4.3 Configuring LCM Workflows
Key Takeaways
The default LCM business processes are LCM Provisioning, LCM Create and Update, LCM Manage Passwords, and LCM Registration.
LCM Provisioning runs the Identity Request Initialize, Violation Review, Approve, Provision, Notify, and Finalize subprocesses, plus the Provisioning Approval Subprocess.
approvalScheme chooses who approves (for example manager, owner, securityOfficer, or none), and approvalMode chooses how several approvers act (serial, serialPoll, parallel, parallelPoll, or any).
policyScheme decides how policy violations found during a request are handled, and notificationScheme decides who is emailed.
Copy an out-of-the-box workflow under a new name and select the copy on the Business Processes tab, because upgrades overwrite product workflows.
Configuring LCM Workflows
Objective 2.3 is configure LCM workflows. In IdentityIQ, workflow and business process mean the same thing. The UI says "business process," and implementers working with the object model say "workflow." Each Lifecycle Manager action launches the workflow selected for it on gear icon > Lifecycle Manager > Business Processes.
The Default LCM Workflows
| Workflow | Handles |
|---|---|
| LCM Provisioning | Request Access (roles, entitlements, removals) and Manage Accounts |
| LCM Create and Update | Create Identity and Edit Identity |
| LCM Manage Passwords | Password changes and resets on applications. By default it needs no manager or owner approval and emails the user. |
| LCM Registration | Self-service registration from the login page |
The workflow-type table in the documentation lists LCM Provisioning (Lifecycle Manager provisioning tasks), LCM Identity (identity tasks such as LCM Create and Update), and LCM Registration as separate types.
These four, plus Identity Update, appear in the Basic View of the Business Process Editor. That is a form view of the most commonly changed process variables. The Advanced View exposes every variable and step. Workflow types matter: the drop-downs on configuration pages list only workflows of the matching type.
How LCM Provisioning Is Built
LCM Provisioning is a master workflow that calls subprocess workflows:
- Identity Request Initialize builds the IdentityRequest, compiles the plan into a project, and checks policies.
- Identity Request Violation Review lets the requester review policy violations when the policy scheme is interactive.
- Identity Request Approve, through the Provisioning Approval Subprocess, builds the approval set and creates approval work items.
- Do Provisioning Forms collects missing data (section 4.2).
- Identity Request Provision provisions the approved items, with retries through Provision with Retries.
- Identity Request Notify sends notifications.
- Identity Request Finalize completes the IdentityRequest record that powers request tracking.
Knowing this chain helps with troubleshooting. For example, a request that is stuck with no approval work item is a problem at the approval step, not a connector failure.
The Process Variables You Must Know
| Variable | Purpose | Typical values |
|---|---|---|
approvalScheme | Who must approve | none, manager, owner, securityOfficer, or a comma-separated combination such as manager,owner |
approvalMode | How multiple approvers interact | serial, serialPoll, parallel, parallelPoll, any |
fallbackApprover | Receives the approval when the resolved approver does not exist | Commonly initialized to spadmin |
policyScheme | What to do when the request causes policy violations | none, continue, interactive, fail |
notificationScheme | Who gets emails | For example user,requester,manager,securityOfficer |
securityOfficerName | The identity used for the securityOfficer scheme | An identity or workgroup name |
foregroundProvisioning | Provision in the requester's session instead of in the background | true / false |
optimisticProvisioning | Update the identity cube as if provisioning succeeded, without waiting for aggregation | true / false |
enableRetryRequest | Allow retries when a connector returns a retryable error | true / false |
trace | Write workflow trace output to the log | true / false |
Approval Modes in Detail
- serial – approvers are asked one after another, and one rejection rejects the item.
- serialPoll – one after another. All answers are collected, and AfterScript logic decides the outcome.
- parallel – everyone is asked at once, and one rejection rejects the item.
- parallelPoll – everyone at once. Answers are collected, and AfterScript logic decides.
- any – everyone at once, and the first response decides for the group.
Policy Scheme and What Requesters See
The request-violation behaviors in the documentation map to the policy scheme: reject and cancel a request with violations, reject interactively (the requester can change or cancel it), allow non-interactively (the request proceeds without notice), or allow interactively (the requester can change, cancel, or continue, possibly with a required comment or sunset date).
What the Variables Look Like in XML
Process variables are <Variable> elements with an initializer. The initializer is used only when no value is passed in when the workflow starts:
<Variable name="approvalScheme" initializer="manager,owner" input="true"/>
<Variable name="approvalMode" initializer="serial" input="true"/>
<Variable name="policyScheme" initializer="interactive" input="true"/>
<Variable name="notificationScheme" initializer="user,requester" input="true"/>
<Variable name="trace" initializer="string:false"/>
The Basic View edits the same values through a form, so you rarely need XML for these changes.
Customizing Safely
- Copy, do not edit, the product workflow. Clone LCM Provisioning (for example, "ACME LCM Provisioning"). Out-of-the-box workflows are overwritten during upgrades (section 3.2).
- Change variables first, steps second. Most requirements, such as manager plus owner approval, parallel approvals, or failing on violations, are variable changes.
- Point LCM at the copy on the Business Processes tab.
- Test with trace on and email redirection (section 3.4), then turn trace off.
- Run it from the console if needed.
workflow "LCM Provisioning" provFile.xmlruns a workflow with variables from a file, andvalidatechecks a workflow definition without running it (section 14.3).
Beyond LCM Requests
Other workflows are wired in elsewhere. Lifecycle events are set on the Lifecycle Events page (section 5.1). The Identity Update, Identity Refresh, and role-change processes are set in Global Settings > IdentityIQ Configuration (Identities, Roles, and Miscellaneous tabs). Value change workflows are set on identity attributes, and policy violation workflows are set on each policy.
A company wants every access request approved first by the requestee's manager and then by the application owner, with any rejection stopping the request. Which LCM Provisioning variable settings express this?
approvalScheme set to manager,owner and approvalMode set to serial
approvalScheme set to none and approvalMode set to any
notificationScheme set to manager,owner and policyScheme set to fail
approvalScheme set to securityOfficer and approvalMode set to parallelPoll
Which approval mode sends the item to all approvers at once and lets the first person who responds decide for the group?
serialPoll
parallelPoll
serial
any
An implementer customizes approval steps directly in the out-of-the-box LCM Provisioning workflow. What risk does this create?
The workflow can no longer be selected on the Business Processes tab.
A future IdentityIQ upgrade can overwrite the product workflow and remove the customization.
LCM Provisioning stops using the Identity Request subprocesses.
The workflow type changes to Subprocess.
A requester submits a role request that creates a separation-of-duties violation. The requester should be able to change, cancel, or continue the request. Which setting controls this behavior?
approvalMode
fallbackApprover
policyScheme set to interactive handling
foregroundProvisioning
Sections you finish are checked off in the contents.