Skip to main content

Source and target systems

System roles guide

A system’s role is determined by what NIM is doing with it: collecting identity data, provisioning a change, or both.

The short versionDirect link to The short version

NIM does not maintain separate source-system and target-system objects. You add a system once, using its connector. That system is in a source context when NIM reads its data and in a target context when NIM writes changes to it.

How the same system can have two rolesDirect link to How the same system can have two roles

NIM activitySystem contextWhat NIM doesNext step
CollectionSourceReads the connector’s available tables into the Vault.Choose tables, keys, and relationships in the data model.
Mappings and the active role modelTargetSends supported create, update, delete, and membership changes to the connected system.Build mappings, roles, and jobs.

For example, an HR system usually supplies employee data for collection, making it the practical source of truth. Active Directory can be collected too, then used as a target when NIM provisions accounts and group memberships. Both are simply NIM systems; their context changes with the operation.

Collect before you provisionCollection is the starting point for every connector. NIM needs current system data in the Vault before you can match records, build mappings, or evaluate roles.

What a connector can doDirect link to What a connector can do

The connector defines the data and operations available to a system. Every official connector supports collection. Target capabilities vary by connector and resource type.

Connector capabilityWhat it enables
Data tablesReading records during collection and using them in filters, relations, mappings, and roles.
Create, update, and delete operationsProvisioning supported resources, such as users or groups, through mappings.
Group membership operationsManaging role-based membership changes when the connector supports them.

Use the connector’s page in Integrations to check its supported operations before designing a workflow. A system can be a source without being a target: many HR systems are intentionally read-only. Directory and SaaS connectors often support both contexts, but the exact resources and operations still differ.

Plan a source-to-target workflowDirect link to Plan a source-to-target workflow

  1. Identify the system that owns each type of identity data, such as HR data, student data, or directory accounts.
  2. Add and configure the systems, then collect their data.
  3. Configure the data model so NIM can identify and relate records consistently.
  4. Use filters and mappings to decide which records should result in target-system changes.
  5. Test the target connector’s supported operations with a limited set of records before scheduling a production job.
tip

Calling a system a “source” or “target” is useful shorthand, but it is not a permanent NIM setting. Focus on the data flow and the operation you want NIM to perform.

Need a connector capability?Direct link to Need a connector capability?

If an official connector does not expose a required table, resource, or operation, contact Tools4ever Support. For custom connector development, see Developers.