# Passing Transform-Generated Value to Attribute Generator Rule in SailPoint ISC

**URL:** <https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572>\
**Category:** SHF Discussion and Questions\
**Tags:** transforms, provisioning, identity-security-cloud, rules\
**Created:** [December 25, 2024, 3:17pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572 "2024-12-25T15:17:26Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 25, 2024, 3:17pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/1 "2024-12-25T15:17:26Z")

</div>

Hi Everyone,

I’m working on a use case in SailPoint ISC, where I need to pass a value generated by a transform itself into Attribute Generator Rule as input. Here’s the context:

1. There is a **provisioning policy** that invokes a rule.
2. The rule depends on a **transform** for generating the input for the `lastName` variable within the rule.
3. The transform in **CREATE policy** structure is as follows:

```auto
{
    "name": "mail",
    "transform": {
        "attributes": {
            "input": {
                "type": "replaceAll",
                "attributes": {
                    "table": {
                        "abc\\s*(\\S+)": "abc$1",
                        "m c\\s*(\\S+)": "mc$1"
                    },
                    "inputToRule": {
                        "type": "trim",
                        "attributes": {
                            "input": {
                                "type": "lower",
                                "attributes": {
                                    "input": {
                                        "type": "identityAttribute",
                                        "attributes": {
                                            "name": "lastName"
                                        }
                                    }
                                }
                            }
                        }
                    }
                }
            },
            "name": "AttributeGeneratorRule"
        },
        "type": "rule"
    },
    "attributes": {},
    "isRequired": false,
    "type": "string",
    "isMultiValued": false
}

```

In the rule (`AttributeGeneratorRule`), I attempted to reference the `inputToRule` attribute as follows:

```auto
String firstName = StringUtils.trimToNull(identity.getFirstname());
//referencing the input - inputToRule
String lastName = StringUtils.trimToNull(inputToRule);

```

My challenge lies in:

1. Correctly referencing the transformed value (`inputToRule`) within the rule logic.
2. Ensuring the transform output is properly passed to the rule during execution.

### Assistance Needed

I need guidance on:

1. How to accurately reference the transform-generated `inputToRule` attribute in the rule logic.
2. Best practices for configuring the transform and rule to ensure seamless data flow.

Your assistance in resolving this would be greatly appreciated. Please let me know if additional details are needed.

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![vasanthrajsp29](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vasanthrajsp29/32/20713_2.png) [@vasanthrajsp29](https://developer.sailpoint.com/discuss/u/vasanthrajsp29)\
**Post date:** [December 25, 2024, 5:59pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/2 "2024-12-25T17:59:36Z")

</div>

Hi @GOKUL_ANANTH_M,

I have one doubt why can’t we create an identity attribute and modify(transform) the value in identity profile and reference in rule.

Based on my experience we did the same setup. Is there any specific reason in going provisioning policy transform ?

-Vasanth

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 25, 2024, 6:29pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/3 "2024-12-25T18:29:18Z")

</div>

Hi @vasanthrajsp29 ,

This can be handled directly within the rule. However, for every additional requirement to replace words, we would need to modify the rule and deploy it.

With that in mind, and also this create policy will be triggered only once. So, I thought of providing input via a policy over creating an identity attribute.

If there’s no way to handle this through the policy, then creating an identity attribute seems like the better approach, in my opinion.

Does this sound like a fine way to proceed?

Thanks,  
Gokul

---

<div class="post-metadata">

**Author:** ![vasanthrajsp29](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vasanthrajsp29/32/20713_2.png) [@vasanthrajsp29](https://developer.sailpoint.com/discuss/u/vasanthrajsp29)\
**Post date:** [December 26, 2024, 12:56pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/4 "2024-12-26T12:56:05Z")

</div>

Hi Gokul,

I’ve not seen any documentation or reference article related to **“inputToRule”**  
We never tried this complex logic where we use transform o/p to rule i/p.

Please post your result once your provisioning policy is success bit curious to know the outcome.

-Vasanth

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [December 26, 2024, 1:41pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/5 "2024-12-26T13:41:28Z")

</div>

Hi @GOKUL_ANANTH_M

Below are some other ways to achieve it which might be helpful. I am not sure about what the best practices but i believe you can choose any of the below three approach and it should be fine.

1. In this approach you can have a variable defined under the connector attributes something like below

```auto
"regExExpressionsToBeChecked":{
                       "abc\\s*(\\S+)": "abc$1",
                        "m c\\s*(\\S+)": "mc$1"
}

```

Then in the rule you can then retrieve this attribute from application content and loop over the each expression to use the regular expression pattern to be tested and if they return true then you can use the value above dictionary to replace that. I am not sure about $1 used above but believe you can overcome that.

