Monitoring and jobs
Administrators follow Nova's operation in the “Monitoring” area. The background jobs come together there as well: tasks such as imports, deadlines and retries that Nova runs on a schedule or at the push of a button.
The “Monitoring” area
| Tab | Content |
|---|---|
| “Background Jobs” | all jobs with their schedule and last run; the most recent runs with status, progress, duration and trigger; key figures such as the failed runs of the last 24 hours |
| “System Health” | CPU, memory and disk usage; state of the application and the database; reachability of the local AI server; result of the last check per target system |
| “Application Log” | warnings and errors of the application, filterable by level, period and text |
| “Audit Log” | logged actions in Nova |
| “Provisioning Log” | provisioning runs, individual provisioning events and changes in the target systems in one list, filterable by type and system |
| “Outbox” | outgoing notifications with their status; this is where administrators set sending to “Active”, “Paused” or “Off” |
“System Health”, “Application Log”, “Audit Log” and “Outbox” are reserved for administrators. “Background Jobs”, “System Health” and “Provisioning Log” refresh every five seconds.
Managing jobs
Only administrators may create, edit, schedule, start, cancel and delete jobs; new jobs are created with “New job”. A schedule sets weekdays and a time, or a one-off date. “Run Now” runs a job immediately. “Cancel” marks a running run as cancelled; whatever it has written up to that point stays in place. A job's runs remain in the history even if the job is deleted.
Nova evaluates all schedules in the Europe/Berlin time zone. This time zone is fixed and does not depend on NOVA_TIMEZONE. On start, Nova writes the scheduled jobs and their next run time to the container log.
Preset jobs
After installation, four jobs are created, enabled and scheduled:
| Job | Schedule | Task |
|---|---|---|
| “Retry Failed Provisioning” | every 15 minutes | retries failed provisioning runs of the last 24 hours at growing intervals (10, 20, 40 minutes), at most three times |
| “Leave-Date Scan” | daily at 02:00 | runs the leaver routine for active identities whose leave date has passed |
| “Activate Pending Assignments” | daily at 02:30 | pushes future-dated assignments on their start date to target systems without validity dates of their own |
| “Target System Health Poll” | every 10 minutes | checks that the target systems can be reached; when a system newly goes offline, Nova records it in the “Audit Log” |
Nova recreates deleted preset jobs on the next start. To stop using one of these jobs, disable it.
In addition, internal tasks run that do not appear in the job list: Nova sends queued notifications about every 20 seconds and cleans up every day – completed outbox entries older than 90 days (default), plus expired exports.
Further job types
Administrators create further jobs as needed, among them:
- Lifecycle and HR: “Import HR users”, “Apply future changes”, “Purge Deleted Users” – permanently deletes identities from the trash once the retention period has passed
- Entitlements: “Cleanup Expired Assignments”, “Mass Role Assignment”, “Check System Roles”
- Governance: “SoD Violation Scan”, “Approval Escalation”, “Recertification Deadline Reminder”, “Agent Review Scan”
- Target systems: imports per connector, such as “Sync SAP Users”, “Import SAP Roles”, “Import LDAP Groups”, “Import Entra Groups”, “Import Keycloak Groups”, “Import SCIM groups” and “Sync SAP OM”
Expired assignments
“Cleanup Expired Assignments” is not created during installation. The job removes assignments whose validity has ended. If “Auto-provision backend systems” is switched on (“Administration” → “Provisioning” → “Mapping”), it also triggers the removal in the target systems. Anyone working with end dates should create the job and schedule it, for example daily.
Notification of failures
If a job run fails, Nova notifies the administrators by email and – if the Microsoft Teams add-on is enabled and set up – in Teams as well. Each recipient receives at most one message per job, error and hour. If a provisioning run fails completely or partly, messages also go to the administrators, and for runs resulting from an approved access request to the person who requested it as well.
Nova does not send a message when a target system goes offline; this shows up in the “Audit Log” and under “System Health”. Messages by email require email sending to be set up, see Requirements. The “Outbox” shows what was sent.