# Help with Transform logic

**URL:** <https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536>\
**Category:** SHF Discussion and Questions\
**Tags:** transforms, identity-security-cloud\
**Created:** [November 6, 2023, 7:47pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536 "2023-11-06T19:47:04Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mpotti](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mpotti/32/2916_2.png) [@mpotti](https://developer.sailpoint.com/discuss/u/mpotti)\
**Post date:** [November 6, 2023, 7:47pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/1 "2023-11-06T19:47:04Z")

</div>

Hello,

I am working on a transform that when a user is in more then 1 HR source and one of the accounts is disabled to populate the correct email value. This value is used for attribute sync so my goal is to accurately show the primary email of the user. This is my first time writing a complex transform and want to make sure that I am thinking about this logic correctly. Any pointers on the below logic?

```auto
{
    "name": "findEmail",
    "type": "firstValid",
    "attributes": {
        "ADEmail":{
            "values":[
                {
                    "attributes": {
                        "attributeName": "mail",
                        "sourceName": "Active Directory"
                    },
                    "type": "accountAttribute"
                }
            ]
        },
        "workDayEmail":{
            "values": [
                {
                    "attributes": {
                        "attributeName": "EMAIL_ADDRESS_WORK",
                        "sourceName": "Workday Sandbox"
                    },
                    "type": "accountAttribute"
                }
            ]
        },
        "secZettaEmail":{
            "values":[
                {
                    "attributes": {
                        "attributeName": "personal_email",
                        "sourceName": "SecZetta"
                    },
                    "type": "accountAttribute"
                }
            ]
        },
        "SNEmail":{
            "values":[
                {
                    "attributes": {
                        "attributeName": "email",
                        "sourceName": "ServiceNow - SSMHCTEST"
                    },
                    "type": "accountAttribute"
                }
            ]
        },
        "noEmail":{
            "values":[
                {
                    "attributes": {
                        "value": "noemail@noemail.com"
                    },
                    "type": "static"
                }
            ]
            
        },
        "value": #if($workdayStatus == true)$secZettaEmail#elseif($workdayStatus == false)$workdayEmail#elseif($ADEmail != null)$ADEmail#elseif($SNEmail != null)$SNEmail#{else}$noEmail#end
    },
    "internal": false
} 

```

---

<div class="post-metadata">

**Author:** ![ethompson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ethompson/32/17298_2.png) [@ethompson](https://developer.sailpoint.com/discuss/u/ethompson)\
**Post date:** [November 6, 2023, 8:42pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/2 "2023-11-06T20:42:10Z")

</div>

$workdayStatus does not appear to be defined so that may an accountAttribute from Workday or additional logic. You also need double quotes around the velocity code.

```auto
"#if()#{else}#end"

```

In order to use the “value”, the top level type should be “static”.

I would recommend wrapping the accountAttribute types in a firstValid with a fallback value to check if null (“none”).

```auto
"adMail": {
    "type": "firstValid",
    "attributes": {
        "values": [
            {
                "type": "accountAttribute",
                "attributes": {
                    "sourceName": "AD",
                    "attributeName": "mail"
                }
            },
            "none"
        ]
    }
}

```

For the static value, you can either define that without the static type:

```auto
"noEmail": "noemail@noemail.com"

