Skip to main content
Rules decide which accounts Primo prepares for a new hire. Each rule targets a set of employees and lists the SaaS they get, with the role, group, licence, or organizational unit to assign in each SaaS. When an onboarding starts, Primo combines every rule the new hire matches and pre-fills the onboarding’s email and SaaS provisioning steps.

Prerequisites

  • The SaaS read permission to see rules, and the SaaS write permission to create or edit them.
  • The SaaS you want to provision, connected or tracked manually. See Connect your SaaS and Track a SaaS manually.

Understand the default rule

Every company has a built-in All employees rule. It applies to every new hire, regardless of other rules, and has no target to edit. Use it for the SaaS everyone gets, such as your email provider or chat tool.

Create a rule

1

Go to SaaS > Rules

The list shows the All employees rule and every rule you created.
2

Click Create new rules

Enter a Rule name, for example Engineering, then confirm.
3

Set the target

Open the Target tab. Under Targeted employees, add one or more conditions on Team, Work location, Job Title, Legal entity, or Manager, using is, is any of, or is not. Click Save.By default, an employee must match every condition. Turn on Match any filter to target employees who match at least one.
4

Add SaaS

Open the Apps tab. SaaS already in the rule appear under SaaS used in profile, and the others under SaaS available for use. Select a SaaS to add it.If the SaaS has roles, groups, licences, or organizational units, the Setup provisioning modal opens. Choose the values to assign under Roles selection, Groups selection, License selection, and Organizational units selection, then save.
Once a target is set and before you add SaaS, click Suggest with AI to get a first list of SaaS for the targeted employees.
Only SaaS that can create accounts appear in the Apps tab: SaaS connected with provisioning, and SaaS tracked manually. For a manually tracked SaaS, the onboarding gets a Provision [app name] task assigned to the SaaS owner instead of an automatic account creation.

How rules combine

A new hire can match several rules. Primo applies all of them, plus the All employees rule:
  • Apps from every matching rule are added together.
  • Values that allow several entries, such as groups, are combined.
  • Values that allow a single entry, such as a role or a licence, come from your own rules first, over the All employees rule. If two of your rules set different values for the same SaaS, the result depends on which rule was created first. Avoid overlapping targets for the same SaaS.

When rules apply

Rules apply once, when an onboarding starts. They pre-fill:
  • The Provision email step, for your email provider.
  • The Provision SaaS accounts step, for every other SaaS.
You can review and change the pre-filled accounts on the onboarding before they are created. See Automate your onboardings.
Rules don’t change existing accounts. Editing a rule, or an employee’s HR data changing after their onboarding, does not add or remove access. To remove access, use offboarding or the employee’s identities.

Manage rules

From SaaS > Rules, you can:
  • Rename a rule.
  • Duplicate a rule to start a similar one.
  • Delete a rule. New hires are no longer targeted by it; their other matching rules still apply.