Leaver Configuration
The Leaver process defines the operations that are launched when someone leaves your organization.
Move the slider to enable Leaver Processing, then configure global behavior for leaver processing.
Note: see Sample Rules for Rapid Setup for information about sample rules included with Rapid Setup.
Option |
Description |
Generate Approvals |
Enable this option if the leaver process should include approvals. The approval path is defined in the Leaver Business Process you specify below. Note that the default RapidSetup – Leaver business process delegates approvals to the LCM Provisioning business process. |
Exclude Uncorrelated Identities |
Exclude uncorrelated identities from joiner processing. A correlated identity is an identity that has an account on an authoritative application. |
Remove Assigned Roles |
Remove assigned roles from an identity during leaver processing. |
Reassign Artifacts |
Reassign objects, such as applications, workgroups, or policies, that are owned by a leaving user. |
Reassignment Artifacts Types |
Choose which types of object should be reassigned, if the current owner is the leaving identity. |
Reassign Artifacts to Manager |
Reassign the objects selected above to the manager of the leaving identity. |
Reassign Artifacts Rule |
Handle reassignment of object using a rule. If the Reassign Artifacts to Manager option is also enabled, the leaver process will first attempt to assign objects to the manager, then will use the rule chosen here, if no manager can be determined. |
Reassign Artifacts Alternate |
Reassign objects to this identity if none were discovered for manager or by the reassignment rule. |
Reassign Identities |
If the leaving identity is the owner or administrator of other identities, such as service accounts or RPA / bot identities, enable this option to reassign those identities to another identity or workgroup. |
Reassign Identities to Manager |
Reassign the identities to the manager of the leaving identity. |
Reassign Identities Rule |
Handle reassignment of managed identities using this rule, if a manager cannot be determined, or if the Reassign Identities to Manager option is not enabled. |
Reassign Identities Alternate |
Reassign managed identities to this identity, if no identity was discovered as a manager or by the reassignment rule. |
Send Leaver Notification to this Workgroup |
Select a workgroup to receive leaver notification emails, rather than a manager. |
Ownership Reassignment Notification Email Template |
Email template to compose the email notification regarding reassignments (used for both artifact and identity reassignment). For more information on email templates, see IdentityIQ Email Templates. |
Leaver Completed Notification Email Template |
The template to use for notification emails. For more information on email templates, see IdentityIQ Email Templates. |
Post Leaver Rule |
Rules can drive custom actions outside of the standard leaver processes. If you want to run a rule as the final step of the leaver process, choose the rule here. Rules of type |
Threshold Type |
Identity Processing Thresholds stop lifecycle events before they are fully processed, in case of accidentally-triggered workflows, To enable an Identity Processing Threshold, choose from Fixed or Percentage. For more information, see Using Identity Processing Thresholds for Error Prevention. |
Threshold |
Enter a value to use in conjunction with the Threshold Type, for Identity Processing Thresholds. |
Leaver Business Process |
Choose the business process for leaver processing. |
Trigger Filter |
Trigger filters define what is considered a "leaver" in your organization. For example, if change in an identity's status from "Active" to "Inactive" should trigger leaver processing, you can set a Trigger Filter using the "Inactive" attribute with the operator "Changed To" set to a value of "True" to select leaver identities. You can use attributes, populations, or a combination of both to define your leaving identities. You can use "And" and "Or" conditions for filtering, and the gear icon to the right of your criteria lets you move, duplicate, or delete rows. For more information, see Defining Trigger Filters. |