Policies manage the data that is synchronized between the Identity Vault and the remote data store. The policies are stored in policy sets. Identity Manager installs iManager plug-ins that allow you to create and manage policies.
In order to access the objects that are used in policies, see iManager Navigation.
As part of understanding how policies work, it is important to understand their components.
Policies are made up of rules.
Actions can have dynamic arguments that derive from tokens that are expanded at run time.
Tokens are divided into two classifications: nouns and verbs.
Regular expressions (see Understanding Policies for Identity Manager 4.0.1) and XPath 1.0 expressions (see Understanding Policies for Identity Manager 4.0.1) are commonly used in the rules to create the desired results for the policies.
A policy operates on an XDS document and its primary purpose is to examine and modify that document.
An operation is any element in the XDS document that is a child of the input element and the output element. The elements are part of Novell’s nds.dtd; for more information, see Identity Manager 4.0.1 DTD Reference.
An operation usually represents an event, a command, or a status.
The policy is applied separately to each operation. As the policy is applied to each operation in turn, that operation becomes the current operation. Each rule is applied sequentially to the current operation. All of the rules are applied to the current operation unless an action is executed by a prior rule that causes subsequent rules to no longer be applied.
A policy can also get additional context from outside of the document and cause side effects that are not reflected in the result document.
The following sections explain how to create and use policies.