```

Or include that directly in the static “value”. Full example below (added check if Workday/SecZetta Email is “none”.

```auto
{
    "name": "findEmail",
    "type": "static",
    "attributes": {
        "workDayEmail":{
            "type": "firstValid",
            "attributes": {
                "values": [
                    {
                        "type": "accountAttribute",
                        "attributes": {
                            "sourceName": "Workday",
                            "attributeName": "EMAIL_ADDRESS_WORK"
                        }
                    },
                    "none"
                ]
            }
        },
        "SNEmail":{
            "type": "firstValid",
            "attributes": {
                "values": [
                    {
                        "type": "accountAttribute",
                        "attributes": {
                            "sourceName": "ServiceNow - SSMHCTEST",
                            "attributeName": "email"
                        }
                    },
                    "none"
                ]
            }
        },
        "ADEmail": {
            "type": "firstValid",
            "attributes": {
                "values": [
                    {
                        "type": "accountAttribute",
                        "attributes": {
                            "sourceName": "AD",
                            "attributeName": "mail"
                        }
                    },
                    "none"
                ]
            }
        },
        "workdayStatus": {
            "type": "firstValid",
            "attributes": {
                "values": [
                    {
                        "type": "accountAttribute",
                        "attributes": {
                            "sourceName": "Workday",
                            "attributeName": "status"
                        }
                    },
                    "none"
                ]
            }
        },
        "secZettaEmail": {
            "type": "firstValid",
            "attributes": {
                "values": [
                    {
                        "type": "accountAttribute",
                        "attributes": {
                            "sourceName": "SecZetta",
                            "attributeName": "personal_email"
                        }
                    },
                    "none"
                ]
            }
        },
        "value": "#if($workdayStatus == 'true' && $secZettaEmail != 'none')$secZettaEmail#elseif($workdayStatus == 'false' && $workdayEmail != 'none')$workdayEmail#elseif($ADEmail != 'none')$ADEmail#elseif($SNEmail != 'none')$SNEmail#{else}noemail@noemail.com#end"
    },
    "internal": false
}

```

If you did not have the Workday Status condition, you could just use firstValid like the below:

```auto
{
    "id": "af45ca02-45c0-491a-9067-8447b14c3c48",
    "name": "Work Email",
    "type": "firstValid",
    "attributes": {
        "values": [
            {
                "type": "accountAttribute",
                "attributes": {
                    "sourceName": "AD",
                    "attributeName": "mail"
                }
            },
            {
                "type": "accountAttribute",
                "attributes": {
                    "sourceName": "Workday",
                    "attributeName": "EMAIL_ADDRESS_WORK"
                }
            },
            "no-email@example.com"
        ]
    },
    "internal": false
}

```

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [November 6, 2023, 9:16pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/3 "2023-11-06T21:16:09Z")

</div>

You don’t need a static Transform for this, firstValid type is the best for your requirement. To have email from only enabled account, we use accountPropertyFilter attribute in Transform. Every source has an attribute that defines the status of the account. For example, in AD it is UAC. I have added that option, find respective status attribute in each source and update filters accordingly.

FirstValid is nothing but if-else ladder in order.

```auto
{
  "attributes": {
    "values": [
      {
        "attributes": {
          "sourceName": "Active Directory",
          "attributeName": "mail",
		  "accountPropertyFilter": "(userAccountControl == \"512\")"
        },
        "type": "accountAttribute"
      },
      {
        "attributes": {
          "sourceName": "Workday Sandbox",
          "attributeName": "EMAIL_ADDRESS_WORK",
		  "accountPropertyFilter": "(userAccountControl == \"512\")"
        },
        "type": "accountAttribute"
      },
      {
        "attributes": {
          "sourceName": "SecZetta",
          "attributeName": "personal_email",
		  "accountPropertyFilter": "(userAccountControl == \"512\")"
        },
        "type": "accountAttribute"
      },
	  {
        "attributes": {
          "sourceName": "ServiceNow - SSMHCTEST",
          "attributeName": "email",
		  "accountPropertyFilter": "(userAccountControl == \"512\")"
        },
        "type": "accountAttribute"
      },
	  {
        "attributes": {
         "value": "noemail@noemail.com"
        },
        "type": "static"
      }
    ]
  },
  "type": "firstValid",
  "name": "Email first valid Transform"
}

```

---

<div class="post-metadata">

**Author:** ![ethompson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ethompson/32/17298_2.png) [@ethompson](https://developer.sailpoint.com/discuss/u/ethompson)\
**Post date:** [November 6, 2023, 10:34pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/4 "2023-11-06T22:34:48Z")

</div>

The main issue is that if they want to use SecZetta’s Email if Workday is enabled. So getting the SecZetta attribute with the filter may not give that info, thus requiring the additional static Transform.

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [November 7, 2023, 9:20am UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/5 "2023-11-07T09:20:58Z")

</div>

Ya I missed that, your Transforms covers all the scenarios.

