Joiners, movers, leavers
For the events in the lifecycle of an identity – joiner, mover, leaver, rehire and archive – Nova has one routine each: a sequence of steps. Administrators define the steps under “Administration” → “Identity Management” → “User Lifecycle”; for each routine, steps can be added, reordered with the drag handle and switched on or off individually. The built-in steps carry German labels in both interface languages; the table under “The steps” below explains them.
The routines and their triggers
Joiner
- Trigger: on the dashboard, the “HR Integration” window lists the day's joiners from the HR import. “Onboard” starts the routine for the selected people, after a preview of the steps.
- Default: “Setze Identität aktiv - Entsperrung von Konten” and “Setze Identität auf Planstelle”.
Mover
- Trigger: the HR import, when a person's position has changed; adding a person to an organisational unit, removing them or moving them; “Run move” in the “HR Integration” window.
- Default: “Setze Identität auf Planstelle”.
Leaver
- Trigger: the “Leave-Date Scan” job (pre-configured to run daily at 02:00) for active identities whose leave date has passed; deleting an identity, which Nova then moves to the recycle bin.
- Default: “Ownership-Übergabe für KI-Agenten” and “Setze Identität inaktiv - Sperrung von Konten”. The default routine does not revoke assignments; a step such as “Entzug aller bestehenden Berechtigungen (Clean Start)” can be added for that.
A grace period after which Nova removes the entitlements of terminated identities is part of the status model in Identities and their status. planned
Rehire
- Trigger: the HR import finds an active person whose identity is in the recycle bin – recognised by personnel number or e-mail address – and brings the identity back.
- Default: “Entzug aller bestehenden Berechtigungen (Clean Start)”, switched off. Assignments the identity still has are therefore kept; with the step switched on, it starts without old access.
Archive
- Trigger: the permanent deletion of an identity from the recycle bin – with “Delete permanently” or by a job of the “Purge Deleted Users” type. This job deletes identities that have been in the recycle bin longer than the retention period; the default is 90 days, adjustable under “Retention (days)”.
- Default: no steps.
The steps
| Step | Effect |
|---|---|
| “Setze Identität aktiv - Entsperrung von Konten” | sets the identity to active and starts a run that unlocks its linked accounts in the target systems |
| “Setze Identität inaktiv - Sperrung von Konten” | sets the identity to inactive and starts a run that locks its linked accounts |
| “Setze Identität auf Planstelle” | places the identity on the position from the personnel data (attribute P0001-PLANS); it receives the position's business roles. Requires the “Planstellen (OSP)” add-on |
| “Zuweisung Standardmitarbeiterrolle” | assigns the business role with the ID standard-mitarbeiter, if it exists |
| “Entzug aller bestehenden Berechtigungen (Clean Start)” | removes all assignments of the identity |
| “Irreversible Löschung von Backend Konten” | starts a run that permanently deletes all linked accounts in the target systems |
| “Ownership-Übergabe für KI-Agenten” | transfers the AI agents of the departing person to their deputy, otherwise to their manager derived from the organisation; without a successor, Nova marks the agent as orphaned |
With “Manage methods”, administrators create methods of their own. These consist solely of building blocks from a fixed catalogue – such as setting a status, assigning or revoking a business role, creating, locking or deleting an account, or creating an access request – and can be tied to conditions on fields of the identity. When AI is switched on, “Generate with AI” proposes a method from a description in plain words. “Test” really runs a method against a selected identity; it is not a dry run.
How a routine runs
- Nova runs the switched-on steps in the defined order.
- If a step fails, Nova rolls back its changes and continues with the next step.
- If the steps have changed assignments, Nova starts a provisioning run per identity when automatic provisioning is switched on. Steps that lock, unlock or delete accounts start their runs even when automatic provisioning is switched off – see How access is granted and removed.