Processing
Identity data processing
Turn current Vault data into clear, reusable decisions that mappings, roles, jobs, and reports can act on.
Processing sits between Systems and Output. It does not directly provision accounts. Instead, it connects, selects, shapes, and generates the values that output workflows use to make supported changes in target systems.
Choose the tool for the jobDirect link to Choose the tool for the job
Connect systems
Relate records across systems, such as an HR employee and a directory account, so filters can work across both data sets.
Configure inter-system relations →Select and shape data
Create filters that identify the people, accounts, groups, and records a workflow should process.
Build filters →Generate unique names
Transform source values into usernames, email addresses, and other target attributes with uniqueness rules.
Create name generators →Generate passwords
Create initial passwords that meet target-system requirements and can be used in account-create mappings.
Create password generators →A typical processing pathDirect link to A typical processing path
- Collect systems and verify their current data in the Vault.
- Create inter-system relations when a workflow must connect data across systems.
- Build a filter that returns exactly the records the workflow should process.
- Add a name or password generator when the target mapping needs a derived username, email address, or initial credential.
- Send the validated filter output into mappings, roles, exports, or notifications.
How processing tools work togetherDirect link to How processing tools work together
| Tool | Input | Output | Common use |
|---|---|---|---|
| Inter-system relation | Keyed records from two systems | A usable cross-system relationship | Match employees to existing directory accounts. |
| Filter | Current Vault data and optional relations | A selected, shaped set of records | Find active employees without a target account. |
| Name generator | Filter columns | One or more generated target values | Create a unique username or email address. |
| Password generator | Optional filter columns and password rules | A generated password value | Set an initial password during account creation. |
Before using processing output in productionDirect link to Before using processing output in production
- Confirm the source data is current and the required tables, columns, keys, and relations are configured.
- Test filters with records that should match, should not match, and represent edge cases such as missing data.
- Review generated values for collisions, prohibited characters, and target-system requirements.
- Test a single mapping operation before scheduling a job that creates, updates, or removes many records.
If data is correct in a system table but missing from a filter, inspect the filter’s start table, expressions, relations, and column exclusions before changing the mapping that consumes it.
Next stepDirect link to Next step
Most implementations begin with Filters. When the filter output is correct, continue to Output to map the result to target-system changes.