> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a SaaS account task on a ticket

> Create, remove or update an employee's account on a SaaS application as a SAAS_PROVISIONING task on a ticket, so the account can be scheduled, cancelled and completed like any task. Pass the untyped ticket the work belongs to, such as an onboarding ticket, as `parentTicketId`; without one Primo opens a ticket for the employee to hold the task. `createTicket` and `createTask` cannot make a typed task.

With an API integration the account is carried out by Primo, at once or on `scheduleDate`, and the task completes itself. Without one the task waits for an admin, who creates the account by hand and marks the task done, which records the account in Primo. Cancelling the task cancels the account change.

Use `provisionSaasIdentity` or `deprovisionSaasIdentity` for an account change nobody needs to track on a ticket. Returns the intent `id`, its `taskId` and the `ticketId` holding it. Entitlements are `{ id, name }` pairs from `getSaasById`.

Refused with `PARENT_TICKET_IS_TYPED` or `PARENT_TICKET_IS_A_TASK` (pass the untyped ticket instead), `PARENT_TICKET_NOT_FOUND`, `EMPLOYEE_NOT_FOUND`, `CREDENTIALS_RECIPIENT_REQUIRED` for an application that generates a password (create that account from the cockpit), `SAAS_APPLICATION_USER_REQUIRED` for an UPDATE without `identityId`, and `SAAS_APPLICATION_USER_NOT_FOUND` for an `identityId` that belongs to another employee or application.

<span className="badge-write">Key: Write</span><span className="badge-company">Scope: Company</span>


## OpenAPI

````yaml https://api.getprimo.com/openapi.json post /saas/{saasId}/provisioning-intents
openapi: 3.1.1
info:
  title: Public API - BETA
  description: Read docs on https://docs.getprimo.com/
  version: '1.0'
  contact: {}
servers:
  - url: https://api.getprimo.com
security:
  - apikey: []
tags: []
paths:
  /saas/{saasId}/provisioning-intents:
    post:
      tags:
        - Saas
      summary: Create a SaaS account task on a ticket
      description: >-
        Create, remove or update an employee's account on a SaaS application as
        a SAAS_PROVISIONING task on a ticket, so the account can be scheduled,
        cancelled and completed like any task. Pass the untyped ticket the work
        belongs to, such as an onboarding ticket, as `parentTicketId`; without
        one Primo opens a ticket for the employee to hold the task.
        `createTicket` and `createTask` cannot make a typed task.


        With an API integration the account is carried out by Primo, at once or
        on `scheduleDate`, and the task completes itself. Without one the task
        waits for an admin, who creates the account by hand and marks the task
        done, which records the account in Primo. Cancelling the task cancels
        the account change.


        Use `provisionSaasIdentity` or `deprovisionSaasIdentity` for an account
        change nobody needs to track on a ticket. Returns the intent `id`, its
        `taskId` and the `ticketId` holding it. Entitlements are `{ id, name }`
        pairs from `getSaasById`.


        Refused with `PARENT_TICKET_IS_TYPED` or `PARENT_TICKET_IS_A_TASK` (pass
        the untyped ticket instead), `PARENT_TICKET_NOT_FOUND`,
        `EMPLOYEE_NOT_FOUND`, `CREDENTIALS_RECIPIENT_REQUIRED` for an
        application that generates a password (create that account from the
        cockpit), `SAAS_APPLICATION_USER_REQUIRED` for an UPDATE without
        `identityId`, and `SAAS_APPLICATION_USER_NOT_FOUND` for an `identityId`
        that belongs to another employee or application.
      operationId: createSaasProvisioningIntent
      parameters:
        - name: saasId
          required: true
          in: path
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSaasProvisioningIntentBody'
      responses:
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SaasProvisioningIntent_Output'
components:
  schemas:
    CreateSaasProvisioningIntentBody:
      type: object
      properties:
        employeeId:
          description: >-
            The Primo employee the account is for (`id` from the employee
            endpoints).
          type: string
          pattern: ^[a-f\d]{24}$
        direction:
          description: >-
            PROVISION creates the account, DEPROVISION removes it, UPDATE
            re-applies the entitlements on it.
          type: string
          enum:
            - PROVISION
            - DEPROVISION
            - UPDATE
        identityId:
          description: >-
            The SaaS identity to update or remove (from
            `getEmployeeSaasIdentities`). Required for UPDATE.
          anyOf:
            - type: string
              pattern: ^[a-f\d]{24}$
            - type: 'null'
        groups:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
        roles:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
        licenses:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
        organizationUnits:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
        parentTicketId:
          description: >-
            The untyped ticket the work belongs to, such as the onboarding
            ticket. Omit it and Primo opens one.
          anyOf:
            - type: string
              pattern: ^[a-f\d]{24}$
            - type: 'null'
        scheduleDate:
          description: >-
            Creates the task SCHEDULED: an integrated application is provisioned
            when it wakes on this date, not now.
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
      required:
        - employeeId
        - direction
    SaasProvisioningIntent_Output:
      type: object
      properties:
        id:
          type: string
          description: Intent id
        taskId:
          description: The SAAS_PROVISIONING task that tracks the account
          anyOf:
            - type: string
            - type: 'null'
        ticketId:
          type: string
          description: >-
            The ticket holding that task: the parentTicketId sent, or the one
            Primo opened
        employeeId:
          type: string
        saasId:
          type: string
        direction:
          type: string
          enum:
            - PROVISION
            - DEPROVISION
            - UPDATE
        identityId:
          anyOf:
            - type: string
            - type: 'null'
        groups:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
            additionalProperties: false
        roles:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
            additionalProperties: false
        licenses:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
            additionalProperties: false
        organizationUnits:
          type: array
          items:
            type: object
            properties:
              id:
                description: >-
                  The entitlement id from `getSaasById`, or null for one only an
                  admin knows by name
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                type: string
                minLength: 1
            required:
              - id
              - name
            additionalProperties: false
        executedAt:
          description: >-
            When Primo carried the account out; null while it waits on its date
            or on the admin
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
      required:
        - id
        - taskId
        - ticketId
        - employeeId
        - saasId
        - direction
        - identityId
        - groups
        - roles
        - licenses
        - organizationUnits
        - executedAt
        - createdAt
      additionalProperties: false
  securitySchemes:
    apikey:
      scheme: bearer
      bearerFormat: API key
      type: http
      description: >-
        Use your Primo API key in the Authorization header as `Bearer
        <API_KEY>`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.