# SailPoint Non-Employee Risk Management Admin Help
> SailPoint Non-Employee Risk Management Admin Help
# SailPoint Non-Employee Risk Management Admin Help
# SailPoint Non-Employee Risk Management Admin Help
Managing non-employees is a key part of ensuring your organization's security. SailPoint's Non-Employee Risk Management product helps you track and manage non-employees and their lifecycles within your company.
Important
Non-Employee Risk Management can be used as an authoritative source for your organization's non-employee identity governance information, but it should not be the sole repository. Your organization is responsible for maintaining a separate, regularly backed-up source to ensure data integrity and availability. For more information on best practices related to backing up Non-Employee Risk Management data, refer to the [API Documentation](https://developer.sailpoint.com/docs/api/nerm/v1/get-profiles/), or contact SailPoint Support.
You are restricted from including certain personal information and other regulated sensitive information in Non-Employee Risk Management. This includes restrictions set forth in your company’s contract(s) with SailPoint. Consult with your Legal Department before proceeding.
Your company is charged with obtaining consent from data subjects before including their personal information in Non-Employee Risk Management.
Should you have any questions, contact your Legal Department.
You can find documentation for end users of your non-employee system in our [User Help](https://documentation.sailpoint.com/ne-user/help/) section.
## Non-Employee Risk Management Overview
Non-Employee Risk Management allows you to manage non-employees such as contractors, vendors, and other partners. The non-employees in your site, and the data about them, will be managed by profiles. The users you add to your site can help you create, link, and manage these profiles.
When users are added to your tenant, the [roles](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) they have determine which profiles they can manage.
To allow users to create profiles, start by creating [forms](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) and building them into [pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) that users will fill out when creating new profiles.
Create the [profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/index.html) that will categorize data about your non-employees. For example, you could create profile types for the non-employees themselves, the list of organizations they come from, or the projects they're working on.
Create [workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html), which your users will use to [create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows) and [update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows) the profiles within each profile type.
Each profile type will need its own set of workflows, which can be activated by users to create and manage the profiles within it.
Once this is complete, you and the other users in your site can create [profiles](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html) within each profile type. These can be linked together until your organization has a complete map of all the non-employee data it needs to track.
Track [user](https://documentation.sailpoint.com/ne-admin/help/reports/index.html) and [workflow activity](https://documentation.sailpoint.com/ne-admin/help/reports/reporting.html#workflow-activity-details) to make sure everything is working correctly.
You can use the SailPoint Solution Center icon in the upper-left corner to quickly access your other SailPoint products.
# Initial Tenant Setup
When you first get access to your Non-Employee Risk Management instance, you'll need to make some basic configurations as needed for your organization.
- **[Configure Administrators](https://documentation.sailpoint.com/ne-admin/help/users/manage-admins.html)** - Create an initial set of administrators in your site.
- **[Configure Authentication](https://documentation.sailpoint.com/ne-admin/help/setup/authentication.html)** - Integrate your SSO provider with Non-Employee to enable users to sign in.
- **[Update Branding](https://documentation.sailpoint.com/ne-admin/help/setup/branding.html)** - Customize the visual appearance of the product, including logos and color schemes.
- **[Import Configuration Data](https://documentation.sailpoint.com/ne-admin/help/setup/import.html)** - Upload configuration files for objects from a lower environment, such as a test tenant. Contact SailPoint Support for assistance obtaining these configuration files.
- **[Configure Languages](https://documentation.sailpoint.com/ne-admin/help/setup/languages.html)** - Choose which languages your tenant can be translated to and provide translations for custom elements.
# Managing API Settings
The Non-Employee Risk Management API allows you and your applications to leverage product features programmatically. For example, you can use the API to support application integrations or to upload profile data.
You can use personal access tokens and API keys to allow API clients to integrate with Non-Employee Risk Management. To access the APIs, go to the [SailPoint Developer Community](https://developer.sailpoint.com/docs/api/nerm/v1).
Important
Personal Access Tokens in Non-Employee Risk Management provide enhanced security and are recommended instead of API keys. Tenants created after June 2025 will be required to use [Personal Access Tokens](#authenticate-using-a-personal-access-token) generated within SailPoint Identity Security.
## Authenticate Using SailPoint Identity Security API Credentials
You can use API keys and personal access tokens generated within SailPoint Identity Security to authenticate with Non-Employee Risk Management. Specify the scope of these credentials so they can be used with your Non-Employee system.
### Generating a New Personal Access Token
A personal access token is a set of user credentials that an API client can use to connect to Non-Employee Risk Management. Tokens improve integration security by replacing the need to store the user's username and password in your client application.
Non-Employee Risk Management authenticates personal access tokens against their user permissions. Only Non-Employee Risk Management Admin users are authorized to access the Non-Employee Risk Management API.
For more information about personal access tokens, refer to the [SailPoint Developer Community](https://developer.sailpoint.com/docs/api/authentication/#personal-access-tokens).
API calls made with a user's personal access token must follow the network and trusted geography requirements defined in their SailPoint Identity Security [identity profile](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html#setting-up-identity-profiles).
Personal access tokens created within SailPoint Identity Security are valid for a maximum of 6 months regardless of the last used date, and are automatically deleted once expired.
**To create a personal access token:**
1. Within SailPoint Identity Security, select **Preferences** from the dropdown list under your username.
1. Select **Personal Access Tokens** from the left menu and select **New Token**.
Note
Each user can have up to 10 personal access tokens.
1. Specify where this token will be used in the **What is this token for?** field. This can help you recognize when a token is no longer needed and can be [deleted from SailPoint Identity Security](https://documentation.sailpoint.com/saas/help/common/api_keys.html#deleting-a-personal-access-token).
1. Select the `nerm:general:manage` scope.
1. Select **Create Token** at the bottom of the window to generate and view the Secret and the Client ID.
Important
Copy and save the Secret value before you close this panel. Otherwise, you will have to delete the token and create a new one since this value cannot be retrieved later.
1. Save the Secret value somewhere safe.
You can now use this personal access token. For additional guidance on managing Personal Access Tokens in SailPoint Identity Security, refer to [Managing Personal Access Tokens](https://documentation.sailpoint.com/saas/help/common/api_keys.html#managing-personal-access-tokens).
### Authenticate Using a SailPoint Identity Security API Key
A SailPoint Identity Security [API key](https://documentation.sailpoint.com/saas/help/common/api_keys.html#creating-an-api-key) allows applications and integrations to authenticate with the Non-Employee Risk Management API without being associated with a specific user's permissions.
To use this API key to manage Non-Employee Risk Management tasks, you must assign the `nerm:general:manage` scope to it during its creation.
**To create an API key within SailPoint Identity Security:**
1. Go to **Admin > Global > Security Settings**.
1. Select the **API Management** tab.
1. Select **Create API Client**.
1. Enter a meaningful description for your API key and select **Client Credentials** as the OAuth 2.0 Grant Type.
1. Select the `nerm:general:manage` scope.
1. Select **Create** to generate the client credentials.
1. Copy the client ID and client secret somewhere safe.
Important
Do not close this window without copying your client secret. You cannot view it later, and you need these credentials to authenticate with the Non-Employee Risk Management API.
You can now use this API key to authenticate with the Non-Employee Risk Management API.
## Authenticate Using a Non-Employee Risk Management API Key
An API key is a set of credentials that an API client can use to connect to Non-Employee Risk Management.
Important
- For enhanced security, SailPoint recommends using [SailPoint Identity Security](#authenticate-using-sailpoint-identity-security-api-credentials) credentials instead of Non-Employee Risk Management API keys. Tenants created after June 2025 are required to use credentials created in SailPoint Identity Security.
- API keys generated within Non-Employee Risk Management can't be used by FedRAMP customers.
### Generating a New API Key
You can generate multiple API keys to fulfill individual use cases, making it easier to track API activity.
To manage and review API activity and keys:
1. Within Non-Employee Risk Management, go to **Admin > System > Api** in the left navigation.
The KEYS and SETTINGS tabs are displayed.
1. Select **+ Api Key**.
1. In the **Name** field, enter a unique name for the key and select **Create**.
A token is automatically generated and the key appears in the list of API keys. All API keys are displayed here, regardless of the admin who created them.
### Managing Existing API Keys
You can update the names of existing API keys, delete them, or view their transaction history from the list of API keys.
To manage existing API keys:
1. Within Non-Employee Risk Management, go to **Admin > System > Api**.
1. To edit a specific API key, select the name of the key you want to edit.
The INFO tab is displayed.
1. To edit the API key's name, update the information in the **Name** field and select **Save**.
1. To review authentication requests submitted to the API gateway using this key, select the **TRANSACTIONS** tab.
GET requests are not listed in this tab because they do not alter data.
### Deleting an API Key
You can delete an API key if it is no longer needed.
To delete an API key:
1. Within Non-Employee Risk Management, go to **Admin > System > Api**.
1. Select the checkbox beside each key you want to delete.
1. Select the ellipsis icon and select **Delete**.
1. Select **Delete**. Your API keys and their transaction histories are permanently deleted.
### Updating API Security Settings
You can specify the IP addresses that can make API requests for your environment.
To update your API's security settings:
1. Within Non-Employee Risk Management, go to **Admin > System > Api**.
1. Select the **SETTINGS** tab.
1. Under **IP WHITELIST**, in the **Permitted ips** section, enter an IP address that should be allowed to make API calls.
1. Select the **Add to list** icon .
1. Repeat steps 3 and 4 until the **Permitted ips** list contains all IP addresses that should be allowed to access your environment's APIs.
Select the **Delete** icon beside an IP address to remove it from the list.
1. Select **Save**.
# Authentication and Timeouts
In most cases, users will authenticate into Non-Employee Risk Management by authenticating into SailPoint Identity Security using an identity provider and navigating to Non-Employee Risk Management. These users are known as [lifecycle users](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-lifecycle-users).
Users that access Non-Employee Risk Management using the Collaboration service are authenticated through a [portal](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html). These users are known as [portal users](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-portal-users). SailPoint Identity Security administrators can always access Non-Employee Risk Management.
Note
All lifecycle users must authenticate into Non-Employee Risk Management by authenticating into SailPoint Identity Security.
Non-Employee Risk Management customers integrating with IdentityIQ or SailPoint Identity Security will receive a SailPoint Identity Security tenant which is used for authentication.
Customers without SailPoint Identity Security should contact their account team to receive their SailPoint Identity Security tenant.
## Configuring Authentication through SailPoint Identity Security
You can configure your identity provider so that when a user authenticates into SailPoint Identity Security, they can automatically authenticate into Non-Employee Risk Management as well.
If a user doesn't have an account within Non-Employee the first time they try to authenticate, one will be created for them automatically through Just-In-Time provisioning. Depending on your configurations, they can also be granted roles based on their groups within your SSO provider.
1. Within your identity provider, configure your attribute claim to contain the following attributes:
- `name`
- `email`
If your identity provider prepends a namespace to your attribute names, it must be removed before the attributes are sent to Non-Employee Risk Management.
Important
If you have configured your tenant to [grant roles](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) to lifecycle users based on the groups that are included in your identity provider's SAML assertion, you must also include the `groups` attribute in your attribute claim.
The `groups` string must contain the groups, or entitlements, used to grant users the roles they have within Non-Employee Risk Management. This includes the groups that grant administrator access.
For example, you might be required to provide an attribute claim in XML format. You could use the following format:
```
John Smith
SampleValue1
SampleValue2
john.smith@sample.com
```
1. Configure SailPoint Identity Security as a [service provider](https://documentation.sailpoint.com/saas/help/common/config_idn_service_provider.html).
Note
SailPoint Identity Security requires fewer attributes to enable SAML than Non-Employee Risk Management does. Your identity provider should still be configured to send the `name` and `email` attributes so that they can be used to authenticate into Non-Employee Risk Management. If your tenant grants roles using the groups in the SAML assertion, the `groups` attribute must also be included in your attribute claim.
When users authenticate into SailPoint Identity Security using your SSO provider, they can go to the SailPoint Solutions Center to access Non-Employee Risk Management.
If a SailPoint Identity Security administrator signs in without using an identity provider, they will be granted Non-Employee Risk Management administrator access based on their administrator [user level](https://documentation.sailpoint.com/saas/help/common/users/user_level_matrix.html) regardless of their permissions within Non-Employee Risk Management.
Note
To authenticate directly in to SailPoint Identity Security, bypassing your identity provider, go to your Non-Employee Risk Management site and add `/?internal_login=true` to the URL. Select **Log in with Identity Security Cloud**.
Authenticate with a user name and password and navigate to the **SailPoint Solution Center**.
Select **Non-Employee Risk Management**.
If your SailPoint Identity Security account has administrator privileges, you will be granted admin access in Non-Employee Risk Management.
## Configuring an SSO Integration for Portal Users
For collaboration users, you can configure an integration between your identity provider and Non-Employee Risk Management directly with a SAML connection.
Note
Integration directly between your identity provider and Non-Employee Risk Management is only supported for [portals](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html). Lifecycle users must [authenticate through SailPoint Identity Security](#configuring-authentication-through-sailpoint-identity-security).
If a user doesn't have an account within Non-Employee the first time they try to authenticate, one will be created for them automatically through Just-In-Time provisioning, and they are granted roles based on their groups within your SSO provider.
You can also upload a [CSV file](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#importing-new-users) of users to create accounts for them before they sign in, so they can be used in workflows and other processes.
If you have non-employees who manage other non-employee profiles, they must sign in using the [portal](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html).
To configure an SSO integration with Non-Employee Risk Management:
1. Within your identity provider, configure Non-Employee Risk Management as a service provider.
Configure your attribute claim within your identity provider to contain the attributes corresponding to the user's name, email, and groups within Non-Employee Risk Management.
The `groups` string must contain the groups, or entitlements, used to grant users the roles they have within Non-Employee Risk Management.
1. Within Non-Employee Risk Management, go to **Admin > Collaboration > Portals**.
1. Create a new [portal](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html) or select the portal you want to edit.
1. Select the **SSO** tab.
1. In the **BASIC SETTINGS** section:
- **SAML SSO** - Set to ON to enable SAML SSO for your site.
- **SSO Name** - Enter the name of your SSO provider to display on the login page. For example, if you enter *Acme SSO* in this field, the login page will display a button that says "Login with Acme SSO".
The Encrypt SAML Assertions field, the Metadata URL field, and the CERTIFICATES section can be used later to configure SAML encryption.
Caution
Do not enable **Encrypt SAML Assertions** until after copying your certificate data to your identity provider to avoid being locked out of Non-Employee Risk Management.
- **SSO Only** - Choose whether the username and password fields are hidden from users who are signing in.
Leave the **SSO Only** switch set to **OFF** unless all of the users in the system, or in the portal you're editing, will be authenticating through your SSO provider.
1. In the **SERVICE PROVIDER** section:
- **Domain** - The tenant domain where users should be redirected after authenticating using the IDP.
Most often, this will be a URL similar to `https://[tenant].portal.nonemployee.com`, where `[tenant]` is the name of your Non-Employee tenant.
In some cases, you will need to append `?portal_url=[portal]` to the end of this URL, where `[portal]` is the URL value of your portal.
The Consumer Service URL and the Logout URL will be updated when you fill in the Domain field.
- **SP Entity ID** - Enter the ID of Non-Employee Risk Management as a service provider. This must match what is configured in your identity provider.
- **Name Attribute** - Enter the attribute your identity provider uses for *name*.
1. In **Login Lookup Mode**, choose how the attribute used to authenticate the user should be selected.
- If you select **NameID**, Non-Employee Risk Management will authenticate the non-employee user based on the NameID attribute within the SAML assertion.
- If you select **Assertion Attribute**:
- Enter the name of an attribute in the **Assertion Attribute** field that appears. This should be the name of the attribute that your identity provider uses for authentication in a SAML assertion.
1. Complete the following fields:
- **Email Attribute** - Enter the attribute your identity provider uses for *email address*.
- **Groups Attribute** - Enter the attribute your identity provider uses for *groups* or entitlements.
1. In the **IDENTITY PROVIDER** section:
- If you have the identity provider's metadata XML file, upload it using the **Import File** field.
- If a metadata XML file is not available, complete the following fields:
- **IDP Login URL** - Enter the Login URL provided by your identity provider. Users will be redirected to sign in when they select **Log in with SSO**.
- **X.509 Certificate** - Enter the digital certificate issued by the provider.
- **Fingerprint Algorithm** - Enter the type of encryption used to generate the fingerprint. This is either rsa-sha1 or rsa-sha256.
- **IDP Logout URL** - Enter the URL where users are redirected when they log out of Non-Employee Risk Management.
- **Certificate Fingerprint** - Enter the unique fingerprint for the identity provider's certificate.
- **IDP Entity ID** - Enter the ID of the identity provider.
1. Select **Save**.
Users or portal users can now authenticate into Non-Employee Risk Management using your identity provider.
If you want to encrypt your SAML assertions, you must complete some additional configurations.
1. Optional: To encrypt your SAML assertions, copy the SAML assertion encryption details to your identity provider.
If your identity provider supports certificate details in the form of a link, you can copy the link in the **Metadata URL** section and add it within the correct field in your identity provider.
You can also download the certificate within the CERTIFICATES section by selecting the download icon , then upload this certificate to your identity provider.
Caution
Verify that these certificate details have been provided correctly to your identity provider before enabling SAML encryption within Non-Employee Risk Management to avoid being locked out of your tenant.
1. In the BASIC SETTINGS section, enable **Encrypt SAML Assertions**.
1. Select **Save**.
SAML assertions between your identity provider and this portal or sign-in page are now encrypted.
## Configuring Timeout Settings
If you don't have a SailPoint Identity Security tenant, you can configure Non-Employee Risk Management to require users to reauthenticate after a period of inactivity within the application.
To configure timeout settings:
1. Go to **Admin > System > Authentication**.
The SESSIONS tab is displayed.
1. In the **SESSION SETTINGS** section, choose a value in the **Activity Timeout** field.
You can choose a time period between 5 minutes and 7 days. The user will be signed out after this length of time with no activity.
1. Select **Save**.
# Branding and Logos
You can use custom logos and colors for your Non-Employee Risk Management site to match your corporate branding scheme.
## Uploading Custom Logos
You can choose custom logos that will be displayed in several parts of your tenant.
To upload custom logos:
1. Go to **Admin > System > Branding**.
1. Select the **LOGOS** tab.
Select a logo to replace it with an image from your computer.
Within the **BRANDING** section, you can upload images to replace the following logos:
- **Login Logo** - The logo on the log in page. This logo is used for all login pages that don't have a separate [portal](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html) logo configured.
- **Navigation Panel Logo** - The logo that appears over the left navigation panel for both users and admins.
Within the **NAVIGATION PANEL SECTION HEADERS** section, you can replace the following logos:
- **Lifecycle Logo** - The logo displayed in the Lifecycle section of the left navigation panel for users and admins.
- **Collaboration Logo** - The logo displayed in the Collaboration section of the left navigation panel for admins.
## Colors
You can choose custom colors for your site's navigation and buttons to be consistent with your brand and logos.
To choose custom colors for your tenant:
1. Go to **Admin > System > Branding**.
1. Select the **COLORS** tab.
1. Enter hex codes and make additional selections in the following sections:
- **NAVIGATION PANEL BACKGROUND** - Enter a hex code for a color to use behind the expandable sections within the left navigation.
- **NAVIGATION PANEL SECTIONS** - Enter a hex code for a color to use for active links and highlighted items within the navigation panel.
- **HEADER** - Enter a hex code for a color to use as the background color for the main header over each page.
- Under **Text Color**, choose whether you want the text in the header of each navigation section within the user dashboard to be black or white.
- **BUTTONS** - Enter a hex code to use as the color for the selected types of buttons.
- **Primary Buttons** are typically used for the main action you can take on a given page, such as a Save button or a Continue button. The color is also applied to tabs, pagination, and item count table elements.
- **Secondary Buttons** are typically used for additional actions you can take on a page, such as a Cancel button.
Select the **Use as Link Button color** checkbox beside any section to use your selected color for all links within your tenant. You can see a preview of the link button color within the BUTTONS section.
As you enter hex codes, the image to the right of each section displays a preview of your selected colors.
To remove all custom colors and revert to the default color scheme, select the **Reset All** button.
# Importing Tenant Configuration
The Configuration Import page allows you to import some configurations from your lower environment to production. For example, you might have a test, development, or sandbox tenant. You can import its configurations into your production environment.
Caution
- Migrating a tenant's configuration incorrectly can result in serious configuration and database errors. Contact [SailPoint Support](https://community.sailpoint.com/t5/Contact-Support/ct-p/Contact-Support) for questions regarding the configuration import process or [SailPoint Expert Services](https://community.sailpoint.com/t5/Working-With-Services/ct-p/Working_with_PS) for hands-on assistance with migrating a tenant's configuration.
- If you intend to use the configuration import tool as described in this document, always make your environment configurations within your lower tenant. Do not create these objects or configurations in both your lower and production tenants.
- Importing configuration objects doesn't remove components of those objects. For example, if you import a form from your lower environment that has had one or more attributes removed, those attributes will not be removed from the corresponding form in your production environment.
## Preparing for a Tenant Migration
Before you can export your tenant's configuration, you'll need to:
- Determine which objects you will migrate. [Review](#objecttypes) a list of the types of objects that can be migrated.
- [Verify](#verifying-object-ids) the UID and GUID of each object to migrate.
- [Generate](https://documentation.sailpoint.com/ne-admin/help/setup/api.html) a new API token.
An [API token](https://documentation.sailpoint.com/ne-admin/help/setup/api.html) is required for tenant migrations.
**The following types of objects can be migrated:**
- Within the **Lifecycle** section:
- Profile Types
- User Roles
- Workflows
- Within the **Collaboration** section:
- Portals
- User Roles
- Workflows
- Within the **Templates** section:
- Attributes
- Forms
- Notifications
- Pages
- Value Builders
Important
- Profiles can't be migrated between environments. If a specific profile is required for another object, such as a workflow action or condition, it must be created in the new environment before importing any workflow configurations. Before uploading your workflow's JSON, replace the GUID of any profiles referenced within the JSON of the workflow with the GUID of the applicable profiles from your production tenant.
- When an object such as a workflow is exported, objects connected to the workflow or any of its steps are also exported, with the exception of profiles. This includes user roles that can access the workflow, the profile type the workflow runs on, any forms and pages the workflow uses, and other configurations. If an exported workflow contains a Run Workflow step, that workflow and the objects connected to it are also exported.
Some specific configurations can be made directly to objects within your production environment. Review [Manually Updating Objects](#manually-updating-objects) for details.
### Verifying Object IDs
As you create objects within your environment, they are assigned an ID on the configuration page. This is the UID.
A GUID is automatically generated for each object in your environment. This is not visible while the object is being created, but it can be accessed later.
If you migrate an existing object from your lower environment to your production environment, both the UID and the GUID must be identical for each object between both environments. If either ID for the object isn't the same between the two environments, a new object will be created in the new environment when it's uploaded.
**To verify the UID and GUID of an object:**
1. Navigate to the configuration page for that object.
For example, a portal's configuration page can be located by going to **Admin > Collaboration > Portals** and selecting the name of the portal you want to view.
1. Locate the **Uid** field on the page. This value should be identical between the object in your lower environment and production.
1. Within the URL, locate the string of letters and numbers after the name of the object type. This is the GUID. The GUID should also be identical for this object between your lower and production environments.
For example, in the sample portal URL `https://tenant-name.com/neaccess_admin/portals/f52a14bc-6a73-4h95-ba3c-dfedabd643ae/info`, the GUID can be found between `portals` and `info`.
## Exporting Objects
SailPoint recommends that you export configurations one at a time to enable you to troubleshoot issues as they arise.
To export objects from your lower environment:
1. Navigate to the object within your lower environment.
1. Select the objects you want to export.
1. Select the menu icon beside **Actions** and select **Export**.
A JSON file is generated that contains the selected object. JSON files for exported workflows also contain the JSON for many dependent objects such as attributes, forms, and pages.
1. Select the **Download** button.
Repeat these steps for each object you're exporting from your lower environment.
## Importing Objects
When you have verified the UID and GUID for each object you are migrating, you can begin importing many of your configurations.
### Prerequisites for Importing Objects
Before importing certain types of objects to your production environment, you must make some additional changes to them.
- Within your production environment, create any profiles that are referenced by your workflows' actions or conditions. Add the GUIDs of those production profiles to the JSON for he workflow that uses them.
- Edit the endpoints and API tokens of API actions within your workflows to point to your production environment.
Best Practice
To ensure that workflows and notifications work correctly, update any URLs within notifications to point to your production environment.
### Importing Configuration Objects
SailPoint recommends you import and validate your configuration objects one at a time. To simplify the migration process, import foundational objects such as user roles and profile types, before importing workflows.
To import an object:
1. Go to **Admin > System > Configuration Import**.
1. Select **Get Started**.
1. Under **Import File**, select the plus icon and choose an object in JSON format to upload.
1. Select **Next**.
1. Under **CREATE REVIEW**, review each object that will be created as a result of this import.
If you see unexpected items in this list, or copies of existing items, review the UID and GUID of each object you're importing to ensure they match the existing objects in your tenant.
Select **Next**.
1. Under **UPDATE REVIEW**, review each object that will be updated. Select **Next**.
When your configurations have been imported successfully, a success message is displayed.
## Validating Configuration Imports
Some objects require manual verification or additional configuration once they have been imported to your production environment. Review the list of object types below and complete your tenant's configuration.
**Attributes**
- Verify that the permissions and validations associated with imported attributes match the intended configuration.
- Verify that any options such as checkboxes or radio buttons that you need to remove from the attribute have been removed.
**Forms**
- Review forms for duplicate fields.
- Verify that all conditional forms, configured with **Add form to options**, appear correctly.
- Remove any attributes and options that no longer apply from forms.
**Pages**
- Verify that all forms within both workflow pages and profile pages appear correctly.
- Remove any forms that no longer apply from pages.
**Profile Pages**
- Verify that profile pages are displaying information as expected based on the profile type configurations.
**Profile Types**
- Review the profile naming schema. If you see duplicate attributes within the schema, remove all attributes from the profile naming field and reimport the profile type.
**Tables**
- Go to **Admin > Templates > Tables** and update the attributes displayed.
**User Roles**
- Navigate to the configuration for each role and update the permissions for your lifecycle and collaboration roles as necessary.
**Workflow Pages**
- Verify that workflow pages are displaying information as expected based on the profile type configurations for that workflow.
**Workflows**
- In **Duplicate Prevention** steps, review and update the attributes used for the Duplicate Search Settings Criteria.
- In **Collaboration Account** steps in Collaboration Registration workflows, update the **Roles to assign the user** field.
- Review actions that contain conditional logic. If a condition uses static profiles or static text values, update those values to use the correct profile or text.
## Manually Updating Objects
There are some configurations that can be made directly within the production environment.
If you make these changes to one environment, apply them to all other environments as well to ensure your tenants remain in sync.
| Object Type | Allowed Changes |
| ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Attributes | - Edit the label and description for existing attribute. - Update the tool tip for existing attributes. |
| Branding | - Update the colors used in your tenant for buttons and other interface elements. |
| Legal | - Enable or disable the cookie banners for the user dashboard and collaboration portals. - Edit the privacy policies for the user dashboard and collaboration portals, and enable or disable them. - Edit the terms and conditions for the user dashboard and collaboration portals, and enable or disable them. |
| Notifications | - Edit the contents or subject of existing notification templates. - Add or remove attachments from any existing notification templates. - Change the **Include link to request?** option on existing notification templates. |
| Roles | - Edit the permissions in the Application, Attributes, Profile Access, Workflows, and API categories on any existing role. |
| SMTP | - Choose whether to use your own SMTP configuration or SailPoint's SMTP configuration. |
| SSO | - Edit information related to your identity provider and service provider. |
| Tables | - Toggle whether the Status, ID, and Identity Proofing columns are displayed. - Add and remove columns from existing tables. |
| Users | - Enable and disable users. |
# Language Settings
Non-Employee Risk Management provides multi-language support for Lifecycle users. Admins can set a default language for the tenant and enable additional languages. The Lifecycle dashboard for end users is displayed in the default language. If a user [selects an enabled language](https://documentation.sailpoint.com/ne-user/help/dashboard/index.html#language-selection), the selected language will become the user's default language, and will be remembered for future logins.
