Skip to main content

Lifecycle Automation

Identity solution

Automate the identity work that follows a person joining, changing roles, or leaving—using trusted data, controlled account actions, and operational safeguards.

At a glance

NIM lifecycle automation uses authoritative source data to identify joiner, mover, and leaver events, then applies controlled account and access changes through filters, mappings, jobs, and schedules. A reliable lifecycle workflow starts with current source data and relations, tests changes with a limited population, and monitors every scheduled result.

For joiners, NIM can prepare and activate accounts through the onboarding workflow. For urgent exits, use a controlled termination process to remove access across managed systems. For routine changes, define the qualifying population precisely before a mapping or job updates target-system data.

Build the solution

Connect authoritative data
Collect HR, SIS, or other source data that identifies the lifecycle event and the affected person.

Activate joiners securely
Prepare an account, verify the new user, let them set a password, and activate access without sharing credentials.

Handle urgent exits
Use a controlled termination experience when access needs to be removed quickly across managed systems.

Design each lifecycle outcome

Lifecycle outcomeAuthoritative signalNIM workflowVerify before scheduling
JoinerA person becomes eligible for employment, enrollment, or another covered population.Use a filter to select the person, mappings to prepare required accounts, and roles to apply baseline access. Use onboarding when the person must securely activate access.The selected person receives the intended accounts, attributes, and baseline access without exposing credentials.
MoverA role, department, location, manager, status, or other source attribute changes.Use filters and role models to identify the changed eligibility, then apply the required mapping or role membership changes through a job.The new access is present and access that no longer applies is handled according to the defined rule.
LeaverA person leaves the covered population or requires urgent access removal.Use a clearly scoped filter and target operations to disable, remove, or otherwise change managed accounts and access. Use the controlled termination experience when an urgent, administrator-led response is appropriate.The selected accounts and entitlements have the intended state in every managed target system.

The exact source attributes, target actions, and timing are implementation decisions. Keep each event definition explicit: identify the source of truth, the qualifying filter, the target systems in scope, and the expected result when a record is processed.

A safe lifecycle automation pattern

  1. Collect the authoritative source and every managed target system, then inspect the data in the Vault.
  2. Create a focused filter for one lifecycle outcome and test people who should qualify, should not qualify, and represent missing or changing data.
  3. Configure the mappings and roles required for that outcome; add them to a job.
  4. Run the job manually for a limited, safe population and confirm every target-system result.
  5. Set a sync task frequency that matches the urgency of the event, then review job results after scheduled runs.

For an end-to-end example of the first four steps, follow Build your first workflow. If a selected person does not receive the expected account or access change, use Troubleshoot NIM provisioning failures before retrying a broader job.

Keep it reliable

  • Use filters to define exactly which people qualify for each lifecycle event.
  • Use mappings and jobs to make account changes consistently.
  • Schedule the workflow and use Administration & operations to monitor outcomes and respond to failures.
Start with the foundation

If systems, relations, mappings, and jobs are not yet in place, complete Your first provisioning workflow first.