Creating and Applying Rules for Data Handling

These are the rules that can be customized to handle data the manipulation requirements of the aggregation or provisioning processes for each application. Rules are specific to connectors and are used throughout the product. You can write more than one of each type and select the rule to use from drop-down lists.

A file containing an example of each rule type is included in the IdentityIQ installation package. The examplerules.xml file is located in the IdentityIQ_HOME/WEB-INF/config directory.

Many rule types apply to all applications and are called by the aggregation process. Other connectors may include additional rule options that are specific to the connector type.

For each rule type, you can select a rule that has already been created from the drop down. To edit or create a new rule, click the "..." icon next to a rule drop-down list to access the rule editor throughout IdentityIQ. Choose to either create a new rule, or edit an existing rule structure.

Aggregation Rules

These rules define behavior when aggregating data from the application. Aggregation Rules are used during part of the aggregation process that occurs after the connector has created valid ResourceObjects for the accounts or groups being aggregated, which occurs after the defined connector rules have all been run.

Provisioning Rules

These rules run during the processing of provisioning requests. Some are connector specific and some apply for all connectors, as indicated in their descriptions. Provisioning-related rules which apply to all application types are:

Schema Rules

Schema rules vary by connector and are used for customization. Schema rules allow you to segregate business logic account and group objects respectively, avoiding the need to check whether the resourceobject represents an account or non-account object.