This will avoid your need to be dependent on the deploying the rule again if new regEx expressions are needed to be added into the logic as you can simply change these values in the source json. But in case there is another requirement like converting the special characters like ü to corresponding English alphabet like u, then this may not be possible and you will need to update the rule. So in my opinion if only replace is the action you foresee then this approach can be utilized. ofcourse here you will need to deploy your own attribute generator rule 🙂 .

1. Second approach which you can use but i think it will be applicable if this is for Active directory type of source. So you can still use the same transform but instead of using this transform in mail attribute directly, you can create one temporary attribute on the create policy. Make sure this temporary attribute is placed above the mail attribute. In this attribute then you can use this transform and in the mail attribute then you can pass this attribute (as $tempAttr ) as the input. This will give you the overview also of the value generated for this attribute in the events and you can see them when ever any new account is created.

But this will mean when ISC tries to create the attribute in the target application it will try to provision this temp Attribute as well for the user and it may fail as this attribute is not available in the target application. For that you can add the attribute in **excludeAttributesFromProvisioning** block in source json under connector attributes and that should avoid including this attribute in the provisioning plan but you can still use it for generating the email. But i have seen exclude block only in AD type of sources so not sure if this be applicable if this is a non-AD source.  
But for AD source this also looks to be a decent approach unless i am missing anything here.

1. You can also prefer using another identity attribute which is most traditional way of achieving this requirement but to have identity attribute for this requirement may be the last option i would prefer unless we can use this value in some other sources as well then this would be the best way i believe.

I hope this helps, if you have any queries please let me know.

Regards  
Vikas

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 27, 2024, 4:15pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/6 "2024-12-27T16:15:39Z")

</div>

Hi @vguleria ,

I have read your second approach, you have mentioned about the attribute **excludeAttributesFromProvisioning** , do we have any documentation for that in SailPoint?

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [December 30, 2024, 9:25am UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/7 "2024-12-30T09:25:31Z")

</div>

Hi @GOKUL_ANANTH_M

No, Unfortunately, I do not find this attribute information in the connector’s official documentation but i think this is a standard attribute but can not confirm as believe it should be confirmed by SailPoint colleagues.

Although I found this post where the mention of same attribute is there one of the comments which you can check;

> [@Pass Non-Provisioned Attributes from Before Provision rule to Connector Rules](https://developer.sailpoint.com/discuss/t/pass-non-provisioned-attributes-from-before-provision-rule-to-connector-rules/20470):
>
> Introduction A common use case when developing for provisioning is the need to provide information to a connector rule that is not available on the virtual appliance (VA). This can occur because you need identity information to perform additional logic, or because a request payload requires information that is not actively changing in the account. The first case can often occur in Active Directory and Azure Native Rules, where a developer must take additional actions based on…

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/d/5/d50bc0fde69fbb1be78c62faed7e18d16e4c7d37.png)

I addition to that I would suggest you to either check with SailPoint support regarding if we can use this attribute or may be just a give a quick try by adding some static attribute create policy and then add that attribute in this block in source json and see if AD provisioning is working fine. I also see in the above post that it is mentioned that we can use this attribute even in other connectors too so i think this could be helpful.

I hope this helps.

Regards  
Vikas.

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 30, 2024, 1:42pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/8 "2024-12-30T13:42:38Z")

</div>

Great! But I also saw another post which is same as to the issue raised here.

> [@Retrieving Another Account Profile Attribute in an Attribute Generator Rule](https://developer.sailpoint.com/discuss/t/retrieving-another-account-profile-attribute-in-an-attribute-generator-rule/18096):
>
> Hi all. We are building an email generator through cloud-executed attribute generator rule. However, we encounter one use case, which is in certain scenario in the rule, we will use the sAMAccountName as part of the email generation, while other logics will be handled in the rule. Both generations are quite complex and thus must be handled in cloud rules instead. We understand that through static field, $sAMAccountName@mail.com is the way if we place this attribute above the mail attribute in t…

But still if I use this directly in my rule, as I have mentioned already,

```auto
String lastName = StringUtils.trimToNull(inputToRule);

```

This was not accepted by SailPoint rule validator.

Do I missed anything here?

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [December 30, 2024, 1:58pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/9 "2024-12-30T13:58:16Z")

</div>

Hi @GOKUL_ANANTH_M

What error are you receiving in the rule validator ? Is it related to method not available ?  
I am not sure what is the use of this method trimToNull? Also, I can not find stringUtils library in the java documents either i am missing something or it has been replaced with utils lib as i can see lot of string related method in this library e.g. trimWhitespace.