Core elements, such as page titles, form headers, default buttons and tables are automatically translated. Custom elements, such as attribute labels and descriptions, notification subject and bodies, page headers and HTML elements must have custom translations added.
Note
Supported languages are only applied for end users. The Admin dashboard will remain in English.
**To enable a language:**
1. Go to **Admin > System > Languages**.
1. Set the **Active** toggle to **ON** for the language you want to enable.
The enabled language is available for selection by Lifecycle users.
**To set the default language:**
1. Go to **Admin > System > Languages**.
1. Enable the **Default** radio button for the language you want to set as default.
End users will see the interface in the default language unless they have selected another language.
**To add individual custom attribute translations:**
1. Go to **Admin > System > Languages**.
1. Select **Edit** beside the language for which you want to add custom translations.
1. For each attribute, enter the translation in the **Translation** field.
1. Select **Save**.
The added translations will be displayed for the attributes when the user is using the selected language.
**To upload translations for custom attributes in bulk:**
1. Go to **Admin > System > Languages**.
1. Select **Edit** beside the language for which you want to add custom translations.
1. Select **Download Translations**.
1. Open the CSV and enter your translations.
1. In Non-Employee Risk Management, select **Upload Translations**.
1. Select the CSV and select **Upload Translations**.
The custom translations are available for the selected language.
# Email Settings and Notifications
Non-Employee Risk Management can notify you by email of certain activity within your tenant, such as workflow failures or password resets. You can configure other email notifications within your workflows.
Emails from your non-employee tenant are sent using an SMTP server.
## SMTP Settings
By default, Non-Employee tenants use SailPoint's SMTP server configuration. However, you can update these settings and use your own SMTP configuration.
To update the SMTP settings for your tenant:
1. Go to **Admin > System > Smtp**.
1. Under **Use my own smtp**, select **Yes**.
1. Within the **AUTHENTICATION** section, complete the following fields:
- **User name** - The user name for the SMTP server.
- **Password** - The corresponding password for the SMTP server.
- **Enable STARTTLS** - Set to **true** if your server uses STARTTLS.
1. Within the **SMTP SETTINGS** section, complete the following fields:
- **SMTP address** - The address of the email server.
- **SMTP port** - The port number used by the email server.
- **From address** - The email address to use as the From address for emails coming from Non-Employee.
- **authentication** - Select the type of authentication to use. Choose from none, plain, login, or CRAM-MD5.
- **HELO domain** - If your SMTP server requires a HELO domain, enter the fully qualified domain name to use in HELO checking.
## Notifications
A notification is any email that comes from Non-Employee. This includes both system notifications and custom notifications that come from workflows.
Emails generated by workflows can be edited. These notifications support Liquid template language and HTML. Refer to the [Liquid documentation](http://shopify.github.io/liquid) for more information.
System notifications can't be edited.
### Creating a Notification
In most cases, custom notifications are used to notify stakeholders about the progress of a profile request during a workflow execution.
To create a new notification for use within workflows:
1. Go to **Admin > Templates > Notifications**.
1. Select **+ Notification**.
1. Complete the fields on the New Notification page.
- **Name** - Enter a unique name for the new notification. This is used to select the notification when configuring a workflow.
- **Uid** - Enter a unique identifier for the notification. This can't be changed later.
- **Description** - Enter a description for this notification.
1. Select **Create**.
The LAYOUT tab for the notification is displayed.
1. Complete the **Subject** and **Body** fields of the notification.
The recipient of the email is configured within the workflow notification step that uses this email.
- To include an attribute from the request being submitted, copy and paste the value from the **method** column within the **Request attributes** table.
- To include an attribute from the profile being updated, copy the value in the **id code** column within the **Your Attributes** table.
- To include an attachment with the notification, select **Choose Files** underneath the notification body.
- To include a link to the applicable request at the bottom of your notification, select **Yes** under **Include link to request**.
- To customize the body styling use standard inline HTML and CSS.
1. Select **Save**.
1. To preview the formatting and style of your notification, select the **Preview** button. Any variables included in your notification will not be replaced with data in this preview.
Note
If you have security and compliance restrictions on your emails, some HTML and CSS email styling might not display correctly for end users.
### Updating an Existing Notification
To view and update existing workflow notifications:
1. Go to **Admin > Templates > Notifications**.
Active, or enabled, notifications are displayed in the **Active** tab. Inactive, or disabled, notifications can be found in the **Archived** tab.
1. Select the name of the notification you want to edit.
1. Edit the notification itself and its variables within the **LAYOUT** tab. Edit the name and other details about the notification in the **INFO** tab.
1. Select **Save**.
### Managing Existing Notifications
You can change the status of existing notifications, copy them, or export them.
To manage existing workflow notifications:
1. Go to **Admin > Templates > Notifications**.
Active, or enabled, notifications are displayed in the **Active** tab. Inactive, or disabled, notifications can be found in the **Archived** tab.
1. Select the checkbox beside the notifications you want to edit, or select the checkbox beside the NOTIFICATIONS header to select all notifications in the table.
1. Select the ellipsis icon beside the NOTIFICATIONS header.
1. Choose from the available options.
- **Archive** - Move the selection notifications to the **Archived** tab. Archived notifications can't be selected within workflows.
- **Unarchive** - Move the selected archived notifications to the **Active** tab.
- **Clone** - Create copies of all selected notifications. These copies appear in the same tab as the original notification, with a number added to the notification's name.
- **Export** - Export the notifications in JSON format.
# Managing Non-Employee Risk Management Users
You can add users to your Non-Employee tenant to manage specific profiles or profile types. Users can be employees of your organization, or non-employees you invite to help manage profiles. Grant permissions to users with roles based on the type of user they are. Refer to [Establishing Authentication](https://documentation.sailpoint.com/ne-admin/help/setup/authentication.html) for more information on adding users.
You can learn more about managing the types of users in Non-Employee and their permissions in the following documentation:
- **[Managing Users](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html)** - Enable and disable users, update their information, and change their roles. If necessary, assign managers to users.
- **[Managing Admins](https://documentation.sailpoint.com/ne-admin/help/users/manage-admins.html)** - Create an administrator role and assign it to users.
- **[Managing System Default Roles](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html)** - Manage the Profile Owner and Profile Contributor roles used to grant users permissions on specific profiles.
- **[Managing Lifecycle User Roles](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html)** - Create additional user roles for Lifecycle users, and determine the permissions each role should have.
- **[Managing Collaboration User Roles](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html)** - Create user roles for Portal users and configure the permissions for those roles.
# Managing Collaboration User Roles
Collaboration user roles define the permissions and level of access granted to a portal user within Non-Employee.
Collaboration user roles are assigned to portal users to grant them access to parts of your Non-Employee tenant. [Lifecycle roles](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) can't be applied to portal users, and collaboration roles can't be applied to lifecycle users.
Collaboration roles are assigned to portal users within the [Collaboration Account Action](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#collaboration-account) in workflows, or automatically based on the groups or entitlements they have on your identity provider.
## Creating Collaboration Roles
Before you can grant portal users access to your site, you must create one or more collaboration roles.
1. Go to **Admin > Collaboration > Portal User Roles**.
1. On the Portal Group Roles page, select **+ Role**.
1. On the Create Portal Role page:
- Enter a unique name for the role.
The UID is generated automatically based on the name. This can be modified during the role's creation, but it can't be edited later.
- In the **Directory groups** field, enter the complete and exact names of one or more groups from your identity provider.
Portal users with one or more of these groups, that have access to the portals associated with this role, will be granted this role and the access that comes with it.
1. In the Portals column, choose which portals this role applies to.
Only users with access to the portals you select here can be assigned this role.
1. Select **Create**.
The INFO tab of the role is displayed.
1. Select the **PERMISSIONS** tab. Choose the permissions you want users with this role to have.
- In the **Attributes** section, choose whether users with this role can view attributes on a profile, edit them directly on that profile, or whether they should have no access to those attributes.
- In the **Workflows** section, choose which workflows users with this role should be allowed to execute on the profiles they're assigned to. Users with this role who don't have permission to execute workflows can still approve or deny requests associated with the workflow, complete fulfillment tasks, and contribute to the workflow in other ways.
Note
If a portal user has more than one role, including [default roles](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html), the permissions applied to each portal user for a profile type are cumulative.
## Editing Collaboration Roles
You can view and edit the collaboration roles in your system.
1. Go to **Admin > Collaboration > Portal User Roles**.
In the PORTAL GROUP ROLES page, you can see the active and archived portal roles in your tenant.
1. Make any necessary changes to the roles on the list.
Review the possible changes you can make below.
#### Update Roles in Bulk
You can make some changes to the roles in your tenant in bulk.
1. Select the checkbox beside the roles you want to edit.
To select all roles, select the the checkbox next to the **PORTAL GROUP ROLES** header.
1. Select the ellipsis icon next to Actions button to display the available actions.
- **Archive** - Immediately deactivates the selected roles and moves them to the Archived tab.
- **Unarchive** - Immediately activates the selected roles and moves them to the Active tab.
- **Export** - Generates a JSON file containing the metadata about the selected roles and any related configuration. When the file has been generated, select **Download** to save the metadata to a local file.
#### Update an Individual Role
1. Select the name of the role you want to edit.
1. In the **INFO** tab, make changes to the settings of the role.
Note
- The Uid of a role can't be edited once the role has been created.
- Removing a group from the **directory groups** list causes users with that group to lose access to the role, unless they have another group in the list.
1. In the **PERMISSIONS** tab, make any necessary changes to the permissions this role grants to users.
Users with this role will have their permissions updated when you save the role.
# Managing System Default Roles
Non-Employee Risk Management includes two roles by default: Profile Owner and Profile Contributor. Each of these roles is a type of *contributor*. These roles are used to grant both lifecycle and portal users specific access to manage profiles within Non-Employee.
These roles are customizable. You can choose the access each role grants to users to suit your business needs. Users assigned either of these roles can make the specific configurations it allows on the profiles assigned to them. While each profile can have many Profile Contributors, it can only have a single Profile Owner.
The system default roles are the only roles that can be granted to lifecycle users without entitlements or groups from your identity provider. Instead, they are granted to users on the details page for an individual profile, through assignment in workflows, or with a profile attribute. Refer to [Assigning System Default Roles to Users](#assigning-system-default-roles-to-users) for details.
## Editing System Default Roles
You can make changes to the access granted by the Profile Owner and Profile Contributor roles.
To update the system default roles:
1. Go to **Admin > Lifecycle > User Roles**.
1. Select the **SYSTEM DEFAULTS** tab.
1. Select the role you want to edit.
1. In the **PERMISSIONS** section, make changes to the permissions you want users with this role to have.
- In the **Application** section, choose whether users with this role should be allowed to perform bulk approvals and rejections of requests, bulk cancellations of requests, add additional contributors to the profiles they're assigned to, or whether they can delegate their assigned work to other users.
Note
To perform bulk approvals and rejections, workflows using the Approval Form action must have the [Allow bulk approval or rejection](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#approval-form) setting enabled.
- In the **Attributes** section, choose whether users with this role can view or edit attributes on the profiles they're assigned to, or whether they should have no access to those attributes.
- In the **Workflows** section, choose which workflows users with this role should be allowed to execute specific workflows on the profiles they're assigned to. Users with this role who don't have permission to execute workflows can still approve or deny requests associated with the workflow, complete fulfillment tasks, and contribute to the workflow in other ways.
1. Select **Save**.
## Assigning System Default Roles to Users
The Profile Owner and Profile Contributor roles can be assigned to users in several ways.
- By assigning the owners or contributors directly on a profile.
- By including a step in a workflow to add an owner or contributor automatically.
- By adding an [attribute](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) to the profile with a *contributor* or *owner* type, so that contributors can be added manually during profile creation.
When a user is assigned the Profile Owner or Profile Contributor role for a profile, they are granted the permissions you configured for that role on that profile.
### Assigning Contributors Directly to a Profile
You can grant a specific user the Profile Owner or Profile Contributor roles for a specific profile by editing the list of contributors for that profile.
To add an owner or contributor to a profile directly:
1. Go to **Admin > Lifecycle > Profiles**.
1. Select the profile you want to edit.
1. Go to the **CONTRIBUTORS** tab.
You can see a list of current contributors to this profile, as well as the custom [lifecycle](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) and [collaboration](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html) roles that allow users to manage the profile.
1. In the **Add contributor** field, begin typing the name of a user you want to add as a contributor to this profile. Select the user you want to add.
The user you selected is granted the Profile Contributor role for this profile.
1. To grant the user the Profile Owner role, select the **make owner** icon to the right of the status column in the table.
The permissions you assigned to the role are granted automatically to the user for the selected profile.
Adding a new profile owner using this method converts the previous owner to a contributor.
Select the **Delete** icon beside a contributor to remove them from the list.
### Assigning System Default Roles Using Workflows
When creating a workflow to create or update a profile, you can configure that workflow to assign profile owners or contributors to that profile automatically.
For more information, refer to the [Contributors](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#contributors) action within workflows.
Adding a new profile owner using this method removes the previous owner from the list of contributors.
### Add a System Default Role Using a Profile Attribute
You can create an attribute that assigns owners and contributors to profiles. The attribute can be included in forms and pages. When a new profile is requested and the pages are sent to a user to complete, that user can manually add a contributor or owner to the profile using that attribute.
To add a contributor attribute to profiles:
1. Go to **Admin > Templates > Attributes**.
1. Select **+ Attribute**.
1. In **Field type**, select one of the following options. The user filling out the new profile's attributes will assign a contributor based on the field type you select.
- **contributor search** - Search for a user to assign as a contributor for this profile.
- **contributor select** - Choose from a list of users to assign as a contributor for this profile.
- **owner search** - Search for a user to assign as an owner for this profile.
- **owner select** - Choose from a list of users to assign as an owner for this profile.
1. Complete the remaining fields and select **Create**.
1. Complete the remaining fields on the Basic Info page and select **Finish**.
For more information about creating attributes, refer to [Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html).
1. Create a [form](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) that includes this attribute, and add that form to a [page](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html).
1. Add the page to a workflow using the [Request Form](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#request-form) action.
When a new profile is created using this workflow, the form will be assigned to a user. That user can manually assign a contributor or owner within the attribute you created.
Adding a new profile owner using this method removes the previous owner from the list of contributors.
# Managing Lifecycle User Roles
User roles define the permissions and level of access granted to an end user of the system, as well as which users are allowed access to the admin console.
You can create and manage custom user roles within Lifecycle with extremely granular controls. In addition, there are two [default user roles](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) within the product that can grant users specific permissions related to profile types.
Refer to [Managing Administrators](https://documentation.sailpoint.com/ne-admin/help/users/manage-admins.html) for details on creating the administrator role.
Note
Lifecycle roles can't be applied to [portal users](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-portal-users), and collaboration roles can't be applied to [lifecycle users](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-lifecycle-users). Refer to [Collaboration User Roles](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html) to create and manage collaboration roles for portal users.
Roles can be assigned to users three ways:
- By assigning roles to the users in the form of entitlements, within SailPoint Human Fabric.
- Based on the permissions sent by your identity provider in the SAML assertion.
- By selecting users from within the user roles update screen.
By default, new tenants are configured to use roles that have been assigned as entitlements within SailPoint Human Fabric for lifecycle roles.
Caution
Use caution when updating this setting. If you have roles assigned to users already, updating this setting can cause your current users to lose access to Non-Employee Risk Management.
## Assigning Roles with SailPoint Human Fabric
You can configure your tenant to grant roles to your users automatically within SailPoint Human Fabric. This allows those roles to be governed, in the form of entitlements, within SailPoint Human Fabric, through processes such as certification campaigns and lifecycle states.
**Prerequisites:**
- You have created a [Non-Employee Risk Management Users](https://documentation.sailpoint.com/ne-admin/help/connector/users_connector.html) source within SailPoint Human Fabric.
- **Identity Security Cloud Entitlements for Roles** is set to **ON**. You can verify this setting in **Admin > System > Authentication** on the **ISC AUTHENTICATION** tab.
Caution
Use caution when updating this setting. If you have roles assigned to users already, updating this setting can cause your current users to lose access to Non-Employee Risk Management.
To prevent your users from losing access when you enable this setting, make sure that your Non-Employee Risk Management Users source has been set up correctly and has aggregated users and entitlements at least once. After this, you can enable the **Use Identity Security Cloud Entitlements for Roles** setting.
**To manage Non-Employee Risk Management roles as entitlements using SailPoint Human Fabric:**
1. Go to **Lifecycle > User Roles**.
1. On the **ASSIGNABLE ROLES** tab, select the **+ New Role** button.
For each role you want to assign in your tenant, create a role.
- Enter a unique name for the role.
The UID is generated automatically based on the name. This can be modified during the role's creation, but it can't be edited later.
- Select the **Private** checkbox to hide this role from users on the user dashboard within the profile's CONTRIBUTORS tab.
- [Assign permissions](#assigning-permissions-to-roles) to your role.
- Select **Create**.
1. When you have finished creating roles, go to SailPoint Human Fabric.
1. Within SailPoint Human Fabric, go to **Admin > Connections > Sources** and select the Non-Employee Risk Management Users source.
1. In **Entitlement Management**, select **Entitlement Aggregation**.
1. Select **Start Aggregation**.
The roles you created earlier within Non-Employee Risk Management will be aggregated to SailPoint Human Fabric as entitlements.
1. Assign those entitlements to SailPoint Human Fabric users who will be given Non-Employee Risk Management access.
Users can be assigned this entitlement in any way that entitlements are granted. For example:
- The entitlement can be added to an access profile that is marked as [requestable](https://documentation.sailpoint.com/saas/help/requests/config_entitlements.html), and users can request access to it.
- The entitlement can be added to a SailPoint Human Fabric [role](https://documentation.sailpoint.com/saas/help/access/roles.html) that is [assigned](https://documentation.sailpoint.com/saas/help/provisioning/role_assignment.html) to users automatically.
- The entitlement can be added to an access profile that is added to a [lifecycle state](https://documentation.sailpoint.com/saas/help/provisioning/lifecycle.html) and assigned to users automatically.
1. When [provisioning](https://documentation.sailpoint.com/saas/help/provisioning/index.html) is configured for your Non-Employee Risk Management users source, those identities can be provisioned to your Non-Employee Risk Management tenant. The entitlements that have been assigned to them are provisioned to those users, and the roles are assigned to the appropriate users within Non-Employee Risk Management.
## Assigning Roles with your Identity Provider
You can configure specific groups from your identity provider's SAML assertion to grant roles to Non-Employee Risk Management users.
**Prerequisite:**
- Identity Security Cloud Entitlements for Roles\*\* is set to **ON**. You can verify this setting in **Admin > System > Authentication** on the **ISC AUTHENTICATION** tab.
Important
Use caution when updating this setting. If you have roles assigned to users already, updating this setting can cause your current users to lose access to Non-Employee Risk Management.
To prevent your users from losing access when you disable this setting, ensure that your users have been granted the appropriate groups within your identity provider and that those groups are assigned to roles within Non-Employee Risk Management. After this, you can disable the **Use Identity Security Cloud Entitlements for Roles** setting.
**To manage Non-Employee Risk Management roles using your identity provider:**
1. Go to **Admin > Lifecycle > User Roles**.
1. On the **DIRECTORY GROUPS** tab, select the **+ New Role** button.
1. In the **BASIC SETTINGS** section:
- Enter a unique name for the role.
The UID is generated automatically based on the name. This can be modified during the role's creation, but it can't be edited later.
- Select the **Private** checkbox to hide this role from users on the user dashboard within the profile's CONTRIBUTORS tab.
- In the **Directory groups** field, enter the complete and exact names of one or more groups from your identity provider.
Users with one or more of these groups will be granted this role and the access that comes with it. These groups must be included within the `groups` attribute in the SAML assertion sent by your identity provider during authentication to be applied to the user.
- [Assign permissions](#assigning-permissions-to-roles) to your role.
- Select the **Create** button.
Your roles have been created and are granted to users with the appropriate groups when they authenticate for the first time.
## Managing User Role Assignments from the User Role Update Screen
While editing a user role, you can manage the list of users to whom the user role should be assigned. You can add users to the assignee list, or remove users from the list as needed.
### Creating Role Assignments
While editing a user role, you can assign the user role to users in the system.
**To assign a role:**
1. Go to **Admin > Lifecycle > User Roles**.
1. On the **Active** tab, select a role from the list.
1. In the **Select users to be assigned to this role** field, enter a specific user's name, and then select them from the results list to assign the role to them.
The user is automatically assigned the role once you select their name.
### Removing Role Assignments
While editing a user role, you can remove users from the list of assignees.
**To remove individual users from the assignees list:**
1. Go to **Admin > Lifecycle > User Roles**.
1. On the **Active** tab, select a role from the list.
1. Locate the users you need to remove from the list.
To search for a specific user, enter the user's name in the search field above the list of assignees. The list automatically updates as you enter their name.
1. To remove a single user, select the **Remove** icon to the right of the user's row.
**To remove users from the assignees list in bulk:**
1. Go to **Admin > Lifecycle > User Roles**.
1. On the **Active** tab, select a role from the list.
1. Locate the users you need to remove from the list.
To search for a specific user, enter the user's name in the search field above the list of assignees. The list automatically updates as you enter their name.
1. Select the checkbox beside the users' names.
To select all users in the list, select checkbox next to the USERS ASSIGNED TO ROLE header.
Once you've made your selection, select **Remove** to the right of the selected user counter.
## Assigning Permissions to Roles
In the **PERMISSIONS** section, choose the permissions you want users with this role to have.
- In the **Application** section, choose the access users with this role should have within your Non-Employee tenant, such as whether they can perform bulk approvals and rejections of requests, bulk cancellations of requests, add additional [contributors](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) to a profile, or whether they can delegate their assigned work to other users.
Note
To perform bulk approvals and rejections, approval workflows must have the [Allow bulk approval or rejection](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#approval-form) setting enabled.
- In the **Profile Access** section, choose the access this role should grant to the profile types in your tenant. If you choose **All Users With This Role**, users with this role can manage profiles in that profile type. If you choose **Only Contributors**, users with this role won't be able to manage profiles in this profile type unless they are already marked as a profile [contributor](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) for the profile.
Selecting a profile type in this section grants users the access you select in the Attributes and Workflows sections for this profile type.
- In the **Attributes** section, choose whether users with this role can view or edit attributes on the profiles they can access, or whether they should have no access to those attributes.
- In the **Workflows** section, choose which workflows users with this role should be allowed to execute on the profiles they're assigned to. Users with this role who don't have permission to execute workflows can still approve or deny requests associated with the workflow, complete fulfillment tasks, and contribute to the workflow in other ways.
- Under **API Access**, choose the types of API calls users with this role should be permitted to make related to a variety of functions within Non-Employee. This doesn't impact what the users can access within the UI. This section is only available to customers using a legacy on-premise implementation.
Note
When a user has more than one role, including [default roles](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html), the permissions applied to each user for a profile type are cumulative.
## Editing a Custom Lifecycle Role
You can view and edit existing custom roles.
1. Go to **Admin > Lifecycle > User Roles**.
In the DIRECTORY GROUPS page, you can see the active and archived user roles in your tenant.
1. Make any necessary changes to the roles on the list.
Review the possible changes you can make below.
### Update Roles in Bulk
You can make some changes to the roles in your tenant in bulk.
1. Select the checkbox beside the roles you want to edit.
To select all roles, select the the checkbox next to the **NEPROFILE GROUP ROLES** header.
1. Select the ellipsis icon next to the Actions button to display the available actions.
- **Archive** - Immediately deactivates the selected roles and moves them to the Archived tab.
- **Unarchive** - Immediately activates the selected roles and moves them to the Active tab.
- **Export** - Generates a JSON file containing the metadata about the selected roles and any related configuration. When the file has been generated, select **Download** to save the metadata to a local file.
### Update an Individual Role
You can make updates to the details and permissions for a specific role.
1. Select the name of the role you want to edit.
1. In the **BASIC SETTINGS** section, make any necessary changes to the name and other settings for the role.
Note
- The Uid of a role can't be edited once the role has been created.
- Removing a group from the **Directory groups** list causes users with that group to lose access to the role, unless they have another group in the list.
1. In the **PERMISSIONS** section, make any necessary changes to the permissions this role grants to users.
Users with this role will have their permissions updated when you save the role.
1. Select **Save**.
# Managing Administrators
Administrators within Non-Employee are responsible for the configuration and management of your tenant within the admin console. Because administrators have access to all settings and features, consider carefully before assigning the administrator role to a user.
Access to the admin console is granted to users through a lifecycle role. This role can be assigned to users within [SailPoint Human Fabric](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-roles-with-sailpoint-human-fabric), or based on their membership in a group within your [identity provider](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-roles-with-your-identity-provider).
## Creating the Administrator Role
**Prerequisite:**
- If you are configuring your roles to be assigned through your identity provider, assign a unique group or entitlement within your identity provider to all users you intend to mark as administrators within Non-Employee. This allows them to be granted the administrator role automatically the first time they sign in.
For example, you might name this group **Non-Employee Admins**.
**To create the administrator role:**
1. Begin creating a new role as described in [Managing User Roles](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html).
Best Practice
When creating the administrator role, use a descriptive name to indicate that this role grants administrative access.
1. (Optional) If you are configuring roles to be granted through groups within your [identity provider](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-roles-with-your-identity-provider), in the **Directory groups** field, select the group from your identity provider you configured in the prerequisite, corresponding to the users that will be granted admin access.
1. In the **PERMISSIONS** section, under the **Application** header, select the **Yes** radio button beside **admin**.
1. Review the rest of the permissions available for Non-Employee roles and grant them as appropriate.
1. Select the **Create** button.
If you are assigning roles to users by assigning them as entitlements within SailPoint Human Fabric, begin an entitlement aggregation and grant the entitlement to the users who should be given admin permissions. Refer to [Assigning Roles with SailPoint Human Fabric](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-roles-with-sailpoint-human-fabric) for more details.
If you are assigning roles to users based on their groups in your identity provider, this grants users with the selected group access to the admin console the next time they authenticate.
# Managing Users
Most users are granted accounts within Non-Employee Risk Management through your [SSO provider](https://documentation.sailpoint.com/ne-admin/help/setup/authentication.html) or through an imported CSV file. These are known as *lifecycle users*.
If you use the Collaboration service, you can also grant non-employees accounts they can access through [portals](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html) you create. These are known as *[portal users](#managing-portal-users)*.
You can manage both types of users within your Non-Employee tenant.
## Managing Lifecycle Users
On the **Users** page, you can review a list of lifecycle users in your environment, update existing users, or import new users.
### Importing New Users
Users are granted accounts within Non-Employee automatically when they authenticate using your identity provider. However, you can also add new lifecycle users to your environment by importing a CSV file containing their information. This allows you to use them in workflows before they sign in to your environment.
This CSV file must contain:
- The new user's name.
- Their email address.
- A username.
- If you grant roles to users based on their groups in your identity provider, and you want to grant these users a role, include a column in your CSV file that contains a group string corresponding to an existing user role.
Note
- The value used for username must be unique among all users in your environment. If an imported file contains duplicate usernames or usernames that already exist in your system, those imported users will fail.