I liked the way you presented the solution. 🙂

---

<div class="post-metadata">

**Author:** ![mpotti](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mpotti/32/2916_2.png) [@mpotti](https://developer.sailpoint.com/discuss/u/mpotti)\
**Post date:** [November 7, 2023, 1:58pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/6 "2023-11-07T13:58:00Z")

</div>

> [@ethompson](#):
>
> ` && $workdayEmail != 'none'`

Thank you I will give this a try and let you know the results. Sorry I missed the part of the logic for Workday Status I have added it below for more context to help anyone who finds this at a later date and also needs help.

```auto
{
    "attributes":{
        "workdayStatus":{
            "values": [
                {
                    "attributes": {
                        "sourceName": "WorkDay Sandbox",
                        "attributeName": "disabled"
                    }
                },
                "no workday account correlated"
            ],
            "type": "accountAttribute"
        }
    }

}

```

---

<div class="post-metadata">

**Author:** ![mpotti](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mpotti/32/2916_2.png) [@mpotti](https://developer.sailpoint.com/discuss/u/mpotti)\
**Post date:** [December 1, 2023, 1:05pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/7 "2023-12-01T13:05:49Z")

</div>

I did as you suggested. Here is the error message I got.

```auto
There was an exception while calculating the value for this attribute. Error running account attribute transform for attribute 'null' on identity 'null' :java.lang.IllegalStateException: Unable to query for applications id in the account attribute transform neither sourceId or sourceName specified.

```

Here is the updated transform.

```auto
{
    "id": "f29865b9-3a40-4493-8dc7-61b46de16b19",
    "name": "Transform - Static - WDSZ - FindEmail",
    "type": "static",
    "attributes": {
        "workdayStatus": {
            "values": [
                {
                    "attributes": {
                        "sourceName": "WorkDay Sandbox",
                        "attributeName": "disabled"
                    }
                },
                "no workday account correlated"
            ],
            "type": "accountAttribute"
        },
        "ADEmail": {
            "values": [
                {
                    "attributes": {
                        "attributeName": "mail",
                        "sourceName": "Active Directory"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "workDayEmail": {
            "values": [
                {
                    "attributes": {
                        "attributeName": "EMAIL_ADDRESS_WORK",
                        "sourceName": "Workday Sandbox"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "secZettaEmail": {
            "values": [
                {
                    "attributes": {
                        "attributeName": "personal_email",
                        "sourceName": "SecZetta"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "SNEmail": {
            "values": [
                {
                    "attributes": {
                        "attributeName": "email",
                        "sourceName": "ServiceNow - SSMHCTEST"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "value": "#if($workdayStatus == true && $secZettaEmail != 'none')$secZettaEmail#elseif($workdayStatus == false && $workdayEmail != 'none')$workdayEmail#elseif($ADEmail != 'none')$ADEmail#elseif($SNEmail != 'none')$SNEmail#{else}noemail@noemail.com#end"
    },
    "internal": false
}

```

---

<div class="post-metadata">

**Author:** ![mpotti](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mpotti/32/2916_2.png) [@mpotti](https://developer.sailpoint.com/discuss/u/mpotti)\
**Post date:** [December 1, 2023, 1:19pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/8 "2023-12-01T13:19:10Z")

</div>

I also tried the following and got a different message this time.

```auto
There was an exception while calculating the value for this attribute. Error rendering template: #if($workdayStatus == true && $secZettaEmail != 'none')$secZettaEmail#elseif($workdayStatus == false && $workdayEmail != 'none')$workdayEmail#elseif($ADEmail != 'none')$ADEmail#elseif($SNEmail != 'none')$SNEmail#{else}noemail@noemail.com#end

```

Here is the transform:

```auto
{
    "id": "f29865b9-3a40-4493-8dc7-61b46de16b19",
    "name": "Transform - Static - WDSZ - FindEmail",
    "type": "static",
    "attributes": {
        "workdayStatus": {
            "type": "firstValid",
            "values": [
                {
                    "type": "accountAttribute",
                    "attributes": {
                        "sourceName": "WorkDay Sandbox",
                        "attributeName": "disabled"
                    }
                },
                "no workday account correlated"
            ]
        },
        "ADEmail": {
            "type": "firstValid",
            "values": [
                {
                    "attributes": {
                        "attributeName": "mail",
                        "sourceName": "Active Directory"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "workDayEmail": {
            "type": "firstValid",
            "values": [
                {
                    "attributes": {
                        "attributeName": "EMAIL_ADDRESS_WORK",
                        "sourceName": "Workday Sandbox"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "secZettaEmail": {
            "type": "firstValid",
            "values": [
                {
                    "attributes": {
                        "attributeName": "personal_email",
                        "sourceName": "SecZetta"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "SNEmail": {
            "type": "firstValid",
            "values": [
                {
                    "attributes": {
                        "attributeName": "email",
                        "sourceName": "ServiceNow - SSMHCTEST"
                    },
                    "type": "accountAttribute"
                },
                "none"
            ]
        },
        "value": "#if($workdayStatus == true && $secZettaEmail != 'none')$secZettaEmail#elseif($workdayStatus == false && $workdayEmail != 'none')$workdayEmail#elseif($ADEmail != 'none')$ADEmail#elseif($SNEmail != 'none')$SNEmail#{else}noemail@noemail.com#end"
    },
    "internal": false
}

