Prerequisites
- The SaaS read permission to see rules, and the SaaS write permission to create or edit them.
- The SaaS you want to provision, connected or tracked manually. See Connect your SaaS and Track a SaaS manually.
Understand the default rule
Every company has a built-in All employees rule. It applies to every new hire, regardless of other rules, and has no target to edit. Use it for the SaaS everyone gets, such as your email provider or chat tool.Create a rule
1
Go to SaaS > Rules
The list shows the All employees rule and every rule you created.
2
Click Create new rules
Enter a Rule name, for example Engineering, then confirm.
3
Set the target
Open the Target tab. Under Targeted employees, add one or more conditions on Team, Work location, Job Title, Legal entity, or Manager, using is, is any of, or is not. Click Save.By default, an employee must match every condition. Turn on Match any filter to target employees who match at least one.
4
Add SaaS
Open the Apps tab. SaaS already in the rule appear under SaaS used in profile, and the others under SaaS available for use. Select a SaaS to add it.If the SaaS has roles, groups, licences, or organizational units, the Setup provisioning modal opens. Choose the values to assign under Roles selection, Groups selection, License selection, and Organizational units selection, then save.
How rules combine
A new hire can match several rules. Primo applies all of them, plus the All employees rule:- Apps from every matching rule are added together.
- Values that allow several entries, such as groups, are combined.
- Values that allow a single entry, such as a role or a licence, come from your own rules first, over the All employees rule. If two of your rules set different values for the same SaaS, the result depends on which rule was created first. Avoid overlapping targets for the same SaaS.
When rules apply
Rules apply once, when an onboarding starts. They pre-fill:- The Provision email step, for your email provider.
- The Provision SaaS accounts step, for every other SaaS.
Rules don’t change existing accounts. Editing a rule, or an employee’s HR data changing after their onboarding, does not add or remove access. To remove access, use offboarding or the employee’s identities.
Manage rules
From SaaS > Rules, you can:- Rename a rule.
- Duplicate a rule to start a similar one.
- Delete a rule. New hires are no longer targeted by it; their other matching rules still apply.