# Transform to create unique email only if condition satisfies

**URL:** <https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud\
**Created:** [September 3, 2025, 3:37am UTC](https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847 "2025-09-03T03:37:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulghare1](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@rahulghare1](https://developer.sailpoint.com/discuss/u/rahulghare1)\
**Post date:** [September 3, 2025, 3:37am UTC](https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847/1 "2025-09-03T03:37:58Z")

</div>

I am trying to create unique email in create provisional policy only if user is full time employee. I tried below transform but it is not working. is it possible to use transform for this logic

```auto
{
  "attributes": {
    "expression": "$inactiveMail eq TRUE",
    "positiveCondition": "",
    "negativeCondition": "$mail",
    "inactiveMail": {
      "attributes": {
        "attributeName": "employmentStatus"
      },
      "type": "identityAttribute"
    },
    "mail": {
		"type": "usernameGenerator",
		"attributes": {
			"sourceCheck": true,
			"patterns": [
				"$(firstname).$(lastname)$(emailDomain)",
				"$(firstname).$(lastname)$(uniqueCounter)$(emailDomain)"
			],
			"firstname": {
				"type": "identityAttribute",
				"attributes": {
					"name": "firstname"
				}
			},
			"lastname": {
				"type": "identityAttribute",
				"attributes": {
					"name": "lastname"
				}
			},
			"emailDomain": {
				"type": "identityAttribute",
				"attributes": {
					"name": "emailDomain"
				}
			}
		}
    }
  },
  "type": "conditional"
}

```

---

<div class="post-metadata">

**Author:** ![udayputta](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/udayputta/32/14195_2.png) [@udayputta](https://developer.sailpoint.com/discuss/u/udayputta)\
**Post date:** [September 3, 2025, 4:31am UTC](https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847/2 "2025-09-03T04:31:37Z")

</div>

> [@rahulghare1](#):
>
> full time employee

Hi I could see couple of mistakes in your transform

1. When you are getting employmentStatus you have to use “name” not attributeName in identityAttribute operation transform
2. In the expression you are doing a check if employmentstatus is TRUE which means employee is full time. If it is true your transform retruns empty value as it goes to positive condition.
3. In usernameGenerator you have use the syntax for uniqueCounter like this ${uniqueCounter}. So that is also not correct.

I have made those adjustments and created a new transform check if this works for you.

```json
{
    "name": "mail",
    "transform": {
        "type": "conditional",
        "attributes": {
            "expression": "$userEmployeeStatus eq TRUE",
            "positiveCondition": "$generatedEmail",
            "negativeCondition": "$existingEmail",
            "userEmployeeStatus": {
                "attributes": {
                    "name": "employmentStatus"
                },
                "type": "identityAttribute"
            },
            /* Use existing email for full time employee if present else use blank */
            "existingEmail": {
                "type": "firstValid",
                "attributes": {
                    "values": [
                        {
                            "type": "identityAttribute",
                            "attributes": {
                                "name": "email"
                            }
                        },
                        {
                            "type": "static",
                            "attributes": {
                                "value": ""
                            }
                        }
                    ]
                }
            },
            /* Generate a unique email */
            "generatedEmail": {
                "type": "usernameGenerator",
                "attributes": {
                    "sourceCheck": true,
                    "patterns": [
                        "$fn.$ln$emailDomain",
                        "$fn.$ln${uniqueCounter}$emailDomain"
                    ],
                    "fn": {
                        "type": "lower",
                        "attributes": {
                            "input": {
                                "type": "identityAttribute",
                                "attributes": {
                                    "name": "firstname"
                                }
                            }
                        }
                    },
                    "ln": {
                        "type": "lower",
                        "attributes": {
                            "input": {
                                "type": "identityAttribute",
                                "attributes": {
                                    "name": "lastname"
                                }
                            }
                        }
                    },
                    "emailDomain": {
                        "type": "lower",
                        "attributes": {
                            "input": {
                                "type": "identityAttribute",
                                "attributes": {
                                    "name": "emailDomain"
                                }
                            }
                        }
                    }
                }
            }
        }
    },
    "attributes": {
        "cloudMaxSize": "100",
        "cloudMaxUniqueChecks": "25",
        "cloudRequired": "true"
    },
    "isRequired": false,
    "type": "string",
    "isMultiValued": false
}

```

I have added some comments to understand better. remove them when you are testing.

For negativeCondition I have used firstValidTransform to get the existing email instead of returning blank. If that is the your use case you can return blank

Also use cloud\* attribute that will allow to do a uniqueness retry

---

<div class="post-metadata">

**Author:** ![rahulghare1](https://avatars.discourse-cdn.com/v4/letter/r/ed8c4c/32.png) [@rahulghare1](https://developer.sailpoint.com/discuss/u/rahulghare1)\
**Post date:** [September 3, 2025, 6:00am UTC](https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847/3 "2025-09-03T06:00:06Z")

</div>

> [@udayputta](#):
>
> loud\*

Thanks @udayputta for your response. I am getting uniqueness retry issue as follows:

```auto
trackingId: 22a525b3fc294e6d98ba20eef7b0ed3a java.lang.RuntimeException: sailpoint.tools.GeneralException: Unable to generate a unique value for 'unittest13@aaa.com', action UniqueAccountIdValidator[nativeIdentity=unit13.test13@bbb.com,app=Active Directory] is not retry-able due to ConnectorException: [InvalidConfigurationException] [Error details] Required string attribute 'User' is not defined.It must have a valid value.

```

Could you please elaborate more on how to use **cloud\* attribute** that will allow to do a uniqueness retry.

---

<div class="post-metadata">

**Author:** ![udayputta](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/udayputta/32/14195_2.png) [@udayputta](https://developer.sailpoint.com/discuss/u/udayputta)\
**Post date:** [September 3, 2025, 6:33pm UTC](https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847/4 "2025-09-03T18:33:28Z")

</div>

hi Rahul,

In the tranform that I have shared is already using that attribute. For more information you can refer the below link and use the correct count for your scenario

> **[Username Generator | SailPoint Developer Community](https://developer.sailpoint.com/docs/extensibility/transforms/operations/username-generator)**
>
> Derive a unique value for an attribute in an account create profile.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [November 2, 2025, 6:33pm UTC](https://developer.sailpoint.com/discuss/t/transform-to-create-unique-email-only-if-condition-satisfies/175847/5 "2025-11-02T18:33:45Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
