Skip to content
Proud to collaborate with Microsoft for Startups

identity.end-user.actor-binding.reconcile ​

Suspend Staff-actor end-user bindings that no longer pass eligibility (scheduled sweep)

Sweep active Staff-actor end-user bindings and suspend those failing eligibility E1-E5.

Scheduled every 15 minutes (cron */15 * * * *). Scoped to the run's organization when one is present, platform-wide otherwise. A paused actor (ACTOR_NOT_ACTIVE) and an unavailable evaluation (ELIGIBILITY_UNAVAILABLE) never suspend.

Inputs:

  • organization_uuid: restrict the sweep (optional)
  • dry_run: report without writing (optional, default false)
  • limit: maximum bindings scanned (optional, default 5000)

Outputs (terminal state_data):

  • scanned, suspended_count, eligible_count, paused_count, unavailable_count, suspensions [{end_user_uuid, staff_actor_uuid, identity_app_uuid, code, reason}], dry_run

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo——
dry_runbooleanNo——
limitintegerNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
scannedintegerNo——
suspended_countintegerNo——
eligible_countintegerNo——
paused_countintegerNo——
unavailable_countintegerNo——
suspensionslistNo——
dry_runbooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
reasonstringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "identity.end-user.actor-binding.reconcile",
  "initial_data": {
    "organization_uuid": "value",
    "dry_run": true,
    "limit": 123
  }
}