- Users must have a role in order to sign in to Non-Employee. If you don't include a groups string in your CSV file, the user's role can be granted when they [authenticate](https://documentation.sailpoint.com/ne-admin/help/setup/authentication.html#configuring-an-sso-integration-for-portal-users) into Non-Employee with your identity provider, or you can assign them a role within [SailPoint Human Fabric](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-roles-with-sailpoint-human-fabric).
To upload a user file, from the Admin console:
1. Select **System > Users** in the left navigation.
1. Select .
1. Select the CSV file containing your users. Select **Open**.
An Import Users dialog box is displayed, including the columns from the CSV file.
1. Use the dropdown lists over the columns to select which columns contain the names, emails, and usernames for the imported users.
If your CSV file does not contain column headers, clear the **Use first row of .csv file as column headers** checkbox to ensure all users are imported correctly. Use the horizontal scroll bar to find all of the columns you uploaded with the CSV file.
Select **Import**.
The users you upload appear in the list of users. They can be edited and used in workflows as needed.
### Editing Lifecycle Users
You can make changes to a user's status or other details about their Non-Employee account.
**To update a lifecycle user:**
1. Go to **Admin > System > Users**.
Active, or enabled, users are displayed in the Active tab. Disabled users are displayed in the Disabled tab.
You can find details such as the user's name, email address, status, and lifecycle roles by selecting their name from the list. These attributes cannot be edited directly and must be edited within your identity provider.
1. Make any necessary changes to the users on the list.
Review the possible changes you can make below.
#### To enable or disable users:
1. Select the checkboxes beside the users you want to edit, or select the checkbox beside the USER ACCOUNTS header to select all accounts.
1. Select the ellipsis icon next to the USER ACCOUNTS header.
- Select **Enable** to enable the users and move them to the Active tab.
- Select **Disable** to disable the users and move them to the Disabled tab. These users will not be able to access Non-Employee.
You can also enable or disable a user by clicking their name and selecting the **enable user** or **disable user** button at the top of the screen.
#### To edit a user's avatar:
1. Select the name of the user you want to edit.
The INFO tab is displayed.
1. Hover over the user's avatar and select the edit icon .
1. Select **Choose File** to upload a new file, then select **Update**.
#### To add a manager for a user:
1. Select the name of the user you want to edit.
1. Select the **MANAGERS** tab.
1. In the **Add manager** field, begin typing the name of the user's manager. Select the name of the manager to add them to the table.
#### To add direct reports for a user:
1. Select the name of the user you want to edit.
1. Select the **MANAGED USERS** tab.
1. In the **Add managed user** field, begin typing the name of a user reports to the user you selected. Select the name of the user to add them to the table.
#### To review the access this user has on your identity provider:
1. Select the name of the user you want to review.
1. Select the **GROUPS** tab.
The user's groups, or entitlements, on the identity provider are displayed.
#### To add this user as a contributor to a profile:
1. Select the name of the user you want to edit.
1. Select the name of the profile type that contains the relevant profile.
1. In the **add** field containing the name of the profile type, begin typing the name of a profile. Select a profile to add this user as a [contributor](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html#editing-profiles) on that profile.
## Managing Portal Users
You can invite non-employees to join your Non-Employee tenant and collaborate on managing profiles. These non-employees are known as *portal users*.
### Creating Portal Users
Before you can invite portal users, you must create a [portal](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html) and its associated [registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows) and [login](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#login-workflows) workflows.
These non-employees must be invited to join your tenant using the [Registration Invitation](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#registration-invitation) action within a registration workflow. When they have registered and authenticated into your tenant, they are automatically added to your list of portal users.
To assign and manage portal users' roles, refer to [Managing Collaboration User Roles](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html).
**To update a portal user:**
1. Go to **Admin > Collaboration > Portal Users**.
Active, or enabled, users are displayed in the **Active** tab. Disabled users are displayed in the **Disabled** tab.
You can find details such as the user's name, email address, status, and roles by selecting their name from the list.
1. Make any necessary changes to the users on the list.
Review the possible changes you can make below.
#### To enable or disable portal users:
1. Select the checkboxes beside the users you want to edit, or select the checkbox beside the USER ACCOUNTS header to select all accounts.
1. Select the ellipsis icon next to the PORTAL USERS header.
- Select **Enable** to enable the users and move them to the Active tab.
- Select **Disable** to disable the users and move them to the Disabled tab. These users will not be able to access Non-Employee.
You can also enable or disable a user by clicking their name and selecting the **enable user** or **disable user** button at the top of the screen.
#### To edit a user's avatar:
1. Select the name of the user you want to edit.
The INFO tab is displayed.
1. Hover over the user's avatar and select the edit icon .
1. Select **Choose File** to upload a new file, then select **Update**.
#### To review a portal user's access:
1. Select the name of the user you want to review.
The INFO tab is displayed.
1. Select the **GROUPS** tab.
If this portal user has any groups or entitlements, that access is displayed here.
#### To add this user as a contributor to a profile:
1. Select the name of the user you want to edit.
1. Select the name of the profile type that contains the relevant profile.
1. In the **add** field containing the name of the profile type, begin typing the name of a profile. Select a profile to add this user as a [contributor](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html#editing-profiles) on that profile.
# Collaboration
Collaboration within Non-Employee Risk Management allows non-employees to participate in managing non-employee profiles.
Collaboration gives you the ability to configure [portals](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html) where non-employees can authenticate into the product, as well as workflows to control [registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows) and [login](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#login-workflows) processes.
Once signed in, these non-employee users can manage their own profiles or other profiles based on their assigned [user roles](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html). Use the Collaboration [Activity Log](https://documentation.sailpoint.com/ne-admin/help/reports/portal-activity.html) to track registrations and authentications.
# Creating and Managing Portals
Portals allow [non-employees](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-portal-users) to sign in to your Non-Employee Risk Management tenant to update their own information in your system.
Each portal in your tenant can have its own authentication directory, password policy, and registration process. The login pages for each portal can use unique URLs and logos so that each portal has a unique look and feel.
## Creating a Portal
To create a portal:
1. Go to **Admin > Collaboration > Portals**.
1. Select **+ Portal**.
1. On the New Portal page, complete the following fields:
- **Name** - A unique name for the portal.
The Uid is generated automatically based on the name. This can be modified during the portal's creation, but it can't be edited later.
- **Url** - The subdirectory name for the URL. This is appended to the end of your tenant's URL to create the unique URL for the portal. For example, if you enter `Physicians` in this field, the portal URL will be `.portal.nonemployee.com/Physicians`.
- **Login workflow** - The [login workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#login-workflows) to use for this portal. This can be selected later if no login workflows have been created yet.
- **Password recovery workflow** - The [password reset workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#password-reset-workflows) to use when users from this portal need to reset their passwords. This can be selected later if no password reset workflows have been created yet.
- **Registration workflows** - Select one or more registration workflows to allow users to register within this portal. Each registration workflow appears as a button to register on the login page. If no registration workflows have been created yet, these can be set later. Refer to [Registration Workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows) to learn more.
- **inactivity timeout (minutes)** - The amount of time, in minutes, that a user in this portal can be inactive before they're automatically logged out.
- **Retries** - The number of times a user in this portal is allowed to attempt certain authentication-related tasks, such as logging in, answering security questions, or entering an email address to verify.
- **Logo** - The logo to use for this portal. If no logo is uploaded, the logo configured in the [Branding](https://documentation.sailpoint.com/ne-admin/help/setup/branding.html) page will be used.
1. Select **Create**.
You can configure the JIT provisioning options by [editing the portal](#configuring-just-in-time-provisioning).
## Editing a Portal
To edit a portal:
1. Go to **Admin > Collaboration > Portals**.
1. Select the name of the portal you want to edit.
1. On the **INFO** tab, edit the basic information about your portal, such as its name and workflows.
1. On the **SSO** tab, edit the information about the SSO provider for this portal, if applicable. Refer to [Configuring an SSO Integration for Portal Users](https://documentation.sailpoint.com/ne-admin/help/setup/authentication.html#configuring-an-sso-integration-for-portal-users) for details.
1. On the **ROLES** tab, review the [roles](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html) that grant users access to this portal. You can select the name of a role to [edit](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html#editing-collaboration-roles) it.
### Configuring Just-In-Time Provisioning
You can configure Just-In-Time provisioning for portal users authenticating into your tenant from your SSO provider. This means that users can be granted an account as they're authenticating for the first time.
**Prerequisites:**
- The portal on which accounts will be added must have been created and saved.
- An SSO integration must be configured for the portal.
To configure Just-In-Time (JIT) Provisioning for a portal:
1. Go to **Admin > Collaboration > Portals**.
1. Select the name of the portal you want to edit.
1. On the **INFO** tab, set the **JIT** toggle to **ON** enable just-in-time provisioning.
1. Fill out the other required fields:
- **Profile Type** - If **Profile Creation** in step 5 is set to **ON**, select the profile type to add the profile to if a new profile is created to represent this portal user.
- **Profile Attribute Mapping** - Select the attribute used as the unique identifier for Non-Employee portal accounts. This attribute will be populated by the data within the IDP Mapping Attribute when a new account is created.
- **IDP Mapping Attribute** - Enter the name of the attribute used as the unique identifier for the identity provider, corresponding to the attribute you selected in Profile Attribute Mapping.
1. Choose whether to allow Non-Employee to create a [profile](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html) for non-employee users authenticating to this portal for the first time.
If **Profile Creation** is set to **ON**, when a non-employee that doesn't have an account attempts to authenticate into this portal, an account will be created for them. If they don't have a profile, one will be created for them as well.
If **Profile Creation** is set to **OFF**, non-employees must have an existing profile to be granted a new account through JIT provisioning and to authenticate into Non-Employee.
# Managing Security Questions
You can create and edit security questions for use in collaboration workflows as an additional verification method for portal users to log in or change their passwords. Portal users set their answers to security questions within a [registration workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows).
Security questions can't be deleted.
## Creating Security Questions
To create a security question:
1. Go to **Admin > Collaboration > Security Questions**.
1. Select **+ Security Question**.
1. Complete the following fields:
- **Question** - Enter the question users will be required to answer.
- **Uid** - Enter a unique identifier for the security question. This can't be edited after the question is created.
1. Select **Create**.
## Updating Security Questions
Important
Do not edit your security questions after they're in use to avoid issues with user authentication.
To edit a security question:
1. Go to **Admin > Collaboration > Security Questions**.
1. Select the security question you want to edit.
1. Make any necessary changes to the security question.
The question's Uid can't be edited once it's created.
1. Select **Save**.
# Configuring Profile Types
Profile types are used to group and manage similar *profiles*, or objects you want to manage within Non-Employee Risk Management. The profile type determines the data users will be asked to complete when creating a new profile.
New tenants have four [default profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types): assignments, jobs, non-employees, and organizations. You can also create [custom profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#creating-a-custom-profile-type) to manage data that doesn't fit into any of those categories.
Each profile type has its own attributes and workflows, and can be managed on its own or linked to other profile types to create detailed maps of the relationships within your organization.
- Use [attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) to manage the details about each profile in a profile type. Attribute values can be generated programmatically with [value builders](https://documentation.sailpoint.com/ne-admin/help/profile-types/value-builders.html) or used to [link profiles](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#linking-profiles) together.
- Attributes can be combined into [forms](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) to determine how they're displayed to users, then into [pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) to configure how they're displayed in relation to each other.
- Once your profile types have been created and their supporting content is ready, you can configure [workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/index.html) to create and manage profiles within your organization.
# Managing Attributes
An attribute is a single characteristic of a profile. A set of attributes make up the data about a profile.
Creating an attribute allows you to use that attribute in [forms](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) and [pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html), which are used when a profile is being created.
You can create and manage the attributes within your tenant so that each profile contains all the data you need to manage your non-employees.
The 4 [core profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) have a set of pre-configured default attributes that can't be deleted. However, custom attributes can be added to manage information for those profiles. Custom profile types always use custom attributes.
## Creating Custom Attributes
**To create a custom attribute:**
1. Go to **Admin > Templates > Attributes**.
1. Select **+ Attribute** .
1. In the **Create an attribute** screen, add a name in the **Label** field.
The **Uid** is generated automatically based on the label and can't be edited once the attribute has been created.
1. In the **Field type** field, select the type of attribute you are creating. This determines the type of field the user will see and the tasks they must perform when they are creating a new profile using a page of forms.
The following table describes:
- The field type
- What the user must do to populate this attribute when filling out pages to create a profile
- Additional configuration steps the admin must take before adding this attribute to forms and pages
| Field type | User task | Additional admin configurations |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **attachment** | Upload a file to use as the attribute's value. | **Extension list** - Enter the list of filetypes the user can upload for this attribute. These filetypes must include a period and be separated by spaces. For example, `.json, .txt`. |
| **check boxes** | Select a check box beside one or more options. | **Options** - Enter the options users can select from. Select the **Add to list** icon between each option. |
| **contributor search** | Search for a user to assign as a [contributor](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) to this profile. | - **Add role** - Enter the name of one or more roles. Users with these roles can be selected as contributors to the profile. - **Allow multiple selections?** - Choose whether users can add multiple contributors at a time to the profile. |
| **contributor select** | Select a [contributor](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) from a list of users. This list displays a maximum of 500 users. | **Add role** - Enter the name of one or more roles. Users with these roles can be selected as contributors to the profile being created. |
| **date** | Choose a date using a date picker. | **Date format** - Choose the date format users must use when entering the date. You can use a tooltip to display the required format to users. |
| **drop-down** | Choose an option from a drop-down list. | **Options** - Enter the options users can select from. Select the **Add to list** icon between each option. |
| **owner search** | Search for a specific user to assign as the [owner](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) of this profile. | **Add role** - Enter the name of one or more roles. Users with these roles can be selected as the owner of the profile being created. |
| **owner select** | Select an [owner](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) from a list of users. This list displays up to 500 users. | **Add role** - Enter the name of one or more roles. Users with these roles can be selected as the owner of the profile being created. |
| **profile search** | Search for an existing profile to link to the profile being created. | Refer to [Linking Profiles](#linking-profiles) for more information. |
| **profile select** | Select an existing profile from a list to link to the profile being created. This list displays up to 500 profiles. | Refer to [Linking Profiles](#linking-profiles) for more information on linking profiles. |
| **radio buttons** | Select one option from a list. | **Options** - Enter the options users can select from. Select the **Add to list** icon between each option. |
| **tags** | Enter one or more terms to serve as tags for the new profile, separated by the Enter key. | No additional configurations. |
| **text area** | Enter a string in a text box. | - **Number of Characters** - Choose the maximum, minimum, or exact number of characters this string can contain. - **Custom Format?** - If this attribute must be entered in a specific format, enter a regular expression representing the required format. Users will be notified if the attribute value they enter doesn't match the pattern specified by the regex string. - **Email Format?** - Require the text the user enters to be in an email address format. - **Prevent Special Characters?** - Require the user to enter a string using only the characters a-z and 0-9. - **Numbers Only?** - Require the user to enter a string using only numbers. - **Unique?** - Require the user to enter an attribute value that is unique among profiles and pending requests in this profile type. |
| **text field** | Enter a single-line string in a text box. | - **Number of Characters** - Choose the maximum, minimum, or exact number of characters this string can contain. - **Custom Format?** - If this attribute must be entered in a specific format, enter a regular expression representing the required format. Users will be notified if the attribute value they enter doesn't match the pattern specified by the regex string. - **Email Format?** - Require the text the user enters to be in an email address format. - **Prevent Special Characters?** - Require the user to enter a string using only the characters a-z and 0-9. - **Numbers Only?** - Require the user to enter a string using only numbers. - **Unique?** - Require the user to enter an attribute value that is unique among profiles and pending requests in this profile type. |
You can make some additional configurations regardless of the field type you choose. These include:
- **Tool tip** - Enter some help text to display in a icon beside the attribute's label. This is used to help users fill in the attribute's value correctly.
- **Description** - Enter a description to display on the list of attributes in the Admin console.
- **Required?** - Choose whether this attribute is required when creating a profile.
You can assign risk to some types of attributes to identify risks and help assess the threat they pose. Risk can be assigned to attributes with the [types](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) check boxes, radio buttons, profile search, and profile select. Refer to [Configuring and Managing Risk](https://documentation.sailpoint.com/ne-admin/help/risk/index.html) for additional information.
1. Select **Create**.
1. Complete each page of configurations and select **Next**.
1. When you have finished all configurations, select **Finish**.
### Linking Profiles
Profiles are linked together by using one profile as an attribute on another profile. By linking profiles together, you can track relationships between profile types so that updating information on one profile automatically updates information on others. When an attribute links to a specific profile, it is said to *contain* that profile.
To allow profiles to be connected together, you'll configure an attribute on a profile to use another profile as its value. For example, you could assign a **non-employee** profile to use an **agency** profile as its *agency_name* attribute.
The user creating the **non-employee** profile will select which agency should be used as the *agency_name* attribute.
To allow profiles to be linked together:
1. When [creating an attribute](#creating-custom-attributes), in **Field Type**, select **Profile Search** or **Profile Select**.
1. Select **Next**.
1. In addition to the fields available for all attribute types, complete the following fields:
- **Reverse relationship** (Optional) - If the relationship between two profiles should go in both directions, choose the attribute on the linked profile that should be used to store the profile being created.
For example, a user creating a new **Assignment** profile might choose a **Department** profile in the *assignment_department* attribute to track who will be responsible for the assignment. In the **Reverse relationship** field, you can choose the *department_assignment* attribute so that when the user creates the **Assignment** profile, that entire profile is added to the *department_assignment* attribute on the **Department** profile. Updates made to one will be propagated to the other.
- **Ownership driven?** - Choose whether the user populating this attribute should be limited to selecting profiles for which they're an owner or contributor.
- **Can have more than one profile?** - Choose whether the user populating this attribute should be allowed to select multiple values for this field.
1. Select **Next**.
1. Under **Available Options**:
- In the **Profile type** field, select the profile type that contains the profiles that will be linked to this attribute.
Linked Profiles Example
For example, if you're creating the *non-employee_location* attribute for the **Non-Employees** profile type, you can choose the **Locations** profile type in this field so that users creating new non-employees will be able to select from existing location profiles when filling in this attribute.
- In the **Status** field, choose whether to filter the profiles that are displayed to the user by status. You can allow the user to select active profiles, inactive profiles, or all.
1. (Optional) To filter the profiles displayed to the user based on an attribute they've previously selected for the profile, set the **Filter** toggle to **ON**.
Contact your Customer Success Manager for assistance filtering the profiles displayed to users.
Filtering Linked Profiles Example
For example, you might be creating a *job_title* attribute to assign to a **Non-Employee** profile, where the *job_title* attribute is selected from the profiles in the **Job Titles** profile type. You might want to filter the job titles displayed to the user creating the non-employee based on the non-employee's department, selected earlier.
The attribute being used to filter the options available to users must also be a *profile select* or *profile search* type attribute.
1. In the **Filtering attribute** field, choose an attribute.
This attribute must come from the profile type that contains the profile the user selected earlier in the process. In the example above, this attribute comes from the **Departments** profile type.
The profiles in this profile type must also contain the specific attribute set in the **Filter field** in the next step.
1. In the **Filter** field, choose another attribute.
This attribute must be in the profile type selected in **Profile type** in step 5. It must also be a profile select or profile search type attribute, and it must link to the profile type associated with the **Filtering attribute** field in step 6.a.
In the **Filtering Linked Profiles Example**, the attribute is on the **Job Titles** profile type, and it links to the **Departments** profile type.
In other words, profiles are displayed to users to use as the value for your new attribute only if:
In other words, when a user is selecting a profile value for this attribute, they'll only see profiles if:
- They are in the profile type selected in step 5.
- They have an attribute (selected in step 6.b.) that links to the profile type selected in step 6.a.
- A profile value for the attribute selected in 6.a. has been entered earlier in the process of creating the profile.
For a detailed example of filtering profiles in an attribute, review [Filtering a Profile Search or Profile Select Attribute](https://support.sailpoint.com/csm?id=kb_article_view&sys_kb_id=fa1a6793937bbd908c7e34aefaba10fc).
1. Select **Next**.
1. Complete the attribute's configuration as described in [Creating an Attribute](#creating-custom-attributes).
## Updating Custom Attributes in Bulk
You can make changes to several custom attributes at once by updating them in bulk.
**To update multiple attributes at once:**
1. Go to **Admin > Templates > Attributes**.
You can see a list of the active and archived attributes in your tenant.
1. Select the checkbox beside the attributes you want to edit.
To select all attributes, select the checkbox next to the **ATTRIBUTES** header.
1. Select the ellipsis icon next to the **Actions** button to display the available actions.
- **Archive** - Deactivates the selected attributes and moves them to the Archived tab.
- **Unarchive** - Activates the selected attributes and moves them to the Active tab.
- **Export** - Generates a JSON file containing the metadata about the selected attributes and any related configuration. When the file has been generated, select **Download** to save the metadata to a local file.
Notes
- Attributes can't be archived if they're being used by forms.
- If an attribute is being used by a profile when it is archived, the attribute will continue to appear on the profile, but it can't be edited.
## Updating Custom Attributes Individually
**To update a single custom attribute:**
1. Go to **Admin > Templates > Attributes**.
You can see a list of the active and archived attributes in your tenant.
1. Select the name of the attribute you want to edit.
1. On the **INFO** tab, make edit the basic settings of the attribute such as its name, type, and description.
1. On the **VALIDATIONS** tab, determine whether the attribute should be required.
Depending on the type of attribute, you might be able to make other changes on this tab.
1. On the **PERMISSIONS** tab, review the list of roles and the permissions they have to this attribute.
1. To edit these permissions for this attribute, in the **Attribute Permission** column:
- Select **View** to grant users read-only access.
- Select **Edit** to grant users edit access.
- Select **None** to prevent users with this role from seeing or editing this attribute.
By default, all roles have their access set to **None**.
1. On attributes with the type *profile search* or *profile select*, you can also see the **Selected Profile Access** column.
Select **Yes** to allow users with the listed role to view the profile stored in this attribute, regardless of their other permissions. Select **No** to deny users with the listed role access to the profile stored in this attribute, unless the user has other permissions granting access to that profile.
1. Optionally make changes to the fields on the other tabs on this attribute. These will vary based on the type of attribute you're editing.
1. Select **Save**.
Once an attribute has been created, its values can be filled in programmatically using a [value builder](https://documentation.sailpoint.com/ne-admin/help/profile-types/value-builders.html), or it can be filled in by users as part of a [form](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html).
## Selecting the Date Format for Core Attributes
You can select a different date format and delimiter for DateAttribute type core attributes. Setting this configuration improves synchronization for systems in regions that use a format other than the default `mm/dd/yyyy` format.
**To select a different date format for DateAttribute type core attributes:**
1. Go to **Admin > Templates > Attributes**.
1. On the **Core** tab, select the DateAttribute type core attribute you want to edit.
1. Under **Date format**, use the dropdown list to select a date format. You can select from the following date formats:
- `dd/mm/yyyy` or `dd-mm-yyyy`
- `mm/dd/yyyy` or `mm-dd-yyyy`
- `yyyy/dd/mm` or `yyyy-dd-mm`
1. Select **Save**
# Creating and Editing Forms
A form is a set of fields, each representing an attribute on a profile. Forms are combined into [pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html), which can be sent to users to fill out when certain [workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html) are executed.
By default, all [core profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) have forms and pages associated with them already. You can [edit those forms](#editing-forms) by rearranging the attributes on them, and by adding and removing custom attributes, but you can't remove required core attributes. Optional core attributes are not required and can be removed from core forms. Removing optional core attributes from a core form doesn't remove the attributes from the tenant. You can add the core attributes back to the core form if needed.
## Creating a Custom Form
You can create a new form to collect the values for a profile's attributes.
Note
If you selected the **Create supporting content?** checkbox when creating a [custom profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#creating-a-custom-profile-type), an empty form has been created using the name of the profile type. If this is the case, you do not need to create a new form, and you can proceed to [Editing Forms](#editing-forms).
**To create a new custom form:**
1. Go to **Admin > Templates > Forms**.
1. On the Custom tab, select **+ Form**.
1. On the **Create New Form** page:
- Enter a unique name for your form.
The UID is generated automatically based on the name. This can be modified during the form's creation, but it can't be edited later.
- Optionally enter a description for the form.
1. Select **Create**.
The LAYOUT tab is displayed.
1. In the **Add attributes** field, search for and select one or more attributes to add to your form.
These are the [attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) a user must fill out when creating or editing a profile. The type of field presented to a user depends on the attribute's type.
Forms are three columns wide.
1. When adding attributes, you might be able to select additional options on your form.
- Select **edit** to edit the attribute. Edits apply to the attribute everywhere it's used.
- Select **break** to add an empty space in the column after this attribute.
- If you are editing attributes with the *check box*, *drop-down*, and *radio button* types, you can select **Add forms to options** to add forms when the user selects specific options from the list. Refer to [Adding Conditional Forms](#adding-conditional-forms) for more information.
1. To remove and reorder the attributes in your form:
- Select the name of the attribute and drag it to another spot in the form to change its order.
- Select the **Delete** icon to remove this attribute from the form.
1. When you're finished adding attributes to your form, select **Save**.
1. (Optional) Select the **Preview** button to preview what your form will look like to the user.
Note
Forms are always visible to users completing them as part of a workflow, regardless of their permissions. Forms in profile pages are only visible to users with View or Edit [permissions](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#attribute-permissions) for the applicable attributes.
## Editing Forms
You can edit custom forms in [bulk](#updating-forms-in-bulk) or [individually](#editing-an-individual-form). Core forms can only be edited individually.
### Updating Forms in Bulk
You can make changes to your custom forms in bulk.
1. Go to **Admin > Templates > Forms**.
1. On the Custom tab, select the checkbox beside the forms you want to edit.
To select all forms, select the checkbox next to the **FORMS** header.
1. Select the **ellipsis** icon next to **Actions** to display the available actions:
- **Archive** - Immediately deactivates the selected forms and moves them to the **Archived** tab. Forms can't be archived if they're used by any pages.
- **Unarchive** - Immediately activates the selected forms and moves them to the **Active** tab.
- **Export** - Generates a .json file containing the metadata about the selected forms and related configurations. When the file has been generated, select **Download** to save the metadata to a local file.
- **Clone** - Makes an identical copy of the selected forms and adds it to the list with a number appended to its name.
### Editing an Individual Form
You can edit an individual form when you need to change which attributes it collects, how they're arranged, or the form's name and description.
**To edit an individual form:**
1. Go to **Admin > Templates > Forms**.
1. Select the **Core** tab to edit core forms.
Select the **Custom** tab to edit custom forms.
1. Select the name of the form you want to edit.
1. In the **LAYOUT** tab, add, remove, or reorder the attributes in your form:
- Search for and select one or more attributes to add to your form in the **Add attributes** field.
- Select the name of the attribute and drag it to another spot in the form to change its order.
- Select the **Delete** icon to remove this attribute from the form.
Important
While you can remove optional core attributes from core forms, required core attributes can't be deleted from core forms. You can add optional core attributes to core forms if needed.
1. Select **Save**.
1. In the **INFO** tab for custom forms, update the name and description of the form. The information in the INFO tab for core forms can't be updated.
Note
The UID can't be edited once the form has been created.
1. Select **Save**.
### Adding Conditional Forms
You can display additional forms when users select certain options within a form. For example, if a user selects their region, you can configure a dropdown list to appear so they can select the specific office they are part of within that region.
Notes
- Additional forms you want to display must be created and saved separately.
- This option is available on *check box*, *drop-down*, and *radio button* attribute types.
To display forms conditionally, based on a user's selections:
1. On the **LAYOUT** tab, select **Add Forms to options** on an applicable attribute.
A list of the options associated with this attribute is displayed.
1. Locate the option for that attribute that should have an additional form display when it is selected. In the drop-down underneath that option, select the additional form that should be displayed when that option is selected.
1. Select **Save**.
When the user selects that option within that attribute, the additional form you selected will appear and they'll be required to fill out that form as well.
