Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Is it possible to let Saviynt Birthright role to trigger Access Request thru API

lihjong
New Contributor
New Contributor

Hi,

Currently in our user onboarding process, user’s manager will need to open access request after Saviynt create a new user account. There is an issue user may not have enough access in the day 1 If user’s manger delay or forget to open that access request.

I am trying to close that gap and hope Saviynt can automatically open access request after create a new account.

Do you think is it possible thru API call?

Thanks

Mark

 

7 REPLIES 7

PremMahadikar
Regular Contributor III
Regular Contributor III

Hi @lihjong ,

Yes, this is possible.

Follow the below steps:

1. Create a Technical rule where necessary conditions match from the user details to trigger this rule with configured actions (below in screenshot has both role and entitlement in action) Make sure you check box the 'Birthright' and 'Dectective'

PremMahadikar_3-1710449528799.png

2. Create job trigger which will trigger this technical rule and choose to schedule never to run by giving cron expression 0 0 22 1 1 ? 2099

PremMahadikar_5-1710449726993.png

3. Setup an API call to trigger this job {{URL}}/{{path}}/runJobTrigger 

{
    "jobgroup": "Utility",
    "triggername":"<Job trigger name>",
    "jobname": "DETECTIVEPROVISIONINGRULESJOB"
}

Once you trigger this API, this should run the technical rule and assign birthright access to the user.

 

If this answers your question, please consider selecting Accept As Solution and hit Kudos

Prem,

Thanks your detail information. I will try it.

Thanks your help again.

Mark

Prem,

I discussed your solution with my Saviynt engineer and he said "this is a solution to trigger the BR rule via the Saviynt API. not the other way around".  I think we want BR rule can call Access Request API so Saviynt can automatically generate a request ticket and then that ticket still can follow workflow process so additional approver can still approve that ticket before Saviynt add user into AD group.

Do you think is it possible?

Thanks

Mark

PremMahadikar
Regular Contributor III
Regular Contributor III

@lihjong ,

BR rule calling access request API, this is not possible in Saviynt.

 

ok Thanks.. so there is no way to resolve my issue?

Mark

use custom jar


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Prem's solution not work. Still want to see if there is other solution,

Thanks

Mark