User Lifecycle Rules

A UserLifecycleRule represents a rule that applies to users based on their inactivity, state and authentication method.

The rule either disable or delete users who have been inactive or disabled for a specified number of days.

The authentication_method property specifies the authentication method for the rule, which can be set to "all", "all_non_sso", or a specific authentication method.

The rule can also include or exclude site and folder admins from the action.

A Custom Workspace rule applies only to users who belong to that Workspace. Default Workspace users with access to a Custom Workspace, including Workspace Administrators, remain covered by Default Workspace rules.

List User Lifecycle Rules

Command

files-cli user-lifecycle-rules list

Output

Outputs a list of UserLifecycleRule objects according to the output format.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator, a Workspace Administrator for the relevant workspace, or a Partner Administrator for the relevant partner.

Additional Arguments

Example Request

files-cli user-lifecycle-rules list

Show User Lifecycle Rule

Command

files-cli user-lifecycle-rules find

Output

Outputs a UserLifecycleRule object according to the output format.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator, a Workspace Administrator for the relevant workspace, or a Partner Administrator for the relevant partner.

Flags

FlagDescription
--id=
int64
Required
User Lifecycle Rule ID.

Example Request

files-cli user-lifecycle-rules find \
  --id=1

Create User Lifecycle Rule

Command

files-cli user-lifecycle-rules create

Output

Outputs a UserLifecycleRule object according to the output format.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.

Flags

FlagDefaultDescription
--apply-to-all-workspaces
boolean
falseIf true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0.
--authentication-method=
string
User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.
Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso
--group-ids=
array(int64)
Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users.
--inactivity-days=
int64
Number of days of inactivity before the rule applies
--include-site-admins
boolean
falseIf true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0.
--include-folder-admins
boolean
falseIf true, the rule will apply to folder admins.
--name=
string
User Lifecycle Rule name
--notify-users
boolean
falseIf true, users will be emailed before the rule disables or deletes them.
--partner-tag=
string
If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--user-state=
string
"inactive"State of the users to apply the rule to (inactive or disabled)
Possible values: inactive, disabled
--user-tag=
string
If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--workspace-id=
int64
0Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users.

Example Request

files-cli user-lifecycle-rules create

Update User Lifecycle Rule

Command

files-cli user-lifecycle-rules update

Output

Outputs a UserLifecycleRule object according to the output format.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.

Flags

FlagDescription
--id=
int64
Required
User Lifecycle Rule ID.
--apply-to-all-workspaces
boolean
If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0.
--authentication-method=
string
User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.
Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso
--group-ids=
array(int64)
Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users.
--inactivity-days=
int64
Number of days of inactivity before the rule applies
--include-site-admins
boolean
If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0.
--include-folder-admins
boolean
If true, the rule will apply to folder admins.
--name=
string
User Lifecycle Rule name
--notify-users
boolean
If true, users will be emailed before the rule disables or deletes them.
--partner-tag=
string
If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--user-state=
string
State of the users to apply the rule to (inactive or disabled)
Possible values: inactive, disabled
--user-tag=
string
If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--workspace-id=
int64
Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users.

Example Request

files-cli user-lifecycle-rules update \
  --id=1

Delete User Lifecycle Rule

Command

files-cli user-lifecycle-rules delete

Output

No output is returned.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.

Flags

FlagDescription
--id=
int64
Required
User Lifecycle Rule ID.

Example Request

files-cli user-lifecycle-rules delete \
  --id=1

The UserLifecycleRule Object

Some of the commands above return a UserLifecycleRule object. The attributes of this object are listed below.

AttributeDescription
id
int64
User Lifecycle Rule ID
authentication_method
string
User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.
Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso
group_ids
array(int64)
Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users.
action
string
Action to take on inactive users (disable or delete)
Possible values: disable, delete
inactivity_days
int64
Number of days of inactivity before the rule applies
include_folder_admins
boolean
If true, the rule will apply to folder admins.
include_site_admins
boolean
If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0.
apply_to_all_workspaces
boolean
If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0.
name
string
User Lifecycle Rule name
notify_users
boolean
If true, users will be emailed before the rule disables or deletes them.
partner_tag
string
If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
site_id
int64
Site ID
workspace_id
int64
Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users.
user_state
string
State of the users to apply the rule to (inactive or disabled)
Possible values: inactive, disabled
user_tag
string
If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.