Create a Condition
You can create or remove conditions, however you cannot change a condition. To make an update to a condition, you would create a new condition and deactivate the old one.
Conditions can only be added and removed from rules that are in a staged state. Once a rule is activated,
it is effectively locked in place and conditions cannot be modified. However, you can still create a duplicate
rule with the desired conditions and deprecate or deactivate the old one (flexible versioning).
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Policy Rule ID
Body
CreatePolicyConditionData
attribute, identity, manager, user, unmanaged ^dratr_[0-9a-hjkmnp-tv-z]{26}$"dratr_01hq8xyzabc123def456ghi789"
^drusr_[0-9a-hjkmnp-tv-z]{26}$"drusr_01hq8xyzabc123def456ghi789"
The ID of the integration for identity-type conditions (polymorphic)
The type of the integration for identity-type conditions (polymorphic)
^drusr_[0-9a-hjkmnp-tv-z]{26}$"drusr_01hq8xyzabc123def456ghi789"
The array key in the Directory Identity profile to check. This is the same as the profile_key for the dimension
55The calculation comparison operator when evaluating the profile_value
equals, not, empty, exists, greater, less, prefix, suffix, contains The array value in the Directory Identity profile to match against
255Response
PolicyConditionDetailedResponseData
"pocon_01hq8xyzabc123def456ghi789"
Whether this condition was created automatically when a Workspace Integration attribute was imported. If false, the condition was created manually by an administrator
The type of condition that this policy condition represents
attribute, identity, manager, user, unmanaged The ID of the resource based on the type of condition
"dratr_01hq8xyzabc123def456ghi789"
"drusr_01hq8xyzabc123def456ghi789"
"wsitg_01hq8xyzabc123def456ghi789"
The reference key for the condition based on its type. Except for identity type conditions, condition matching uses database relationships based on the resource ID (not string matching). This value is fetched in real time based on the resource ID for human readability (not stored in condition database table).
identity: Identity profile array raw key that is used for string matching. This is usually the same as theprofile_keyon a dimension.attribute: Name of Directory Dimension that the attribute is associated with.manager: nulluser: null
"department"
"Department"
The operator for the condition based on its type. All conditions are case insensitive and are converted to lowercase for matching
equals, not, empty, exists, greater, less, prefix, suffix, contains "equals"
The reference value for the condition based on its type. Except for identity type conditions, condition matching uses database relationships based on the resource ID (not string matching). This value is fetched in real time based on the resource ID for human readability (not stored in condition database table).
identity: Identity profile array raw value that is used for string matchingattribute: Name of the Directory Attribute for the respective Dimensionmanager: Full name of the manager useruser: Full name of the user
"IT Helpdesk"
"IT Helpdesk"
"Kate Libby"
"Dade Murphy"
A human readable description of the condition
The timestamps for the policy condition record
Count of related resources
Included related resources
API hyperlinks related to the policy condition record