13.3 Common Connector Rule Types

Key Takeaways

  • Connector rules vary by connector type and generally run before aggregation rules, while the connector reads and transforms incoming data.

  • Pre-Iterate runs once before the data is read, and Post-Iterate runs once after, for jobs such as decompressing, validating, or archiving a file.

  • BuildMap turns one raw row into an attribute Map; MergeMaps combines maps for objects that span several rows; Map To ResourceObject builds the ResourceObject.

  • The JDBC connector supports provisioning rules, either one for all operations or one per operation (Create, Modify, Delete, Enable, Disable, Unlock).

  • With partitioned aggregation, set runRuleEachPartition to false so Pre- and Post-Iterate rules run once instead of once per partition.

Last updated: September 2026

Common Connector Rule Types

Objective 5.6 asks you to understand common connector rule types. The documentation separates connector rules, which are specific to a connector type, from aggregation rules, which are common to all applications (section 13.2):

Connector rules are used during aggregation from specific connectors, such as Delimited File, JDBC, and SAP. Connector rules generally run before aggregation rules. They pre-process data, post-process data, and manipulate, merge, or transform incoming data as it is read.

Delimited File Connector Rules (Read Path)

RuleWhen it runsInputs and outputTypical use
Pre-IterateOnce, before the file is readapplication, schema, stats; no returnCheck the file exists, decompress or decrypt it, validate a trailer record, record the start time
BuildMapOnce per rowcols, record, application, schema, state → MapSplit or combine columns, clean values, derive attributes, rename columns
MergeMapsWhen merging is enabled and rows for one object must be combined→ combined MapCustom merge logic instead of the default "merge these columns" behavior
Map To ResourceObjectWhen turning the map into a ResourceObject→ ResourceObjectFull control over how the object is built
Post-IterateOnce, after the file is processedapplication, schema, stats; no returnArchive or delete the file, write a summary, clean up temporary data

The file settings interact with these rules. Columns can rename the fields the BuildMap rule sees. Merging (index column, sorted data, columns to merge) handles multi-line objects without code. The Filter String drops rows before rules need to handle them.

Partitioned Aggregation and Iterate Rules

When a Delimited File aggregation is partitioned, Pre- and Post-Iterate rules only need to run once. The connector documentation says to add a runRuleEachPartition entry to the application XML so they run once rather than in every partition. In IdentityIQ XML, an empty <Boolean> element means false:

<entry key="runRuleEachPartition">
  <value><Boolean></Boolean></value>
</entry>

JDBC Connector Rules

  • BuildMap / MergeMaps – the JDBC connector also supports a BuildMap rule for shaping each row. The documentation's example is setting account status when a stored procedure cannot be changed. Merging handles accounts that span rows, with the SQL ordered by the index columns.
  • Provisioning rules – a JDBC application can write to its database through one provisioning rule for all operations, or a separate rule per operation: Create, Modify, Delete, Enable, Disable, and Unlock. The rule receives the plan or request and runs the needed SQL. An example is in examplerules.xml.
  • Troubleshooting note: the JDBC guide lists "provisioning rule executing multiple times" as a known symptom to investigate. Design provisioning rules so that repeating them is harmless.

Other Connectors (Recognize the Pattern)

  • SAP and other enterprise connectors have their own connector-specific rules for custom attributes or provisioning.
  • Web Services connectors typically offer before-operation and after-operation rules that change requests and parse responses for each configured endpoint.
  • Active Directory relies on the IQService for Windows-side work. Its connector guide describes options for running native scripts before or after provisioning actions.

When the exam lists rule names you do not recognize, apply the pattern. If a rule's name is tied to a connector and to reading, parsing, or writing raw data, it is a connector rule. If it concerns matching accounts to identities, creating identities, or saving accounts, it is an application aggregation rule.

Performance Notes for Connector Rules

BuildMap and similar per-row rules run for every record, often hundreds of thousands per aggregation:

  • Avoid database queries inside per-row rules. Load reference data once, for example in a Pre-Iterate rule, and keep it in the connector state map, which persists across rows during one run.
  • Prefer file settings, such as filter strings, merging, and column names, over code wherever they can do the job.
  • Keep logging at debug level so production runs do not write a line per record.

Connector Rules vs. Application Rules

QuestionConnector ruleApplication rule
Is it available for every application type?No, only for that connectorYes, for most rules
When does it run?While the connector reads or writes raw dataAfter valid ResourceObjects exist, or around provisioning
ExampleBuildMap, Pre-Iterate, JDBC provisioningCorrelation, Creation, Customization, BeforeProvisioning
If the connector has no connector rules, where does account manipulation go?Not applicableCustomization rule

Worked Example: A Messy HR Extract

An HR vendor drops hr_extract.csv.gz nightly. It has a FULL_NAME column, dates in two formats, and one row per job assignment.

  1. Pre-Iterate: decompress the file and fail fast if the trailer count does not match.
  2. BuildMap: split FULL_NAME, normalize dates, and trim codes.
  3. Merging: index on EMPLOYEE_ID with the data sorted, and merge JOB_CODE so assignments become one multi-valued attribute.
  4. Post-Iterate: move the file to an archive folder.
  5. Aggregation rules: a Creation rule sets new identities' names, and a Customization rule marks terminated rows as disabled.

The connector makes the data clean and well-shaped. The application rules decide what it means for identities.

Test Your Knowledge

A delimited HR file arrives compressed every night and must be decompressed before parsing and archived afterward. Which connector rules should be used?

A

Pre-Iterate to decompress and Post-Iterate to archive

B

BuildMap to decompress and Customization to archive

C

Correlation to decompress and Creation to archive

D

BeforeProvisioning and AfterProvisioning

Test Your Knowledge

A partitioned Delimited File aggregation runs the Pre-Iterate rule once per partition, repeatedly decompressing the same file. What does the connector documentation recommend?

A

Disable partitioning permanently.

B

Move the logic into the BuildMap rule.

C

Change the Pre-Iterate rule into a Correlation rule.

D

Add the runRuleEachPartition entry to the application XML, set to false, so the iterate rules run only once.

Test Your Knowledge

In general, when do connector rules such as BuildMap run relative to aggregation rules such as Correlation?

A

After correlation has saved the Link

B

Before aggregation rules, while the connector reads and transforms raw data into ResourceObjects

C

Only during provisioning

D

Only during identity refresh

Test Your Knowledge

A JDBC application must run different SQL for enabling accounts than for disabling them. What does the JDBC connector support?

A

Only a single Customization rule for all writes

B

Provisioning through the IQService only

C

Separate provisioning rules per operation, such as Enable, Disable, Unlock, Delete, Create, and Modify

D

Provisioning rules only for group objects

Sections you finish are checked off in the contents.