You can edit your selections later by selecting **Edit form options** on this attribute.
# Creating and Editing Pages
Pages are a collection of forms, text, and other elements that define how information is presented to an end user.
There are two types of pages within Non-Employee Risk Management: workflow pages and profile pages.
Workflow pages are presented to a user during the execution of a workflow, such as when they're creating or updating a profile.
Profile pages are displayed on an individual profile. The information displayed to a user is based on their [attribute permissions](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#attribute-permissions).
Workflow pages and profile pages both support [Liquid Template Language](http://shopify.github.io/liquid) in text fields.
## Workflow Pages
A workflow page is any page used within a [workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html). They can collect or display data during the workflow's execution.
Users fill out workflow pages as part of a workflow's execution, such as when a profile is created or updated. These pages are displayed to users regardless of the permissions they have to the attributes for this profile type, so that a user can complete the tasks assigned to them and the workflow can proceed.
By default, all [core profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) have forms and pages associated with them already. You can [edit those pages](#editing-workflow-pages) by rearranging the forms on them, or by adding and removing custom forms, but you can't delete the core forms from them.
If you selected the **Create supporting content?** checkbox when creating a [custom profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#creating-a-custom-profile-type), an empty workflow page and profile page have been created using the name of the profile type. If this is the case, you do not need to create a new form, and you can search for and edit the [workflow page](#editing-workflow-pages) or [profile page](#editing-profile-pages) that was created.
### Creating Workflow Pages
Workflows are used to create and update profiles, so workflow pages are used to gather the information for the attributes on a profile within a specific profile type. Because workflow pages are primarily used to gather information, they are created and managed separately from [profile pages](#profile-pages).
1. Go to **Admin > Templates > Pages**.
The WORKFLOWS tab is displayed.
1. Select **+ Workflow Page**.
1. Complete the following fields:
- **Name** - Add a unique name for the workflow page.
- **Uid** - The unique identifier for this workflow page. This can't be changed once the page has been created.
- **Description** - Add a description for this page.
1. Select **CSreate**.
The LAYOUT tab of the new workflow page is displayed.
To add objects to your workflow page, select one of the options in the panel on the right of the Page Content canvas.
Review the available options below:
**Forms**
When a form is part of a workflow page, a user will be required to complete the fields within the forms on this page.
1. Select the **Forms** option in the right panel.
A list of forms is displayed.
1. Select and drag a form into the Page Content canvas.
**Read Only Forms**
You can use read-only forms to display additional context to a user on a page, such as attributes from a form that a different user filled out earlier in the workflow.
For example, you can use a read-only form to display *organization* information when creating a new *assignment* profile applicable to that organization.
1. Select the **Read Only Forms** option in the right panel.
A list of forms is displayed. These are the same forms visible in the Forms section, but when displayed to the user, they won't be editable.
1. Select and drag a form into the Page Content canvas.
**Text**
You can add headers, text, and HTML to your pages, so that you can provide users with instructions and section dividers on a page.
1. Select the **Text** option in the right panel.
1. Select and drag a type of text field into the Page Content canvas.
Choose from the following options:
- **Form Header** - Adds a text header and a dividing line between two sections of a page.
- **Large Header** - Adds the largest header to the page.
- **Medium Header** - Adds a mid-sized header to the page.
- **Small Header** - Adds the smallest header size to the page.
- **Paragraph** - Adds body text to the page.
- **Html** - Adds an HTML field to the page. This can be edited to support tables, hosted images and logos, and other supporting content.
**Other**
Add additional options in the Other section.
1. Select the **Other** option in the right panel.
1. Select and drag an option into the Page Content canvas.
The options include:
- **Owner** - Display the profile owner on this page.
- **Progress Bar** - Add a progress bar to this page so that users can track the progress of the workflow as a whole.
1. Drag and drop the tiles within the Page Content canvas to reorder them. Select the **Delete** icon to remove the object from the page.
1. Select **Save**.
1. (Optional) To preview the page as it will be displayed to users, select **Preview**.
### Editing Workflow Pages
You can view and edit existing workflow pages.
- Learn more about updating workflow pages [in bulk](#update-workflow-pages-in-bulk).
- Learn more about updating an [individual](#update-an-individual-workflow-page) workflow page.
To begin editing workflow pages:
1. Go to **Admin > Templates > Pages**.
The WORKFLOWS tab is displayed.
1. Make any necessary changes to the pages on the list.
Review the changes you can make below.
#### Update Workflow Pages in Bulk
You can make some changes to your workflow pages in bulk.
1. Select the checkbox beside the pages you want to edit.
To select all pages, select the checkbox next to the **WORKFLOW PAGES** header.
1. Select the ellipsis icon next to the Actions button to display the available actions.
- **Archive** - Immediately deactivates the selected pages and moves them to the Archived tab.
- **Unarchive** - Immediately activates the selected pages and moves them to the Active tab.
- **Export** - Generates a JSON file containing the metadata about the selected pages and any related configuration. When the file has been generated, select **Download** to save the metadata to a local file.
- **Clone** - Makes an identical copy of the selected pages and adds it to the list with a number appended to their names.
Note
If a workflow page is in use by one or more workflows, it can't be archived. An error message displays containing the names of the pages that couldn't be archived and the workflows that use them.
#### Update an Individual Workflow Page
You can make changes to the details and layout of an individual workflow page.
1. From the list of workflow pages, select the name of the page you want to edit.
1. In the **LAYOUT** tab, make changes to the forms, text, and other objects within this workflow page. Refer to the available options in the [Creating Workflow Pages](#layout-tab) section.
1. In the **INFO** tab, make changes to the name and description of the page. The Uid can't be edited once the page has been created.
## Profile Pages
Profile pages are displayed to users viewing an individual profile after it's been created. In many cases, these pages are read-only, which is why they are configured separately from [workflow pages](#workflow-pages). However, if a user has a [role](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#attribute-permissions) that allows them to edit a specific attribute on a profile, or if they're an [owner or contributor](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) to a profile, they'll be able to edit the attribute values on a profile page.
By default, all [core profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) have forms and pages associated with them already. You can [edit those pages](#editing-profile-pages) by rearranging the forms on them, or by adding and removing custom forms, but you can't delete the core forms from them.
Custom profile pages are created automatically when a [profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html) is created. If **Create supporting content** was selected when the profile type was created, the profile page associated with this type will contain the empty form created as [supporting content](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#supporting_content). Otherwise, the profile page for the profile type will be empty.
### Editing Profile Pages
You can view and edit existing profile pages.
- Learn more about updating profile pages [in bulk](#update-profile-pages-in-bulk).
- Learn more about updating an [individual](#update-an-individual-profile-page) workflow page.
Note
Profile pages can't be created independently. They are created when a [profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html) is created, and can be edited.
To begin editing workflow pages:
1. Go to **Admin > Templates > Pages**.
The WORKFLOWS tab is displayed.
1. Select **PROFILES**.
1. Make any necessary changes to the pages on the list.
Review the changes you can make below.
#### Update Profile Pages in Bulk
You can make some updates to your profile pages in bulk.
1. Select the checkbox beside the pages you want to edit.
To select all pages, select the checkbox next to the PROFILE PAGES header.
1. Select the ellipsis icon next to the Actions button to display the available actions.
- **Export** - Generates a JSON file containing the metadata about the selected pages and any related configuration. When the file has been generated, select **Download** to save the metadata to a local file.
Note
Profile pages are archived when the profile type associated with them is archived. They cannot be archived manually.
#### Update an Individual Profile Page
You can make changes to the details and layout of an individual profile page.
1. From the list of profile pages, select the name of the page you want to edit.
The profile page's Edit page is displayed.
1. Add and remove objects from your profile page as necessary.
Review the available options below:
**Permission Forms**
Permission forms are forms used to display and edit attributes. The actions a user can take on these forms are based on the permissions of the user's [roles](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#attribute-permissions).
1. Select the **Permission Forms** option in the right panel.
A list of forms is displayed.
1. Select and drag a form into the Page Content canvas.
**Text**
You can add headers, text, and HTML to your pages, so that you can provide users with information and section dividers on a page.
1. Select the **Text** option in the right panel.
1. Select and drag a type of text field into the Page Content canvas.
Choose from the following options:
- **Form Header** - Adds a text header and a dividing line between two sections of a page.
- **Large Header** - Adds the largest header to the page.
- **Medium Header** - Adds a mid-sized header to the page.
- **Small Header** - Adds the smallest header size to the page.
- **Paragraph** - Adds body text to the page.
- **Html** - Adds an HTML field to the page. This can be edited to support tables, hosted images and logos, and other supporting content.
**Other**
Add additional options in the Other section.
1. Select the **Other** option in the right panel.
1. Select and drag an option into the Page Content canvas.
The options include:
- **Owner** - Display the profile owner on this page.
1. Select **Save**.
1. Select **Preview** to preview the page.
# Creating and Editing Profile Types
Profile types are used to group similar [profiles](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html). They represent a type of object that Non-employee Risk Management governs, such as vendors, projects, or non-employees. All profiles must be part of a profile type.
By default, new tenants are created with 4 default profile types, also known as *core* profile types, that come with default attributes designed to simplify the onboarding process. You can also create as many custom profile types as necessary to meet your business needs.
A profile's type determines the workflows, forms, and pages used to create that profile. You can assign [contributors](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) to a profile type so they can manage profiles of that type.
Before you can create profiles within a profile type, you must have the following:
- The [attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) that will be used within profiles.
- [Forms](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) to gather the data needed to populate those attributes when a profile is being created.
- [Pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) from those forms so that they can be included in workflows to create and update profiles for this profile type.
- [Create Workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows) using the pages and forms set up for this profile type. When the workflow associated with this profile type is executed, those forms and pages are used to fill out the attributes associated with new profiles of this profile type.
## Managing Default Profile Types
By default, new tenants come with 4 configured profile types, called the core or default profile types. These profile types are:
- **Organizations** - An entity used to manage the teams or groups of non-employees within your company. For example, this can be a staffing agency, a vendor, or an internal team or department.
- **Jobs** - A specific time-bound initiative that an organization and its non-employees have been assigned to complete.
- **Non-Employees** - The individuals contracted to perform work for an organization on a job for a specific period of time.
- **Assignments** - A non-employee’s time-bound association with a job within an organization.
Each of these profile types comes pre-configured with a set of attributes to organize the profiles within them and the relationships between them.
These profile types and the core attributes they contain can't be deleted. You can create, edit, and delete custom attributes for these core profile types and update the permissions associated with them.
### Editing Default Profile Types
1. Go to **Admin > Lifecycle > Profile Types**.
1. Select one of the core profile types.
1. In the **BASIC SETTINGS** section, review the list of attributes. You can also edit the following fields:
- **Role filtering** - Choose whether to filter the users that can be selected as [contributors](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) for this profile type based on their role.
- If you select **ALLOW** and add roles within the **Add role** field, only users with one or more of the roles in this list can be added as contributors to profiles in this profile type.
- If you select **ALLOW** and don't add any roles, users can't be added as contributors to profiles in this profile type.
- If you select **BLOCK** and add roles within the **Add role** field, users with those roles can't be added as contributors to profiles in this profile type.
- If you select **BLOCK** and don't add any roles, filtering will not be applied and users can be selected as contributors regardless of their role.
1. In the **DUPLICATION PREVENTION** section, make selections to determine how duplicate profiles should be identified and resolved.
- In the **Error message** field, enter an error message to display when users attempt to create a duplicate profile in this profile type.
- In **Allow user to bypass?**, select whether the user creating the profile can create it even if Non-Employee Risk Management detects that the new profile might be a duplicate.
- In the **Add attributes** field, choose one or more attributes that Non-Employee Risk Management should use to check for duplicate profiles. When you add an attribute in this field, it appears in the **Duplication protection** field.
1. In the **PERMISSIONS** section, choose whether or not the users from any additional roles, separate from the default roles, should be granted access to this profile type, based on the [permissions](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-permissions-to-roles) granted to users with that role in the Profile Access section of its Permissions.
Notes
- In the **Contributors** section, you can see that the Profile Owner and the Profile Contributor have access to profiles in this profile type regardless of their other roles.
- The permissions in the PERMISSIONS section can be applied to both [lifecycle](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) and [collaboration](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html) roles.
- If you select **ALLOW** and add one or more roles within the **Add role** field, users with the roles you select can access this profile type regardless of whether they are also contributors.
- If you select **ALLOW** and don't add any roles, users who aren't contributors to this profile type won't be able to access it.
- If you select **BLOCK** and add one or more roles within the **Add role** field, users with the roles you select will not be able to access this profile type unless they are also contributors. However, users with any other roles can access this profile type regardless of whether they are also contributors.
- If you select **BLOCK** and don't add any roles, users with any role can access this profile type regardless of whether they are also contributors.
1. Select **Save**.
1. Optionally, in the **ISC SOURCE SETTINGS** section, choose whether this profile type should be connected to SailPoint Human Fabric so it can be managed as a source. Refer to [Creating a Source in SailPoint Human Fabric](https://documentation.sailpoint.com/ne-admin/help/connector/profile_connector.html) for details.
You can also add additional [attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) to this profile type by adding custom attributes to [forms](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) and [pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) associated with this profile type.
## Managing Custom Profile Types
If you need to manage additional data beyond what is covered by the core profile types, or if your tenant was created before core profile types were added, you can manage your data using custom profile types.
### Creating a Custom Profile Type
To create a profile type:
1. Go to **Admin > Lifecycle > Profile Types**.
1. Select **CUSTOM**.
1. Select **+ New Profile Type**.
1. In the **BASIC SETTINGS** section, complete the following fields:
- **Name** - Add a unique name for the profile type.
- **UID** - Add a unique identifier for the profile type. This can't be changed once the profile type has been created.
- **Category** - Choose the category of profile for this profile type. The available options are:
- Employee - An employee that works directly for your company.
- Job - A specific time-bound initiative that an organization and its non-employees have been assigned to complete.
- Non-Employee - Non-employees such as contractors or vendors that work with your company.
- Organization - An external company that provides contractors to your company or is otherwise affiliated with your organization.
- Assignment - A specific engagement or project.
- Other - Profiles that don't fit other categories, such as departments or locations.
- **Create supporting content?** - Select this checkbox to create some additional content when you save your profile type. This content includes:
- An empty form using the name of the new profile type.
- A [Workflow Page](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html#workflow-pages) with the name "Create ".
- A [Profile Page](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html#profile-pages) containing the empty form created with this profile type.
- A disabled [Create Workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows) containing two steps. These are the "Request Form" action, containing the "Create " Workflow Page; and the "Create" action.
You can rename and edit supporting content.
- **Role filtering** - Choose whether to filter the users that can be selected as [contributors](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) for this profile based on their role.
- If you select **ALLOW** and add roles within the **Add role** field, only users with one or more of the roles in this list can be added as contributors to profiles in this profile type.
- If you select **ALLOW** and don't add any roles, users can't be added as contributors to this profile type.
- If you select **BLOCK** and add roles within the **Add role** field, users with those roles can't be added as contributors to profiles in this profile type.
- If you select **BLOCK** and don't add any roles, filtering will not be applied and users can be selected as contributors regardless of their role.
Note
The **ACCESS PERMISSIONS** section is read-only and states that profile owners and profile contributors will have access to this profile type.
1. In the **PERMISSIONS** section, choose whether or not the users from any additional roles, separate from the default roles, should be granted access to this profile type, based on the [permissions](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-permissions-to-roles) granted to users with that role in the Profile Access section of its Permissions.
Notes
- In the **Contributors** section, you can see that the Profile Owner and the Profile Contributor have access to profiles in this profile type regardless of their other roles.
- The permissions in the PERMISSIONS section can be applied to both [lifecycle](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) and [collaboration](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html) roles.
- If you select **ALLOW** and add one or more roles within the **Add role** field, users with the roles you select can access this profile type regardless of whether they are also contributors.
- If you select **ALLOW** and don't add any roles, users who aren't contributors to this profile type won't be able to access it.
- If you select **BLOCK** and add one or more roles within the **Add role** field, users with the roles you select will not be able to access this profile type unless they are also contributors. However, users with all other roles can access this profile type regardless of whether they are also contributors.
- If you select **BLOCK** and don't add any roles, users with any role can access this profile type regardless of whether they are also contributors.
1. Select **Create**.
Your custom profile type is saved. The PROFILE NAMING tab is displayed.
1. In the **Name Attributes** section, in the **Add attributes** field, enter the names of one or more attributes. The attributes you select here will be used to construct the unique name of each profile in this type.
For example, if you choose the attributes `firstName`, `lastName`, and `employeeNumber` in that order, a profile representing a user named John Smith with an employee number of 001 would be called `JohnSmith001`.
By default, the `id` attribute is used as the name attribute.
1. Select **Save**.
Your profile type has been created. Before you can add profiles to this profile type, you must complete the following tasks:
- Create the [attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) that will be used within profiles.
- Create [forms](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html) to gather the data needed to populate those attributes when a profile is being created.
- Create [pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) from those forms so that they can be included in workflows to create and update profiles for this profile type.
- Add those pages to [Create Workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows). When the workflow associated with this profile type is executed, those forms and pages are used to fill out the attributes associated with new profiles of this profile type.
Note
If you selected **Create supporting content?** while initially creating the profile type, a workflow, page, and form were created already, using the name of the profile type you created. These objects are empty and must be edited before they can be used.
You can make additional changes to your profile type after it's been created, such as configuring [duplicate prevention](#duplicate-prevention).
### Editing Custom Profile Types
You can view and edit custom profile types in [bulk](#updating-custom-profile-types-in-bulk) or [individually](#updating-an-individual-custom-profile-type).
#### Updating Custom Profile Types in Bulk
You can make some changes to the custom profile types in your tenant in bulk.
1. Go to **Admin > Lifecycle > Profile Types**.
1. Select the checkbox beside the profile types you want to edit.
To select all profile types, select the checkbox next to the **PROFILE TYPES** header.
1. Select the ellipsis icon next to the Actions header to display the available actions.
- **Archive** - Deactivates the selected profile types and moves them to the Archived tab.
Profile types that are in use can't be archived. You must delete or archive any items connected to this profile type before it can be deleted. A list of the items that use each profile type that can't be deleted is displayed.
- **Unarchive** - Immediately activates the selected profile types and moves them to the Active tab.
- **Export** - Generates a .json file containing the metadata about the selected profile types. When the file has been generated, select **Download** to save the metadata to a local file.
#### Updating an Individual Custom Profile Type
You can make updates to most information about a custom profile type.
1. Go to **Admin > Lifecycle > Profile Types**.
1. Select the name of the profile type you want to edit.
1. On the **BASIC SETTINGS** tab, make any necessary changes to the basic information for your profile type.
This includes the Name, Category, and Role Filtering fields that you configured when first creating this profile type.
You can also configure several additional fields:
- **Id label** - The label that should be used for the unique technical ID for each profile in this profile type.
- **Show profile id in header** - Whether to display the value of the ID on each profile in this profile type.
If you have previously created a profile type without a category, you must assign it a category before you can save changes to your profile type.
1. In the **PROFILE NAMING** tab, edit how the name attribute is configured as described in [Creating a Custom Profile Type](#creating-a-custom-profile-type).
1. In the **DUPLICATE PREVENTION** tab, enter an error message in the **Error message** field to display when users attempt to create a duplicate profile in this profile type.
1. In **Allow user to bypass?**, select whether the user creating the profile can create it even if Non-Employee Risk Management detects that the new profile might be a duplicate.
1. In the **Add attributes** field, choose one or more attributes that Non-Employee Risk Management should use to check for duplicate profiles. When you add an attribute in this field, it appears in the **Duplication protection** field.
1. In the PERMISSIONS tab, edit the permissions for this profile type as described in [Creating a Custom Profile Type](#creating-a-custom-profile-type).
1. Select **Save**.
# Creating and Editing Value Builders
Value builders allow you to generate patterns for profile attributes, so that the selected attributes are populated with either random or systematic values. Value builders can be used as part of a [Set Attribute Values](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#set-attribute-values) step within a workflow.
## Creating Value Builders
To create a value builder:
1. Go to **Admin > Templates > Value Builders**.
1. Select **+ Value Builder**.
1. Complete the following fields:
- **Name** - Add a unique name for this value builder.
- **Uid** - Add a unique identifier.
1. Select **Create**.
The FORMULA tab is displayed. The formula is the pieces of your value builder In existing value builders, the current formula is displayed here.
1. In the **FORMULA** section, in **Add Attributes**, search for and select attributes to include in the value builder's formula.
When this attribute has been added to your formula, you will see the **Selector** dropdown list within the **Formula** section. Choose from the following options:
- **All** - Use the entire contents of the selected attribute value in the value builder.
- **First** - Use the first characters in an existing attribute value in the value builder. Select the number of characters in the **Count** dropdown list that appears.
- **Last** - Use the last characters in an existing attribute value in the value builder. Select the number of characters in the **Count** dropdown list that appears.
1. In **Add Helper**, select an option to assign additional values to the attribute.
- **Random Numbers** - Add up to 10 random numbers to the attribute's value.
- **Static Value** - Add a static string to attributes that use this value builder.
- **Incremented Number** - Add an integer to the value builder that increases by 1 when the value builder is used.
- **Random String** - Add up to 10 random Latin characters to the attribute's value.
1. In the **OTHER SETTINGS** section, choose an option under **Case Conversion**.
- **none** - Make no changes to the capitalization of the strings in the value builder.
- **lower** - All letters in the attributes used in the value will be lowercase.
- **upper** - All letters in the attribute value will be uppercase.
- **capital** - The first letter of each string attribute used in the value will be uppercase. For example, the attribute "john smith" would be converted to "John smith" in the resulting value.
- **title** - The first letter of each word in a string attribute used in the value will be uppercase. For example, the attribute "john smith" would be converted to "John Smith" in the resulting value.
Static strings and random strings are not affected by Case Conversion settings.
For example, the value builder formula in the screenshot below combines the first letter of a first name attribute, 3 random numbers, a period, the last name attribute, and the string `@sample.com`. These attributes and helpers are combined to form an email address.
Applied to the profile John Smith, this value builder might generate `j423.smith@sample.com`.
1. Select **Save**.
1. (Optional) Test your value builder by choosing a profile in the **TESTING** section within the **Profile** field. A value will be generated based on your selections in the **FORMULA** section and displayed underneath the **Profile** field.
## Editing Value Builders
You can view and edit existing value builders.
1. Go to **Admin > Templates > Value Builders**.
1. To export a JSON file containing the metadata about the selected value builders and any related configuration:
1. Select the checkbox beside the value builders you want to export. To select all value builders, select the checkbox beside the **VALUE BUILDERS** header.
1. Select the **ellipsis** icon next to **Actions** and select **Export**. When the file has been generated, select **Download** to save the metadata to a local file.
1. To edit an individual value builder, select the name of the value builder.
1. In the **FORMULA** section, make any necessary changes to the formula used in this value builder.
Note
If you make changes to an Incremented Number helper, the counter for that helper will be reset.
1. In the **INFO** section, make any necessary changes to the name and UID for this value builder.
1. Select **Save**.
When your value builders are complete, you can add them to workflows using the [Set Attribute Values](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#set-attribute-values) action.
# Workflows
A workflow is a customizable series of actions that completes a specific task in Non-Employee Risk Management. There are several types of workflows that can be used depending on the services you use within Non-Employee.
## Lifecycle Workflows
Lifecycle workflows are used to create and update profiles within Non-Employee Risk Management. Refer to [Creating and Managing Workflows in Lifecycle](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html) for more information on how to create each type of workflow.
Within Lifecycle, there are 4 types of workflows.
- **Create Workflow** - A create workflow is used to facilitate the creation of profiles within the application.
- **Update Workflow** - An update workflow is used to facilitate updates to existing profiles.
- **Automated Workflow** - An automated workflow is used to trigger actions based on data type attributes.
- **Batch Workflow** - A batch workflow is used to update the same attribute(s) for many profiles without having to take individual actions.
## Collaboration Workflows
Collaboration workflows are used to manage portal accounts within the Collaboration service in Non-Employee Risk Management. Refer to [Creating and Managing Workflows in Collaboration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html) for more information on how to create each type of workflow.
- **Registration Workflow** - A registration workflow allows portal users to register for a Non-Employee Risk Management account and fill out forms and pages related to their profiles.
- **Login Workflow** - A login workflow allows registered portal users to sign in to Non-Employee.
- **Password Reset Workflow** - A password reset workflow allows registered portal users to update their portal passwords.
Each type of workflow has a set of actions that you can configure. These are the actions that will take place every time this workflow is executed. Refer to [Workflow Actions](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html) for a list of the actions that can be included in workflows and the types of workflows they apply to.
# Workflow Actions
There are several different actions you can include in your Lifecycle workflows. The possible actions are listed below, along with the types of workflows in which they can be used.
## Approval Form
Approval Form is an action used when a workflow requires an approval or a rejection, typically from another user.
Approval Form is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure an Approval Form step, from the New Action page:
1. Select the **Approval Form** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Page: select the page to use in the approval form being created. Select [Pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) for more information. Selecting the preview icon presents the administrator with a preview of the page.
1. Require comments: select Yes if end user comments are required.
1. Allow bulk approval or rejection: select Yes if the approver can perform bulk approvals and rejections.
Note
To perform bulk approvals and rejections, users must have the [bulk approve/reject](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html#assigning-permissions-to-roles) user role permission.
1. Skippable approval: select Yes if the requester can perform the approval.
- NOTIFICATIONS
1. Approved email: select a notification template to send to the requester when the action requiring review is approved.
1. Rejected email: select a notification template to send to the requester when the action requiring review is rejected.
1. Performer notification email: select a notification template to send to the Approver to inform them that action is required. Selecting the preview icon next to any of these presents the administrator with a preview of the notification. Select [Notifications](https://documentation.sailpoint.com/ne-admin/help/setup/notifications.html) for more information.
- APPROVERS
1. From the request: select The requester if the requestor of the action should perform the approval.
1. From the requests profile: select either or both Profiles owner or Profiles contributors if these users should perform the approval.
1. Users with NEProfile role: select any of the NEProfile application roles and any user within the selected role(s) can perform the approval.
1. Users with Collaboration role: select any of the NEAccess application roles and any user within the selected role(s) can perform the approval.
1. Contributors from another profile: select another profile to inherit the contributors/owners of that profile. Those contributors/owners of the that profile can perform the approval within this workflow.
1. Selected contributor: select an attribute to inherit the profile owner or contributor of that attribute. Those contributors/owners of the that attribute can perform the approval within this workflow. Select [Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) for more information.
1. Selected contributors managers: select an attribute to inherit the profile owner or contributor of that attribute. The assigned manager of the contributors/owners of the that attribute can perform the approval within this workflow.
1. Select **Create**.
1. The Approval Form action appears on the Workflows page.
## Ask Security Questions
Ask Security Questions is an action used to define the number of security questions a user must answer upon logging in as an additional authentication factor.
Ask Security Questions is available for the following workflow types:
- [Collaboration Login](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#login-workflows)
- [Collaboration Password Reset](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#password-reset-workflows)
Important
A "Set Security Questions" action must be included in the registration workflow for "Ask Security Questions" to be used in the login workflow.
1. Select the **Add Security Questions** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Number of Questions: select the number of questions the user must answer. The maximum number to select is set by the number of security questions currently created.
- AUTHENTICATION
1. Authentication expiration: enter a valid number based on the selection of one of the following to set how often the user will need to perform that type of validation.
1. Hours: selecting this value will require a user to re-authenticate after x number of hours
1. Days: selecting this value will require a user to re-authenticate after x number of days
1. Login attempts: selecting this value will require a user x number of failed attempts to authenticate before system lockout
1. Always: selecting this value will require a user to always authenticate.
1. Select **Create**.
1. The Ask Security Questions action appears on the Workflows page.
## Auto Assign
Auto Assign is an action used to automatically assign contributors to a profile.
