Skip to main content

sailpoint.role_propagation.RolePropagationApi

Role Change Propagation ensures that any changes to the composition of a role’s access objects (entitlements, access profiles, or dimensions) are applied to all member identities. For example: If an entitlement is removed from a role, all identities assigned to that role should lose access to that entitlement as part of this process.

All URIs are relative to https://sailpoint.api.identitynow.com

MethodHTTP requestDescription
cancel-role-propagation-v1POST /role-propagation/v1/terminateTerminate Role Propagation process
get-ongoing-role-propagation-v1GET /role-propagation/v1/is-runningGet ongoing Role Propagation process
get-role-propagation-config-v1GET /role-propagation-config/v1Get Role Change Propagation Configuration
get-role-propagation-status-v1GET /role-propagation/v1/{rolePropagationId}/statusGet status of Role-Propagation process
set-role-propagation-config-v1PUT /role-propagation-config/v1Update Role Change Propagation Configuration
start-role-propagation-v1POST /role-propagation/v1Initiate Role Propagation process

cancel-role-propagation-v1

experimental

This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.

setting x-sailpoint-experimental header

on the configuration object you can set the x-sailpoint-experimental header to `true' to enable all experimantl endpoints within the SDK. Example:

  configuration = Configuration()
configuration.experimental = True

Terminate Role Propagation process This endpoint terminates the ongoing role change propagation process for a tenant.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
x_sail_point_experimentalstr(optional) (default to 'true')Use this header to enable this experimental API.

Return type

(empty response body)

Responses

CodeDescriptionData TypeResponse headers
204Role Propagation has been successfully terminated.-
400Client Error - Returned if the request body is invalid.Errorresponsedto-
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.StartRolePropagationV1401Response-
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.Errorresponsedto-
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.StartRolePropagationV1429Response-
500Internal Server Error - Returned if there is an unexpected error.Errorresponsedto-

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

from sailpoint.role_propagation.api.role_propagation_api import RolePropagationApi
from sailpoint.role_propagation.api_client import ApiClient
from sailpoint.configuration import Configuration
configuration = Configuration()

configuration.experimental = True

with ApiClient(configuration) as api_client:
x_sail_point_experimental = 'true' # str | Use this header to enable this experimental API. (optional) (default to 'true') # str | Use this header to enable this experimental API. (optional) (default to 'true')

try:
# Terminate Role Propagation process

RolePropagationApi(api_client).cancel_role_propagation_v1()
# Below is a request that includes all optional parameters
# RolePropagationApi(api_client).cancel_role_propagation_v1(x_sail_point_experimental)
except Exception as e:
print("Exception when calling RolePropagationApi->cancel_role_propagation_v1: %s\n" % e)

[Back to top]

get-ongoing-role-propagation-v1

experimental

This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.

setting x-sailpoint-experimental header

on the configuration object you can set the x-sailpoint-experimental header to `true' to enable all experimantl endpoints within the SDK. Example:

  configuration = Configuration()
configuration.experimental = True

Get ongoing Role Propagation process This endpoint returns the information of ongoing role change propagation process for a tenant. It returns the information whether the role propagation process is currently running or not, If it is running it returns the details of the ongoing role propagation process. The execution stage of the role propagation process can be one of the following: - PENDING - The role propagation process is queued to be executed. - DATA_AGGREGATION_RUNNING - The role propagation process is currently aggregating data. - LAUNCH_PROVISIONING - The role propagation process has started to provision the access to the identities. - SUCCEEDED - The role propagation process has successfully completed. - FAILED - The role propagation process has failed. - TERMINATED - The role propagation process was externally terminated.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
x_sail_point_experimentalstr(optional) (default to 'true')Use this header to enable this experimental API.

