5.4 Rapid Setup in Lifecycle Events and Identity Operations
Key Takeaways
Rapid Setup comes with Lifecycle Manager and is configured globally on Global Settings > Rapid Setup Configuration, with Joiner, Mover, Leaver, Identity Operations, and Miscellaneous tabs.
Per-application behavior is set on Applications > Rapid Setup, and each process must be enabled globally first.
Trigger filters should detect a change (for example, "Inactive Changed to True") rather than a state ("Inactive Equals True").
Leaver takes priority over joiner and mover, and joiner takes priority over mover.
Immediate termination without approvals is started from Identities > Identity Operations, one identity at a time, with a required reason.
Rapid Setup in Lifecycle Events and Identity Operations
Objective 2.7 asks you to leverage Rapid Setup in lifecycle events and identity operations. Rapid Setup is included with Lifecycle Manager, so there is nothing separate to install. It gives business users a guided way to define joiner, mover, leaver, and termination behavior. It does not replace native lifecycle events (section 5.1). It is an alternative, centralized way to configure them with preconfigured, best-practice business processes such as RapidSetup – Joiner, Mover, and Leaver.
Rapid Setup separates technical onboarding (connection parameters and schema, done first in Application Definition) from business onboarding (what happens to accounts when people join, move, or leave).
Global Configuration
Go to gear icon > Global Settings > Rapid Setup Configuration. Each tab has an enable slider. A dot on a tab means unsaved changes, and a checkmark on the dot means the changes are saved.
Joiner Tab
- Generate Approvals. The default RapidSetup – Joiner process delegates approvals to LCM Provisioning.
- Automatically Join New Empty Identities includes new identities with no accounts and bypasses trigger filters for them.
- Exclude Uncorrelated Identities. A correlated identity has an account on an authoritative application.
- Alternative Workgroup for the Joiner Completed email, a Joiner Completed Notification Email Template, and Send Temporary Password Email.
- Post Joiner Rule (rule type PostLifecycle), Threshold Type/Threshold, Joiner Business Process, and Trigger Filters.
Mover Tab
- Launch a Targeted Certification of the mover's access. The new manager is the default certifier, and you can Include Previous Manager as a Certifier. You can also stage the certification, include birthright roles, set a certification owner, and set a backup certifier. If joiner processing is part of the move, the certification must complete before joiner processing starts.
- Joiner Processing re-applies birthright roles and account-only provisioning as part of the move.
- Post Mover Rule, threshold, business process, and a trigger filter that defines what a "move" is, such as Manager Changed.
Leaver Tab
- Remove Assigned Roles and Reassign Artifacts, such as applications, workgroups, and policies owned by the leaver. Reassignment goes to the manager, then a rule, then an alternate.
- Reassign Identities, such as service accounts and RPA or bot identities the leaver administers.
- A notification workgroup, the reassignment and completed email templates, Post Leaver Rule (type LeaverReassignment), threshold, business process, and trigger filter.
Identity Operations and Miscellaneous Tabs
- Identity Operations enables Terminate Processing with the same reassignment options, a Terminate Business Process, and a Post Terminate Rule.
- Miscellaneous sets the Business Process Requester (for auditing), the RapidSetup No Manager workgroup, the Rapid Setup Error Notification workgroup, email style sheet, header, and footer templates, and the role types treated as birthright roles (default type
rapidSetupBirthright).
Trigger Filters: The Most Tested Idea
Trigger filters decide which identities each process acts on. They use identity attributes or saved populations with AND/OR groups. The documentation stresses:
Use change operators. "Inactive Equals True" selects every inactive identity on every run. "Inactive Changed to True" selects only identities that just became inactive.
Date criteria fire at midnight local time on the specified date. Populations built in Advanced Analytics can exclude groups, such as executives, from standard mover processing.
Event Priority
| If an identity qualifies for… | Rapid Setup launches |
|---|---|
| Leaver and joiner | Leaver only |
| Leaver and mover | Leaver only |
| Joiner and mover | Joiner only |
Per-Application Settings (Applications > Rapid Setup)
- Joiner: Perform Account-Only provisioning, which creates an empty account even with no entitlements. Identity Selection can be Everyone, Filter, Script, a Rule (type IdentitySelector), or a Population. You can also Automatically Start Joiner Processing for Newly Created Identities during aggregation and add email instructions.
- Mover: include additional entitlements or targeted permissions in the certification, and account-only provisioning.
- Leaver: either Use rule (one rule handles leaver and termination) or Configure the actions: Delete Account, Disable Account, Scramble Password, Move Account (Active Directory OU only), Remove Entitlements with exceptions, and Add Comment. Each can run Now or Later, after a number of days. Termination can reuse the leaver settings or have its own. Create the provisioning policies needed for delete, disable, and unlock, plus a password policy for scrambling, before configuring leavers.
Immediate Termination
- Go to Identities > Identity Operations.
- Select one identity.
- Choose Terminate and enter the required reason.
- Review and Submit. The leaver-style termination runs immediately without approvals.
How Rapid Setup Connects to Lifecycle Events
Rapid Setup processing still runs through identity refresh. The Lifecycle Events page includes a Rapid Setup event type that launches a Rapid Setup business process when the selected RapidSetup process is detected. So the same scheduling rule applies as for native events: aggregate the authoritative source, then run Identity Refresh with Process Events. The exception is the joiner option Automatically Start Joiner Processing for Newly Created Identities, which starts joiner processing during aggregation when a new identity is created.
When should you use Rapid Setup instead of hand-built lifecycle events? Rapid Setup fits standard joiner, mover, and leaver patterns that business users need to maintain per application. Custom lifecycle events and workflows fit unusual logic, such as a reinstatement process with custom approvals. Both can exist in one installation.
Safety Net: Identity Processing Thresholds
A fixed or percentage threshold on joiner, mover, or leaver processing stops the Identity Refresh task before it updates anyone when too many identities qualify. Process events must be enabled in the refresh for the threshold to apply. For troubleshooting, set the sailpoint.rapidsetup and sailpoint.workflow.RapidSetupLibrary loggers to debug in log4j2.properties. Sample rules are in WEB-INF/config/rapidsetup/rsexamplerules.xml.
A Rapid Setup leaver trigger filter uses "Inactive Equals True." What problem will this cause?
Leavers will never be detected because Equals is not supported.
Every inactive identity is selected on every run, not just identities that newly became inactive.
Only contractors will be processed.
The filter will override the identity processing threshold.
An identity meets both the joiner and leaver trigger filters during the same refresh. What does Rapid Setup do?
It launches only the leaver process.
It launches the joiner process first and then the leaver process.
It launches both processes in parallel.
It launches neither and raises a threshold error.
Security must remove all of a departing administrator's access immediately, without waiting for approvals or the next HR feed. Which Rapid Setup feature is designed for this?
A mover targeted certification with the previous manager as certifier
Automatically Join New Empty Identities
The Miscellaneous tab's Business Process Requester
Terminate from Identities > Identity Operations, with a required reason
In Rapid Setup, how is a role marked as a birthright role that joiner and mover processing assign automatically?
By adding it to the Joiner Email Instructions field
By giving the role a role type that the Miscellaneous tab lists as a birthright type, such as the default rapidSetupBirthright
By marking the role Requestable = false
By attaching a PostLifecycle rule to the role
Sections you finish are checked off in the contents.