Auto Assign is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure an Auto Assign step, from the New Action page:
1. Select the **Auto Assign** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- ASSIGNMENT
1. NEProfile roles: select any of the NEProfile application roles and any user within the selected role(s) will be automatically assigned as a contributor.
1. NEAccess roles: select any of the NEAccess application roles and any user within the selected role(s) will be automatically assigned as a contributor.
1. Contributors from another profile: select a profile search/select attribute to be completed in the workflow. When selected the contributors/owners of that profile will assigned as a contributor.
1. Select **Create**.
1. The Auto Assign action appears on the Workflows page.
Close Session Action is an action used to close the current workflow session.
## Close Session Action
Ends the workflow. Any actions in a workflow after the Close Session action won't be executed.
Close Session Action is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Close Session Action step, from the New Action page:
1. Select the **Close Session Action** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Select **Create**
1. The Close Session action appears on the Workflows page.
## Collaboration Account
Collaboration Account is an action used to create a Collaboration user account for a profile.
Collaboration Account is available for the following workflow types:
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
1. Select the **Collaboration Account** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- ACCOUNT CREATION
1. Username: select an available value builder to generate the username for this account. Refer to [Value Builder](https://documentation.sailpoint.com/ne-admin/help/profile-types/value-builders.html) for more information.
1. Secondary username: select an available value builder to generate a secondary username for this account if the first username is not available.
1. Store type: select if the user should be created as a directory or local account.
1. If Directory is selected:
- Directory: select the appropriate directory
- Groups to assign to user: search and select the groups this user should be added to. Multiple groups can be added here.
1. If Local is selected:
- Roles to assign to the user: search and select the roles this user should be added to. Multiple roles can be added here.
- PERFORMERS
1. From the request: select The requester if the requestor is the user that should perform the action.
1. From the requests profile: select either or both Profiles owner or Profiles contributors if these users should perform the action.
1. Users with NEProfile role: select any of the NEProfile application roles and any user within the selected role(s) should perform the action.
1. Users with NEAccess role: select any of the NEAccess application roles and any user within the selected role(s) should perform the action.
1. Contributors from another profile: select a profile search/select attribute to be completed in the workflow. When selected the contributors/owners of that profile should perform the action.
1. Selected contributor: select an attribute to inherit the profile owner or contributor of that attribute. Those contributors/owners of the that attribute should perform the action. Refer to [Managing Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) for more information.
1. Selected contributors managers: select an attribute to inherit the profile owner or contributor of that attribute. The assigned manager of the contributors/owners of the that attribute should perform the action.
1. Select **Create**
1. The Collaboration Account action appears on the Workflows page.
## Contributors
Contributors allows a user to manually assign owners or other contributors to a profile.
Contributors is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Contributors step, from the New Action page:
1. Select the **Contributors** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Assignment options: select an option to control what the performer will assign: Owner, Contributor and/or roles.
The options displayed are determined by the [Role Filtering](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#creating-a-custom-profile-type) configuration for the profile type associated with this workflow.
- NOTIFICATIONS
1. Performer notification email: select a notification template to send to the approver to inform them that action is required. Selecting the preview icon presents the administrator with a preview of the notification. Select [Notifications](https://documentation.sailpoint.com/ne-admin/help/setup/notifications.html) for more information.
- PERFORMER
1. From the request: select The requester if the requester of the action should perform the assignment.
1. From the requests profile: select either or both Profiles owner or Profiles contributors if these users should perform the assignment.
1. Users with NEProfile role: select any of the NEProfile application roles and any user within the selected role(s) will be able to perform the assignment.
1. Users with Collaboration role: select any of the NEAccess application roles and any user within the selected role(s) should receive the notification.
1. Contributors from another profile: select a profile search/select attribute to be completed in the workflow. When selected the contributors/owners of that profile will be able to perform the assignment.
1. Selected contributor: select an attribute to inherit the profile owner or contributor of that attribute. Those contributors/owners of the that attribute will be able to perform the assignment. Select [Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) for more information.
1. Selected contributors managers: select an attribute to inherit the profile owner or contributor of that attribute. The assigned manager of the contributors/owners of the that attribute will be able to perform the assignment.
1. Select **Create**.
1. The Contributors action appears on the Workflows page.
## Create
Create is the action that stores all attributes collected during the workflow in the database to create a profile.
When multiple create actions are applied to a single workflow, additional create actions after the first act as update actions.
Create is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Create step, from the New Action page:
1. Select the **Create** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Make the requester the default owner?: select Yes or No. Selecting Yes will set the requester as the default owner of the created profile if no owner is specified during the request process.
1. Select **Create**.
1. The Create action appears on the Workflows page.
## Duplicate Prevention
Duplicate Prevention is an action used to check the specified attribute(s) against existing profiles to find duplicates. If a duplicate is identified, the application prompts the requester to select that existing profile or create a new one from the request.
Duplicate Prevention is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Duplicate Prevention step, from the New Action page:
1. Select the **Duplicate Prevention** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- DUPLICATE SETTINGS
1. Attributes used to search for profile: search and select for the desired attributes. Multiple attributes can be added here.
- NOTIFICATIONS
1. Performer notification email: select a notification template to send to the requester to inform them of the duplicate. Selecting the preview icon presents the administrator with a preview of the notification. Select [Notifications](https://documentation.sailpoint.com/ne-admin/help/setup/notifications.html) for more information.
1. PERFORMERS
1. From the request: select The requester if the requestor is the user that should perform the action.
1. From the requests profile: select either or both Profiles owner or Profiles contributors if these users should perform the action.
1. Users with NEProfile role: select any of the NEProfile application roles and any user within the selected role(s) should perform the action.
1. Users with Collaboration role: select any of the NEAccess application roles and any user within the selected role(s) should perform the action.
1. Contributors from another profile: select a profile search/select attribute to be completed in the workflow. When selected the contributors/owner of that profile should perform the action.
1. Selected contributor: select an attribute to inherit the profile owner or contributor of that attribute. Those contributors/owners of the that attribute should perform the action. Select [Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) for more information.
1. Selected contributors managers: select an attribute to inherit the profile owner or contributor of that attribute. The assigned manager of the contributors/owners of the that attribute should perform the action.
1. Select **Create**.
1. The Duplicate Prevention action appears on the Workflows page.
## Email Verification
Email Verification is an action used to initiate an email address verification process.
Establishing this in the workflow, sends the end user a code with an expiration time. The code is sent to the user’s email address and serves as verification that the user’s email address is valid.
Email Verification is available for the following workflow types:
- [Collaboration Login](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#login-workflows)
- [Collaboration Password Reset](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#password-reset-workflows)
1. Select the **Email Verification** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Email expiration (minutes): enter the number of minutes that the code sent via email remains valid.
- AUTHENTICATION
1. Authentication expiration: enter a valid number based on the selection of one of the following to set how often the user will need to perform that type of validation.
1. Hours: selecting this value will requires a user to re-authenticate after x number of hours
1. Days: selecting this value will requires a user to re-authenticate after x number of days
1. Login attempts: selecting this value will requires a user x number of failed attempts to authenticate before system lockout
1. Always: selecting this value will require a user to always authenticate.
1. Select **Create**.
1. The Email Verification action appears on the Workflows page.
## Fulfillment
Fulfillment is an action used when a workflow requires information from other users through the workflow.
Fulfillment is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Fulfillment step, from the New Action page:
1. Select the **Fulfillment** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Page: select the page to use in the fulfillment process. Select [Pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) for more information. Selecting the preview icon presents the administrator with a preview of the page.
1. Description: enter text to describe the purpose of this action.
1. Require comments: select yes if end user comments are required.
- NOTIFICATIONS
1. Performer notification email: select a notification template to send to the fulfiller to inform them that action is required. Selecting the preview icon presents the administrator with a preview of the notification. Select [Notifications](https://documentation.sailpoint.com/ne-admin/help/setup/notifications.html) for more information.
- PERFORMER
1. From the request: select The requester if the requestor of the action should perform the fulfillment action.
1. From the requests profile: select either or both Profiles owner or Profiles contributors if these users should perform the fulfillment action.
1. Users with NEProfile role: select any of the NEProfile application roles and any user within the selected role(s) can perform the fulfillment action.
1. Users with Collaboration role: select any of the NEAccess application roles and any user within the selected role(s) can perform the fulfillment action.
1. Contributors from another profile: select another profile to inherit the contributors/owners of that profile. Those contributors/owners of the that profile can perform the fulfillment action within this workflow.
1. Selected contributor: select an attribute to inherit the profile owner or contributor of that attribute. Those contributors/owners of the that attribute can perform the fulfillment action within this workflow. Select [Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) for more information.
1. Selected contributors managers: select an attribute to inherit the profile owner or contributor of that attribute. The assigned manager of the contributors/owners of the that attribute can perform the fulfillment action within this workflow.
1. Select **Create**.
1. The Fulfillment action appears on the Workflows page.
## Identity Proofing
Identity Proofing is an action used to verify the identity of a new profile using your existing identity verification provider. We support the following identity verification providers:
- [ID Dataweb](#id-dataweb)
- [Microsoft Entra ID](#ms-entra-id)
Identity Proofing is available for the following workflow types:
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
**To configure an Identity Proofing step using ID Dataweb, from the New Action page:**
1. Select the **Identity Proofing** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
- Vendor: select **ID Dataweb**.
- Description: enter text to describe the purpose of this action.
- Proofing Type: enter the type of proofing applied, provided by ID Dataweb.
- Client ID: enter the Client ID from ID Dataweb.
- Client Secret: enter the Client Secret from ID Dataweb.
- LOGIN HINTS
You can include login hints within ID Dataweb to make it easier for users to authenticate into your identity proofing provider. Redacted versions of the user's first and last name will be displayed in the identity proofing provider when the user is registering.
To include login hints, select an attribute within the **First Name** and **Last Name** fields.
The attributes available for these fields depend on the attributes that are set earlier in the workflow using the [Request Form](#request-form) or [Set Attribute Values](#set-attribute-values) action. For example, if you use a Request Form action to set the `firstname` attribute, it will be available to select here in the Identity Proofing action.
Login hints are not required. The user will still have to enter their first and last name when they go to ID Dataweb.
- ENVIRONMENT
Select the type of ID Dataweb environment for the proofing type selected in this action.
**To configure an Identity Proofing step using Microsoft Entra ID, from the New Action page:**
1. Select the **Identity Proofing** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
- Vendor: select **Microsoft Entra ID**.
- Description: enter text to describe the purpose of this action.
- Proofing Type: enter the type of proofing applied, provided by Microsoft Entra ID.
- Client ID: enter the Client ID from Microsoft Entra ID.
- Client Secret: enter the Client Secret from Microsoft Entra ID.
- (Optional) Company Logo URL: enter the full URL of the logo that is displayed on the self-service registration page.
- (Optional) Terms of Service URL: enter the full URL for the terms of use of the verifiable credential, provided by Microsoft Entra ID.
- LOGIN HINTS
The First Name and Last Name attributes are collected from registrants in the registration form, and must map to a Non-Employee Risk Management attribute.
To map the attributes, select an attribute within the **First Name** and **Last Name** fields.
The values provided by registrants for the attributes will be sent to Microsoft Entra ID for verification, and once verified will be set on the profile created in Non-Employee Risk Management.
- ISSUANCE REQUEST SETTINGS
These settings indicate the type of credentials that will be issued by the identity verification vendor, using Microsoft Entra ID.
- Authority: enter the issuer's decentralized identifier (DID) URL, provided by Microsoft Entra ID.
- Credential type: enter the credential type, provided by Microsoft Entra ID.
- Manifest: enter the verifiable credential manifest document URL, provided by Microsoft Entra ID.
- CREDENTIAL VERIFICATION REQUEST SETTINGS
Sets the criteria for credentials that will be accepted during non-employee onboarding. This can correspond to the criteria configured on the [issuance request settings](#issuance-request), or admins can configure additional credential types that will be accepted for onboarding, such as credentials issued by business partners or governments.
- Authority: enter the issuer's decentralized identifier (DID) URL, provided by Microsoft Entra ID.
- Purpose: enter text to describe the purpose of this accepted credential type.
- Credential Type: enter the credential type, provided by Microsoft Entra ID.
- (Optional) Photo claim: enter the claim name used for liveness checks, provided by Microsoft Entra ID.
- Accepted Issuers: enter the issuer's decentralized identifier (DID) URL, provided by Microsoft Entra ID.
Select **+ Add Accepted Credential Type** to add an additional credential criteria.
Note
In order to verify identities using Microsoft Entra ID, the Microsoft Entra Verified ID feature must be enabled in your Microsoft Entra tenant. For more information on how to configure Verified ID in your Microsoft Entra tenant, including issuing credentials, refer to the [Microsoft Entra Verified ID documentation](https://learn.microsoft.com/en-us/entra/verified-id/).
## Notification
Notification is an action used when a workflow requires sending an email to a particular recipient(s).
Notification is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Notification step, from the New Action page:
1. Select the **Notification** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Email: select the template to use for the notification. Select [Notifications](https://documentation.sailpoint.com/ne-admin/help/setup/notifications.html) for more information.
1. Description: enter text to describe the purpose of this action.
- RECIPIENTS
1. Email addresses: enter the list of email addresses, separated by commas, that will receive this notification.
1. Email attribute: select an attribute apply to the notification.
1. From the request: select The requester if the requestor of the action should receive the notification.
1. From the requests profile: select either or both Profiles owner or Profiles contributors if these users should receive the notification.
1. Users with NEProfile role: select any of the NEProfile application roles and any user within the selected role(s) should receive the notification.
1. Users with Collaboration role: select any of the NEAccess application roles and any user within the selected role(s) should receive the notification.
1. Contributors from another profile: select another profile to inherit the contributors/owners of that profile. Those contributors/owners of the that profile should receive the notification.
1. Selected contributor: select an attribute to inherit the profile owner or contributor of that attribute. Those contributors/owners of the that attribute should receive the notification. Select [Attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html) for more information.
1. Selected contributors managers: select an attribute to inherit the profile owner or contributor of that attribute. The assigned manager of the contributors/owners of the that should receive the notification.
1. Select **Create**.
1. The Notification action appears on the Workflows page.
## Profile Check
Profile Check can be used to prevent duplicate profiles or to detect related profiles.
Profile Check is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
To configure a Profile Check step, from the New Action page:
1. Select the **Profile Check** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- PROFILE CHECKING
1. Attributes used to search for profile: search and select attributes used to validate against.
1. What should happen if an existing profile is found?: select either:
- Perform this workflow against the profile thats found: if a profile is found that matches the attribute selected the existing profile is added to current request and the workflows is executed against the existing profile.
- Create a relationship to the profile thats found: if a profile is found that matches the attribute selected then a relationship between the current profile and the existing profile.
1. Select **Create**.
1. The Profile Check action appears on the Workflows page.
## Registration Invitation
Registration Invitation is an action limited to customers who have purchased Collaboration. This action allows a user to send an invitation to a third-party to self-register in a Collaboration portal and would link the registration to the already created profile.
Registration Invitation is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
If a user receives more than one registration email, they must always register using the most recent invitation.
To configure a Registration Invitation step, from the New Action page:
1. Select the **Registration Invitation** button.
1. Specify the appropriate information in each field.
- INVITATION SETTINGS
1. Registration Workflow: select the registration workflow from Collaboration.
1. Portal: select the Collaboration Portal that the invite should include.
1. Email Attribute: select an email address attribute.
1. Email: select the Notification Template the invite should use.
1. Wait for completion: select Yes to set the primary action to wait for the secondary action to complete.
1. Wait until what action completes?: only available when Yes is selected. Select from the available list of actions. Caution: If No is selected, conflicts may arise
1. INVITATION SESSION ATTRIBUTES
- Attributes to send to the new request: search and select attributes to send from the current workflow session to the new workflow session.
1. INVITATION WORKFLOW COMPLETION
- Return the profile to this request: select Yes to send the profile created during the registration workflow to be sent back for further processing.
- Attributes to receive back once complete: search and select attributes that should be returned once the secondary workflow completes.
1. BASIC SETTINGS
- Description: enter text to describe the purpose of this action.
1. VALIDATION SETTINGS
- Validate Completed Registration: selecting Yes, prevents invitations from being sent to an email address that belongs to a user that has already completed a registration workflow.
- Validate In-Progress Registration: selecting Yes, prevents invitations from being sent to an email address that belongs to a user that has already has a pending registration workflow.
1. Select **Create**.
1. The Registration Invitation action appears on the Workflows page.
## Request Form
Request Form is an action used when a workflow requires a page for the end user that allows information to be entered about the profile being created. A request form is commonly the first step in a workflow where the end user’s interaction is required to initiate a process.
Request Form is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Request Form step, from the New Action page:
1. Select the **Request Form** button.
1. Specify the appropriate information in each field.
- Page: select the page to use in the request form being created. Select [Pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) for more information. Selecting the preview icon presents the administrator with a preview of the page.
- Description: enter text to describe the purpose of this action.
- Require Comments: select Yes if end user comments are required.
1. Select **Create**.
1. The Request Form action appears on the Workflows page.
## Reset Password
Prompts the user to provide a new password for their portal account.
Portal users' passwords must meet the following criteria:
- The password must be 8 or more characters long.
- It must contain at least 3 out of these 4 types of characters:
- Lowercase letters
- Uppercase letters
- Numeric characters
- Special characters
Note
This action is included in all [Collaboration Password Reset](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#password-reset-workflows) workflows and can't be modified or deleted.
## REST API
REST API is an action used to send or receive data from and to other applications.
REST API is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
If your REST API request takes longer than 60 seconds to complete during a workflow's execution, the action will time out and the workflow will fail.
To configure a REST API step, from the New Action page:
1. Select the **REST API** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- AUTHENTICATION
1. Auth Type: select from the following options
- None: (default), requires no additional information.
- Basic: enter the Username and Password the endpoint recognizes.
- Oauth2: enter the appropriate values for each field:
1. Access token url
1. Client id
1. Client secret
1. Scope
- Oauth2 w/ Mutual TLS: enter the appropriate values for each field:
1. Access token url
1. Access token server certificate (choose a file)
1. Client id
1. Scope
1. Client certificate (choose a file)
1. Client key (choose a file)
- REQUEST
1. Http verb: select from one of the following options
- Get: attempts to request data from the endpoint.
- Post: attempts to create a new record at the endpoint.
- Patch: attempts to update a specified record at the endpoint.
- Put: attempts to completely replace a record at the endpoint.
- Delete: attempts to delete a specified record at the endpoint.
1. End point: enter in the full URL of the API to send the request.
1. Headers: select the + Add header button. Enter the Header key and Value for each header added.
1. Json body: define the expected HTTP body using JSON. Liquid can be used here to pull data from the requester or the profile that is being worked on in the workflow.
- RESPONSE
1. Mappings: to store any of the response data, define the mapping here, by searching and selecting an Attribute and specifying the Path to the key that has the desired value.
1. Select **Create**.
1. The REST API action appears on the Workflows page.
## Review Form
Review Form is an action used when the workflow requires review from the original requester. This is like a final review before submitting the request.
Review Form is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Review Form step, from the New Action page:
1. Select the **Review form** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Page: select the page to use in the review process. Select [Pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html) for more information. Selecting the preview icon presents the administrator with a preview of the page.
1. Description: enter text to describe the purpose of this action.
1. Require comments: select **yes** if end user comments are required.
- NOTIFICATIONS
1. Performer notification email: select a notification template to send to the requestor to inform them that action is required. Selecting the preview icon presents the administrator with a preview of the notification. Select [Notifications](https://documentation.sailpoint.com/ne-admin/help/setup/notifications.html) for more information.
1. Select **Create**.
1. The Notification action appears on the Workflows page.
## Run Workflow
Run Workflow is an action used to trigger another workflow or “sub-routines” from the current workflow.
Run Workflow is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Run Workflow step, from the New Action page:
1. Select the **Run workflow** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- NEW REQUEST
In some instances, when the sub-workflow is triggered, administrators can choose to send information from the current request for the secondary workflow to operate against.
1. Profile to send to new request: select one of the available profile options
- None: select to prevent the requests profile being set to anything else.
- Current Profile: select to set the requests profile to the current pending profile from the primary workflow.
- Profile(s) from attribute: select to set the requests profile to a related profile based on an attribute.
- What attribute?: select attribute
- All related profiles by type: select to set the requests profile to a one-to-many relationship.
- What profile type?: select the profile type
1. Attributes to send to the new request: search and select the attribute(s) from the current workflow session to update in the new workflow session.
1. For each attribute set the following
- Operation: select one of the following:
1. set value
1. remove value
- Send: select one of the following (options may be different based on attribute type):
1. another attributes value
1. another profiles value
1. another users account value
1. another users profile value
1. requestors account value
1. requestors profile
1. requestors profile value
1. requests value
1. static value
1. value builder
If a date attribute is selected and the operator selected is "more than," "less than," or exactly," 2 more additional fields called Days and Timeframe will appear.
- SUBWORKFLOW COMPLETION
1. Attributes to receive back once complete: when a secondary workflow competes, administrators can request attributes back from the secondary workflow session. Search and select the attribute(s)
- For each attribute set the following
1. Operation: select one of the following:
- set value
- remove value
1. Send: select one of the following (options may be different based on attribute type):
i. another attributes value ii. another profiles value iii. another users account value iv. another users profile value v. requestors account value vi. requestors profile vii. requestors profile value viii. requests value ix. static value x. value builder
If a date attribute is selected and the operator selected is "more than," "less than," or exactly," 2 more additional fields called Days and Timeframe will appear.
- SUBWORKFLOW
1. Workflow to run: select the secondary workflow to run when this action is triggered.
1. Wait for Completion: select Yes to set the primary workflow to wait for the secondary workflow to complete.
1. Wait until what action completes?: only available when Yes is selected. Select from the available list of actions. Caution: If No is selected, conflicts may arise. For example, the current workflow may complete and create a new profile before the subroutine completes.
1. Select **Create**.
1. The Run Workflow action appears on the Workflows page.
## Set Attribute Values
Set Attribute Values is an action used to predefine an attribute to a specific value.
Set Attribute Values is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Set Attribute Values step, from the New Action page:
1. Select the **Set Attribute Values** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Attributes: search and select the attribute to predefine
1. For each attribute selected set the following
- Operation: select one of the following
1. set value
1. remove value
- Set as: select one of the following
1. static value: enter the value
1. value builder: select the appropriate value builder
1. requestors account value: select the appropriate attribute
1. another users account value: select the appropriate values within each field
- From what user attribute?
- Attribute
1. another attribute value: select the appropriate attribute
1. another profiles value: select the appropriate values within each field
- What profile: select one of the profile search or profile select attributes from the dropdown list. This attribute will contain a profile chosen earlier in the workflow or that already exists on this request's profile.
- From what Attribute: select an attribute from the profile stored in the attribute you selected in the `What profile` field. The value of this attribute will be copied to the attribute you are setting with this workflow action.
1. requestors profile value: select the appropriate attribute
1. another users profile value: select the appropriate values within each field
- What user
- From what Attribute
If a date attribute is selected, Set As can be set to static or dynamic value. If static value is chosen, select a date. If dynamic value is chosen, the administrator can specify the number of days before or after a value of either:
- days before today
- days after today
- days before attribute (admins will have to search and select the attribute)
- days after attribute
- same day as attribute
1. Select **Create**.
1. The Set Attribute Values action appears on the Workflows page.
## Set Security Questions
Set Security Questions is an action used to define the number of [security questions](https://documentation.sailpoint.com/ne-admin/help/collaboration/security-questions.html) a user must answer to facilitate self-service password resets or as an additional authentication factor.
Set Security Questions is available for the following workflow types:
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
Important
When using a Set Security Questions action, it must come after the [Collaboration Account Action](#collaboration-account) action in the workflow.
1. Select the **Set Security Questions** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Number of Questions: select the number of questions the user must answer.
1. Select **Create**.
1. The Set Security Questions action appears on the Workflows page.
## SOAP API
SOAP API is an action used to send or receive data from and to other applications.
SOAP API is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
To configure a SOAP API step, from the New Action page:
1. Select the **SOAP API** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- ENVELOPE SETTINGS:
1. WSDL URL: provide the link to the XML file where the Web Services Description Language is defined.
1. Operation: enter the name of the operation that this action should use.
- AUTHENTICATION
1. Auth Type: select from the following options
- None: (default) requires no additional information.
- Basic: enter the Username and Password the endpoint recognizes.
- WSSE: enter the Username and Password for the WS-Security Username Token
- REQUEST XML
1. Enter the XMLHttpRequest object to be used to request the data. Liquid can be used here to pull data from the requester or the profile that is being worked on in the workflow.
- RESPONSE HANDLING
1. Mappings: to store any of the response data, define the mapping here, by searching and selecting an Attribute and specifying the Path to the key that has the desired value.
Add another Key Label for each layer if the value is nested in the response.
1. Select **Create**.
1. The SOAP API action appears on the Workflows page.
## Status Change
Status Change is an action used to change the current status of a profile.
Status Change is available for the following workflow types:
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Collaboration Registration](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#registration-workflows)
To configure a Status Change step, from the New Action page:
1. Select the **Status Change** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. New status: select from the available statuses
1. Select **Create**.
1. The Status Change action appears on the Workflows page NOTE: The status change takes effect immediately. If the status change should be approved, move the Status Change action after the Approval action.
## Un-Assign
Un-assign is an action used to automatically remove contributors from a profile.
Un-Assign is available for the following workflow types:
- [Create](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows)
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
To configure an Un-Assign step, from the New Action page:
1. Select the **Un-assign** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
- UNASSIGNMENT
1. NEProfile roles: select any of the NEProfile application roles and any user within the selected role(s) will be automatically unassigned.
1. NEAccess roles: select any of the NEAccess application roles and any user within the selected role(s) will be automatically unassigned.
1. Select **Create**.
1. The Un-assign action appears on the Workflows page.
## Update
Update is an action used to update a profile using the values in the workflow.
Update is available for the following workflow types:
- [Update](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows)
- [Automated](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#automated-workflows)
- [Batch](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#batch-workflows)
To configure an Update step, from the New Action page:
1. Select the **Update** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Description: enter text to describe the purpose of this action.
1. Select **Create**.
1. The Update action appears on the Workflows page.
## Username and Password
Prompts the user for their username and password.
Note
This action is included in all [Collaboration Login](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html#login-workflows) workflows and can't be modified or deleted.
# Creating and Managing Workflows in Collaboration
Collaboration provides administrators the ability to create three types of workflows for portal registration, login, and password resets. Multiple workflows can exist within each type and can include an unlimited number of steps and actions required by the assigned user.
## Registration Workflows
A registration workflow is used to facilitate the registration process through an Collaboration portal. Multiple registration workflows can be applied to a portal.
### Creating a Registration Workflow
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. By default, the PORTAL REGISTRATION tab is presented.
1. Select the **+ Registration Workflow** button.
1. Specify the appropriate information in each field:
- Name: enter the name for the registration workflow.
- UID: is a system generated unique identifier, it cannot be changed after the registration workflow is created. During creation, Administrators can accept the default or choose to specify this value.
- Profile Types: from the drop-down select from the available profile types to apply this workflow.
- Description: provide a brief description for this workflow.
- Position: if multiple Registration workflows are present, this value defines the order in which they should appear on the First Time Users section of the login screen.
1. Select **Create**.
1. The administrator is presented with a default create action that can be edited or deleted and the following buttons and tabs:
### Conditions
Registration workflows can contain conditions to evaluate whether an action in the workflow should be triggered. Conditions are not available for Login or Password Reset workflows.
Selecting this button displays the New Workflows Condition page.
1. Select the **+ Condition** button.
In **BASIC SETTINGS**, in the **Name** field, enter the name of the condition.
1. Select the **Create** button.
In the CONDITION section:
- Attributes:
1. Search for and select the desired attribute.
1. Once the selection has been made, the Operator and Value fields appear.
1. In Operator:
- Select the desired operator. The values available will vary based on attribute selected.
1. Value
- Enter the filter criteria of the data to view.
1. Select the to add the condition to the Conditions list below.
- Conditions: Displays the applied conditions. Defaults to None.
1. Once the conditions are created, an action should be dragged into the condition. The workflow will evaluate the condition and determine if the action should be performed or skipped. Multiple conditions can be added.
Conditions are identified by the icon on the Workflows page
### Enabling Registration Workflows
When a workflow is enabled, a button for that workflow appears within the Collaboration application.
Selecting the **Enable Workflow** button enables the workflow.
Selecting the **Disable Workflow** button disables the active workflow.
**ACTIONS Tab** - The ACTIONS tab is the default view on the Registration Workflow page. Here administrators can view and update the actions, conditions, and other settings for that workflow.
**INFO tab** - The INFO tab provides a view of the settings for the registration workflow entered on the New Registration Workflow page. Refer to [Creating a Registration Workflow](#creating-a-registration-workflow) for more information.
Administrators can edit all fields except UID.
### Restricting Registration by Domain
Administrators can restrict portal registrations to specific domains. The default configuration allows Any. Administrators can choose to allow only a specific set of domains, or block a specific set of domains.
**WHITELIST tab**
This WHITELIST tab allows administrators to restrict registrations to specified domains. The default configuration allows Any. If nothing is specified or updated, then all domains will be accepted.
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select workflows.
1. In the bottom table, select the workflow to view/edit.
1. Select the WHITELIST tab.
1. Specify the appropriate information in each field
- Permitted domain attributes: search and select attributes that will be referenced for valid domains.
- From these profile types: search and select profile types that will be referenced for valid domains.
- Whitelisted domains: enter the domain portion of an email address limit registration to only those domains (i.e. gmail.com)
1. Select **Save**
**BLACKLIST Tab**
This BLACKLIST tab allows administrators to block registrations from specified domains during the registration process. The default configuration allows Any. If nothing is specified or updated, then all domains will be accepted.
From the Admin Console:
1. Select **Collaboration** in the left navigation
1. Select workflows
1. In the bottom table, select the workflow to view/edit
1. Select the BLACKLIST tab
1. Specify the appropriate information in each field
a. Blacklisted domains: enter the domain portion of an email address to block any registrations from this domain (i.e. gmail.com). Multiple domains can be added.
1. Select save
### Managing Registration Workflows
From the Admin Console:
1. Select Collaboration in the left navigation
1. Select **Portal Workflows**.
1. By default, the PORTAL REGISTRATION tab is presented.
1. The tabs at the top of the workflow table are:
- All: (default) displays all active workflows whether they are enabled or disabled
- Enabled: displays all active workflows that are enabled
- Disabled: displays all active workflows that are disabled
- Archived: displays all inactive workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow.
Selecting the checkbox next to the REGISTRATION WORKFLOWS header, selects all registration workflows in that status.
Once a registration workflow or multiple workflows are selected, perform an action by:
1. Selecting the ellipsis next to Actions header to display the available actions.
1. Select the appropriate action to apply.
- Archive: deactivates the selected registration workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected registration workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on the status.
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected registration workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the download button and choose a location to save the file.
### Updating a Registration Workflow
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. By default, the PORTAL REGISTRATION tab is presented.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow.
Select the **Edit** icon to edit the action or condition selected.
Select the **Preview** icon to preview the page or form for the action selected.
Select the **Delete** icon to delete the action or condition selected.
1. On the INFO tab, set **Disable failure email notifications** to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
1. Once the changes have been made, select **Save**.
## Login Workflows
A login workflow is used to facilitate the authentication process through a Collaboration portal. Only one login workflow can be applied to a portal.
### Creating a Login Workflow
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. Select the **PORTAL LOGIN** tab.
1. Select **+ Login Workflow** button.
1. Specify the appropriate information in each field.
1. Name: enter the name for the login workflow.
1. UID: is system generated unique identifier, it cannot be changed after the login workflow is created. During creation, administrators can accept the default or choose to specify this value.
1. Description: provide a brief description for this workflow.
1. Timeout: enter the number of minutes that a session should terminate after inactivity.
1. Select **Create**.
Note
The Login workflow has a default action for [Username and Password](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#username-and-password) that cannot be modified or deleted.
### Enabling Login Workflows
When a Login workflow is enabled, it is available to an administrator to add to a portal.
Selecting the **Enable Workflow** button enables the workflow.
Selecting the **Disable Workflow** button disables the active workflow.
**ACTIONS Tab**
The ACTIONS tab is the default view on the Login Workflow page. Here administrators can view and update the actions workflow.
**INFO tab**
The INFO tab provides a view of the settings for the login workflow entered on the New Login Workflow page. Select [New Login Workflow](#creating-a-login-workflow) for more information. Administrators can edit all fields except UID.
### Managing Login Workflows
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. Select the **PORTAL LOGIN** tab.
1. The tabs at the top of the workflow table are:
1. All: (default) displays all active workflows whether they are enabled or disabled
1. Enabled: displays all active workflows that are enabled
1. Disabled: displays all active workflows that are disabled
1. Archived: displays all inactive workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow
Selecting the checkbox next to an individual login workflow enables the Actions functionality. Selecting the checkbox next to the LOGIN WORKFLOWS header selects all login workflows in that status.
Once a login workflow or multiple workflows are selected, perform an action by:
1. Selecting the ellipsis next to Actions header to display the available actions
1. Select the appropriate action to apply
- Archive: deactivates the selected login workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected login workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on the status.
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected login workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the download button and choose a location to save the file.
### Updating a Login Workflow
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. Select the **PORTAL LOGIN** tab.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow.
Select the **Edit** icon to edit the action selected.
Select the **Delete** icon to delete the action selected.
1. On the INFO tab, set **Disable failure email notifications** to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
1. Once the changes have been made, select **save**.
## Password Reset Workflows
A password reset workflow is used to provide existing users forgotten authentication credentials. Only one password reset workflow can be applied to a portal.
### Creating a Password Reset Workflow
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. Select the **PASSWORD RESET** tab.
1. Select the **+ Password Reset Workflow** button.
1. Specify the appropriate information in each field.
1. Name: enter the name for the login workflow.
1. UID: is system generated unique identifier, it cannot be changed after the password reset workflow is created. During creation, Administrators can accept the default or choose to specify this value.
1. Description: provide a brief description for this workflow.
1. Timeout: enter the number of minutes that a session should terminate after inactivity.
1. Select **Create**.
Note
The Password Reset workflow has a default action for [Reset Password](https://documentation.sailpoint.com/ne-admin/help/workflows/actions.html#reset-password) that cannot be modified or deleted.
### Enabling Password Reset Workflows
When a Password Reset workflow is enabled, it is available to an administrator to add to a portal.
Selecting the **Enable Workflow** button enables the workflow.
Selecting the **Disable Workflow** button disables the active workflow.
**ACTIONS Tab**
The ACTIONS tab is the default view on the Password Reset Workflow page. Here administrators can view and update the actions workflow.
**INFO tab**
The INFO tab provides a view of the settings for the Password Reset workflow entered on the New Password Reset page. Refer to [Creating a Password Reset Workflow](#creating-a-password-reset-workflow) for more information. Administrators can edit all fields except UID.
### Managing Password Reset Workflows
From the Admin Console:
1. Select **Collaboration** in the left navigation
1. Select **Portal Workflows**.
1. Select the **PASSWORD RESET** tab.
1. The tabs at the top of the workflow table are:
1. All: (default) displays all active workflows whether they are enabled or disabled
1. Enabled: displays all active workflows that are enabled
1. Disabled: displays all active workflows that are disabled
1. Archived: displays all inactive workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow. Selecting the checkbox next to an individual password reset workflow enables the Actions functionality.
Selecting the checkbox next to the PASSWORD RESET WORKFLOWS header, selects all password reset workflows in that status
Once a password reset workflow or multiple workflows are selected, perform an action by:
1. Selecting the ellipsis next to Actions header to display the available actions
1. Select the appropriate action to apply:
- Archive: deactivates the selected password reset workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected password reset workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on the status
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected password reset workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the download and choose a location to save the file.
### Updating a Password Reset Workflow
From the Admin Console:
1. Select **Collaboration** in the left navigation.
1. Select **Portal Workflows**.
1. Select the **PASSWORD RESET** tab.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow.
1. There are several actions available for administrators to update the workflow.
Select the **Edit** icon to edit the action selected.
Select the **Delete** icon to delete the action selected.
1. On the INFO tab, set **Disable failure email notifications** to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
1. Once the changes have been made, select **Save**.
# Creating and Managing Workflows in Lifecycle
Lifecycle workflows allow you to create and update profiles. Each workflow can have a series of actions added to it to meet your business needs. Review the types of workflows and how to manage them below.
You can also add conditions to your workflows, allowing you to choose sets of actions to run or skip based on the results an attribute comparison.
Collaboration workflows allow portal users to sign in and manage their non-employee profile and account. Refer to [Collaboration Workflows](https://documentation.sailpoint.com/ne-admin/help/workflows/col-workflow-types.html) for details.
## Create Workflows
A create workflow is used to facilitate the creation of profiles within the application.
### Creating a Create Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. By default, the **CREATE** tab is presented.
1. Select the **+ Create Workflows** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Name: enter the name for the create workflow.
1. UID: is system generated unique identifier, it cannot be changed after the create workflow is created. During creation, Administrators can accept the default or choose to specify this value.
1. Profile Type: from the dropdown select the profile type this workflow will create profiles for.
1. Description: provide a brief description for this workflow.
1. Position: if multiple create workflows are present, this value defines the order in which they should appear on the dashboard.
1. Bulk Import Usage: whether end users with access to this workflow should be allowed to use it to process a CSV file of new profiles. Workflows enabled for Bulk Import Usage can only be launched using the CSV Import process from the Profiles page.
Caution
Use caution when enabling bulk imports. Users can import up to 1,000 profiles at once and workflows are executed on each profile, which can lead to unintended consequences for some actions like Approval Form, Request Form, and Notification.
For example, if bulk imports are used in a workflow containing the Notification action, a notification will be generated for each profile in the CSV and the configured email addresses for this action could receive up to 1,000 emails.
1. Disable failure email notifications: Set to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
- PERMISSIONS
1. If limiting the user roles that can execute this workflow, choose whether to allow or block users with specific roles with the Role Access field.
A list of the roles allowed or blocked based on the selection in Role Access.
1. Select **Create**.
1. The administrator is presented with a create action that can be edited or deleted along with the following buttons and tabs:
Buttons:
- **+ Action**
- **+ Condition**
- **Enable Workflow**
Tabs:
- ACTIONS
- INFO
- ROUTING
- PERMISSIONS
### Enabling Create Workflows
When a workflow is enabled, a button for that workflow appears on the Lifecycle dashboard for users that have access to it.
- Selecting this button enables the workflow.
- Selecting this button disables the active workflow.
On the main workflow page, you can see four tabs:
**ACTIONS Tab** - The ACTIONS tab is the default view on the Create Workflow page. Here administrators can view and update the actions, conditions, and other settings for that workflow.
**INFO tab** - The INFO tab provides a view of the settings for the create workflow entered on the New Create Workflow page. Administrators can edit all fields except UID.
**ROUTING tab** - The ROUTING tab allows administrators to configure where the requester is redirected under certain conditions. The following options are available:
- **When the workflow finishes**
The **When the workflow finishes** option dictates where the requester is directed upon successful completion of a workflow.
- dashboard home: directs the requester to the dashboard home page
- request status page: directs the requester to the status page for this workflow session. Found in **Lifecycle tab > activity**
- Request profile page: directs the requester to the associated profile page
- **When the workflow is waiting on another action**
The **When the workflow is waiting on another action** option dictates where the requester is directed when the current workflow is waiting on an action.
- dashboard home: directs the requester to the dashboard home page.
- request status page: directs the requester to the status page for this workflow session. Found in **Lifecycle tab > activity**
- Request profile page: directs the requester to the associated profile page.
- **When the workflow fails**
The **When the workflow fails** option dictates where the requester is directed when the current workflow has an error.
- dashboard home: directs the requester to the dashboard home page
- request status page: directs the requester to the status page for this workflow session. Found in **Lifecycle tab > activity**
- Request profile page: directs the requester to the associated profile page
**PERMISSIONS Tab** - The PERMISSIONS tab allows administrators to view and update the permissions assigned to the workflow during creation.
### Managing Create Workflows
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. By default, the CREATE tab is presented.
1. The tabs at the top of the workflow table are:
- All: (default) displays all workflows whether they are enabled or disabled
- Enabled: displays all workflows that are enabled
- Disabled: displays all workflows that are disabled
- Archived: displays all archived workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow.
Selecting the checkbox next to an individual create workflow enables the Actions functionality. Selecting the checkbox next to the CREATE WORKFLOWS header, selects all create workflows in that status.
Once a create workflow or multiple workflows are selected, perform an action by:
1. Selecting the ellipsis next to Actions header to display the available actions.
1. Select the appropriate action to apply:
- Archive: deactivates the selected create workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected create workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on the status.
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected create workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the download and choose a location to save the file.
### Updating a Create Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. By default, the **CREATE** tab is presented.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow. Actions can also be dragged and dropped to change their order within the workflow.
1. Once the changes have been made, select **Save**.
- Select the edit icon to edit the action or condition selected.
- Select the Preview icon to preview the page or form for the action selected.
- Select the Delete icon to delete the action or condition selected.
Note
If you update a workflow, any executions of that workflow that are already in progress will be completed using the steps that were in place when the workflow was started. Any workflow executions initiated after the update use the new configuration.
## Update Workflows
An update workflow is used to facilitate updates to existing profiles.
### Creating an Update Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **UPDATE** tab.
1. Select the **+ Update Workflows** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Name: enter the name for the update workflow.
1. UID: is system generated unique identifier, it cannot be changed after the update workflow is created. During creation, Administrators can accept the default or choose to specify this value.
1. Profile type: from the dropdown select the profile type this workflow will create profiles for.
1. Profile status: from the drop-down select either active, inactive or all to determine the availability of a workflow for profiles in that status.
1. Description: provide a brief description for this workflow.
1. Position: if multiple update workflows are present, this value defines the order in which they should appear.
1. Bulk Import Usage: whether end users with access to this workflow should be allowed to use it to process a CSV file of updated profiles. Workflows enabled for Bulk Import Usage can only be launched via the CSV Import process from the Profiles page.
Caution
Use caution when enabling bulk imports. Users can import up to 1,000 profiles at once and workflows are executed on each profile, which can lead to unintended consequences for some actions like Approval Form, Request Form, and Notification.
For example, if bulk imports are used in a workflow containing the Notification action, a notification will be generated for each profile in the CSV and the configured email addresses for this action could receive up to 1,000 emails.
1. Disable failure email notifications: Set to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
- PERMISSIONS
1. If limiting the user roles that can execute this workflow, choose whether to allow or block users with specific roles with the Role Access field.
A list of the roles allowed or blocked based on the selection in Role Access.
1. Select **Create**.
1. The administrator is presented with an update action that can be edited or deleted along with the following buttons and tabs:
Buttons:
- **+ Action**
- **+ Condition**
- **Enable Workflow**
Tabs:
- ACTIONS
- INFO
- ROUTING
- PERMISSIONS
### Enabling Update Workflows
When a workflow is enabled, a button for that workflow appears on the dashboard pages for profiles in the workflow's profile type.
- Selecting this button enables the workflow.
- Selecting this button disables the active workflow.
**ACTIONS Tab** - The ACTIONS tab is the default view on the Update Workflow page. Here administrators can view and update the actions, conditions, and other settings for that workflow.
**INFO tab** - The INFO tab provides a view of the settings for the update workflow entered on the New Update Profile Workflow page. Administrators can edit all fields except UID.
**ROUTING tab** - The ROUTING tab allows administrators to configure where the requester is redirected under certain conditions. Select [Routing](#routing) to learn more.
**PERMISSIONS Tab** The PERMISSIONS tab allows administrators to view and update the permissions assigned to the workflow during creation.
### Managing Update Workflows
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **UPDATE** tab.
1. The tabs at the top of the workflow table are:
- All: (default) displays all workflows whether they are enabled or disabled
- Enabled: displays all workflows that are enabled
- Disabled: displays all workflows that are disabled
- Archived: displays all archived workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow.
Selecting the checkbox next to an individual update workflow enables the Actions functionality. Selecting the checkbox next to the UPDATE WORKFLOWS header, selects all update workflows in that status.
Once an update workflow or multiple workflows are selected, perform an action by:
1. Selecting the ellipsis next to Actions header to display the available actions.
1. Select the appropriate action to apply:
- Archive: deactivates the selected update workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected update workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on the status.
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected update workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the download button and choose a location to save the file.
### Updating an Update Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **UPDATE** tab.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow. Actions can also be dragged and dropped to change their order within the workflow.
1. Once the changes have been made, select **Save**.
- Select the edit icon to edit the action or condition selected
- Select the Preview icon to preview the page or form for the action selected
- Select the Delete icon to delete the action or condition selected
Note
If you update a workflow, any executions of that workflow that are already in progress will be completed using the steps that were in place when the workflow was started. Any workflow executions initiated after the update use the new configuration.
## Automated Workflows
An automated workflow is used to trigger actions based on data type attributes. Enabled automated workflows run once daily. The start time is dependent on the time zone in which the tenant is hosted and cannot be changed.
| | | |
| ------------------------ | -------------- | ---------------- |
| Tenant AWS Region | Code | Start Time (UTC) |
| Canada (Central) | ca-central-1 | 6:00 AM |
| US East (N. Virginia) | us-east-1 | |
| US West (Oregon) | us-west-2 | |
| Middle East (UAE) | me-central-1 | 7:00 PM |
| Asia Pacific (Tokyo) | ap-northeast-1 | 10:00 PM |
| Asia Pacific (Singapore) | ap-southeast-1 | |
| Asia Pacific (Sydney) | ap-southeast-2 | |
| Europe (Frankfurt) | eu-central-1 | |
| Europe (Ireland) | eu-west-1 | |
| Europe (London) | eu-west-2 | |
### Creating an Automated Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **AUTOMATED** tab.
1. Select the **+ Automated Workflows** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Name: enter the name for the automated workflow.
1. UID: is system generated unique identifier, it cannot be changed after the automated workflow is created. During creation, administrators can accept the default or choose to specify this value.
1. Description: provide a brief description for this workflow.
1. Disable failure email notifications: Set to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
- PROFILES
1. Filter the profiles this workflow will run against. A profile must meet all the configured profile conditions to be included in the workflow.
- Profile ID
- Profile attribute
- Profile risk level
- Profile status
- Profile type
1. Select **add filter** to add multiple profiles. The available settings for each PROFILES option will vary.
1. Select **Create**.
1. The administrator is presented with update action that can be edited or deleted along with the following buttons and tabs:
Buttons:
- **+ Action**
- **+ Condition**
- **Enable Workflow**
Tabs:
- ACTIONS
- INFO
- ROUTING
- PERMISSIONS
### Enabling Automated Workflows
Unlike other types of workflows, when an automated workflow is enabled, no button will be present in the application. The workflow will run automatically at a set time.
- Selecting this button enables the workflow.
- Selecting this button disables the active workflow.
**ACTIONS Tab** - The ACTIONS tab is the default view on the Automated Workflow page. Here administrators can view and update the actions, conditions, and other settings for that workflow.
**INFO tab** - The INFO tab provides a view of the settings for the Automated workflow entered on the New Automated Workflow page. Administrators can edit all fields except UID.
**ROUTING tab** - The ROUTING tab allows administrators to configure where the requester is redirected under the certain conditions. Select [Routing](#routing) to learn more.
**PERMISSIONS tab** - The PERMISSIONS tab allows administrators to view and update the permissions assigned to the workflow during creation.
### Managing Automated Workflows
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **AUTOMATED** tab.
1. The tabs at the top of the workflow table are:
- All: displays all workflows whether they are enabled or disabled
- Enabled: displays all workflows that are enabled
- Disabled: displays all workflows that are disabled
- Archived: displays all archived workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow.
Selecting the checkbox next to an individual automated workflow enables the Actions functionality. Selecting the checkbox next to the AUTOMATED WORKFLOWS header, selects all update workflows in that status.
Once an automated workflow or multiple workflows are selected, perform an action:
1. Select the ellipsis next to Actions header to display the available actions.
1. Select the appropriate action to apply:
- Archive: deactivates the selected automated workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected automated workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on the status.
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected automated workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the download button and choose a location to save the file.
### Updating an Automated Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **AUTOMATED** tab.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow. Actions can also be dragged and dropped to change their order within the workflow.
1. Once the changes have been made, select **Save**.
- Select the edit icon to edit the action or condition selected.
- Select the Preview icon to preview the page or form for the action selected.
- Select the Delete icon to delete the action or condition selected.
Note
If you update a workflow, any executions of that workflow that are already in progress will be completed using the steps that were in place when the workflow was started. Any workflow executions initiated after the update use the new configuration.
## Batch Workflows
A batch workflow is used to perform the same actions on many profiles in a single workflow, rather than multiple update workflows.
### Creating a Batch Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **BATCH** tab.
1. Select the **+ Batch Workflows** button.
1. Specify the appropriate information in each field.
- BASIC SETTINGS
1. Name: enter the name for the batch workflow.
1. UID: is system generated unique identifier, it cannot be changed after the batch workflow is created. During creation, Administrators can accept the default or choose to specify this value.
1. Make all profiles available: selecting Yes will make all profiles available, selecting No will only return profiles the user is a contributor or owner for.
1. Create a new request for each profile selected: selecting Yes will create a separate request for each profile selected, selecting No will create one request for all profiles.
1. Disable failure email notifications: Set to ON to disable email notifications about workflow failures for this workflow and any of its child workflows.
1. Description: provide a brief description for this workflow.
1. Position: if multiple create workflows are present, this value defines the order in which they should appear.
- SCOPE
1. Search and select an attribute to set the conditions to limit a user's search. This condition will be ‘locked’ in when a user runs the batch workflow and cannot be changed from the dashboard. Select [CONDITIONS](#conditions) for more information.
1. Select **Save**.
1. The administrator is presented with update action that can be edited or deleted along with the following buttons and tabs:
Buttons:
- **+ Action**
- **+ Condition**
- **Enable Workflow**
Tabs:
- ACTIONS
- INFO
- ROUTING
- PERMISSIONS
### Enabling Batch Workflows
When a workflow is enabled, a button for that workflow appears within the Lifecycle application.
- Selecting this button enables the workflow.
- Selecting this button disables the active workflow.
**ACTIONS Tab** - The ACTIONS tab is the default view on the Batches Workflow page. Here administrators can view and update the actions, conditions, and other settings for that workflow.
**INFO Tab** - The INFO tab provides a view of the settings for the Batches workflow entered on the New Batch Workflow page. Administrators can edit all fields except UID.
**ROUTING Tab** - The ROUTING tab allows administrators to configure where the requester is redirected under the certain conditions. Select [Routing](#routing) to learn more.
**PERMISSIONS Tab** - The PERMISSIONS tab allows administrators to view and update the permissions assigned to the workflow during creation.
### Managing Batch Workflows
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **BATCH** tab.
1. The tabs at the top of the workflow table are:
- All: (default) displays all workflows whether they are enabled or disabled
- Enabled: displays all workflows that are enabled
- Disabled: displays all workflows that are disabled
- Archived: displays all archived workflows
1. Select a workflow or workflows by placing a check in the box next to the workflow.
Selecting the checkbox next to an individual batch workflow enables the Actions functionality. Selecting the checkbox next to the BATCH WORKFLOWS header, selects all update workflows in that status.
Once a batch workflow or multiple workflows are selected, perform an action by:
1. Selecting the ellipsis next to Actions header to display the available actions.
1. Select the appropriate action to apply:
- Archive: deactivates the selected batch workflows. Once this option is chosen, the selected workflows are immediately archived. These will appear on the Archived tab.
- Unarchive: activates the selected batch workflows. Once this option is chosen, the selected workflows are immediately activated. These will appear on the All tab and either the Enabled or Disabled tab depending on their status.
- Enable: activates the selected workflows
- Disable: deactivates the selected workflows
- Export: exports the selected batch workflows into a .json file that can be saved locally. Once this option is selected, administrators are prompted to download. Select the Download button and choose a location to save the file.
### Updating a Batch Workflow
From the Admin Console:
1. Select **Lifecycle** in the left navigation.
1. Select **Workflows**.
1. Select the **BATCH** tab.
1. In the bottom table, select the workflow to view/edit.
1. There are several actions available for administrators to update the workflow. Actions can also be dragged and dropped to change their order within the workflow.
1. Once the changes have been made, select **Save**.
- Select the edit icon to edit the action or condition selected.
- Select the Preview icon to preview the page or form for the action selected.
- Select the Delete icon to delete the action or condition selected.
Note
If you update a workflow, any executions of that workflow that are already in progress will be completed using the steps that were in place when the workflow was started. Any workflow executions initiated after the update use the new configuration.
## Routing
The ROUTING tab allows administrators to configure where the requester is redirected under certain conditions. The following options are available:
**When the workflow finishes**
The **When the workflow finishes** option dictates where the requester is directed upon successful completion of a workflow.
- dashboard home: directs the requester to the dashboard home page.
- request status page: directs the requester to the status page for this workflow session. Found in **Lifecycle tab > activity**.
- Request profile page: directs the requester to the associated profile page.
**When the workflow is waiting on another action**
The **When the workflow is waiting on another action** option dictates where the requester is directed when the current workflow is waiting on an action.
- dashboard home: directs the requester to the dashboard home page.
- request status page: directs the requester to the status page for this workflow session. Found in **Lifecycle tab > activity**.
- Request profile page: directs the requester to the associated profile page.
**When the workflow fails**
The **When the workflow fails** option dictates where the requester is directed when the current workflow has an error.
- dashboard home: directs the requester to the dashboard home page.
- request status page: directs the requester to the status page for this workflow session. Found in **Lifecycle tab > activity**.
- Request profile page: directs the requester to the associated profile page.
## Conditions
Workflows can contain conditions to evaluate whether a set of actions should be completed or skipped based on the results an attribute comparison.
To add a new condition to your workflow:
1. Select the **+ Condition button**.
- BASIC SETTINGS
1. Name: enter the name of the condition
1. Select the **Create** button.
- CONDITION
1. Conditions: displays the applied conditions. Defaults to None
1. Attributes:
1. Search and select for the desired attribute.
1. Once the selection has been made, the Operator and Value fields appear.
1. Operator
- Select the desired operator.
- These values available will vary based on attribute selected.
1. Value
- Enter the filter criteria of the data to view.
1. Select the Add icon to add the condition.
1. Once the conditions are created, an action should be dragged into the condition. The workflow will evaluate the condition and determine if the action should be performed or skipped.
Conditions are identified by the icon on the Workflows page.
## Resending Notifications
Administrators can resend workflow notifications and registration invitations from the workflow activity log.
# Creating and Editing Profiles
A profile is any individual, organization, or other object managed within Non-Employee Risk Management, as well as the data about that object. This includes non-employees, the organizations they come from, or the assignments they work on, and additional data related to non-employees in your organization.
When your tenant is set up for the first time, your tenant has 4 [core profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) that already have attributes. If you create [custom profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-custom-profile-types), you must create custom attributes to use in each of those profile types.
Attributes are added to forms, where they can be added to [workflow pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html#workflow-pages) and [profile pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html#profile-pages) so that they can be used to create profiles.
There are several ways to create profiles within your environment:
- End users can create new profiles based on the [Create Workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#create-workflows) configured for the profile types they work with.
