User Lifecycle Rules

A UserLifecycleRule represents a rule that applies to users based on their inactivity, state and authentication method.

The rule either disable or delete users who have been inactive or disabled for a specified number of days.

The authentication_method property specifies the authentication method for the rule, which can be set to "all", "all_non_sso", or a specific authentication method.

The rule can also include or exclude site and folder admins from the action.

List User Lifecycle Rules

Command

files-cli user-lifecycle-rules list

Output

Outputs a list of UserLifecycleRule objects according to the output format.

Authorization Requirement

Available to all authenticated keys or sessions.

Additional Arguments

Example Request

files-cli user-lifecycle-rules list

Show User Lifecycle Rule

Command

files-cli user-lifecycle-rules find

Output

Outputs a UserLifecycleRule object according to the output format.

Authorization Requirement

Available to all authenticated keys or sessions.

Flags

FlagDescription
--id=
int64
Required
User Lifecycle Rule ID.

Example Request

files-cli user-lifecycle-rules find \
  --id=1

Create User Lifecycle Rule

Command

files-cli user-lifecycle-rules create

Output

Outputs a UserLifecycleRule object according to the output format.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDefaultDescription
--apply-to-all-workspaces
boolean
falseIf true, a default-workspace rule also applies to users in all workspaces.
--authentication-method=
string
User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.
Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso
--group-ids=
array(int64)
Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users.
--inactivity-days=
int64
Number of days of inactivity before the rule applies
--include-site-admins
boolean
falseIf true, the rule will apply to site admins.
--include-folder-admins
boolean
falseIf true, the rule will apply to folder admins.
--name=
string
User Lifecycle Rule name
--notify-users
boolean
falseIf true, users will be emailed before the rule disables or deletes them.
--partner-tag=
string
If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--user-state=
string
"inactive"State of the users to apply the rule to (inactive or disabled)
Possible values: inactive, disabled
--user-tag=
string
If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--workspace-id=
int64
0Workspace ID. 0 means the default workspace.

Example Request

files-cli user-lifecycle-rules create

Update User Lifecycle Rule

Command

files-cli user-lifecycle-rules update

Output

Outputs a UserLifecycleRule object according to the output format.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDescription
--id=
int64
Required
User Lifecycle Rule ID.
--apply-to-all-workspaces
boolean
If true, a default-workspace rule also applies to users in all workspaces.
--authentication-method=
string
User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.
Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso
--group-ids=
array(int64)
Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users.
--inactivity-days=
int64
Number of days of inactivity before the rule applies
--include-site-admins
boolean
If true, the rule will apply to site admins.
--include-folder-admins
boolean
If true, the rule will apply to folder admins.
--name=
string
User Lifecycle Rule name
--notify-users
boolean
If true, users will be emailed before the rule disables or deletes them.
--partner-tag=
string
If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--user-state=
string
State of the users to apply the rule to (inactive or disabled)
Possible values: inactive, disabled
--user-tag=
string
If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
--workspace-id=
int64
Workspace ID. 0 means the default workspace.

Example Request

files-cli user-lifecycle-rules update \
  --id=1

Delete User Lifecycle Rule

Command

files-cli user-lifecycle-rules delete

Output

No output is returned.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDescription
--id=
int64
Required
User Lifecycle Rule ID.

Example Request

files-cli user-lifecycle-rules delete \
  --id=1

The UserLifecycleRule Object

Some of the commands above return a UserLifecycleRule object. The attributes of this object are listed below.

AttributeDescription
id
int64
User Lifecycle Rule ID
authentication_method
string
User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.
Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso
group_ids
array(int64)
Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users.
action
string
Action to take on inactive users (disable or delete)
Possible values: disable, delete
inactivity_days
int64
Number of days of inactivity before the rule applies
include_folder_admins
boolean
If true, the rule will apply to folder admins.
include_site_admins
boolean
If true, the rule will apply to site admins.
apply_to_all_workspaces
boolean
If true, a default-workspace rule also applies to users in all workspaces.
name
string
User Lifecycle Rule name
notify_users
boolean
If true, users will be emailed before the rule disables or deletes them.
partner_tag
string
If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.
site_id
int64
Site ID
workspace_id
int64
Workspace ID. 0 means the default workspace.
user_state
string
State of the users to apply the rule to (inactive or disabled)
Possible values: inactive, disabled
user_tag
string
If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens.