13.3 Common Connector Rule Types
Key Takeaways
Connector rules vary by connector type and generally run before aggregation rules, while the connector reads and transforms incoming data.
Pre-Iterate runs once before the data is read, and Post-Iterate runs once after, for jobs such as decompressing, validating, or archiving a file.
BuildMap turns one raw row into an attribute Map; MergeMaps combines maps for objects that span several rows; Map To ResourceObject builds the ResourceObject.
The JDBC connector supports provisioning rules, either one for all operations or one per operation (Create, Modify, Delete, Enable, Disable, Unlock).
With partitioned aggregation, set runRuleEachPartition to false so Pre- and Post-Iterate rules run once instead of once per partition.
Common Connector Rule Types
Objective 5.6 asks you to understand common connector rule types. The documentation separates connector rules, which are specific to a connector type, from aggregation rules, which are common to all applications (section 13.2):
Connector rules are used during aggregation from specific connectors, such as Delimited File, JDBC, and SAP. Connector rules generally run before aggregation rules. They pre-process data, post-process data, and manipulate, merge, or transform incoming data as it is read.
Delimited File Connector Rules (Read Path)
| Rule | When it runs | Inputs and output | Typical use |
|---|---|---|---|
| Pre-Iterate | Once, before the file is read | application, schema, stats; no return | Check the file exists, decompress or decrypt it, validate a trailer record, record the start time |
| BuildMap | Once per row | cols, record, application, schema, state → Map | Split or combine columns, clean values, derive attributes, rename columns |
| MergeMaps | When merging is enabled and rows for one object must be combined | → combined Map | Custom merge logic instead of the default "merge these columns" behavior |
| Map To ResourceObject | When turning the map into a ResourceObject | → ResourceObject | Full control over how the object is built |
| Post-Iterate | Once, after the file is processed | application, schema, stats; no return | Archive or delete the file, write a summary, clean up temporary data |
The file settings interact with these rules. Columns can rename the fields the BuildMap rule sees. Merging (index column, sorted data, columns to merge) handles multi-line objects without code. The Filter String drops rows before rules need to handle them.
Partitioned Aggregation and Iterate Rules
When a Delimited File aggregation is partitioned, Pre- and Post-Iterate rules only need to run once. The connector documentation says to add a runRuleEachPartition entry to the application XML so they run once rather than in every partition. In IdentityIQ XML, an empty <Boolean> element means false:
<entry key="runRuleEachPartition">
<value><Boolean></Boolean></value>
</entry>
JDBC Connector Rules
- BuildMap / MergeMaps – the JDBC connector also supports a BuildMap rule for shaping each row. The documentation's example is setting account status when a stored procedure cannot be changed. Merging handles accounts that span rows, with the SQL ordered by the index columns.
- Provisioning rules – a JDBC application can write to its database through one provisioning rule for all operations, or a separate rule per operation: Create, Modify, Delete, Enable, Disable, and Unlock. The rule receives the plan or request and runs the needed SQL. An example is in
examplerules.xml. - Troubleshooting note: the JDBC guide lists "provisioning rule executing multiple times" as a known symptom to investigate. Design provisioning rules so that repeating them is harmless.
Other Connectors (Recognize the Pattern)
- SAP and other enterprise connectors have their own connector-specific rules for custom attributes or provisioning.
- Web Services connectors typically offer before-operation and after-operation rules that change requests and parse responses for each configured endpoint.
- Active Directory relies on the IQService for Windows-side work. Its connector guide describes options for running native scripts before or after provisioning actions.
When the exam lists rule names you do not recognize, apply the pattern. If a rule's name is tied to a connector and to reading, parsing, or writing raw data, it is a connector rule. If it concerns matching accounts to identities, creating identities, or saving accounts, it is an application aggregation rule.
Performance Notes for Connector Rules
BuildMap and similar per-row rules run for every record, often hundreds of thousands per aggregation:
- Avoid database queries inside per-row rules. Load reference data once, for example in a Pre-Iterate rule, and keep it in the connector
statemap, which persists across rows during one run. - Prefer file settings, such as filter strings, merging, and column names, over code wherever they can do the job.
- Keep logging at debug level so production runs do not write a line per record.
Connector Rules vs. Application Rules
| Question | Connector rule | Application rule |
|---|---|---|
| Is it available for every application type? | No, only for that connector | Yes, for most rules |
| When does it run? | While the connector reads or writes raw data | After valid ResourceObjects exist, or around provisioning |
| Example | BuildMap, Pre-Iterate, JDBC provisioning | Correlation, Creation, Customization, BeforeProvisioning |
| If the connector has no connector rules, where does account manipulation go? | Not applicable | Customization rule |
Worked Example: A Messy HR Extract
An HR vendor drops hr_extract.csv.gz nightly. It has a FULL_NAME column, dates in two formats, and one row per job assignment.
- Pre-Iterate: decompress the file and fail fast if the trailer count does not match.
- BuildMap: split FULL_NAME, normalize dates, and trim codes.
- Merging: index on EMPLOYEE_ID with the data sorted, and merge JOB_CODE so assignments become one multi-valued attribute.
- Post-Iterate: move the file to an archive folder.
- Aggregation rules: a Creation rule sets new identities' names, and a Customization rule marks terminated rows as disabled.
The connector makes the data clean and well-shaped. The application rules decide what it means for identities.
A delimited HR file arrives compressed every night and must be decompressed before parsing and archived afterward. Which connector rules should be used?
Pre-Iterate to decompress and Post-Iterate to archive
BuildMap to decompress and Customization to archive
Correlation to decompress and Creation to archive
BeforeProvisioning and AfterProvisioning
A partitioned Delimited File aggregation runs the Pre-Iterate rule once per partition, repeatedly decompressing the same file. What does the connector documentation recommend?
Disable partitioning permanently.
Move the logic into the BuildMap rule.
Change the Pre-Iterate rule into a Correlation rule.
Add the runRuleEachPartition entry to the application XML, set to false, so the iterate rules run only once.
In general, when do connector rules such as BuildMap run relative to aggregation rules such as Correlation?
After correlation has saved the Link
Before aggregation rules, while the connector reads and transforms raw data into ResourceObjects
Only during provisioning
Only during identity refresh
A JDBC application must run different SQL for enabling accounts than for disabling them. What does the JDBC connector support?
Only a single Customization rule for all writes
Provisioning through the IQService only
Separate provisioning rules per operation, such as Enable, Disable, Unlock, Delete, Create, and Modify
Provisioning rules only for group objects
Sections you finish are checked off in the contents.