User Lifecycle Rules
A UserLifecycleRule represents a rule that applies to users based on their inactivity, state and authentication method.
The rule either disable or delete users who have been inactive or disabled for a specified number of days.
The authentication_method property specifies the authentication method for the rule, which can be set to "all", "all_non_sso", or a specific authentication method.
The rule can also include or exclude site and folder admins from the action.
A Custom Workspace rule applies only to users who belong to that Workspace. Default Workspace users with access to a Custom Workspace, including Workspace Administrators, remain covered by Default Workspace rules.
List User Lifecycle Rules
SDK Method
userlifecyclerule.List()
Return Object
[]*UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator, a Workspace Administrator for the relevant workspace, or a Partner Administrator for the relevant partner.
Additional Arguments
Show User Lifecycle Rule
SDK Method
userlifecyclerule.Find()
Return Object
UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator, a Workspace Administrator for the relevant workspace, or a Partner Administrator for the relevant partner.
UserLifecycleRuleFindParams Fields
| Field | Description |
|---|---|
| Id int64 Required | User Lifecycle Rule ID. |
Create User Lifecycle Rule
SDK Method
userlifecyclerule.Create()
Return Object
UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.
UserLifecycleRuleCreateParams Fields
| Field | Default | Description |
|---|---|---|
| ApplyToAllWorkspaces boolean | false | If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0. |
| AuthenticationMethod string | User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso | |
| GroupIds array(int64) | Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users. | |
| InactivityDays int64 | Number of days of inactivity before the rule applies | |
| IncludeSiteAdmins boolean | false | If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0. |
| IncludeFolderAdmins boolean | false | If true, the rule will apply to folder admins. |
| Name string | User Lifecycle Rule name | |
| NotifyUsers boolean | false | If true, users will be emailed before the rule disables or deletes them. |
| PartnerTag string | If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. | |
| UserState string | "inactive" | State of the users to apply the rule to (inactive or disabled) Possible values: inactive, disabled |
| UserTag string | If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. | |
| WorkspaceId int64 | 0 | Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users. |
Update User Lifecycle Rule
SDK Method
userlifecyclerule.Update()
Return Object
UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.
UserLifecycleRuleUpdateParams Fields
| Field | Description |
|---|---|
| Id int64 Required | User Lifecycle Rule ID. |
| ApplyToAllWorkspaces boolean | If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0. |
| AuthenticationMethod string | User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso |
| GroupIds array(int64) | Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users. |
| InactivityDays int64 | Number of days of inactivity before the rule applies |
| IncludeSiteAdmins boolean | If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0. |
| IncludeFolderAdmins boolean | If true, the rule will apply to folder admins. |
| Name string | User Lifecycle Rule name |
| NotifyUsers boolean | If true, users will be emailed before the rule disables or deletes them. |
| PartnerTag string | If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |
| UserState string | State of the users to apply the rule to (inactive or disabled) Possible values: inactive, disabled |
| UserTag string | If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |
| WorkspaceId int64 | Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users. |
Delete User Lifecycle Rule
SDK Method
userlifecyclerule.Delete()
Return Object
No return value.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.
UserLifecycleRuleDeleteParams Fields
| Field | Description |
|---|---|
| Id int64 Required | User Lifecycle Rule ID. |
The UserLifecycleRule Object
Some of the methods above return a UserLifecycleRule object. The attributes of this object are listed below.
| Attribute | Description |
|---|---|
| Id int64 | User Lifecycle Rule ID |
| AuthenticationMethod string | User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso |
| GroupIds array(int64) | Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users. |
| Action string | Action to take on inactive users (disable or delete) Possible values: disable, delete |
| InactivityDays int64 | Number of days of inactivity before the rule applies |
| IncludeFolderAdmins boolean | If true, the rule will apply to folder admins. |
| IncludeSiteAdmins boolean | If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0. |
| ApplyToAllWorkspaces boolean | If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0. |
| Name string | User Lifecycle Rule name |
| NotifyUsers boolean | If true, users will be emailed before the rule disables or deletes them. |
| PartnerTag string | If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |
| SiteId int64 | Site ID |
| WorkspaceId int64 | Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users. |
| UserState string | State of the users to apply the rule to (inactive or disabled) Possible values: inactive, disabled |
| UserTag string | If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |