Source and target systems
System roles guide
A system’s role is determined by what NIM is doing with it: collecting identity data, provisioning a change, or both.
The short versionDirect link to The short version
NIM does not maintain separate source-system and target-system objects. You add a system once, using its connector. That system is in a source context when NIM reads its data and in a target context when NIM writes changes to it.
Source context
NIM collects tables and records from the system into the Vault so they can drive identity decisions.
Collect system data →Target context
NIM uses mappings and roles to create, update, or remove supported resources in the system.
Configure mappings →How the same system can have two rolesDirect link to How the same system can have two roles
| NIM activity | System context | What NIM does | Next step |
|---|---|---|---|
| Collection | Source | Reads the connector’s available tables into the Vault. | Choose tables, keys, and relationships in the data model. |
| Mappings and the active role model | Target | Sends supported create, update, delete, and membership changes to the connected system. | Build mappings, roles, and jobs. |
For example, an HR system usually supplies employee data for collection, making it the practical source of truth. Active Directory can be collected too, then used as a target when NIM provisions accounts and group memberships. Both are simply NIM systems; their context changes with the operation.
What a connector can doDirect link to What a connector can do
The connector defines the data and operations available to a system. Every official connector supports collection. Target capabilities vary by connector and resource type.
| Connector capability | What it enables |
|---|---|
| Data tables | Reading records during collection and using them in filters, relations, mappings, and roles. |
| Create, update, and delete operations | Provisioning supported resources, such as users or groups, through mappings. |
| Group membership operations | Managing role-based membership changes when the connector supports them. |
Use the connector’s page in Integrations to check its supported operations before designing a workflow. A system can be a source without being a target: many HR systems are intentionally read-only. Directory and SaaS connectors often support both contexts, but the exact resources and operations still differ.
Plan a source-to-target workflowDirect link to Plan a source-to-target workflow
- Identify the system that owns each type of identity data, such as HR data, student data, or directory accounts.
- Add and configure the systems, then collect their data.
- Configure the data model so NIM can identify and relate records consistently.
- Use filters and mappings to decide which records should result in target-system changes.
- Test the target connector’s supported operations with a limited set of records before scheduling a production job.
Calling a system a “source” or “target” is useful shorthand, but it is not a permanent NIM setting. Focus on the data flow and the operation you want NIM to perform.
Need a connector capability?Direct link to Need a connector capability?
If an official connector does not expose a required table, resource, or operation, contact Tools4ever Support. For custom connector development, see Developers.