# How to pass transform attributes to IdentityAttributeRule

**URL:** <https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157>\
**Category:** SHF Discussion and Questions\
**Tags:** transforms, identity-security-cloud, rules\
**Created:** [March 4, 2026, 5:04am UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157 "2026-03-04T05:04:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahul\_ch77](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@rahul\_ch77](https://developer.sailpoint.com/discuss/u/rahul_ch77)\
**Post date:** [March 4, 2026, 5:04am UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/1 "2026-03-04T05:04:02Z")

</div>

Hi sailers,

I’m trying to understand how values are passed from a **Transform** to a **Cloud IdentityAttributeRule**.

For example, if I define a transform like this:

```json
{
  "attributes": {
    "name": "My Rule Utility",
    "userGroups": "group1, group2",
    "userEmail": {
      "attributes": {
        "sourceName": "HR",
        "attributeName": "email"
      },
      "type": "accountAttribute"
    }
  },
  "type": "rule",
  "name": "Rule Transform"
}

```

Inside the IdentityAttributeRule:

- Can I directly access `userGroups` and `userEmail` as runtime variables similar to `idn`, `log`, `identity` Or are these only available through the `parameters` map?

- If possible, could someone share a simple working example (transform JSON + rule snippet) showing the correct way to access these values?

---

<div class="post-metadata">

**Author:** ![rohit\_wekhande](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rohit_wekhande/32/28501_2.png) [@rohit\_wekhande](https://developer.sailpoint.com/discuss/u/rohit_wekhande)\
**Post date:** [March 4, 2026, 6:09am UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/2 "2026-03-04T06:09:14Z")

</div>

Hello @rahul_ch77 ,

If you are creating a Custom Idnetity Attribute Generator Cloud Rule, then, you cannot pass the runtime parameters from Transforms.

That approach is only for OOTB rule such as “Cloud Services Deployment Utility“.

In the custom **Cloud IdentityAttributeRule** which you are creating\*\*,\*\* you can only call the rule and input parameters will be passed inside the beanshell script.

Refer the below documentations from SailPoint.

> **[Rule | SailPoint Developer Community](https://developer.sailpoint.com/docs/extensibility/transforms/operations/rule/)**
>
> Reuse rule logic that has already been written for a previous use case.

Regards,

Rohit Wekhande.

---

<div class="post-metadata">

**Author:** ![RAKRHEEM](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@RAKRHEEM](https://developer.sailpoint.com/discuss/u/RAKRHEEM)\
**Post date:** [March 4, 2026, 6:26am UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/3 "2026-03-04T06:26:22Z")

</div>

```auto
Hi 
 ,

This is how I had passed it in a Rule.

{

      "name": "MultivalueRule",

    "type": "rule",

    "attributes": {

        "name": "MultivalueRule",

        "cloudSourceName": "PPS Flat File",

        "attributeName": "concatTitleDept"

    },

    "internal": false

}

```

where cloudSourceName what the name of the source and attributeName was the input attribute

---

<div class="post-metadata">

**Author:** ![rahul\_ch77](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@rahul\_ch77](https://developer.sailpoint.com/discuss/u/rahul_ch77)\
**Post date:** [March 4, 2026, 7:13am UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/4 "2026-03-04T07:13:17Z")

</div>

@rohit_wekhande thank you for your response. However, According to the SailPoint documentation for Rule Transforms (type: `"rule"`), any values defined under the `attributes` section of the transform are passed into the rule execution context and can be accessed inside the rule. The documentation example using **Cloud Services Deployment Utility** clearly shows attributes like `operation` and `numChars` being supplied via the transform and consumed by the rule at runtime.

```json
{
  "attributes": {
    "name": "Cloud Services Deployment Utility",
    "operation": "getEndOfString",
    "input": {
      "type": "trim"
    },
    "numChars": "3"
  },
  "type": "rule",
  "name": "Rule Transform"
}

```

@colin_mckibben @philip-ellis @KRM7 @kjakubiak @enistriminsait could you please provide your insights?

---

<div class="post-metadata">

**Author:** ![rohit\_wekhande](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rohit_wekhande/32/28501_2.png) [@rohit\_wekhande](https://developer.sailpoint.com/discuss/u/rohit_wekhande)\
**Post date:** [March 4, 2026, 7:35am UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/5 "2026-03-04T07:35:37Z")

</div>

> [@RAKRHEEM](#):
>
> `attributeName`

Hello @rahul_ch77 ,

Thanks for the insight! If that’s the case, its new for me. But, as per the Identity Attribute Cloud Rule document, its not mentioned anywhere.

> **[Identity Attribute Rule | SailPoint Developer Community](https://developer.sailpoint.com/docs/extensibility/rules/cloud-rules/identity-attribute-rule/)**
>
> This rule calculates and returns an identity attribute for a specific identity.

Can you share you identity attribute cloud rule code as well if possible?

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [March 4, 2026, 12:07pm UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/6 "2026-03-04T12:07:53Z")

</div>

SailPoint has developed a Rule with couple of methods, this Rule will be executed at cloud level.

Imagine a Java class with bunch of methods with inputs, in Transform you mention the method to use and inputs to pass.

Method → Operation

You can also have your own Identity Attribute Rule which is a cloud one, that is completely different. You cannot pass inputs from Transform to Rule.

---

<div class="post-metadata">

**Author:** ![utkirjonkamiljanov](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/utkirjonkamiljanov/32/36695_2.png) [@utkirjonkamiljanov](https://developer.sailpoint.com/discuss/u/utkirjonkamiljanov)\
**Post date:** [March 5, 2026, 8:26pm UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/8 "2026-03-05T20:26:40Z")

</div>

This is a **key distinction** in ISC:

- A **Rule Transform** (`"type": "rule"`) invokes a **Transform Rule** (type `TransformRule`) — NOT an `IdentityAttribute` rule. The variables in the `attributes` block ARE passed as dynamic variables to the `TransformRule`.

- An **IdentityAttribute Rule** is a separate rule type, used directly in Identity Profile mappings via the “Complex Data Source” option — it does **not** receive transform-level attribute variables; it only gets `log`, `idn`, `identity`, and `oldValue`.

- So `userGroups` and `userEmail` from the transform’s `attributes` block are **only available in a TransformRule** , accessed via the standard rule context, not in an `IdentityAttribute` rule. Docs to point to:

- [https://developer.sailpoint.com/docs/extensibility/transforms/operations/rule/](https://developer.sailpoint.com/docs/extensibility/transforms/operations/rule/)

- [https://developer.sailpoint.com/docs/extensibility/rules/cloud-rules/identity-attribute-rule/](https://developer.sailpoint.com/docs/extensibility/rules/cloud-rules/identity-attribute-rule/)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [May 4, 2026, 8:27pm UTC](https://developer.sailpoint.com/discuss/t/how-to-pass-transform-attributes-to-identityattributerule/198157/9 "2026-05-04T20:27:02Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