- Administrators can create an [individual profile](#creating-an-individual-profile) from the list of profiles.
- Administrators can also [upload a CSV file](#uploading-profiles-in-bulk) containing a list of new profiles.
There are also multiple ways to update a profile based on your permissions.
- End users can update profiles using the [Update Workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows) configured for a profile type they work with.
- Administrators can [update a profile](#editing-profiles) directly within the list of profiles.
## Creating Profiles
Administrators can create profiles individually and in bulk.
For more information on creating a workflow so that end users can create new profiles, refer to [Creating and Managing Workflows in Lifecycle](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html)
### Creating an Individual Profile
To create a profile:
1. Go to **Admin > Lifecycle > Profiles**.
1. Select the profile type you want to create a profile in.
1. Select the **+ ** button. The button's name is based on the name of the profile type.
The new profile page is displayed. The fields that appear vary based on the profile page created for profiles in this profile type. Refer to [Profile Pages](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html#profile-pages) for more information.
1. In the **Status** field, select the status of the new profile.
1. Select the **Edit** icon beside each field to enter a value for that field.
1. Select **Create**.
### Uploading Profiles in Bulk
You can upload a CSV file of profiles to your tenant to create profiles in bulk.
**Prerequisite:**
- You have a CSV file containing a list of profiles to add to your tenant.
- Go to **Admin > Lifecycle > Profiles**.
- Select the profile type you want to add profiles to.
- Select .
- Select the CSV file containing your profiles and select **Open**.
The **Import Profiles** dialog box is displayed. The dialog box displays the columns from the CSV file, each representing an attribute that can be included on the profile. There is a dropdown list over each column.
- If the first row of your CSV file contains profile data, instead of column headers, clear the **Use first row of .csv file as column headers** checkbox.
- Use the dropdown list over each column to select the profile attribute that corresponds to the values within the column from the CSV file.
In order to import profiles, you must assign an attribute to at least one column from the CSV file. You must assign all required attributes to a column for the import to be completed successfully.
If you do not select an attribute over a column, that column's values will not be added to the newly-created profiles.
Notes
- Importing a CSV file of profiles in the admin interface can only create profiles and can't update existing profiles. To update multiple profiles at once, use the [bulk upload](https://documentation.sailpoint.com/ne-user/help/profiles/index.html#updating-profiles-in-bulk) feature available to end users.
- Remove unwanted rows from your CSV file before uploading it. It is not possible to omit specific rows within the CSV file as it is imported.
- Select .
Profiles are created for each row in the CSV file. The attributes in the profile are populated by the values in the columns.
## Managing Profiles
You can view and edit the profiles in your system.
### Viewing Profiles
To view existing profiles and filter them based on specific attributes:
1. Go to **Admin > Lifecycle > Profiles**.
1. In the **Profile Type** dropdown, begin typing the name of a profile type. Select the profile type that contains the profiles you want to view.
The following tabs are displayed:
- **All** - Displays all profiles regardless of status.
- **Active** - Displays Active and On-Leave profiles.
- **Inactive** - Displays Inactive and Terminated profiles.
- **Archived** - Displays archived profiles.
You can use the search bar to find profiles by their configured [profile name](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#name-attributes).
In addition to plain text queries, the search bar supports PCRE2 regular expressions.
For example:
- `John D[a-z]* Smith` returns all profiles where the name contains John, any word beginning with D, and then Smith.
- `Contractor.+2025` returns all profiles where the name contains contractor, one or more of any other characters, and then 2025.
- `\(Administrator)\` returns all profiles containing the string, "(Administrator)". Note that the parentheses are escaped by backslashes.
- `(2023|2024) .* Washington` returns all profiles where the name contains 2023 or 2024, any number of additional characters, then Washington.
You can also [filter](#filtering-profiles) the profiles that are displayed.
### Filtering Profiles
You can filter which profiles are displayed in your list of profiles. You can also save those filters and share them with users that have specific roles in your organization.
**To filter the list of profiles:**
1. Go to the [list of profiles](#viewing-profiles) and select the type of profile you want to review.
1. Select the ellipsis icon beside the **Filter** header.
1. Choose whether you want to [create](#creating-a-profile-filter) a new filter or [apply](#applying-a-profile-filter) one that has been created already.
#### Creating a Profile Filter
1. From the filter screen, in the **FILTER BY** tab, choose the type of filter you want to create by selecting the **Type** dropdown list.
Complete the additional fields that are added based on your selection.
1. To add additional filter criteria, select **Add Criteria**.
Choose an operator between each set of criteria. The options are AND or OR.
1. Select **Apply**. Your filter is applied to the list of profiles.
1. To save your filter, select **Save as New Filter**.
Note
You must apply your filter before you can save it.
1. Enter a label for your new filter.
1. If you want to be able to apply your new filter to multiple profile types, type the name of the additional profile types you want to add in the **Profile Type** field and select them from the dropdown list.
1. Select **Save**.
Your profile filter is added to the list of profile filters.
You can also create a new filter by [editing](#editing-a-saved-profile-filter) an existing filter and selecting **Save as New Filter**.
#### Applying a Profile Filter
1. From the filter screen, select the **SAVED FILTERS** tab.
A list of filters that you own or that have been shared with you is displayed.
1. Select the name of the filter you want to use.
The list of profiles is updated to reflect your selected filter.
You can also [edit](#editing-a-saved-profile-filter) a saved filter.
#### Editing a Saved Profile Filter
You can make changes to a saved profile filter.
1. From the filter screen, select the **SAVED FILTERS** tab.
A list of filters that you own or that have been shared with you is displayed.
1. Select the filter you want to edit.
1. In the **Criteria** panel, make the necessary changes to your profile filter. You can edit the existing criteria, delete them, or add new criteria.
1. Select **Apply**.
1. To create a new filter with the criteria you applied, select **Save as New Filter**.
To overwrite the existing filter you edited, select **Update Saved Filter**.
#### Sharing Profile Filters
You can share a filter you own with other users by their roles.
1. From the filter screen, select the **SAVED FILTERS** tab.
A list of filters that you own or that have been shared with you is displayed.
1. Select the **Actions** icon and select **Share**.
1. In the **User Role** field, begin typing the name of a user role. Select the name of the role you want to add.
Repeat for each user role that needs access to this filter.
1. Select **Share**.
Users with any of the roles you selected in the Share Filter screen will be able to use the filter you shared with them. They will not be able to edit the filter or share it with others.
### Viewing Risk on Profiles
Profiles can be assigned risk using attributes to identify risks and help assess the threat they pose. Non-Employee Risk Management calculates the risk and displays a risk score and level on the profile table and profile detail page. Refer to [Configuring and Managing Risk](https://documentation.sailpoint.com/ne-admin/help/risk/index.html) for additional information.
### Editing Profiles
End users can update profiles using the [Update Workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/lc-workflow-types.html#update-workflows) configured for a profile type they work with.
Administrators can [update profiles in bulk](#updating-profiles-in-bulk) from the list of profiles, or select an [individual profile](#updating-an-individual-profile) to edit.
#### Updating Profiles in Bulk
You can make some updates to profiles in bulk.
1. Go to **Admin > Lifecycle > Profiles** and select a profile type.
1. Select the checkboxes next to the profiles you want to edit.
1. Select the ellipsis icon beside the Actions button.
1. Select the action you want to take on the selected profiles.
- **Archive** - Deactivates the selected profiles and moves them to the Archived tab.
- **Unarchive** - Immediately activates the selected profiles and moves them from the Archived tab to the Active tab.
- **Delete** - Permanently delete the selected profiles. If these profiles are needed again, they must be recreated. If they are linked to other profiles in your system, those links will be broken.
#### Updating an Individual Profile
1. Go to **Admin > Lifecycle > Profiles** and select a profile type.
1. Select the name of the profile you want to edit.
The **INFO** tab is displayed. It contains a list of attributes for this profile.
1. On the **INFO** tab, select the **status** dropdown to update the status of this profile.
1. Select the **Edit** icon to edit the value of a specific attribute.
The attributes on this page are based on how the [profile page](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html#profile-pages) is configured. End users might see these attributes depending on their [role](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html).
1. On the **CONTRIBUTORS** tab, add and remove contributors for this profile. Refer to [Assigning Contributors Directly to a Profile](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html#assigning-contributors-directly-to-a-profile) for more information.
The **HISTORY** tab contains a record of recent changes to the profile. The ALL ATTRIBUTES tab is only accessible to administrators, and it displays all attributes associated with the profile regardless of whether they are included on the profile page. The data on these tabs can't be edited.
# Configuring and Managing Risk
Risk is assigned to profiles using attributes to help identify risks and assess the threat they pose. A profile's risk is increased by adding attributes with risk, and decreased by adding attributes to mitigate the risk. Non-Employee Risk Management calculates the risk and is displayed as an [overall risk score](#viewing-overall-risk) and [risk level](#configuring-risk-scale-and-risk-levels) for the profile.
Note
By default risk is disabled for all profile types and must be [enabled](#enabling-risk-for-a-profile-type) for the overall risk score and risk levels to be displayed.
## Configuring Risk Scale and Risk Levels
The risk scale allows risk to be measured on a defined scale between 0 and 10. Risk levels allow you to define named levels of risk based on thresholds configured on the risk scale. Profiles display the risk level name for the risk level that its [overall risk score](#viewing-overall-risk) is within.
The number of risk levels and their threshold values can be configured based upon your organization's requirements. Threshold values are configured using the risk scale. The threshold where a risk level starts and ends is set between 0 and 10, with 0 being the least risk and 10 the greatest. Where one level ends, the next will begin.
By default, configured risk levels are named and ordered as Low, Medium and High. New risk levels are added to the end of the risk scale. Existing and new risk levels cannot be reordered. To change the order, rename existing levels and adjust the thresholds as needed.
**To add a risk level:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **RISK SCALE** tab.
1. In the **levels** section, enter a name in the **Level name** field.
1. Select to add the new level to the end of the risk scale.
1. In the **Global Risk Scale** section, select the slider icon .
1. Drag the slider to the left to decrease, or the right to increase the threshold values. Adjusting a threshold will adjust the threshold of adjoining risk levels.
1. Select **Save**.
**To rename a risk level:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **RISK SCALE** tab.
1. In the **levels** section, select the level you want to rename.
1. Rename the level.
1. Select **Save**.
**To delete a risk level:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **RISK SCALE** tab.
1. In the **levels** section, select next to the level you want to delete.
1. (Optional) To reconfigure remaining risk level thresholds:
- In the **Global Risk Scale** section, select the slider icon .
- Drag the slider to the left to decrease, or the right to increase the threshold values. Adjusting a threshold will adjust the threshold of adjoining risk levels.
1. Select **Save**.
## Adding Risk to Attributes
Once you have configured risk levels in your tenant, you can add risk to profiles by assigning risk scores to attributes.
Risk scores are a defined value that reflects the severity of a risk, and are used to [calculate an attribute's risk](#risk-score-calculation) and contribute to a profile's overall risk score.
A profile's overall risk score is displayed as a graph of impact and probability. Attributes that contribute to a profile's risk score must be assigned a risk type, which determines whether they contribute to a profile's risk impact, probability, or both.
Attributes with risk assigned to them are listed on the **Risk Scoring** page in the **Attributes With Risk** section. Risk can also be assigned when [creating and editing attributes](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html).
[Mitigation](#mitigating-risk) can be applied to an attribute to reduce its risk score. For example you may choose to mitigate risk for an attribute if the non-employee was a previous employee of your organization.
**To assign risk scores to an attribute:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **SCORING** tab.
1. In the **Add Risk to an Attribute** field, start entering the attribute name and select the required attribute.
Note
Only option based attribute [types](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html), such as drop-downs, check boxes, radio buttons, profile search, and profile select can be assigned risk scores.
1. Select the Risk type to assign to the attribute. The available options are dependent on the type of attribute.
- **Impact** - Defines the effect the risk will have.
- **Probability** - Defines the likelihood of the risk occurring.
- **Impact and Probability** - Defines the effect of the risk occurring and the likelihood.
- **Inherited** - Risk is inherited from the selected profile. Inherited risk is only available for profile search, and profile select attribute types.
- **None** - No risk is assigned to the attribute.
1. Enter a risk score between 1 and 10 for each option, with 1 the least risk and 10 the greatest risk. Non-integers are rounded to 2 decimal places.
1. Select **Save**.
The attribute with risk is displayed in the **Attributes With Risk** section. The overall risk score for profiles assigned the attribute are automatically recalculated.
**To edit risk scores for an attribute with risk:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **SCORING** tab.
1. In the **Attributes With Risk** section locate the attribute you wish to configure.
1. Select the Risk type to assign to the attribute. The available options are dependent on the type of attribute.
- **Impact** - Defines the effect the risk will have.
- **Probability** - Defines the likelihood of the risk occurring.
- **Impact and Probability** - Defines the effect of the risk occurring and the likelihood.
- **Inherited** - Risk is inherited from the selected profile. Inherited risk is only available for profile search, and profile select attribute types.
- **None** - No risk is assigned to the attribute.
1. Enter a risk score between 1 and 10 for each option, with 1 the least risk and 10 the greatest risk. Non-integers are rounded to 2 decimal places.
1. Select **Save**.
The overall risk score for profile's assigned the attribute are automatically recalculated.
### Mitigating Risk
Risk can be reduced for an attribute based upon the value of another attribute. For example you may choose to reduce risk if a non-employee that works remotely was a previous employee of your organization.
**To add mitigation to an attribute with risk:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **SCORING** tab.
1. In the **Add With Risk** section locate the attribute you wish to add mitigation to.
1. In the **Mitigating Attributes** field, start entering the attribute name and select the required attribute.
1. Select **Option** and choose the option that applies the mitigation.
1. Enter a mitigation score between 1 and 10 for each option, with 1 the least risk and 10 the greatest risk.
1. Repeat for all attributes you want to apply mitigation to.
1. Select **Save**.
The overall risk score for profile's assigned attributes containing mitigation are automatically recalculated.
### Configuring Subcategories
Subcategories provide an additional risk score for profiles to help identify additional risk. Any attributes with risk can be added to a subcategory. For example, you could create subcategories for departments that have different risk factors, and select different attributes for each.
Subcategories are displayed on a profile's [overall risk breakdown](#viewing-overall-risk), but do not affect the profiles overall risk score.
#### Creating a Subcategory
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **SUBCATEGORIES** tab.
1. Select **+ Subcategory**.
1. In the **New Risk Subcategory** screen, enter a name in the **Label** field.
1. Select **Create**.
1. In the Subcategory Risk section, select the risk attributes to include in the subcategory.
The subcatgory is displayed on the [overall risk breakdown](#viewing-overall-risk) of profile's assigned the selected subcategory risk attributes.
#### Updating a Subcategory
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **SUBCATEGORIES** tab.
1. Select the name of the subcategory you wish to edit.
The DETAILS screen is displayed. It contains the name, and list of available risk attributes for this subcategory.
1. In the **Label** field, update the name.
1. In the Subcategory Risk section, select the risk attributes to include in the subcategory.
1. Select **Save**.
#### Deleting a Subcategory
You can delete subcategories individually or bulk.
1. Go to **Admin > Lifecycle > Risk**.
1. Select **SUBCATEGORIES** tab.
1. Select the checkbox beside the subcategories you want to delete.
1. To select all subcategories, select the checkbox next to the RISK CATEGORIES header.
1. Select the ellipsis icon next to the Actions header and select **Remove**.
### Enabling Risk for a Profile Type
Once you have configured your risk levels and added risk and mitigation to attributes, you can enable risk for a profile type.
**To enable risk for a profile type:**
1. Go to **Admin > Lifecycle > Risk**.
1. Select the **SETTINGS** tab.
1. Set **RISK** to **ON**.
The [overall risk score](#how-the-overall-risk-score-is-calculated) is calculated and displayed on profile's within the enabled profile type.
Tip
Enabling risk for a profile type automatically adds the `risk_score` attribute in a hidden state to its related table. Unhide the attribute to display the overall risk score in the table.
## How the Overall Risk Score is Calculated
The overall risk score for a profile is calculated from the risk scoring and mitigation assigned to each attribute, or risk inherited from other profiles.
Note
[Subcategories](#configuring-subcategories) are displayed on a profile's overall risk breakdown, but do not affect the profile's overall risk score.
The overall risk score for a profile is calculated as follows:
| Risk Element | Calculation |
| ------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Overall Risk Score | The average of the `avg impact score` and `avg probability score`. **NOTE**: If risk is inherited from another profile, and the inherited profile has a greater overall risk score, the overall risk score for the profile will be set to the overall risk score of the inherited profile. For example, if a profile has an overall risk score of 4.0, and its inherited profile has an overall risk score of 7.0, the profile will display an overall risk score of 7.0. |
| Average Impact Score `avg impact score` | Each impact attributes `risk score` less `mitigated by score` to create the impact attributes `residual risk score`. The impact attributes `residual risk scores` are then averaged to calculate an `avg impact score`. |
| Average Probability Score `avg probability score` | Each probability attributes `risk score` less `mitigated by score` to create the probability attributes `residual risk score`. The probability attributes `residual risk scores` are then averaged to calculate an `avg probability score`. |
## Viewing Overall Risk
Selecting the overall risk score on the profile table or profile detail page displays the profile's risk breakdown. Details of each element that is assigned are displayed.
- **Overall Risk** - The overall risk score and [risk level](#configuring-risk-scale-and-risk-levels) assigned to the profile. For further information on how the overall risk score is calculated refer to [Calculating the Overall Risk Score](#how-the-overall-risk-score-is-calculated).
- **Impact** or **Probability** - Attributes with the *impact* or *probability* risk types that are assigned to the profile.
- **Attribute** - The attribute assigned to the profile.
- **value** - The chosen option for the attribute.
- **risk** - The risk score assigned to the chosen option.
- **mitigated by** - The name of the [mitigation attribute](#mitigation-attribute), its chosen option, and the assigned mitigated risk score. If there is no mitigation assigned this will be blank.
- **residual risk** - The attribute's risk score after mitigation is applied.
- **avg impact/probability** - The averaged value of all impact or probability attribute's residual risk scores.
Notes
- If the profile [inherits risk](#inherited-risk) from another profile, the overall risk score is overridden by the inherited profile. An asterisk is displayed on the overall risk score, and details of the inherited profile are displayed at the top of the breakdown chart.
- If the profile includes a [subcategory](#configuring-subcategories), details of the subcategory are displayed at the bottom of the breakdown chart.
# Tables
Tables define the columns presented to the user for each profile type they can access, as well as the columns on the **Needs Action** and **Requests** pages.
Profile tables are automatically created when a profile type is created.
The columns displayed in tables can be updated to display only the most important information to users. Users' ability to view the attributes in these columns is determined by their assigned roles.
To update an existing table, from the Admin Console:
1. In the left navigation, go to **Templates > Tables**.
A list of tables is displayed.
The **Actions** table controls what users see on the Needs Action page. The **Requests** table controls what users see on the Requests page. All other tables correspond to individual profile types.
1. Select the table you want to edit.
1. Choose which attributes should be displayed in the table and how they are displayed.
- Select the **Hide** icon to hide the attribute from the table.
- Select the **Unhide** icon to display a previously-hidden attribute within the table.
- Select the **Delete** icon to delete the attribute from the table. Some attributes are required and can't be deleted, but they can be hidden using the **Hide** icon.
- Add additional attributes by searching in the **Add attributes** field and selecting the attribute you want to add.
- Rearrange the order of the columns by dragging the attributes up or down in the list.
1. Select **Save**.
To see a preview of the table layout as it will be displayed to users, select **Preview Table**.
Note
To show an attribute as a column in a table, the user must have the View or Edit [attribute permission](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#attribute-permissions).
# Connecting Non-Employee Risk Management and SailPoint Human Fabric
You can connect Non-Employee Risk Management and SailPoint Human Fabric to enable you to track your non-employee data and activity more easily.
- Create a [Non-Employee Risk Management Users](https://documentation.sailpoint.com/ne-admin/help/connector/users_connector.html) source to aggregate users from your non-employee system into SailPoint Human Fabric, where their access can be governed.
- Create a [Non-Employee Risk Management](https://documentation.sailpoint.com/ne-admin/help/connector/profile_connector.html) source to manage profiles as identities and correlate them with their other accounts in your system.
- Connect to the [Access Intelligence Center](https://documentation.sailpoint.com/ne-admin/help/connector/aic_connection.html) to discover key insights into your Non-Employee Risk Management administration program.
# Connecting to the Access Intelligence Center
You can synchronize data to the [Access Intelligence Center](https://documentation.sailpoint.com/saas/help/ai/access_insights/access_intelligence.html) in SailPoint Human Fabric to discover key insights into your Non-Employee Risk Management administration program.
## Synchronizing Data to the Access Intelligence Center
To start discovering key insights into your non-employee profile and assignment data, you'll configure one or more person or assignment profile types to synchronize profile data to the Access Intelligence Center.
1. Within Non-Employee Risk Management, go to **Admin > System > Identity Security Cloud Connection Settings**.
1. Select the **NON-EMPLOYEE** or **ASSIGNMENT** tab.
1. In the **Profile Type** dropdown list, select the profile type you want to synchronize to the Access Intelligence Center.
1. In the **Core Attributes** section, review the core account attributes and their corresponding SailPoint Human Fabric attributes.
If you have already configured a [profile connector](https://documentation.sailpoint.com/ne-admin/help/connector/profile_connector.html) and selected **Enable source syncing with Identity Security Cloud**, these mappings are used for the Access Intelligence Center.
If you have not configured a profile connector, choose the account attributes that should be included in Access Intelligence Center reports and map them to SailPoint Human Fabric attributes.
Note
Extended Attributes are not synchronized to the Access Intelligence Center.
1. Select **Save**.
1. When you're finished making configurations to your profile type and mapping attributes, set **Enable syncing with Access Intelligence Center** to **ON**.
1. Select **Save**. Synchronized data will be available in the Access Intelligence Center within 24 hours.
1. Repeat these steps for each profile type you want to synchronize to the Access Intelligence Center.
Important
The quality of reporting available in the Access Intelligence Center is dependent on the extent to which attributes have been mapped. If only partial mapping has been completed, reporting results in the Access Intelligence Center might not be as expected.
Using the mapped attributes the [Access Intelligence Center](https://documentation.sailpoint.com/saas/help/ai/access_insights/access_intelligence.html) provides rich reporting capabilities of your Non-Employee Risk Management data using tables, charts, and graphs. Default reports and visualizations can be customized to report on the metrics that are most important to you.
# Managing Non-Employee Profiles in SailPoint Human Fabric
You can create a source within SailPoint Human Fabric to manage your non-employee and assignment profiles. This allows you to use Non-Employee Risk Management as an authoritative source of your non-employee identity data. You can then correlate their accounts and access from other sources to those identities.
Notes
- The profile management source within SailPoint Human Fabric aggregates and manages [profiles](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html), rather than user accounts. To aggregate user accounts from Non-Employee Risk Management, create a [user management source](https://documentation.sailpoint.com/ne-admin/help/connector/users_connector.html).
- The profile management connector can be used to create an [authoritative source](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html) using person profiles. Do not make sources that contain non-person profiles authoritative. Sources that contain non-person profiles can be used to provide supplemental attributes to identity profiles, but should not be used to create authoritative sources.
- Archived profiles will not be aggregated.
- If you have enabled syncing with the Access Intelligence Center, only the attributes you map within the Core Attributes tab will be synchronized.
You can create a profile management source in SailPoint Human Fabric in two different ways:
- [Automatically](#automatically-creating-a-source-from-profile-types), by configuring one or more profile types in your Non-Employee tenant to be synchronized with SailPoint Human Fabric. When a source is created this way, all profiles are aggregated to a single source and the account schema is created automatically.
- [Manually](#creating-a-source-starting-in-sailpoint-human-fabric), by creating a source within SailPoint Human Fabric and connecting it to your Non-Employee tenant. When sources are created this way, each profile type can be aggregated to a separate source, and you can create the account schemas manually.
### Automatically Creating a Source From Profile Types
To start managing your non-employee data in SailPoint Human Fabric, you'll configure one or more person profile types to send profile data to your source. This includes the [core profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) Non-Employees, as well as any custom [profile types](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-custom-profile-types) with the categories Employees or Non-Employees.
By default, all SailPoint Human Fabric tenants that have an associated Non-Employee Risk Management tenant have a non-employee source created already, marked as Configuration Incomplete. This source will be configured and connected when you enable synchronization with any profile type. If you deleted this source, it will also be automatically recreated when you enable synchronization with SailPoint Human Fabric.
Profiles from all profile types aggregated using this method are associated with a single source.
Once you've aggregated your non-employee profiles and created identities for them, you can make [additional configurations](#additionalconfig) and aggregate assignments. Non-employee sources created using this method support [attribute synchronization](#configuring-attribute-synchronization).
**To begin aggregating person profiles to SailPoint Human Fabric:**
1. Within Non-Employee Risk Management, go to **Admin > System > Identity Security Cloud Connection Settings**.
1. In the NON-EMPLOYEE tab, in the **Profile Type** dropdown list, select the non-employee profile type you want to manage in SailPoint Human Fabric.
Both [core](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-default-profile-types) and [custom](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html#managing-custom-profile-types) profile types are displayed in this list.
Any configurations in the SailPoint Human Fabric Connection Settings page within Non-Employee Risk Management do not apply to sources created manually.
1. In the **Core Attributes** section, choose the account attributes that should be aggregated into SailPoint Human Fabric.
The account attributes in the left column correspond to source attributes within SailPoint Human Fabric. For each account attribute you want to aggregate, select a Non-Employee Risk Management Attribute.
Important
- In addition to the attributes you configure here, SailPoint Human Fabric will aggregate the `Non-Employee Profile ID` attribute, which is a technical attribute used as a unique identifier for profiles. It will be mapped to the `Employee Number` identity attribute within the identity profile. This attribute will be used to create new identities within SailPoint Human Fabric from non-employee profiles. Refer to [Managing Profile Correlation](#managing-profile-correlation) for more details.
- The following attributes must be mapped in the Core Attributes section:
- First Name
- Last Name
- Business Email
1. If you plan to aggregate [assignment profiles](#adding-assignment-data-to-a-source), map an attribute to the **Assignments** core attribute. This attribute must be a `profile search` or `profile select` [attribute](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#linking-profiles) that contains an assignment profile. This attribute links your person profile type to the appropriate assignment profile type so that assignments can be correlated to the correct identity when they are aggregated.
An assignment profile can be correlated to one person profile, but a person profile can have multiple assignments correlated to it.
1. (Optional) To add additional attributes, in the **Extended Attributes** section, select **Add Extended Attribute**.
1. In the **Extended Attribute** column, enter the name of an attribute you would like to add to the account schema within SailPoint Human Fabric.
1. In the **Non-Employee Risk Management Attribute** column, select an attribute to map to the attribute you selected in the Extended Attribute column.
1. Select **Save**.
1. When you're finished making configurations to your profile type and mapping attributes, set **Enable source syncing with Identity Security Cloud** to **ON**.
1. Select **Save**.
If you deleted your default existing Non-Employee source in SailPoint Human Fabric, a new source is created. The attributes you mapped in the Core Attributes and Extended Attributes sections are added to the schema for your non-employee source. You can edit the name and description of this source as necessary.
An [identity profile](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html) is also created automatically with the name of the source.
1. Repeat these steps for each person profile type you want to aggregate into SailPoint Human Fabric. All profiles are aggregated to the same source, and identities are created for each unique profile based on their `Non-Employee Profile ID` attribute.
This source will be automatically synced with SailPoint Human Fabric, and profiles that are created or updated will be added to this source automatically. You can also [schedule regular aggregations](https://documentation.sailpoint.com/saas/help/accounts/loading_data.html#scheduling-aggregations-for-direct-connect-sources) of profiles to ensure that profiles are created, updated, and deleted from your source.
