Configuring the Leaver Process
The leaver process can be configured in one of the following two ways:
All entitlements assigned to a SAP Analytics Cloud account can be removed when the identity to which this account is correlated to reaches the end of its LifeCycle.
-
Create a Group (Team) in SAP Analytics Cloud that has all disabled users as its members.
-
Configure a LifeCycleState for the leaver Identities, and assign the Group for disabled users to this LifecycleState. For more information, refer to Setting Up Lifecycle States - SailPoint Identity Services.
-
When an Identity enters this LifeCycleState, all roles and groups assigned to a SAP Analytics Cloud account will be removed and the account will become a member of the group that was assigned to the leaver LifeCycleState.
-
Admins should manually disable all members in this Group from the SAP Analytics Cloud UI. Admins can be notified via email when an identity enters the leaver LifeCycleState. For more information, refer to Setting Up Lifecycle States - SailPoint Identity Services.
SAP Analytics Cloud account can be deleted when the identity this account is correlated to reaches the end of its LifeCycle. Configure the SAP Analytics Cloud source to disable accounts when an account’s identity reaches the end of its LifeCycle. Disable
requests can be converted to Delete
requests using a before provisioning rule.
Example of the before provisioning rule for a plan with a single AccountRequest:
<?xml version='1.0' encoding='UTF-8'?>
<!DOCTYPE Rule PUBLIC "sailpoint.dtd" "sailpoint.dtd">
<Rule language="beanshell" name="ExampleDeleteRule" type="BeforeProvisioning">
<Description>Rule to change Disable request to delete</Description>
<Source><![CDATA[
import sailpoint.object.ProvisioningPlan.AccountRequest;
// get account request
AccountRequest accountRequest = plan.getAccountRequests().get(0);
// Change disable request to Delete
if (accountRequest.getOperation() == AccountRequest.Operation.Disable) {
accountRequest.setOperation(AccountRequest.Operation.Delete);
}
]]></Source>
</Rule>