# Filter for Provisioning Completed trigger workflow

**URL:** <https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259>\
**Category:** SHF Discussion and Questions\
**Tags:** webservice-connector, workflows, identity-security-cloud\
**Created:** [November 19, 2024, 9:06pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259 "2024-11-19T21:06:43Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasmedina](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jasmedina](https://developer.sailpoint.com/discuss/u/jasmedina)\
**Post date:** [November 19, 2024, 9:06pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/1 "2024-11-19T21:06:43Z")

</div>

Hi All,

We have a requirement to send an email to the admins once a specific entitlement has been added to the user via access request. For our workflow, we are using the Provisioning Completed trigger for this. What would be the filter query to only filter out that specific entitlement from a given source?

This is my initial filter but was not successful in triggering the workflow

> $.accountRequests[?( @.provisioningResult == ‘SUCCESS’ && @.source.name ==‘Source\_name’)].attributeRequests[?(@.operation == ‘Add’ && @.attributeValue == ‘Entitlement\_Name’ )]

---

<div class="post-metadata">

**Author:** ![vkashat](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vkashat/32/9721_2.png) [@vkashat](https://developer.sailpoint.com/discuss/u/vkashat)\
**Post date:** [November 19, 2024, 10:29pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/2 "2024-11-19T22:29:37Z")

</div>

Hi @jasmedina !

So I looked at the documentation of the workflow triggers and using the Provisioning Completed sample JSON (updated with the simpler test values you used in your example), I have this JSON:

```auto
{
    "trackingNumber":"4b4d982dddff4267ab12f0f1e72b5a6d",
    "action":"IdentityRefresh",
    "requester":{
        "id":"2c91808b6ef1d43e016efba0ce470906",
        "name":"Adam Admin",
        "type":"IDENTITY"
    },
    "recipient":{
        "id":"2c91808b6ef1d43e016efba0ce470909",
        "name":"Ed Engineer",
        "type":"IDENTITY"
    },
    "errors":[
        "General Error",
        "Connector AD Failed"
    ],
    "warnings":[
        "Notification Skipped due to invalid email"
    ],
    "sources":"Corp AD, Corp LDAP, Corp Salesforce",
    "accountRequests":[
        {
            "source":{
                "id":"4e4d982dddff4267ab12f0f1e72b5a6d",
                "name":"Source_name",
                "type":"SOURCE"
            },
            "accountId":"CN=example,ou=sample,ou=test,dc=ex,dc=com",
            "accountOperation":"Modify",
            "provisioningResult":"committed",
            "provisioningTarget":"Corp AD",
            "ticketId":"72619262",
            "attributeRequests":[
                {
                    "operation":"Add",
                    "attributeName":"memberOf",
                    "attributeValue":"Entitlement_Name"
                }
            ]
        }
    ]
}

```

I used this filter expression:

```auto
$.accountRequests[?(@.source.name == "Source_name" && @.provisioningResult == "committed" && @.attributeRequests[0].operation == "Add" && @.attributeRequests[0].attributeValue== "Entitlement_Name")]

```

It seems to work, I’m using the JSON path evaluator at this link: [SailPoint Developer Community](https://developer.sailpoint.com/tools/json-path-evaluator/)

Hope that helps!

---

<div class="post-metadata">

**Author:** ![jasmedina](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jasmedina](https://developer.sailpoint.com/discuss/u/jasmedina)\
**Post date:** [November 21, 2024, 8:49am UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/3 "2024-11-21T08:49:00Z")

</div>

Hi @vkashat! Tried this but didn’t work. Also tried to substitute the Entitlement\_Name to Access\_Profile\_Name as we are trying to provision the access profile, but it also didn’t work

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [November 21, 2024, 12:57pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/4 "2024-11-21T12:57:30Z")

</div>

Hi @jasmedina,

Try adding a “committed” also to your result status check and see if it works.

`$.accountRequests[?((@.provisioningResult == 'committed' || @.provisioningResult == "SUCCESS") && @.source.name =='Source_name')].attributeRequests[?(@.operation == 'Add' && @.attributeValue == 'Entitlement_Name')]`

---

<div class="post-metadata">

**Author:** ![liamkokeeffe](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/liamkokeeffe/32/29279_2.png) [@liamkokeeffe](https://developer.sailpoint.com/discuss/u/liamkokeeffe)\
**Post date:** [November 21, 2024, 3:31pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/5 "2024-11-21T15:31:37Z")

</div>

Hi @jasmedina,

We have a similar requirement and are using the below JSON filter.

```auto
$.accountRequests[*].attributeRequests[?(@.source.name == "<Source_Name>" && @.operation == "Add" && @.attributeValue == "<Entitlement_Value>")]

```

Let me know if that works!

