useful operational control

ControlQuestion it answersTest before relying on it
Auditing queryWhat target-system change occurred, to which object, and when?Compare query results with a known change made by a job or App action.
Job Guard notificationDid a scheduled automation produce a failure or unexpected condition?Trigger a safe test condition and verify that the responsible owner receives and can act on the notification.
Certificate-expiration notificationIs a credential that supports NIM approaching expiry?Confirm the notification timing, recipient, and replacement process before the certificate is near expiry.
Event notificationDoes a defined NIM event require an owner’s attention?Test the event, recipient selection, message content, and mail delivery path.

Keep evidence actionable

Name notifications and auditing queries after the condition and owner they support. Include enough context for the recipient to identify the affected workflow, system, or record without exposing unnecessary identity data. Review job results after scheduled runs, investigate exceptions with the corresponding audit data, and update recipients when responsibilities change.

For an automation failure that needs technical diagnosis, follow Troubleshoot NIM provisioning failures. For connector credentials and access errors, review Prepare NIM connector permissions.