You can configure your source within SailPoint Human Fabric to filter which profiles are aggregated. In the source's **Source Setup** section, select the Configuration page. In the **Filter by Status** field, select **All** to aggregate all profiles regardless of status, or select **Active** to only aggregate profiles in the Active and On Leave statuses.
### Managing Profile Correlation
*Correlation* refers to the process of either creating an identity from a profile, or matching a profile to an existing identity.
By default, identities are correlated based on the non-employee profile's `Non-Employee Profile ID` attribute within Non-Employee Risk Management, which is mapped to the `Employee Number` identity attribute within SailPoint Human Fabric.
Important
If you aggregate the Employee Number identity attribute from another source, and you want to configure [attribute sync](#configuring-attribute-synchronization) for the Employee Number attribute, you must complete some additional configurations. Refer to [Configuring the Employee Number Attribute](#configuring-the-employee-number-attribute)
**To choose a different identity attribute for correlation:**
1. In SailPoint Human Fabric, in your non-employee source, select a new identity attribute to use for [correlation](https://documentation.sailpoint.com/saas/help/accounts/correlation.html#configuring-account-correlation).
Your identities will be uncorrelated while you configure the mappings in your identity profile.
1. On the [identity profile](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html#mapping-identity-attribute-values) associated with your non-employee source, locate the **Employee Number** identity attribute and remove the `Non-Employee Profile ID` account attribute.
1. Add the `Non-Employee Profile ID` account attribute to the **Attribute** field on the identity attribute you chose to use for correlation.
1. Save and apply your changes. Your identities are correlated again using the identity attribute you selected as their unique identifier.
**Choose a new set of attributes to use for correlation**
You can also use a different combination of identity and account attributes for correlation.
Caution
Because this process assigns identities a new unique identifier, duplicate identities will be created during this process and must be deleted.
1. In SailPoint Human Fabric, in your non-employee source, choose the identity attributes and account attributes you want to use for [correlation](https://documentation.sailpoint.com/saas/help/accounts/correlation.html#configuring-account-correlation).
Your identities will be uncorrelated.
1. On the [identity profile](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html#mapping-identity-attribute-values) associated with your non-employee source, map the attributes you selected in your correlation configuration.
1. Save and apply your changes.
1. In your non-employee source, [delete](https://documentation.sailpoint.com/saas/help/accounts/index.html#removing-accounts) all accounts on the source.
1. Run an aggregation to load in your non-employee profiles again using your new correlation configuration.
#### Configuring the Employee Number Attribute
By default, the `Employee Number` identity attribute is mapped to the `Non-Employee Profile ID` attribute. It is not possible to provision values to `Non-Employee Profile ID`.
You must take additional actions if you want to do all of the following:
- Continue to use the Employee Number identity attribute for correlation.
- Aggregate the value of the Employee Number attribute from a third-party source rather than Non-Employee Risk Management.
- Configure attribute synchronization from the Employee Number attribute to Non-Employee Risk Management.
If you want to use the Employee Number identity attribute for these purposes, but do not configure the Correlation Attribute within Non-Employee Risk Management as described below, SailPoint Human Fabric might be unable to correlate your aggregated profiles. This can result in duplicate or incomplete identities being created.
**To use the Employee Number attribute from another source:**
1. Within Non-Employee Risk Management, create an attribute with the type `text field` for the non-employee profile type you want to aggregate. This attribute will be mapped to the `Employee Number` identity attribute.
1. Go to **Admin > System > Identity Security Cloud Connection Settings**. In the Core Attributes tab, add the attribute you just created in the Non-Employee Risk Management Attribute column beside the **Correlation Attribute**.
1. Within SailPoint Human Fabric, go to **Admin > Identity Management > Identity Profiles** and select the identity profile corresponding to your profile management source.
1. Select **Mappings**.
1. Under the **Employee Number** attribute, select the source you want to populate that attribute, and select the appropriate account attribute from that source.
The Employee Number attribute will be populated with the value from that source.
1. Go to **Connections > Sources** and select your Non-Employee Risk Management profile management source.
1. Select **Account Management > Account Correlation**.
1. Under [Correlation Configuration](https://documentation.sailpoint.com/saas/help/accounts/correlation.html), in the Identity Attribute field, select **Employee Number**.
1. In the Account Attribute field, select **Correlation Attribute**.
1. Select **Save**.
Profiles aggregated from Non-Employee Risk Management will be correlated to identities when the value of their Correlation Attribute matches the value of the Employee Number identity attribute, which comes from a third-party source.
1. Go to **Account Management > [Create Account](https://documentation.sailpoint.com/saas/help/provisioning/create_profile.html)**.
1. [Add](https://documentation.sailpoint.com/saas/help/provisioning/create_profile.html#adding-existing-attributes) the Correlation Attribute to this list.
1. Select the **Identity Attribute** mapping type and select **Employee Number** in the **Attribute** dropdown.
1. Select **Save**.
When provisioning takes place, the Correlation Attribute within Non-Employee Risk Management will be updated with the value of the identity attribute Employee Number.
1. Go to **Account Management > [Attribute Sync](https://documentation.sailpoint.com/saas/help/provisioning/attr_sync.html)**.
1. Select **Sync with Identity** beside the Employee Number attribute.
When SailPoint Human Fabric detects that the Correlation Attribute on a non-employee profile is out of sync with the Employee Number attribute on the corresponding identity, it will provision that value to the appropriate profile to ensure that profile remains correlated to the identity.
### Creating a Source Starting in SailPoint Human Fabric
You can also start creating your profile source within SailPoint Human Fabric. The account schema must be created before accounts can be aggregated when a source is created this way.
Any configurations in the SailPoint Human Fabric Connection Settings page within Non-Employee Risk Management do not apply to sources created manually. Non-employee sources created starting within SailPoint Human Fabric cannot be configured for attribute synchronization.
**Prerequisites:**
- Create and copy an [API key](https://documentation.sailpoint.com/ne-admin/help/setup/api.html#generating-a-new-api-key) from Non-Employee Risk Management to use within SailPoint Human Fabric.
Best Practice
Use a separate API key for each Non-Employee Risk Management source you create.
- Copy the technical ID of the profile type you want to manage within SailPoint Human Fabric. This can be found in the URL of the profile type or using [the API](https://developer.sailpoint.com/docs/api/nerm/v1/get-profile-types/), and is not the same as the UID of the profile type.
- Copy the UIDs of each [attribute](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html#creating-custom-attributes) you want to aggregate.
To create a profile management source within SailPoint Human Fabric:
1. Sign in to SailPoint Human Fabric and go to **Admin > Connections > Sources**.
1. Select **Create New**.
1. Under **Select a source type**, select **Configure** beside **SailPoint Non-Employee Risk Management**.
1. Enter the following:
- **Source Name** - Enter a name for the new source.
- **Description** - Enter a description for the new source to help distinguish it from similar sources.
- **Source Owner** - Begin typing the name of an owner. Matches appear after you type two or more letters.
- **Governance Group (Optional)** - Select a governance group for source management.
1. Select **Continue**.
The Base Configuration screen is displayed.
1. Select **Configuration** in the left panel.
1. In the **API Key** field, enter the API key you saved within Non-Employee Risk Management for this source.
1. In the **Non-Employee Risk Management Tenant Domain** field, enter the URL for your tenant.
1. In the **Profile Type Id** field, enter the ID of the profile type you want to manage within SailPoint Human Fabric that you saved within Non-Employee Risk Management.
1. In the **Filter by Status** field, select **All** to aggregate all profiles regardless of status, or select **Active** to only aggregate profiles in the Active and On Leave statuses.
1. Select **Save**.
1. Select **Review and Test**.
1. Review the configuration details and select **Test Connection**. A successful test is required for SailPoint Human Fabric to gather data for this source.
#### Manually Configuring an Account Schema
After creating a profile management source and connecting it, map the attributes that SailPoint Human Fabric will aggregate.
1. From the list of sources, select the source you want to edit.
1. In the **Account Management** section, select **Account Schema**.
Several attributes are available by default. These are the system-level attributes available for every profile within Non-Employee Risk Management.
The `name` and `id` attributes will be used as the Account Name and ID.
Note
Do not edit the attributes used for `name` or `id` after you have aggregated profiles into SailPoint Human Fabric. This can cause duplicate identities to be created.
1. Select **+ Add New Attribute**.
1. Enter the following information:
- **Name** - Enter the UID of the attribute you want to add exactly as it appears within your Non-Employee Risk Management tenant.
- **Description** - Add a description for the attribute.
Notes
- The attribute type must be set to **String**. When attributes of other types are aggregated, their value will be converted to a string.
- Aggregating entitlements is not supported. Do not select the **Entitlement** checkbox under **Type**.
1. Select **Save**.
The attribute is added to the list of attributes within the account schema.
When profiles are aggregated into SailPoint Human Fabric, the Non-Employee Risk Management attributes matching the attribute names you provided will be aggregated for all profiles in the configured profile type.
You can [schedule regular aggregations](https://documentation.sailpoint.com/saas/help/accounts/loading_data.html#scheduling-aggregations-for-direct-connect-sources) of profiles into SailPoint Human Fabric so that your data is kept up-to-date.
If you are aggregating person profiles, create an [identity profile](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html) to use the profile data from Non-Employee Risk Management as an authoritative source of identities. You can [configure correlation](https://documentation.sailpoint.com/saas/help/accounts/correlation.html#configuring-account-correlation) to ensure that person and assignment profiles are matched to the right identities.
### Adding Assignment Data to a Source
Once a profile management source has been created that contains person profiles, you can aggregate assignments into the same source.
Within SailPoint Human Fabric, these assignments are treated as additional accounts on the source, and are correlated to an identity based on the identity's `assignment` attribute configured above.
1. Within Non-Employee Risk Management, go to **Admin > System > Identity Security Cloud Connection Settings**.
1. Select the **ASSIGNMENT** tab.
1. In the Profile Type dropdown list, select the assignment profile type you want to manage in SailPoint Human Fabric.
1. In the **Core Attributes** section, choose the account attributes that should be aggregated into SailPoint Human Fabric.
For each account attribute, select a Non-Employee Risk Management Attribute.
1. (Optional) In the **Extended Attributes** section, select **Add Extended Attribute**.
1. In the **Extended Attribute** column, enter the name of an attribute you would like to add to the account schema within SailPoint Human Fabric.
1. In the **Non-Employee Risk Management Attribute** column, select an attribute to map to the attribute you selected in the Extended Attribute column.
1. Select **Save**.
1. When you're finished making configurations to your profile type and mapping attributes, set **Enable source syncing with Identity Security Cloud** to **ON**.
1. Select **Save**.
An aggregation begins in SailPoint Human Fabric that loads your assignment data into your Non-Employee source.
The data in this profile type will be aggregated every time your non-employee source within SailPoint Human Fabric performs an aggregation. The assignments it aggregates will be correlated to person profiles, or identities.
If the assignments you aggregate don't correlate to identities, you can navigate to the [identity profile](https://documentation.sailpoint.com/saas/help/setup/identity_profiles.html) associated with your non-employee source and select **Apply Changes**. In some cases, this will resolve correctly-configured assignments and correlate them to the appropriate identities.
1. Repeat these steps for each assignment profile type you want to aggregate into SailPoint Human Fabric.
### Configuring Attribute Synchronization
[Attribute synchronization](https://documentation.sailpoint.com/saas/help/provisioning/attr_sync.html) allows you to keep the data within Non-Employee Risk Management consistent with the data in SailPoint Human Fabric by populating identity attribute values to the corresponding profile attributes.
Attribute sync is supported for non-employee sources configured within Non-Employee Risk Management using a [profile type](#automatically-creating-a-source-from-profile-types).
In most cases, this is configured entirely within SailPoint Human Fabric. In some cases, you might need to make additional configurations related to the Employee Number attribute. Refer to [Configuring the Employee Number Attribute](#configuring-the-employee-number-attribute) for details.
# Managing User Accounts in SailPoint Human Fabric
You can create a source within SailPoint Human Fabric to manage users who have an account within Non-Employee Risk Management. This connector can also be used to manage their Non-Employee Risk Management [roles](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) by aggregating them as entitlements.
Notes
- This source aggregates and manages [lifecycle users](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html), rather than profiles or portal users. Non-employee and assignment profiles, as well as portal users, can be managed with a [profile management source](https://documentation.sailpoint.com/ne-admin/help/connector/profile_connector.html).
**Prerequisites:**
- Create and copy an [API key](https://documentation.sailpoint.com/ne-admin/help/setup/api.html#generating-a-new-api-key) from Non-Employee Risk Management to use within SailPoint Human Fabric.
Best Practice
Use a separate API key for each Non-Employee Risk Management source you create.
**To create a user-management source in SailPoint Human Fabric:**
1. Within SailPoint Human Fabric, go to **Admin > Connections > Sources**
1. Select **Create New**.
1. Find the SailPoint Non-Employee Risk Management Users source type and select **Configure**.
1. Enter a source name.
1. Enter a description for your source.
1. In the **Source Owner** field, begin typing the name of an owner. Matches appear after you type two letters.
1. (Optional) Select a [governance group](https://documentation.sailpoint.com/saas/help/common/users/governance_groups.html) for source management.
Important
Marking this source as authoritative is not recommended.
1. Select **Continue**.
1. Select **Configuration** in the left panel.
1. In the **API Key** field, enter the API key you saved within Non-Employee Risk Management for this source.
1. In the **Non-Employee Risk Management Tenant Domain** field, enter the URL for your tenant.
1. Select **Save**.
1. Select **Review and Test**.
1. Review the configuration details and select **Test Connection**. A successful test is required for SailPoint Human Fabric to gather data for this source.
After your source has been connected, you can make any additional configurations you need:
- Configure [correlation](https://documentation.sailpoint.com/saas/help/accounts/correlation.html) to ensure that user accounts will be associated with the correct identities.
- You can schedule regular aggregations for [accounts](https://documentation.sailpoint.com/saas/help/accounts/loading_data.html#scheduling-aggregations-for-direct-connect-sources) in this source.
- If you use SailPoint Human Fabric entitlements to grant roles to your users, you should also schedule regular [entitlement aggregations](https://documentation.sailpoint.com/saas/help/loading_entitlements/aggregating_entitlements.html).
- Configure a [Create Account](https://documentation.sailpoint.com/saas/help/provisioning/create_profile.html) policy to configure how accounts and attributes should be provisioned to Non-Employee Risk Management.
- You can also configure [attribute sync](https://documentation.sailpoint.com/saas/help/provisioning/attr_sync.html) to keep Non-Employee Risk Management data synchronized with the authoritative identity attributes from SailPoint Human Fabric.
Note
Custom account schemas are not supported on the Non-Employee Risk Management Users source.
## Synchronizing with SailPoint Human Fabric
Synchronize changes made to users and user roles in Non-Employee Risk Management with their corresponding identities in SailPoint Human Fabric. The synchronization of users and user roles occurs immediately, without requiring a manual aggregation.
Note
To support this feature, you need to provide the SailPoint Human Fabric [source's ID](#updating-the-user-source-id). By default, Non-Employee Risk Management attempts to detect the source ID when you enable this feature. If the source ID can't be detected, Non-Employee Risk Management can help you determine one.
**To enable synchronization with SailPoint Human Fabric:**
1. Go to **Admin > System > Identity Security Cloud Connection Settings** and select the **USERS** tab.
1. Enable the **Sync with Identity Security Cloud** toggle. Non-Employee Risk Management attempts to determine the SailPoint Human Fabric source's ID.
If Non-Employee Risk Management can't detect the SailPoint Human Fabric source's ID, it will display a message. You can [update the source ID](#updating-the-user-source-id) as needed to complete the configuration.
1. Select **Save**.
### Updating the User Source ID
If Non-Employee Risk Management can't determine the SailPoint Human Fabric source's ID, it can create a new one or you can manually enter one. The solution varies depending on the reason why a source ID wasn't found:
- The source doesn't exist.
- The source ID was updated outside of Non-Employee Risk Management.
#### Creating a New Source with Non-Employee Risk Management
Non-Employee Risk Management can create a new source in SailPoint Human Fabric and determine its source ID.
**To allow Non-Employee Risk Management to create a new source:**
1. Go to **Admin > System > Identity Security Cloud Connection Settings** and select the **USERS** tab.
Non-Employee Risk Management displays a message stating that a SailPoint Human Fabric source was not detected.
1. Select **Automatically Create New Source**.
Non-Employee Risk Management creates the new source in SailPoint Human Fabric and updates the **Source ID** entry.
1. Select **Save**.
#### Detecting a New Source ID with Non-Employee Risk Management
If the source ID was updated outside of Non-Employee Risk Management, it can detect the updated source ID and perform the update.
**To allow Non-Employee Risk Management to automatically detect the new source ID:**
1. Go to **Admin > System > Identity Security Cloud Connection Settings** and select the **USERS** tab.
Non-Employee Risk Management displays a message warning of a source ID mismatch.
1. Select **Update Source ID**.
Non-Employee Risk Management determines the new source ID and updates the Source ID entry.
1. Select **Save**.
#### Manually Updating the Source ID
**To manually update the source ID:**
1. Go to **Admin > System > Identity Security Cloud Connection Settings** and select the **USERS** tab.
If Non-Employee Risk Management displays a message, select **Cancel**.
1. Enter the new source ID in the **Source ID** field.
1. Select **Save**.
# Monitoring System Activity
You can track several types of activity within Non-Employee Risk Management.
Refer to [Activity and Reporting](https://documentation.sailpoint.com/ne-admin/help/reports/reporting.html) for details on how to track user activity and updates to profiles.
Review [Tracking Portal Activity](https://documentation.sailpoint.com/ne-admin/help/reports/portal-activity.html) for information on tracking portal registrations and sign-ins.
# Tracking Portal Activity
Administrators can track portal registration and authentication activity and get insight into user requests and statuses.
To track portal activity, go to **Admin > Collaboration > Activity**.
The REGISTRATIONS tab is displayed. You can also navigate to the AUTHENTICATIONS tab.
## Tracking Portal Registrations
You can track portal registrations by reviewing a list of registration workflow activity.
To track the status of portal registrations:
1. Go to **Admin > Collaboration > Activity**.
Review registration workflow activity by status.
- The **All** tab displays all registration workflow requests.
- The **Pending** tab displays registration workflow requests that are incomplete or waiting on approval.
- The **Completed** tab displays finished workflow requests. This includes workflows that completed successfully, failed, were canceled, or that were edited before they completed.
Note
Canceled workflows display the Closed status.
### Filtering Portal Registration Activity
You can filter registration activity to find a specific set of results.
To apply a filter:
1. Select the ellipsis icon next to Filter.
1. In the **Attribute** field, search for and select an attribute.
When you select an attribute, the **Operator** and **Value** fields appear.
1. In the **Operator** field, select an operator. The options that appear vary based on the attribute you selected.
1. In the **Filter** field, enter the value to filter on.
1. Select the **Add** icon to add your criteria to the filter.
The filter appears in the **Conditions** section and the results in the table are updated.
To add additional filters, repeat steps 2-5. The number of filters applied will appear next to the Request header.
By default, when multiple filters are added, they are combined with an AND operator.
1. To change the AND condition to an OR condition, select the switch.
1. To remove a filter, select the **Delete** icon beside the filter you want to remove. Filters are automatically cleared when you navigate away from the page.
## Tracking Portal Authentications
You can find a list of all portal logins and password changes within the AUTHENTICATIONS tab.
To see a list of login and password change activity for your portal:
1. Go to **Admin > Collaboration > Activity**.
1. Select the **AUTHENTICATIONS** tab.
- Select the **Logins** tab to review all login workflow activity.
- Select the **Password Recoveries** tab to review all password update activity.
# Activity and Reporting
User activity in Non-Employee Risk Management is captured in audit events. Audits events are created for the creation and updating of Attributes, Forms, Pages, Portals, Profiles, Profile Types, Roles, Value Builders, and Workflows.
Profile and workflow activity, and user-generated reports can be reviewed within Non-Employee Risk Management. Audit events can also be retrieved using the Non-Employee Risk Management [API](https://developer.sailpoint.com/docs/api/nerm/v1/search).
## Tracking Changes to Profiles
Administrators can track the history of changes to profiles within Lifecycle. Your audit history of profile changes is retained for the lifespan of your Non-Employee tenant.
To review a profile's history:
1. Select **Admin > Profiles** in the left navigation.
1. Choose the profile you want to view.
1. Select the **History** tab.
Review the history of changes to the profile. The History table displays the following columns:
- **Performer** - The username and email of the user that made the change.
- **Date** - The date and time the change was made.
- **Event** - The type of change that was made or the name of the workflow that initiated the change.
## Workflow Activity Details
When a workflow is executed, the execution is known as a request. Lifecycle workflow activity is tracked in the Requests page and is retained for 18 months.
To access a list of workflow requests:
1. Select **Admin > Lifecycle**.
1. Select **Activity**.
Review the list of workflow activity. Each line represents a single execution of a workflow. This table also includes tabs for requests that are pending, failed, or completed. The Activity table displays the following columns:
- **Request** - The name of the workflow that was executed.
- **Date Requested** - The date and time the workflow was started.
- **Request By** - The username of the user who started the workflow.
- **Status** - The current status of the workflow.
1. To see more details about a single execution of a workflow, select the execution you want to view.
You can see additional details about the workflow and its history on this page.
1. To review additional details about this execution of the workflow, scroll to the bottom of the page and select the **Visualization** tab.
You can see a list visualizing the actions taken during the workflow and specific details about the workflow's execution, including child workflows that started as a result of this workflow.
Use the search field to find specific actions or keywords. Separate search terms with a comma, which will be processed as an OR operator. For example, the query `Session, Request` will be processed as `Session OR Request`. Dates are displayed in `dd/mm/yyyy` format.
You can also find this information in the **System Log** tab in a text list.
The data in these tabs is available for 60 days after the last activity on the workflow.
1. In **System Log**, select the copy icon beside an entry to copy its data, or select the download icon to download that entry as a .txt file.
## Downloading User-Generated Reports
End users can create and export reports about the profiles they can access. Administrators can find the reports users generate within the **Reports** page.
To access user-generated reports:
1. Select **Admin > Lifecycle > Reports**.
A list of user-generated reports is displayed. The Report Exports table displays the following columns:
- **Name** - The name of the report.
- **Type** - The filetype of the report. This is always `.csv`.
- **User** - The username of the user that created the report.
- **Description** - The filters applied to the report.
- **Created** - The date and time the report was created.
1. Select a report to download that specific generation of the report.
## Tracking Request Activity in SailPoint Identity Security
If you're an administrator within SailPoint Identity Security, you can find activity related to Non-Employee Risk Management on your Home page. This activity is updated every hour.
You can find information about pending profile requests, as well as failed and completed profile requests in the corresponding widgets on the Home page.
Refer to [Managing the Home Page](https://documentation.sailpoint.com/saas/help/getting_started/dashboard.html) for more information about the Home page.
# Glossary
## A
**[Access Intelligence Center](https://documentation.sailpoint.com/saas/help/ai/access_insights/access_intelligence.html)** (n): A set of dashboards within SailPoint Human Fabric that allow you to gain insight into your identity administration program, including insights from Non-Employee Risk Management. Refer to [Synchronizing Data to the Access Intelligence Center](https://documentation.sailpoint.com/ne-admin/help/connector/aic_connection.html) for details.
**[Administrator](https://documentation.sailpoint.com/ne-admin/help/users/manage-admins.html)** (n): A lifecycle user with access to the admin console based on their role.
**Assignment** (n): A category of [profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html) representing a non-employee's time-bound association with a job or project.
**[Attribute](https://documentation.sailpoint.com/ne-admin/help/profile-types/attributes.html)** (n): A single item of data related to a particular profile and the value contained in it. For example, a user's first name is an attribute.
## C
**[Collaboration](https://documentation.sailpoint.com/ne-admin/help/collaboration/index.html)** (n): A feature within Non-Employee Risk Management that allows non-employees to participate in managing other non-employees within your tenant with user accounts that are linked to profiles. These users are referred to as [portal users](#portal-user).
**[Contributor](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html)**: The title for the default system roles that can be assigned to end users so they can manage profiles. Users can be granted the basic contributor role, or be granted the [owner](#ownercontributor) or [sponsor](#sponsorcontributor) contributor role.
## D
**[Delegate](https://documentation.sailpoint.com/ne-user/help/delegation/index.html)** (n): A user that has been granted temporary access to the profiles managed by another user, so they can manage those profiles for a specified time period.
## F
**[Form](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-forms.html)** (n): A set of fields representing attributes on a profile. Forms can be combined into pages and displayed on profiles or used in workflows to set the attributes on a profile.
## G
**Group** (n): An entitlement or access item on an enterprise application. These can be used to grant roles to users from your identity provider.
## L
**Lifecycle** (n): The base functionality of Non-Employee Risk Management, including managing the relationships between third-party entities and with your organization.
**[Lifecycle User](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-lifecycle-users)** (n): Users employed by your organization with accounts in Non-Employee Risk Management. Lifecycle users can create or update profiles depending on their permissions.
## N
**NEAccess** (n): A legacy term for the Collaboration features.
**NEProfile** (n): A legacy term for the Lifecycle features.
**Non-Employee** (n): An individual contracted to perform work for an organization on a job for a specific period of time.
## O
**Organization** (n): A category of [profile type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html) used to manage the jobs and permissions that non-employees have within your company. Organizations can be internal, such as a team or department, or external, such as a vendor or staffing agency.
**[Owner](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html)** (n): A type of contributor to a profile. The primary user responsible for managing a profile and its associated relationships in profile types with the categories *organization* and *job*.
## P
**[Page](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-pages.html)** (n): A collection of forms, text, and other elements used to display profile data and gather information about profiles.
**[Portal](https://documentation.sailpoint.com/ne-admin/help/collaboration/portals.html)** (n): The login page for [portal users](#portal-user) using the [collaboration](#collaboration) feature.
**[Portal User](https://documentation.sailpoint.com/ne-admin/help/users/manage-users.html#managing-portal-users)** (n): Non-employees that have been invited to Non-Employee Risk Management to participate in managing profiles and other non-employees. These users authenticate into Non-Employee Risk Management using a [portal](#portal).
**[Profile](https://documentation.sailpoint.com/ne-admin/help/profiles/index.html)** (n): Any individual, organization, or other object managed within Non-Employee Risk Management, as well as the data about that object. This includes non-employees, the organizations they come from, or the assignments they work on, and additional data related to non-employees in your organization.
**[Profile Type](https://documentation.sailpoint.com/ne-admin/help/profile-types/manage-prof-types.html)** (n): A group of similar profiles you want to manage, using the same attributes and workflows.
## S
**Sponsor** (n): An attribute on assignment profiles representing a [contributor](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html) who is the primary point of contact for that assignment.
## U
**[User](https://documentation.sailpoint.com/ne-admin/help/users/index.html)** (n): Any individual with an account in Non-Employee Risk Management. Most often, this refers to end users who do not have administrator permissions.
**User Role** (n): The level of access granted to a user within Non-Employee Risk Management. This refers to the [default roles](https://documentation.sailpoint.com/ne-admin/help/users/default-roles.html), as well as custom roles configured for [lifecycle users](https://documentation.sailpoint.com/ne-admin/help/users/lc-user-roles.html) and [collaboration users](https://documentation.sailpoint.com/ne-admin/help/users/col-user-roles.html). [Administrator permissions](https://documentation.sailpoint.com/ne-admin/help/users/manage-admins.html) are also granted based on a user's role.
## V
**[Value builder](https://documentation.sailpoint.com/ne-admin/help/profile-types/value-builders.html)** (n): A customizable set of instructions used to generate profile attributes using either random or programmatic values.
## W
**[Workflow](https://documentation.sailpoint.com/ne-admin/help/workflows/index.html)** (n): A customizable series of sequential actions that are executed to perform specific tasks within Non-Employee Risk Management.