Thanks,

Liam

---

<div class="post-metadata">

**Author:** ![jasmedina](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jasmedina](https://developer.sailpoint.com/discuss/u/jasmedina)\
**Post date:** [November 21, 2024, 6:26pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/6 "2024-11-21T18:26:48Z")

</div>

> [@liamkokeeffe](#):
>
> ```auto
> $.accountRequests[*].attributeRequests[?(@.source.name == "<Source_Name>" && @.operation == "Add" && @.attributeValue == "<Entitlement_Value>")]
> 
> ```

Hi Liam, tried this but also didnt work. Conrollership\_Interactor\_testing entitlement is inside an access profile

` $.accountRequests[*].attributeRequests[?(@.source.name == 'XXX - XXX Training Site' && @.operation == 'Add' && @.attributeValue == 'Controllership_Interactor_testing')]`

---

<div class="post-metadata">

**Author:** ![jasmedina](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jasmedina](https://developer.sailpoint.com/discuss/u/jasmedina)\
**Post date:** [November 21, 2024, 6:27pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/7 "2024-11-21T18:27:02Z")

</div>

This didnt trigger either ☹

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [November 21, 2024, 7:47pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/8 "2024-11-21T19:47:32Z")

</div>

Can you share the output from the trigger step when you tested the workflow?

---

<div class="post-metadata">

**Author:** ![liamkokeeffe](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/liamkokeeffe/32/29279_2.png) [@liamkokeeffe](https://developer.sailpoint.com/discuss/u/liamkokeeffe)\
**Post date:** [November 22, 2024, 12:38am UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/9 "2024-11-22T00:38:25Z")

</div>

Hi Medina,

On the entitlement schema, is Controllership\_Interactor\_testing the entitlement nativeIdentity? In other words, is it set as the id of the object and **not** the display name?

Thanks,

Liam

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [November 22, 2024, 1:10pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/10 "2024-11-22T13:10:08Z")

</div>

Hi @jasmedina,

Here is what you could try to troubleshoot this :

1. Create a simple WF as below (No filter in the trigger)

2. In the HTTP Action, setup a [webhook](https://webhook.site/#!/view/e19f406d-2fa2-4f9e-a60f-7de76b924fcf) call with the body JSON as `$.trigger`

3. Submit a test request with the expected outcome and check the webhook response.

4. Use the JSON path [evaluator](https://developer.sailpoint.com/tools/json-path-evaluator/) on the output to get your correct filter.

---

<div class="post-metadata">

**Author:** ![sagar\_kamalakar](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sagar_kamalakar/32/18893_2.png) [@sagar\_kamalakar](https://developer.sailpoint.com/discuss/u/sagar_kamalakar)\
**Post date:** [November 22, 2024, 5:18pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/11 "2024-11-22T17:18:04Z")

</div>

@jasmedina  
try like this

```auto
$.accountRequests[?(@.source.name == "Corporate Active Directory" && @.provisioningResult == "committed" && @.attributeRequests[0].operation== "Add" &&@.attributeRequests[0].attributeName== "memberOf" && @.attributeRequests[0].attributeValue== "CN=admin,DC=training,DC=com")]

```

Update your sourceName, attributeName and attributeValue. If it won’t work. can you share your trigger output?

---

<div class="post-metadata">

**Author:** ![jasmedina](https://avatars.discourse-cdn.com/v4/letter/j/9de0a6/32.png) [@jasmedina](https://developer.sailpoint.com/discuss/u/jasmedina)\
**Post date:** [November 26, 2024, 3:07pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/12 "2024-11-26T15:07:57Z")

</div>

I was able to trigger the workflow using this filter:

`$.accountRequests[?(@.source.name == "sourceName" && @.provisioningResult == "committed" && (@.attributeRequests[0].operation== "Add" || @.attributeRequests[0].operation== "Modify") && @.attributeRequests[0].attributeValue== "cb13e125-acfc-436f-a7d0-5274c7cf59dd")]`

Is there any way to set the filter attributeValue to the access profile name?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [January 25, 2025, 3:07pm UTC](https://developer.sailpoint.com/discuss/t/filter-for-provisioning-completed-trigger-workflow/90259/13 "2025-01-25T15:07:57Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