```

---

<div class="post-metadata">

**Author:** ![ethompson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ethompson/32/17298_2.png) [@ethompson](https://developer.sailpoint.com/discuss/u/ethompson)\
**Post date:** [December 1, 2023, 3:45pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/9 "2023-12-01T15:45:34Z")

</div>

The second format is correct for getting the account attributes. Try putting the boolean values as strings.

```auto
#if($workdayStatus == 'true' && $secZettaEmail != 'none')$secZettaEmail#elseif($workdayStatus == 'false' && $workdayEmail != 'none')$workdayEmail#elseif($ADEmail != 'none')$ADEmail#elseif($SNEmail != 'none')$SNEmail#{else}noemail@noemail.com#end

```

---

<div class="post-metadata">

**Author:** ![mpotti](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mpotti/32/2916_2.png) [@mpotti](https://developer.sailpoint.com/discuss/u/mpotti)\
**Post date:** [December 1, 2023, 8:53pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/10 "2023-12-01T20:53:51Z")

</div>

Here is what is currently working. We are still testing it to make sure it is a 100% but this is what I have.

```auto
{
    "id": "f29865b9-3a40-4493-8dc7-61b46de16b19",
    "name": "Transform - Static - WDSZ - FindEmail",
    "type": "static",
    "attributes": {
        "workdayStatus": {
            "attributes": {
                "type": "firstValid",
                "values": [
                    {
                        "type": "accountAttribute",
                        "attributes": {
                            "sourceName": "WorkDay Sandbox",
                            "attributeName": "disabled"
                        }
                    },
                    "none"
                ]
            },
            "type": "firstValid"
        },
        "ADEmail": {
            "attributes": {
                "values": [
                    {
                        "attributes": {
                            "attributeName": "mail",
                            "sourceName": "Active Directory"
                        },
                        "type": "accountAttribute"
                    },
                    "none"
                ]
            },
            "type": "firstValid"
        },
        "workDayEmail": {
            "attributes": {
                "values": [
                    {
                        "attributes": {
                            "attributeName": "EMAIL_ADDRESS_WORK",
                            "sourceName": "Workday Sandbox"
                        },
                        "type": "accountAttribute"
                    },
                    "none"
                ]
            },
            "type": "firstValid"
        },
        "secZettaEmail": {
            "attributes": {
                "values": [
                    {
                        "attributes": {
                            "attributeName": "personal_email",
                            "sourceName": "SecZetta"
                        },
                        "type": "accountAttribute"
                    },
                    "none"
                ]
            },
            "type": "firstValid"
        },
        "SNEmail": {
            "attributes": {
                "values": [
                    {
                        "attributes": {
                            "attributeName": "email",
                            "sourceName": "ServiceNow - SSMHCTEST"
                        },
                        "type": "accountAttribute"
                    },
                    "none"
                ]
            },
            "type": "firstValid"
        },
        "value": "#if($workdayStatus == 'true' || $workdayStatus == 'none' && $secZettaEmail != 'none')$secZettaEmail#elseif($workdayStatus == 'false' && $workdayEmail != 'none')$workdayEmail#elseif($ADEmail != 'none')$ADEmail#elseif($SNEmail != 'none')$SNEmail#{else}noemail@noemail.com#end"
    },
    "internal": false
}

```

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [January 30, 2024, 8:54pm UTC](https://developer.sailpoint.com/discuss/t/help-with-transform-logic/20536/11 "2024-01-30T20:54:30Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
