> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up provisioning rules

> Define which SaaS, roles, groups, licences, and organizational units each new hire gets, based on their team, location, job title, legal entity, or manager.

Rules decide which accounts Primo prepares for a new hire. Each rule targets a set of employees and lists the SaaS they get, with the role, group, licence, or organizational unit to assign in each SaaS. When an onboarding starts, Primo combines every rule the new hire matches and pre-fills the onboarding's email and SaaS provisioning steps.

## Prerequisites

* The **SaaS** read permission to see rules, and the **SaaS** write permission to create or edit them.
* The SaaS you want to provision, connected or tracked manually. See [Connect your SaaS](/saas/connect-apps) and [Track a SaaS manually](/saas/manual-saas).

## Understand the default rule

Every company has a built-in **All employees** rule. It applies to every new hire, regardless of other rules, and has no target to edit. Use it for the SaaS everyone gets, such as your email provider or chat tool.

## Create a rule

<Steps>
  <Step title="Go to SaaS > Rules">
    The list shows the **All employees** rule and every rule you created.
  </Step>

  <Step title="Click Create new rules">
    Enter a **Rule name**, for example *Engineering*, then confirm.
  </Step>

  <Step title="Set the target">
    Open the **Target** tab. Under **Targeted employees**, add one or more conditions on **Team**, **Work location**, **Job Title**, **Legal entity**, or **Manager**, using **is**, **is any of**, or **is not**. Click **Save**.

    By default, an employee must match every condition. Turn on **Match any filter** to target employees who match at least one.
  </Step>

  <Step title="Add SaaS">
    Open the **Apps** tab. SaaS already in the rule appear under **SaaS used in profile**, and the others under **SaaS available for use**. Select a SaaS to add it.

    If the SaaS has roles, groups, licences, or organizational units, the **Setup provisioning** modal opens. Choose the values to assign under **Roles selection**, **Groups selection**, **Licence selection**, and **Organizational units selection**, then save.
  </Step>
</Steps>

<Tip>
  Once a target is set and before you add SaaS, click **Suggest with AI** to get a first list of SaaS for the targeted employees.
</Tip>

Only SaaS that can create accounts appear in the **Apps** tab: SaaS connected with provisioning, and SaaS tracked manually. For a manually tracked SaaS, the onboarding gets a **Provision \[app name]** task assigned to the SaaS owner instead of an automatic account creation.

## How rules combine

A new hire can match several rules. Primo applies all of them, plus the **All employees** rule:

* **Apps** from every matching rule are added together.
* **Values that allow several entries**, such as groups, are combined.
* **Values that allow a single entry**, such as a role or a licence, come from your own rules first, over the **All employees** rule. If two of your rules set different values for the same SaaS, the result depends on which rule was created first. Avoid overlapping targets for the same SaaS.

## When rules apply

Rules apply once, when an onboarding starts. They pre-fill:

* The **Provision email** step, for your email provider.
* The **Provision SaaS accounts** step, for every other SaaS.

You can review and change the pre-filled accounts on the onboarding before they are created. See [Automate your onboardings](/employees/automate-onboardings).

<Info>
  Rules don't change existing accounts. Editing a rule, or an employee's HR data changing after their onboarding, does not add or remove access. To remove access, use [offboarding](/employees/automated-offboardings) or the employee's identities.
</Info>

## Manage rules

From **SaaS > Rules**, you can:

* **Rename** a rule.
* **Duplicate** a rule to start a similar one.
* **Delete** a rule. New hires are no longer targeted by it; their other matching rules still apply.

## Related articles

* [Connect your SaaS](/saas/connect-apps)
* [Track a SaaS manually](/saas/manual-saas)
* [Automate your onboardings](/employees/automate-onboardings)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.