We are working on a integration where SailPoint (version 8.2) receives access requests from user and needs to send provisioning request to RPA such that RPA can provision accounts on the end target systems. We would like to know if SailPoint already has exposed REST endpoints or do we need to build a custom endpoint ? Are there any guides having step by step instructions? Any pointers would be helpful
If you want to provision accounts on Target systems , you can configure Webservice Application within Sailpoint and can configure the rest endpoints for the operations like Account Aggregation, Group Aggregation , Create Account etc., offered by Target System
Connector is there in its core of IIQ provisioning engine. There is no such REST endpoint to trigger an provisioning operation like create, modify, delete etc. except launching OOTB workflow ‘LCM Provisioning’ through REST API.
Not sure about your solution design but it looks like IIQ--> RPA--> IIQ. So, question is why RPA is in the middle if eventually IIQ is going auto fulfill provisioning requests.
Secondly, how are applications configured in IIQ? If some integration config represents your RPA engine and apps are part of that, then you would be losing direct provisioning capability of the connector (type of the app) which you wanted to leverage from RPA in IIQ.
You can pass anything you want to any workflow, including a custom one, this way.
In your scenario, since the behavior you want is fairly customized, you probably will want a custom workflow that takes inputs specific to your process, transforms them into an appropriate provisioning plan or other action, and executes it.
Any variable tagged as an “output” in a Workflow will be returned from this REST API call, allowing you to return responses to the caller.
Note that an API user who has the rights to launch a Workflow can launch *any* Workflow. You cannot restrict this.
The third option (my preference) is to create a plugin. Plugins make it trivial to write standard JAX-RS web service Java classes that can do anything you want, with custom security. See the plugin framework documentations and training for details.