Preventing Duplicate User Creation in NERM Using SailPoint ISC Search API

Preventing Duplicate User Creation in NERM Using SailPoint ISC Search API

Overview

While developing a user onboarding workflow in NERM, I needed to prevent duplicate profile creation when a user submits a request with an email address that already exists in SailPoint Identity Security Cloud (ISC).

To solve this, I implemented a duplicate validation check using the SailPoint ISC Search API before the profile creation step. If the email already exists, the workflow automatically cancels the request. If no matching identity is found, the workflow proceeds with profile creation.


Business Requirement

Before creating a new profile in NERM:

  • Check whether the email address already exists in SailPoint ISC.
  • If the email exists, stop the workflow and prevent duplicate profile creation.
  • If the email does not exist, continue with the onboarding process.

Solution Architecture

Request Form
      ↓
REST API Call to ISC Search API
      ↓
Map Response to FOUND_ID
      ↓
Condition Check
      ↓
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚                               β”‚
Identity Found             Identity Not Found
 β”‚                               β”‚
Cancel Session             Create Profile

Step 1: Create Request Form

The NERM request form captures user details, including the email address.

Example Attribute:

attr_demonermemail_ne_attribute

Step 2: Configure REST API Action

Configured a REST API action in NERM to call the SailPoint ISC Search API.

Endpoint

POST https://<tenant>.api.identitynow.com/v3/search

Request Body

{
  "indices": [
    "identities"
  ],
  "query": {
    "query": "attributes.email.exact:\"{{request.attr_demonermemail_ne_attribute}}\""
  }
}

This query searches the Identities index for an exact email match.


Step 3: Create Workflow Attribute

Created a custom workflow attribute:

Attribute Name Type
FOUND_ID Text

This attribute stores the identity ID returned by the Search API.


Step 4: Configure Response Mapping

Mapped the API response to the workflow attribute.

Example API Response:

[
  {
    "id": "f17fd8292a784a818838046f9f2c9d45",
    "email": "tom.cruise@cyberzone.com"
  }
]

Response Mapping:

0 β†’ id β†’ FOUND_ID

Step 5: Configure Workflow Condition

Configured a workflow condition using the REQUEST attribute:

REQUEST β†’ FOUND_ID is present

Important Note

Initially, I used:

PROFILE β†’ FOUND_ID is present

However, the condition always evaluated as false because the profile had not yet been created.

The solution was to use:

REQUEST β†’ FOUND_ID is present

since the value returned from the REST API exists within the workflow request context before profile creation.


Step 6: Configure Workflow Routing

If FOUND_ID is Present

The workflow executes:

Cancel Session

This prevents duplicate profile creation.

If FOUND_ID is Absent

The workflow executes:

Create Profile

and the onboarding process continues.


Benefits

  • Prevents duplicate profile creation.
  • Improves data quality and governance.
  • Provides real-time validation during onboarding.
  • Simple implementation using NERM workflow capabilities and SailPoint ISC APIs.
  • Easily reusable for other duplicate validation use cases.

Conclusion

By integrating the SailPoint ISC Search API within a NERM workflow, I was able to implement an effective duplicate email validation process before profile creation. The key learning was to evaluate the API response using the REQUEST attribute context rather than the PROFILE attribute context, ensuring the workflow correctly identifies existing users and prevents duplicate records.

2 Likes

Thanks for sharing this @chaithu979. Could you please clarify whether this KB is intended to prevent duplicates between NERM and ISC, rather than duplicates within NERM itself? Based on the business requirement that says β€œBefore creating a new profile in NERM,” I believe the intention is to prevent duplicate NERM profile creation.

If the requirement is specifically to prevent duplicate NERM profiles, I believe NERM already provides native controls that may cover this without requiring an additional ISC Search API validation step.

At the Profile Type level, NERM Duplicate Prevention lets you select the attributes used to identify duplicate profiles and set Allow user to bypass? = No. (docs)

SailPoint also provides a Unique option for supported text attributes, such as Text Field and Text Area. When enabled, the documentation states that the value must be β€œunique among profiles and pending requests in this profile type,” which should also help prevent duplicate values from pending requests. (docs)

Thanks, Harish. The requirement is to prevent duplicate profile creation in NERM. While NERM’s native duplicate prevention features can help enforce uniqueness within NERM, our use case also requires validating whether the user already exists in the authoritative Workday source before creating a new profile. That’s why we’re considering the ISC Search API approachβ€”to perform a broader identity check rather than relying solely on NERM profile-level duplicate controls.