Preview the SaaS accounts the rules grant to a person
Judge a person against the company’s published SaaS rules and return, for each APPROVED application whose rule grants them an account, the groups, roles, licenses and organization units they should get. The same judgement decides what a new hire is preselected for at onboarding and which access gaps an application shows.
The person is described by attributes, not by an id: they do not need to exist in Primo yet, so it answers for a future hire as well as for an employee. For an existing employee, pass what getEmployee and getEmployeeCustomFields return for them — the rules may depend on any of it, custom fields included.
It creates nothing. Each entry carries the saasId and the entitlement ids provisionSaasIdentity takes, so a proposal built from it can be carried out once approved. An application without a published rule, or whose rule does not grant the person, is absent.
EXPENSIVE: one AI judgement per application with a published rule. Call it once per person, never in a loop or across the directory.
Authorizations
Use your Primo API key in the Authorization header as Bearer <API_KEY>.
Body
First name of the person.
1Last name of the person.
1Work email of the person.
1Names of the teams the person is in, as the company writes them. A team that does not exist in Primo yet is fine.
1Job titles of the person. A title that does not exist in Primo yet is fine.
1Name of the work location, e.g. an office or a city.
1Name of the legal entity that employs the person.
1Full name of the person's manager.
1Kind of contract, e.g. permanent, contractor, intern.
1The person's employee custom field values. The rules read them by the field's label.
Response
One entry per APPROVED application whose published rule grants the person an account. An application the rules do not grant is absent.