Preventing Duplicate User Creation in NERM Using SailPoint ISC Search API
Overview
While developing a user onboarding workflow in NERM, I needed to prevent duplicate profile creation when a user submits a request with an email address that already exists in SailPoint Identity Security Cloud (ISC).
To solve this, I implemented a duplicate validation check using the SailPoint ISC Search API before the profile creation step. If the email already exists, the workflow automatically cancels the request. If no matching identity is found, the workflow proceeds with profile creation.
Business Requirement
Before creating a new profile in NERM:
- Check whether the email address already exists in SailPoint ISC.
- If the email exists, stop the workflow and prevent duplicate profile creation.
- If the email does not exist, continue with the onboarding process.
Solution Architecture
Request Form
β
REST API Call to ISC Search API
β
Map Response to FOUND_ID
β
Condition Check
β
βββββββββββββββββ΄ββββββββββββββββ
β β
Identity Found Identity Not Found
β β
Cancel Session Create Profile
Step 1: Create Request Form
The NERM request form captures user details, including the email address.
Example Attribute:
attr_demonermemail_ne_attribute
Step 2: Configure REST API Action
Configured a REST API action in NERM to call the SailPoint ISC Search API.
Endpoint
POST https://<tenant>.api.identitynow.com/v3/search
Request Body
{
"indices": [
"identities"
],
"query": {
"query": "attributes.email.exact:\"{{request.attr_demonermemail_ne_attribute}}\""
}
}
This query searches the Identities index for an exact email match.
Step 3: Create Workflow Attribute
Created a custom workflow attribute:
| Attribute Name | Type |
|---|---|
| FOUND_ID | Text |
This attribute stores the identity ID returned by the Search API.
Step 4: Configure Response Mapping
Mapped the API response to the workflow attribute.
Example API Response:
[
{
"id": "f17fd8292a784a818838046f9f2c9d45",
"email": "tom.cruise@cyberzone.com"
}
]
Response Mapping:
0 β id β FOUND_ID
Step 5: Configure Workflow Condition
Configured a workflow condition using the REQUEST attribute:
REQUEST β FOUND_ID is present
Important Note
Initially, I used:
PROFILE β FOUND_ID is present
However, the condition always evaluated as false because the profile had not yet been created.
The solution was to use:
REQUEST β FOUND_ID is present
since the value returned from the REST API exists within the workflow request context before profile creation.
Step 6: Configure Workflow Routing
If FOUND_ID is Present
The workflow executes:
Cancel Session
This prevents duplicate profile creation.
If FOUND_ID is Absent
The workflow executes:
Create Profile
and the onboarding process continues.
Benefits
- Prevents duplicate profile creation.
- Improves data quality and governance.
- Provides real-time validation during onboarding.
- Simple implementation using NERM workflow capabilities and SailPoint ISC APIs.
- Easily reusable for other duplicate validation use cases.
Conclusion
By integrating the SailPoint ISC Search API within a NERM workflow, I was able to implement an effective duplicate email validation process before profile creation. The key learning was to evaluate the API response using the REQUEST attribute context rather than the PROFILE attribute context, ensuring the workflow correctly identifies existing users and prevents duplicate records.