So if you know the use of this method, i suggest you can just use your own logic in the rule to make similar function. e.g. if it performing the trim operation on input, then you can try to use the standard trim operation or use utils.trimWhitespace(inputToRule), may be this will help.

Please check and let me know if that helps.

Regards  
Vikas.

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 30, 2024, 2:10pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/10 "2024-12-30T14:10:01Z")

</div>

```auto
Could not retrieve definition for variable name 'replaced_LastName'
   String lastName = StringUtils .trimToNull ( inputToRule )

```

this was the error returned by rule validator. Not accepting the `inputToRule` reference (expecting a variable named inputTo Rule), any idea on what should be done?

Also, there is no problem `StringUtils .trimToNull`. There is no error in this.

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [December 30, 2024, 2:25pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/11 "2024-12-30T14:25:23Z")

</div>

Hi @GOKUL_ANANTH_M

The error message states for replaced\_LastName, can you please check if this variable is present in your code and not initialized properly ?

I also see a space between StringUtils and trimToNull and the parameters passed but probably that is an issue while writing the code here.

If it is pointing to the same line of code where you are using trimToNull, then most likely this method method internally creates a new variable replaced\_LastName and returns it and probably can throw this error if inputToRule is null. Can you please try below perhaps

```auto
String lastName =(inputToRule ==null)?"":StringUtils.trimToNull(inputToRule )

```

Hopefully this can bypass the error.

Please let us know the outcome though.

Regards  
Vikas.

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 30, 2024, 2:50pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/12 "2024-12-30T14:50:16Z")

</div>

Hi Vikas,

The same error repeats even modifying the code. I think the rule validator is not accepting it. It’s expecting the variable to be declared inside the rule.

I have checked modifying the line like,

```auto
    String lastName = StringUtils.trimToNull(identity.getLastname());

```

It’s accepting fine.

Now, my doubt is that, is the method I done is acceptable or not 🤪

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [December 31, 2024, 9:20am UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/13 "2024-12-31T09:20:06Z")

</div>

Hi @GOKUL_ANANTH_M

I believe the method will be acceptable but the rule will not be deployed unless the validator confirms it. So in my opinion you can either check with sailPoint support if they can help in deploying the rule atleast in your non-prod tenant. Otherwise then you can go for approach 1 as I mentioned above where you can then read the lastname from identity and then read the regEX expressions from the source and then loop over them and apply them, that should do the trick for you.

Thank You.  
Regards  
Vikas.

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [December 31, 2024, 2:20pm UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/14 "2024-12-31T14:20:43Z")

</div>

Hi Vikas,

I think 1st approach will not be suitable as per our requirement. We would have two ways,  
3rd approach - which you mentioned or handling all these requirements directly inside rule.

Will check with sailpoint support.

---

<div class="post-metadata">

**Author:** ![vguleria](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vguleria/32/7884_2.png) [@vguleria](https://developer.sailpoint.com/discuss/u/vguleria)\
**Post date:** [January 1, 2025, 8:32am UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/15 "2025-01-01T08:32:28Z")

</div>

Hi @GOKUL_ANANTH_M

Yes, I think you can still apply 1st approach as i see only regEX validation done there so i was thinking of doing something like below;

```auto
Map regExExpressionsToBeChecked= application.getAttributeName("regExExpressionsToBeChecked");
String lastName = identity.getAttribute("LastName");

for(currentMap:regExExpressionsToBeChecked)
{
  // check for regEx to match if lastName matches then replace them to form the 
}

```

But this approach anyways needs you to write your custom rule so agree you can go for approach 3. You can then use the same logic here as mentioned in approach 1 so that if you need to extend the regEX expressions then you do not need to redeploy the rule. You can just update source configuration and then rule should pick up that.

Good luck with the implementation 🙂 .

Regards  
Vikas.

---

<div class="post-metadata">

**Author:** ![GOKUL\_ANANTH\_M](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gokul_ananth_m/32/14416_2.png) [@GOKUL\_ANANTH\_M](https://developer.sailpoint.com/discuss/u/GOKUL_ANANTH_M)\
**Post date:** [January 1, 2025, 8:56am UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/16 "2025-01-01T08:56:15Z")

</div>

Sure, will look into it.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [March 2, 2025, 8:56am UTC](https://developer.sailpoint.com/discuss/t/passing-transform-generated-value-to-attribute-generator-rule-in-sailpoint-isc/94572/17 "2025-03-02T08:56:47Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
