# Time-based identity refresh

**URL:** <https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906>\
**Category:** Video Library\
**Tags:** developer-days-2025, identity-security-cloud\
**Created:** [May 22, 2025, 2:18pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906 "2025-05-22T14:18:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![NataliaYunusov](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/nataliayunusov/32/22988_2.png) [@NataliaYunusov](https://developer.sailpoint.com/discuss/u/NataliaYunusov)\
**Post date:** [May 22, 2025, 2:18pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/1 "2025-05-22T14:18:22Z")

</div>

https://play.vidyard.com/6DwMAyztWh6CELde4RrncW.html?
# Description

Time-Based Identity Refresh enables precise scheduling of identity processing using the Next Processing Date attribute. This approach ensures critical events, like onboarding and offboarding, occur at the exact required time. In this session, we’ll explore how it works, its benefits, and how to configure it for seamless identity lifecycle management.

**Determine NextProcessingDate Transform:**  
[Determine NextProcessingDate.json](https://developer.sailpoint.com/discuss/uploads/short-url/uUTnvNAljMkLym4XrVnvTDghpt3.json) (9.1 KB)

**Determine LifecycleState Transform:**  
[Determine LifeCycleState.json](https://developer.sailpoint.com/discuss/uploads/short-url/tOUtmvXqTrkoNP4LIr33esjejDa.json) (14.3 KB)

**Sample Input:**  
startDate: `2025-04-01T06:00:00-05:00`.  
endDate: `2026-12-15T15:00:00-05:00`.

**Presentation Deck:**  
[SailPoint\_Time-based identity processing\_ISC Stage 1\_DevDays 5.22.25.pptx](https://developer.sailpoint.com/discuss/uploads/short-url/sr1O6OiL0zRrCbf0yP1KczEL8lJ.pptx) (3.1 MB)

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/d/a/da171c3a4405def8186b42e5ca1a26bfe0046d5f.jpeg)

---

<div class="post-metadata">

**Author:** ![mjos](https://avatars.discourse-cdn.com/v4/letter/m/f08c70/32.png) [@mjos](https://developer.sailpoint.com/discuss/u/mjos)\
**Post date:** [May 22, 2025, 4:58pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/2 "2025-05-22T16:58:04Z")

</div>

Good use case explanation and solution

---

<div class="post-metadata">

**Author:** ![bradleywest](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@bradleywest](https://developer.sailpoint.com/discuss/u/bradleywest)\
**Post date:** [May 28, 2025, 6:50pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/3 "2025-05-28T18:50:05Z")

</div>

Great presentation Natalia,

A quick question though. Is the assumed ISO8601 in UTC? or is that a CST value with an offset

example.

2025-04-01T06:00:00 (UTC)? or 2025-04-01T06:00:00 (CST).

Also, what happens if they include Z at the end of the string  
2025-0401T06:00:00-05:00:00Z

---

<div class="post-metadata">

**Author:** ![NataliaYunusov](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/nataliayunusov/32/22988_2.png) [@NataliaYunusov](https://developer.sailpoint.com/discuss/u/NataliaYunusov)\
**Post date:** [May 28, 2025, 8:54pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/4 "2025-05-28T20:54:51Z")

</div>

Hi Bradley,

Great question — thanks for asking!

The value for `nextProcessingDate` must be in ISO 8601 format, but it **does not need to be in UTC**. You can include a local time with a time zone offset (e.g., CST), and SailPoint will automatically convert it to UTC during processing.

So both of these are valid and supported:

- ✅`2025-04-01T06:00:00-05:00` → 6:00 AM CST (UTC-5)
- ✅`2025-04-01T11:00:00Z` → same moment expressed in UTC

What’s **not valid** is combining both an offset and the `Z` suffix, like this:

- ❌ `2025-04-01T06:00:00-05:00Z`  
This is incorrect because it mixes two different time zone indicators (offset + Zulu/UTC), which creates ambiguity.

---

<div class="post-metadata">

**Author:** ![pradeep1602](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/pradeep1602/32/30858_2.png) [@pradeep1602](https://developer.sailpoint.com/discuss/u/pradeep1602)\
**Post date:** [October 15, 2025, 9:19am UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/5 "2025-10-15T09:19:05Z")

</div>

How do you differentiate the refresh for Lifecycle management vs other things(attribute refresh, attribute sync, Role assignment etc) in this?

---

<div class="post-metadata">

**Author:** ![RPook](https://avatars.discourse-cdn.com/v4/letter/r/b487fb/32.png) [@RPook](https://developer.sailpoint.com/discuss/u/RPook)\
**Post date:** [November 11, 2025, 5:54pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/6 "2025-11-11T17:54:32Z")

</div>

Hello,  
I see that when mapping the nextProcessing attribute, you set your example source to “Workday Fake” and the attribute to “description”. What practical purpose does the “description” attribute server, and how does it help create a date attribute?

---

<div class="post-metadata">

**Author:** ![connor-Maguire](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@connor-Maguire](https://developer.sailpoint.com/discuss/u/connor-Maguire)\
**Post date:** [November 27, 2025, 10:06pm UTC](https://developer.sailpoint.com/discuss/t/time-based-identity-refresh/135906/7 "2025-11-27T22:06:13Z")

</div>

both the source and the attribute for the example are just a place holder. The only requirement is that they resolve to a value so that the transform can get triggered. The value doesn’t end up feeding into the transform - so it can be anything. Commonly we use values like FILENUMBER from workday since its always going to be populated.
