4.3 Configuring LCM Workflows

Key Takeaways

  • The default LCM business processes are LCM Provisioning, LCM Create and Update, LCM Manage Passwords, and LCM Registration.

  • LCM Provisioning runs the Identity Request Initialize, Violation Review, Approve, Provision, Notify, and Finalize subprocesses, plus the Provisioning Approval Subprocess.

  • approvalScheme chooses who approves (for example manager, owner, securityOfficer, or none), and approvalMode chooses how several approvers act (serial, serialPoll, parallel, parallelPoll, or any).

  • policyScheme decides how policy violations found during a request are handled, and notificationScheme decides who is emailed.

  • Copy an out-of-the-box workflow under a new name and select the copy on the Business Processes tab, because upgrades overwrite product workflows.

Last updated: September 2026

Configuring LCM Workflows

Objective 2.3 is configure LCM workflows. In IdentityIQ, workflow and business process mean the same thing. The UI says "business process," and implementers working with the object model say "workflow." Each Lifecycle Manager action launches the workflow selected for it on gear icon > Lifecycle Manager > Business Processes.

The Default LCM Workflows

WorkflowHandles
LCM ProvisioningRequest Access (roles, entitlements, removals) and Manage Accounts
LCM Create and UpdateCreate Identity and Edit Identity
LCM Manage PasswordsPassword changes and resets on applications. By default it needs no manager or owner approval and emails the user.
LCM RegistrationSelf-service registration from the login page

The workflow-type table in the documentation lists LCM Provisioning (Lifecycle Manager provisioning tasks), LCM Identity (identity tasks such as LCM Create and Update), and LCM Registration as separate types.

These four, plus Identity Update, appear in the Basic View of the Business Process Editor. That is a form view of the most commonly changed process variables. The Advanced View exposes every variable and step. Workflow types matter: the drop-downs on configuration pages list only workflows of the matching type.

How LCM Provisioning Is Built

LCM Provisioning is a master workflow that calls subprocess workflows:

  1. Identity Request Initialize builds the IdentityRequest, compiles the plan into a project, and checks policies.
  2. Identity Request Violation Review lets the requester review policy violations when the policy scheme is interactive.
  3. Identity Request Approve, through the Provisioning Approval Subprocess, builds the approval set and creates approval work items.
  4. Do Provisioning Forms collects missing data (section 4.2).
  5. Identity Request Provision provisions the approved items, with retries through Provision with Retries.
  6. Identity Request Notify sends notifications.
  7. Identity Request Finalize completes the IdentityRequest record that powers request tracking.

Knowing this chain helps with troubleshooting. For example, a request that is stuck with no approval work item is a problem at the approval step, not a connector failure.

The Process Variables You Must Know

VariablePurposeTypical values
approvalSchemeWho must approvenone, manager, owner, securityOfficer, or a comma-separated combination such as manager,owner
approvalModeHow multiple approvers interactserial, serialPoll, parallel, parallelPoll, any
fallbackApproverReceives the approval when the resolved approver does not existCommonly initialized to spadmin
policySchemeWhat to do when the request causes policy violationsnone, continue, interactive, fail
notificationSchemeWho gets emailsFor example user,requester,manager,securityOfficer
securityOfficerNameThe identity used for the securityOfficer schemeAn identity or workgroup name
foregroundProvisioningProvision in the requester's session instead of in the backgroundtrue / false
optimisticProvisioningUpdate the identity cube as if provisioning succeeded, without waiting for aggregationtrue / false
enableRetryRequestAllow retries when a connector returns a retryable errortrue / false
traceWrite workflow trace output to the logtrue / false

Approval Modes in Detail

  • serial – approvers are asked one after another, and one rejection rejects the item.
  • serialPoll – one after another. All answers are collected, and AfterScript logic decides the outcome.
  • parallel – everyone is asked at once, and one rejection rejects the item.
  • parallelPoll – everyone at once. Answers are collected, and AfterScript logic decides.
  • any – everyone at once, and the first response decides for the group.

Policy Scheme and What Requesters See

The request-violation behaviors in the documentation map to the policy scheme: reject and cancel a request with violations, reject interactively (the requester can change or cancel it), allow non-interactively (the request proceeds without notice), or allow interactively (the requester can change, cancel, or continue, possibly with a required comment or sunset date).

What the Variables Look Like in XML

Process variables are <Variable> elements with an initializer. The initializer is used only when no value is passed in when the workflow starts:

<Variable name="approvalScheme" initializer="manager,owner" input="true"/>
<Variable name="approvalMode" initializer="serial" input="true"/>
<Variable name="policyScheme" initializer="interactive" input="true"/>
<Variable name="notificationScheme" initializer="user,requester" input="true"/>
<Variable name="trace" initializer="string:false"/>

The Basic View edits the same values through a form, so you rarely need XML for these changes.

Customizing Safely

  1. Copy, do not edit, the product workflow. Clone LCM Provisioning (for example, "ACME LCM Provisioning"). Out-of-the-box workflows are overwritten during upgrades (section 3.2).
  2. Change variables first, steps second. Most requirements, such as manager plus owner approval, parallel approvals, or failing on violations, are variable changes.
  3. Point LCM at the copy on the Business Processes tab.
  4. Test with trace on and email redirection (section 3.4), then turn trace off.
  5. Run it from the console if needed. workflow "LCM Provisioning" provFile.xml runs a workflow with variables from a file, and validate checks a workflow definition without running it (section 14.3).

Beyond LCM Requests

Other workflows are wired in elsewhere. Lifecycle events are set on the Lifecycle Events page (section 5.1). The Identity Update, Identity Refresh, and role-change processes are set in Global Settings > IdentityIQ Configuration (Identities, Roles, and Miscellaneous tabs). Value change workflows are set on identity attributes, and policy violation workflows are set on each policy.

Test Your Knowledge

A company wants every access request approved first by the requestee's manager and then by the application owner, with any rejection stopping the request. Which LCM Provisioning variable settings express this?

A

approvalScheme set to manager,owner and approvalMode set to serial

B

approvalScheme set to none and approvalMode set to any

C

notificationScheme set to manager,owner and policyScheme set to fail

D

approvalScheme set to securityOfficer and approvalMode set to parallelPoll

Test Your Knowledge

Which approval mode sends the item to all approvers at once and lets the first person who responds decide for the group?

A

serialPoll

B

parallelPoll

C

serial

D

any

Test Your Knowledge

An implementer customizes approval steps directly in the out-of-the-box LCM Provisioning workflow. What risk does this create?

A

The workflow can no longer be selected on the Business Processes tab.

B

A future IdentityIQ upgrade can overwrite the product workflow and remove the customization.

C

LCM Provisioning stops using the Identity Request subprocesses.

D

The workflow type changes to Subprocess.

Test Your Knowledge

A requester submits a role request that creates a separation-of-duties violation. The requester should be able to change, cancel, or continue the request. Which setting controls this behavior?

A

approvalMode

B

fallbackApprover

C

policyScheme set to interactive handling

D

foregroundProvisioning

Sections you finish are checked off in the contents.