5.1 Lifecycle Events and Their Workflows
Key Takeaways
Lifecycle events are configured on Setup > Lifecycle Events and are evaluated by Identity Refresh when the Process Events option is enabled.
The event types are Create, Manager Transfer, Attribute Change, Rule, Native Change, Alert, and Rapid Setup.
Attribute Change events can filter on previous and new values, and Manager Transfer events can filter on previous and new managers.
Each event selects a business process to launch; lifecycle events are the one place where workflows of any type can be triggered.
Identity processing thresholds (fixed or percentage) stop the refresh before a flood of accidental events is processed.
Lifecycle Events and Their Workflows
Objective 2.4 asks you to configure lifecycle events and their associated workflows. A lifecycle event is a rule that watches for a change to an identity, such as a new hire, a new manager, or a status changing to inactive. When the change is detected, it launches a business process that grants, changes, or removes access. This is IdentityIQ's native joiner-mover-leaver engine. Rapid Setup (section 5.4) is a guided layer on top of the same ideas.
Where and When Events Fire
- Configure events on Setup > Lifecycle Events. Each row shows the name, type, attribute (for Attribute Change), owner, and whether it is disabled.
- Events are evaluated by the Identity Refresh task when Process Events is selected. Aggregation stores snapshots that approximate each identity's previous state. Refresh compares that snapshot with the updated identity to decide which events apply.
- Aggregation alone does not launch lifecycle events. The usual schedule is: aggregate the authoritative source, then refresh with Process Events. Many teams use Refresh only identities marked as needing refresh during aggregation to keep this incremental.
The Seven Event Types
| Event type | Fires when | Type-specific settings |
|---|---|---|
| Create | A new identity is discovered | None beyond the population |
| Manager Transfer | An identity's manager changes | Previous Manager Filter, New Manager Filter (blank means any) |
| Attribute Change | A chosen identity attribute changes | Attribute, Previous Value Filter, New Value Filter |
| Rule | A rule returns true | Rule (the IdentityTrigger rule type) |
| Native Change | A change is detected directly on an application configured to report it | Native change detection on the application |
| Alert | An alert is triggered | None beyond the population |
| Rapid Setup | The selected Rapid Setup process is detected | RapidSetup Process |
A classic leaver is an Attribute Change event on inactive with New Value Filter = true. A classic mover is a Manager Transfer event, or an Attribute Change on department or location. A classic joiner is a Create event.
Common Settings for Every Event
- Name and Description. The name identifies the event but is not shown on the requests it creates.
- Include Identities limits which identities the event applies to: None (only listed identities), All, Match List (identity attributes, application attributes, or permissions), Filter, Script, Rule, or Population. Use it, for example, to run a contractor leaver process only for identities whose
typeis Contractor. - Threshold Type and Threshold Value set an identity processing threshold. Fixed needs a whole number greater than 1. Percentage needs a whole number from 1 to 100. If an HR mistake marks a whole department as terminated, the threshold stops the Identity Refresh task before any identity is updated and fails the task result with a message. With partitioned refresh, the count is cumulative across partitions. The refresh option Disable identity processing threshold switches the check off for one task.
- Business Process is the workflow to launch.
- Disabled turns the event off without deleting it.
The Associated Workflows
IdentityIQ ships lifecycle workflows of the Identity Lifecycle type: Lifecycle Event – Joiner, Lifecycle Event – Manager Change, Lifecycle Event – Leaver, and Lifecycle Event – Reinstate. They build provisioning plans (for example, disabling accounts for a leaver or notifying the new manager for a transfer). They reuse the same Identity Request subprocesses as LCM, so approvals, forms, provisioning, and notifications work as they do in section 4.3.
Customizing follows the usual pattern: copy the product workflow, change its variables or steps, and select the copy in the event's Business Process field. The workflow-types documentation adds that workflows with custom types can be triggered only from Lifecycle Events, which can launch a workflow of any type.
Worked Example: A Contractor Leaver
Requirement: when a contractor's inactive flag becomes true, disable their accounts, notify their manager, and never run the process for employees.
- Event Type: Attribute Change. Attribute:
inactive. Previous Value Filter:false. New Value Filter:true. - Include Identities: Match List with
type=Contractor, so employees are never selected. - Threshold: Percentage, 5. If the number of identities triggering the event reaches the threshold (five percent of identities), the refresh stops before updating anyone.
- Business Process: a copy of Lifecycle Event – Leaver with its notification variables set to include the manager.
- Schedule: HR delta aggregation, then Identity Refresh with Refresh identity attributes, Process Events, and Provision assignments, limited to identities marked as needing refresh.
Test it by editing a test contractor's inactive value in a non-production HR file. Run the two tasks, check Task Results for the launched workflow, and read the redirected email (section 3.4).
Lifecycle Events vs. Certification Events
A lifecycle event launches a business process. A certification event (Setup > Certifications) uses the same kinds of triggers to launch an access review, for example certifying a mover's access when the manager changes. If a question asks you to "launch a workflow," it is a lifecycle event. If it asks you to "launch a review," it is a certification event (section 6.1).
Troubleshooting Checklist
- Did aggregation actually change the attribute? Check the identity's attributes and history.
- Did Identity Refresh run with Process Events selected?
- Is the event enabled, and do its filters and Include Identities match the identity?
- Did a threshold stop the refresh? Check the task result message.
- Did the business process start? Check Task Results or the workflow case, and turn on
tracein the workflow if needed.
HR changes an employee's inactive attribute to true, and the authoritative aggregation completes, but the leaver business process never starts. What is the most likely missing step?
An Identity Refresh with the Process Events option selected
A Perform Maintenance task with remediation enabled
An Account Group Aggregation on the HR application
Re-importing init-lcm.xml
A mover workflow should run only when an identity moves from the Sales department to any other department. How is this configured?
A Manager Transfer event with the New Manager Filter set to Sales
A Create event with Include Identities set to a Sales population
An Attribute Change event on department with the Previous Value Filter set to Sales
A Native Change event on the HR application
A data error in the HR feed marks 800 employees inactive at once. Which lifecycle event setting could stop the leaver process from running against all of them?
Include Identities set to All
The Disabled checkbox on the Joiner event
The notificationScheme variable on the leaver workflow
An identity processing threshold with a fixed or percentage value
An implementer creates a workflow with a custom type that is not one of IdentityIQ's standard workflow types. From where can it be triggered through the user interface?
Only from the Lifecycle Manager Business Processes tab
Only from Lifecycle Events, which can trigger workflows of any type
Only from a policy's violation workflow setting
It cannot be triggered from the UI at all
Sections you finish are checked off in the contents.