Return type

RolePropagationOngoingResponse

Responses

CodeDescriptionData TypeResponse headers
200Information of ongoing role propagation process.RolePropagationOngoingResponse-
400Client Error - Returned if the request body is invalid.Errorresponsedto-
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.StartRolePropagationV1401Response-
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.Errorresponsedto-
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.StartRolePropagationV1429Response-
500Internal Server Error - Returned if there is an unexpected error.Errorresponsedto-

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

from sailpoint.role_propagation.api.role_propagation_api import RolePropagationApi
from sailpoint.role_propagation.api_client import ApiClient
from sailpoint.role_propagation.models.role_propagation_ongoing_response import RolePropagationOngoingResponse
from sailpoint.configuration import Configuration
configuration = Configuration()

configuration.experimental = True

with ApiClient(configuration) as api_client:
x_sail_point_experimental = 'true' # str | Use this header to enable this experimental API. (optional) (default to 'true') # str | Use this header to enable this experimental API. (optional) (default to 'true')

try:
# Get ongoing Role Propagation process

results = RolePropagationApi(api_client).get_ongoing_role_propagation_v1()
# Below is a request that includes all optional parameters
# results = RolePropagationApi(api_client).get_ongoing_role_propagation_v1(x_sail_point_experimental)
print("The response of RolePropagationApi->get_ongoing_role_propagation_v1:\n")
print(results.model_dump_json(by_alias=True, indent=4))
except Exception as e:
print("Exception when calling RolePropagationApi->get_ongoing_role_propagation_v1: %s\n" % e)

[Back to top]

get-role-propagation-config-v1

experimental

This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.

setting x-sailpoint-experimental header

on the configuration object you can set the x-sailpoint-experimental header to `true' to enable all experimantl endpoints within the SDK. Example:

  configuration = Configuration()
configuration.experimental = True

Get Role Change Propagation Configuration This endpoint fetches the Role Change Propagation Configuration for the tenant

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
x_sail_point_experimentalstr(optional) (default to 'true')Use this header to enable this experimental API.

Return type

RolePropagationConfigResponse

Responses

CodeDescriptionData TypeResponse headers
200Role Change Propagation configuration for the tenant.RolePropagationConfigResponse-
400Client Error - Returned if the request body is invalid.Errorresponsedto-
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.StartRolePropagationV1401Response-
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.Errorresponsedto-
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.StartRolePropagationV1429Response-
500Internal Server Error - Returned if there is an unexpected error.Errorresponsedto-

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

from sailpoint.role_propagation.api.role_propagation_api import RolePropagationApi
from sailpoint.role_propagation.api_client import ApiClient
from sailpoint.role_propagation.models.role_propagation_config_response import RolePropagationConfigResponse
from sailpoint.configuration import Configuration
configuration = Configuration()

configuration.experimental = True

with ApiClient(configuration) as api_client:
x_sail_point_experimental = 'true' # str | Use this header to enable this experimental API. (optional) (default to 'true') # str | Use this header to enable this experimental API. (optional) (default to 'true')

try:
# Get Role Change Propagation Configuration

results = RolePropagationApi(api_client).get_role_propagation_config_v1()
# Below is a request that includes all optional parameters
# results = RolePropagationApi(api_client).get_role_propagation_config_v1(x_sail_point_experimental)
print("The response of RolePropagationApi->get_role_propagation_config_v1:\n")
print(results.model_dump_json(by_alias=True, indent=4))
except Exception as e:
print("Exception when calling RolePropagationApi->get_role_propagation_config_v1: %s\n" % e)

[Back to top]

get-role-propagation-status-v1

experimental

This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.

setting x-sailpoint-experimental header

on the configuration object you can set the x-sailpoint-experimental header to `true' to enable all experimantl endpoints within the SDK. Example:

  configuration = Configuration()
configuration.experimental = True

Get status of Role-Propagation process This endpoint returns the information of the specified role change propagation process. The execution stage of the role propagation process can be one of the following:

  • PENDING - The role propagation process is queued to be executed.
  • DATA_AGGREGATION_RUNNING - The role propagation process is currently aggregating data.
  • LAUNCH_PROVISIONING - The role propagation process has started to provision the access to the identities.
  • SUCCEEDED - The role propagation process has successfully completed.
  • FAILED - The role propagation process has failed.
  • TERMINATED - The role propagation process was externally terminated.

