User Lifecycle Rules
A UserLifecycleRule represents a rule that applies to users based on their inactivity, state and authentication method.
The rule either disable or delete users who have been inactive or disabled for a specified number of days.
The authentication_method property specifies the authentication method for the rule, which can be set to "all", "all_non_sso", or a specific authentication method.
The rule can also include or exclude site and folder admins from the action.
A Custom Workspace rule applies only to users who belong to that Workspace. Default Workspace users with access to a Custom Workspace, including Workspace Administrators, remain covered by Default Workspace rules.
List User Lifecycle Rules
SDK Function
UserLifecycleRule.list()
Return Object
ListIterator<UserLifecycleRule>
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator, a Workspace Administrator for the relevant workspace, or a Partner Administrator for the relevant partner.
Additional Arguments
Show User Lifecycle Rule
SDK Function
UserLifecycleRule.find()
Return Object
UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator, a Workspace Administrator for the relevant workspace, or a Partner Administrator for the relevant partner.
Function Arguments
| Argument | Description |
|---|---|
| id int64 Required | User Lifecycle Rule ID. |
Create User Lifecycle Rule
SDK Function
UserLifecycleRule.create()
Return Object
UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.
Function Arguments
| Argument | Default | Description |
|---|---|---|
| apply_to_all_workspaces boolean | false | If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0. |
| authentication_method string | User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso | |
| group_ids array(int64) | Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users. | |
| inactivity_days int64 | Number of days of inactivity before the rule applies | |
| include_site_admins boolean | false | If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0. |
| include_folder_admins boolean | false | If true, the rule will apply to folder admins. |
| name string | User Lifecycle Rule name | |
| notify_users boolean | false | If true, users will be emailed before the rule disables or deletes them. |
| partner_tag string | If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. | |
| user_state string | "inactive" | State of the users to apply the rule to (inactive or disabled) Possible values: inactive, disabled |
| user_tag string | If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. | |
| workspace_id int64 | 0 | Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users. |
Update User Lifecycle Rule
SDK Function
userLifecycleRule.update();
Return Object
UserLifecycleRule
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.
Attribute Setters
| Setter | Description |
|---|---|
| setApplyToAllWorkspaces boolean | If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0. |
| setAuthenticationMethod string | User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso |
| setGroupIds array(int64) | Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users. |
| setInactivityDays int64 | Number of days of inactivity before the rule applies |
| setIncludeSiteAdmins boolean | If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0. |
| setIncludeFolderAdmins boolean | If true, the rule will apply to folder admins. |
| setName string | User Lifecycle Rule name |
| setNotifyUsers boolean | If true, users will be emailed before the rule disables or deletes them. |
| setPartnerTag string | If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |
| setUserState string | State of the users to apply the rule to (inactive or disabled) Possible values: inactive, disabled |
| setUserTag string | If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |
| setWorkspaceId int64 | Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users. |
Delete User Lifecycle Rule
SDK Function
userLifecycleRule.delete();
Return Object
No return value.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator or a Workspace Administrator for the relevant workspace.
The UserLifecycleRule Object
Some of the functions above return a UserLifecycleRule object. The attributes of this object are listed below.
| Attribute | Description |
|---|---|
| id int64 | User Lifecycle Rule ID |
| authentication_method string | User authentication method for which the rule will apply. Use all_non_sso to target every non-SSO authentication method with one rule.Possible values: all, password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key, all_non_sso |
| group_ids array(int64) | Array of Group IDs to which the rule applies. If empty or not set, the rule applies to all users. |
| action string | Action to take on inactive users (disable or delete) Possible values: disable, delete |
| inactivity_days int64 | Number of days of inactivity before the rule applies |
| include_folder_admins boolean | If true, the rule will apply to folder admins. |
| include_site_admins boolean | If true, the rule includes Site Administrators, who always belong to the Default Workspace. Can only be enabled when workspace_id is 0. |
| apply_to_all_workspaces boolean | If true, a Default Workspace rule also applies to users in all Custom Workspaces. Can only be enabled when workspace_id is 0. |
| name string | User Lifecycle Rule name |
| notify_users boolean | If true, users will be emailed before the rule disables or deletes them. |
| partner_tag string | If provided, only users belonging to Partners with this tag at the Partner level will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |
| site_id int64 | Site ID |
| workspace_id int64 | Workspace whose users the rule applies to. 0 means the Default Workspace. A Custom Workspace rule applies only to users who belong to that Workspace, regardless of access granted to other users. |
| user_state string | State of the users to apply the rule to (inactive or disabled) Possible values: inactive, disabled |
| user_tag string | If provided, only users with this tag will be affected by the rule. Tags must only contain lowercase letters, numbers, and hyphens. |