Lifecycle Manager Requests
Lifecycle Manager is a separately licensed portion of the IdentityIQ product that is designed to manage entitlements using provisioning requests. Based on their manager status and how the Lifecycle Manager is configured, users can make requests for themselves or for other identities.
In a typical configuration:
-
Managers can make requests for their direct reports.
-
Help desk users can make requests for themselves and others.
-
Any user can make requests for themselves.
Lifecycle Manager Toolbar
When Lifecycle Manager is enabled, the Lifecycle Manager toolbar displays at the top of the IdentityIQ view and supports the following actions:
Note: The set of identities for which these actions can be taken is based on the individual user's authority and the Lifecycle Manager configuration. The self-service, Request For Me, options do not include Create Identity.

Request Access includes Role and Entitlement requests. If you are working with a single user, a third tab, Current Access displays that you can use to request the removal of Roles or Entitlements. Use the Lifecycle Manager Request Roles feature to generate requests that:
-
Add the appropriate role to the specified identities.
-
Provision the entitlements the role requires.
-
Provision permitted roles, if added to the request when prompted.
-
Deprovision by removing roles from an identity
This option generates a provisioning request to remove the role assignment from the identities and the entitlements the role requires if another role does not need the entitlements.
Use the Lifecycle Manager Request Entitlements feature to generate requests to:
-
Add the entitlement to the specified identity.
-
Revoke an identity's current entitlements.
This option generates a provisioning request that removes the access from the source application or applications.
By default, when you request a new entitlement on an application and the user already has an account on that application, the entitlement is added to the existing account. If needed, you can create a separate account for specific entitlements.
To create multiple accounts for a single identity on an application or to add an entitlement to a specific existing account when several are available:
-
Navigate to the Lifecycle Manager configuration Additional Options page.
-
In the General Options section, select an application included in the list for Applications that support additional account requests.
-
For the Account selection, select the option to create a new account or the option to add the entitlement to an existing account that the identity already has.

Use the Manage Accounts feature to:
-
Request accounts on additional applications – generates provisioning requests.
-
Revoke or disable existing accounts – generates provisioning requests.
-
Enable disabled accounts – generates provisioning requests to enable or disable accounts.
-
Unlock locked accounts – generates provisioning request.
To use the Manage Accounts to request a new account:
-
Navigate to the Lifecycle Manager configuration Additional Options page.
-
In the Manage Accounts Options section, select an application included in the list of applications that support account-only requests.
-
For the Account selection, select the option to create a new account or the option to add the entitlement to an existing account held by the identity.
Note: You can also select the Manage Accounts option on the Lifecycle Options page for any group, they can enable, disable, and delete accounts for the existing accounts. The connector must support this action and the action must not be disabled through another setting on the Additional Options page.

Other Lifecycle Manager options include the following items:
-
Create Identity – creates provisioning plans that update IdentityIQ. You can create a new IdentityIQ identity with a set of attributes that can be configured. The attributes that you can set or change are defined by a form that can be customized. New identities do not have accounts on any application.
-
Edit Identity – creates provisioning plans that update IdentityIQ. You can modify attributes for an existing IdentityIQ identity. The attributes that you can set or change are defined by a form that can be customized.
Note: Life Cycle Events can cause provisioning outside of IdentityIQ or additional provisioning inside IdentityIQ. In addition. Attribute sync can also cause provisioning outside of IdentityIQ based on create or edit identity.
-
Manage Passwords – resets passwords on target systems which involves a provisioning plan and provisioning action.
-
View Identities – does not have provisioning-related functionality and is read-only.