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
Pathrole_propagation_idstrTrueThe ID of the role propagation process to retrieve the status for.
x_sail_point_experimentalstr(optional) (default to 'true')Use this header to enable this experimental API.

Return type

RolePropagationStatusResponse

Responses

CodeDescriptionData TypeResponse headers
200Information of the role propagation process.RolePropagationStatusResponse-
400Client Error - Returned if the request body is invalid.Errorresponsedto-
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.StartRolePropagationV1401Response-
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.Errorresponsedto-
404Not Found - returned if the request URL refers to a resource or object that does not existErrorresponsedto-
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.StartRolePropagationV1429Response-
500Internal Server Error - Returned if there is an unexpected error.Errorresponsedto-

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

from sailpoint.role_propagation.api.role_propagation_api import RolePropagationApi
from sailpoint.role_propagation.api_client import ApiClient
from sailpoint.role_propagation.models.role_propagation_status_response import RolePropagationStatusResponse
from sailpoint.configuration import Configuration
configuration = Configuration()

configuration.experimental = True

with ApiClient(configuration) as api_client:
role_propagation_id = '47b9fb02-e12e-42ba-8bfe-1860d78c88eb' # str | The ID of the role propagation process to retrieve the status for. # str | The ID of the role propagation process to retrieve the status for.
x_sail_point_experimental = 'true' # str | Use this header to enable this experimental API. (optional) (default to 'true') # str | Use this header to enable this experimental API. (optional) (default to 'true')

try:
# Get status of Role-Propagation process

results = RolePropagationApi(api_client).get_role_propagation_status_v1(role_propagation_id=role_propagation_id)
# Below is a request that includes all optional parameters
# results = RolePropagationApi(api_client).get_role_propagation_status_v1(role_propagation_id, x_sail_point_experimental)
print("The response of RolePropagationApi->get_role_propagation_status_v1:\n")
print(results.model_dump_json(by_alias=True, indent=4))
except Exception as e:
print("Exception when calling RolePropagationApi->get_role_propagation_status_v1: %s\n" % e)

[Back to top]

set-role-propagation-config-v1

experimental

This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.

setting x-sailpoint-experimental header

on the configuration object you can set the x-sailpoint-experimental header to `true' to enable all experimantl endpoints within the SDK. Example:

  configuration = Configuration()
configuration.experimental = True

Update Role Change Propagation Configuration This endpoint enables or disables the Role Change Propagation Process for the tenant

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
Bodyrole_propagation_config_inputRolePropagationConfigInputTrue
x_sail_point_experimentalstr(optional) (default to 'true')Use this header to enable this experimental API.

Return type

RolePropagationConfigResponse

Responses

CodeDescriptionData TypeResponse headers
200Role Change Propagation configuration for the tenant is successfully updated.RolePropagationConfigResponse-
400Client Error - Returned if the request body is invalid.Errorresponsedto-
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.StartRolePropagationV1401Response-
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.Errorresponsedto-
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.StartRolePropagationV1429Response-
500Internal Server Error - Returned if there is an unexpected error.Errorresponsedto-

