Preview the issues the rule draft of a SaaS raises
Judge the DRAFT of the provisioning rule of the given SaaS — the text the rule editor shows, published or not — against the whole directory, exactly as publishing it would: every employee compared to the account they hold, and every identity on the SaaS. Returns the persons it would flag, with the issues (missing or unexpected access, groups, roles, licenses and organization units to add or remove), and compliantCount, the employees it leaves in order. Same issue types as getSaasIssues, which lists what the published rule found.
It creates and stores nothing, and works whatever the approval status of the SaaS. It reads the saved draft, never a text passed in: save it with updateSaasRule first. EXPENSIVE: one AI judgement over the whole directory — call it once per check, never in a loop.
Authorizations
Use your Primo API key in the Authorization header as Bearer <API_KEY>.