# How to Identify the Tenant or Environment in SailPoint Transforms

**URL:** <https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007>\
**Category:** SHF Community Knowledge Base\
**Tags:** transforms, identity-security-cloud\
**Created:** [January 20, 2025, 3:47am UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007 "2025-01-20T03:47:37Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcchasse](https://avatars.discourse-cdn.com/v4/letter/m/7ea924/32.png) [@marcchasse](https://developer.sailpoint.com/discuss/u/marcchasse)\
**Post date:** [January 20, 2025, 3:47am UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/1 "2025-01-20T03:47:37Z")

</div>

Several discussions on the SailPoint Developer Community have raised questions about how to identify the environment (tenant) within a transform:

- [Know the Tenant or Environment in Transforms](https://developer.sailpoint.com/discuss/t/know-the-tenant-or-environment-in-transforms/24517)
- [Any Way to Get Information About Virtual Appliance and/or Environment in a Transform](https://developer.sailpoint.com/discuss/t/any-way-to-get-information-about-virtual-appliance-and-or-environment-in-a-transform/22990)

I needed to conditionally set the Active Directory DN for production and development, but IdentityNow does not provide a built-in way to obtain environment-specific information directly.

### The Solution

I was able to solve this by leveraging an attribute from an authoritative source (in my case, **SuccessFactors** ) to distinguish between environments. Here’s an example transform that checks if the environment is “Development”:

```json
{
    "id": "0db1d640-eb8f-455d-b026-e1caa4e85e20",
    "name": "isDevEnvironment",
    "type": "static",
    "attributes": {
        "value": "#if($identity.getLinksByAppIdOrName(null, \"SuccessFactors [source]\")[0].getApplication().getStringAttributeValue(\"companyId\") == \"<My Dev Proxy Value>\")true#{else}false#end"
    },
    "internal": false
}

```

### Explanation

1. **Source Selection:**

2. **Attribute Extraction:**

### Important Considerations

- **Guaranteed Link Presence:**

- **Flexible Attributes:**

Hope this helps others

---

<div class="post-metadata">

**Author:** ![Santhakumar](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/santhakumar/32/17329_2.png) [@Santhakumar](https://developer.sailpoint.com/discuss/u/Santhakumar)\
**Post date:** [January 20, 2025, 6:43am UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/2 "2025-01-20T06:43:47Z")

</div>

Thanks for the info @marcchasse i too have same case but instead of this we have go with another approach, anyway thanks for the input it helps me and as well as others.

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [January 21, 2025, 2:06pm UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/3 "2025-01-21T14:06:15Z")

</div>

Just curious, but what scenarios do you have that you need to know whether you are running PROD or DEV environments?

---

<div class="post-metadata">

**Author:** ![marcchasse](https://avatars.discourse-cdn.com/v4/letter/m/7ea924/32.png) [@marcchasse](https://developer.sailpoint.com/discuss/u/marcchasse)\
**Post date:** [January 21, 2025, 3:02pm UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/4 "2025-01-21T15:02:50Z")

</div>

In active Directory when we create or move accounts we need to set the distinguished name. That name looks like this:  
CN=mySAM,OU=Clients,OU=Company Users,DC=companyName,DC=com

for our dev and production AD tenants the “paths” are diffrent so knowing the environment helps with picking the correct value to use.

in this scenario I could have alternatively added a custom property to the AD source and had the transform pull from that.

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [January 21, 2025, 3:25pm UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/5 "2025-01-21T15:25:05Z")

</div>

Ok. So using the same transform for both environments rather than two different transforms. I understand the logic.  
However, in my opinion, you are adding ‘dead’ logic to both environments, needlessly complicating your code.

---

<div class="post-metadata">

**Author:** ![brennenscott](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/brennenscott/32/23642_2.png) [@brennenscott](https://developer.sailpoint.com/discuss/u/brennenscott)\
**Post date:** [January 21, 2025, 4:52pm UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/6 "2025-01-21T16:52:47Z")

</div>

This is awesome! Thanks for sharing this, @marcchasse 😄

---

<div class="post-metadata">

**Author:** ![marcchasse](https://avatars.discourse-cdn.com/v4/letter/m/7ea924/32.png) [@marcchasse](https://developer.sailpoint.com/discuss/u/marcchasse)\
**Post date:** [January 21, 2025, 6:14pm UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/7 "2025-01-21T18:14:52Z")

</div>

I agree its adding dead code to both environments and increases complexity, but not needlessly.🙂

It’s as a trade-off, and I’m prioritizing easier deployments. By using the same transform across both environments, we eliminate the need to think about it again when pushing to production.

Since the transform logic is unlikely to change, the added complexity isn’t much of a concern compared to the effort required to remember that dev and prod have different versions and to ensure the dev transform is never moved to production.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [March 22, 2025, 6:15pm UTC](https://developer.sailpoint.com/discuss/t/how-to-identify-the-tenant-or-environment-in-sailpoint-transforms/98007/8 "2025-03-22T18:15:02Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
