5.1 Lifecycle Events and Their Workflows

Key Takeaways

  • Lifecycle events are configured on Setup > Lifecycle Events and are evaluated by Identity Refresh when the Process Events option is enabled.

  • The event types are Create, Manager Transfer, Attribute Change, Rule, Native Change, Alert, and Rapid Setup.

  • Attribute Change events can filter on previous and new values, and Manager Transfer events can filter on previous and new managers.

  • Each event selects a business process to launch; lifecycle events are the one place where workflows of any type can be triggered.

  • Identity processing thresholds (fixed or percentage) stop the refresh before a flood of accidental events is processed.

Last updated: September 2026

Lifecycle Events and Their Workflows

Objective 2.4 asks you to configure lifecycle events and their associated workflows. A lifecycle event is a rule that watches for a change to an identity, such as a new hire, a new manager, or a status changing to inactive. When the change is detected, it launches a business process that grants, changes, or removes access. This is IdentityIQ's native joiner-mover-leaver engine. Rapid Setup (section 5.4) is a guided layer on top of the same ideas.

Where and When Events Fire

  • Configure events on Setup > Lifecycle Events. Each row shows the name, type, attribute (for Attribute Change), owner, and whether it is disabled.
  • Events are evaluated by the Identity Refresh task when Process Events is selected. Aggregation stores snapshots that approximate each identity's previous state. Refresh compares that snapshot with the updated identity to decide which events apply.
  • Aggregation alone does not launch lifecycle events. The usual schedule is: aggregate the authoritative source, then refresh with Process Events. Many teams use Refresh only identities marked as needing refresh during aggregation to keep this incremental.

The Seven Event Types

Event typeFires whenType-specific settings
CreateA new identity is discoveredNone beyond the population
Manager TransferAn identity's manager changesPrevious Manager Filter, New Manager Filter (blank means any)
Attribute ChangeA chosen identity attribute changesAttribute, Previous Value Filter, New Value Filter
RuleA rule returns trueRule (the IdentityTrigger rule type)
Native ChangeA change is detected directly on an application configured to report itNative change detection on the application
AlertAn alert is triggeredNone beyond the population
Rapid SetupThe selected Rapid Setup process is detectedRapidSetup Process

A classic leaver is an Attribute Change event on inactive with New Value Filter = true. A classic mover is a Manager Transfer event, or an Attribute Change on department or location. A classic joiner is a Create event.

Common Settings for Every Event

  • Name and Description. The name identifies the event but is not shown on the requests it creates.
  • Include Identities limits which identities the event applies to: None (only listed identities), All, Match List (identity attributes, application attributes, or permissions), Filter, Script, Rule, or Population. Use it, for example, to run a contractor leaver process only for identities whose type is Contractor.
  • Threshold Type and Threshold Value set an identity processing threshold. Fixed needs a whole number greater than 1. Percentage needs a whole number from 1 to 100. If an HR mistake marks a whole department as terminated, the threshold stops the Identity Refresh task before any identity is updated and fails the task result with a message. With partitioned refresh, the count is cumulative across partitions. The refresh option Disable identity processing threshold switches the check off for one task.
  • Business Process is the workflow to launch.
  • Disabled turns the event off without deleting it.

The Associated Workflows

IdentityIQ ships lifecycle workflows of the Identity Lifecycle type: Lifecycle Event – Joiner, Lifecycle Event – Manager Change, Lifecycle Event – Leaver, and Lifecycle Event – Reinstate. They build provisioning plans (for example, disabling accounts for a leaver or notifying the new manager for a transfer). They reuse the same Identity Request subprocesses as LCM, so approvals, forms, provisioning, and notifications work as they do in section 4.3.

Customizing follows the usual pattern: copy the product workflow, change its variables or steps, and select the copy in the event's Business Process field. The workflow-types documentation adds that workflows with custom types can be triggered only from Lifecycle Events, which can launch a workflow of any type.

Loading diagram...
How a lifecycle event runs

Worked Example: A Contractor Leaver

Requirement: when a contractor's inactive flag becomes true, disable their accounts, notify their manager, and never run the process for employees.

  1. Event Type: Attribute Change. Attribute: inactive. Previous Value Filter: false. New Value Filter: true.
  2. Include Identities: Match List with type = Contractor, so employees are never selected.
  3. Threshold: Percentage, 5. If the number of identities triggering the event reaches the threshold (five percent of identities), the refresh stops before updating anyone.
  4. Business Process: a copy of Lifecycle Event – Leaver with its notification variables set to include the manager.
  5. Schedule: HR delta aggregation, then Identity Refresh with Refresh identity attributes, Process Events, and Provision assignments, limited to identities marked as needing refresh.

Test it by editing a test contractor's inactive value in a non-production HR file. Run the two tasks, check Task Results for the launched workflow, and read the redirected email (section 3.4).

Lifecycle Events vs. Certification Events

A lifecycle event launches a business process. A certification event (Setup > Certifications) uses the same kinds of triggers to launch an access review, for example certifying a mover's access when the manager changes. If a question asks you to "launch a workflow," it is a lifecycle event. If it asks you to "launch a review," it is a certification event (section 6.1).

Troubleshooting Checklist

  1. Did aggregation actually change the attribute? Check the identity's attributes and history.
  2. Did Identity Refresh run with Process Events selected?
  3. Is the event enabled, and do its filters and Include Identities match the identity?
  4. Did a threshold stop the refresh? Check the task result message.
  5. Did the business process start? Check Task Results or the workflow case, and turn on trace in the workflow if needed.
Test Your Knowledge

HR changes an employee's inactive attribute to true, and the authoritative aggregation completes, but the leaver business process never starts. What is the most likely missing step?

A

An Identity Refresh with the Process Events option selected

B

A Perform Maintenance task with remediation enabled

C

An Account Group Aggregation on the HR application

D

Re-importing init-lcm.xml

Test Your Knowledge

A mover workflow should run only when an identity moves from the Sales department to any other department. How is this configured?

A

A Manager Transfer event with the New Manager Filter set to Sales

B

A Create event with Include Identities set to a Sales population

C

An Attribute Change event on department with the Previous Value Filter set to Sales

D

A Native Change event on the HR application

Test Your Knowledge

A data error in the HR feed marks 800 employees inactive at once. Which lifecycle event setting could stop the leaver process from running against all of them?

A

Include Identities set to All

B

The Disabled checkbox on the Joiner event

C

The notificationScheme variable on the leaver workflow

D

An identity processing threshold with a fixed or percentage value

Test Your Knowledge

An implementer creates a workflow with a custom type that is not one of IdentityIQ's standard workflow types. From where can it be triggered through the user interface?

A

Only from the Lifecycle Manager Business Processes tab

B

Only from Lifecycle Events, which can trigger workflows of any type

C

Only from a policy's violation workflow setting

D

It cannot be triggered from the UI at all

Sections you finish are checked off in the contents.