HTTP request headers

  • Content-Type: application/json
  • Accept: application/json

Example

from sailpoint.role_propagation.api.role_propagation_api import RolePropagationApi
from sailpoint.role_propagation.api_client import ApiClient
from sailpoint.role_propagation.models.role_propagation_config_input import RolePropagationConfigInput
from sailpoint.role_propagation.models.role_propagation_config_response import RolePropagationConfigResponse
from sailpoint.configuration import Configuration
configuration = Configuration()

configuration.experimental = True

with ApiClient(configuration) as api_client:
role_propagation_config_input = '''sailpoint.role_propagation.RolePropagationConfigInput()''' # RolePropagationConfigInput |
x_sail_point_experimental = 'true' # str | Use this header to enable this experimental API. (optional) (default to 'true') # str | Use this header to enable this experimental API. (optional) (default to 'true')

try:
# Update Role Change Propagation Configuration
new_role_propagation_config_input = RolePropagationConfigInput.from_json(role_propagation_config_input)
results = RolePropagationApi(api_client).set_role_propagation_config_v1(role_propagation_config_input=new_role_propagation_config_input)
# Below is a request that includes all optional parameters
# results = RolePropagationApi(api_client).set_role_propagation_config_v1(new_role_propagation_config_input, x_sail_point_experimental)
print("The response of RolePropagationApi->set_role_propagation_config_v1:\n")
print(results.model_dump_json(by_alias=True, indent=4))
except Exception as e:
print("Exception when calling RolePropagationApi->set_role_propagation_config_v1: %s\n" % e)

[Back to top]

start-role-propagation-v1

experimental

This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.

setting x-sailpoint-experimental header

on the configuration object you can set the x-sailpoint-experimental header to `true' to enable all experimantl endpoints within the SDK. Example:

  configuration = Configuration()
configuration.experimental = True

Initiate Role Propagation process This endpoint initiates a role change propagation process for a tenant asynchronously. If all preconditions are met, the request is accepted and a rolePropagationId is returned which can be used to view the status. API throws 4xx if any of the following conditions are met - Role propagation feature is disabled - There is an ongoing role propagation for the tenant - Role refresh needs to be kicked off as part of the role propagation (skipRoleRefresh=false) and there is an ongoing refresh for the tenant

API Spec

Parameters

Param TypeNameData TypeRequiredDescription
Queryskip_role_refreshbool(optional) (default to False)When true, the role refresh is not performed. Keeping it false is recommended.
x_sail_point_experimentalstr(optional) (default to 'true')Use this header to enable this experimental API.

Return type

RolePropagationResponse

Responses

CodeDescriptionData TypeResponse headers
202Role Propagation has sucessfully started.RolePropagationResponse-
400Client Error - Returned if the request body is invalid.Errorresponsedto-
401Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.StartRolePropagationV1401Response-
403Forbidden - Returned if the user you are running as, doesn't have access to this end-point.Errorresponsedto-
429Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.StartRolePropagationV1429Response-
500Internal Server Error - Returned if there is an unexpected error.Errorresponsedto-

HTTP request headers

  • Content-Type: Not defined
  • Accept: application/json

Example

from sailpoint.role_propagation.api.role_propagation_api import RolePropagationApi
from sailpoint.role_propagation.api_client import ApiClient
from sailpoint.role_propagation.models.role_propagation_response import RolePropagationResponse
from sailpoint.configuration import Configuration
configuration = Configuration()

configuration.experimental = True

with ApiClient(configuration) as api_client:
skip_role_refresh = False # bool | When true, the role refresh is not performed. Keeping it false is recommended. (optional) (default to False) # bool | When true, the role refresh is not performed. Keeping it false is recommended. (optional) (default to False)
x_sail_point_experimental = 'true' # str | Use this header to enable this experimental API. (optional) (default to 'true') # str | Use this header to enable this experimental API. (optional) (default to 'true')

try:
# Initiate Role Propagation process

results = RolePropagationApi(api_client).start_role_propagation_v1()
# Below is a request that includes all optional parameters
# results = RolePropagationApi(api_client).start_role_propagation_v1(skip_role_refresh, x_sail_point_experimental)
print("The response of RolePropagationApi->start_role_propagation_v1:\n")
print(results.model_dump_json(by_alias=True, indent=4))
except Exception as e:
print("Exception when calling RolePropagationApi->start_role_propagation_v1: %s\n" % e)

[Back to top]