> For the complete documentation index, see [llms.txt](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management.md).

# Lifecycle Management APIs

Programmatic identity lifecycle management for access profiles, policies, and provisioning workflows

Veza's Lifecycle Management APIs enable programmatic management of identity lifecycle processes for your organization. Use these APIs to automate provisioning, access changes, and deprovisioning through Access Profiles and Policy-based workflows.

The Lifecycle Management APIs help you:

* Create and manage Access Profiles that define collections of entitlements
* Build Policy workflows with conditional logic based on identity attributes
* Automate identity synchronization across systems
* Test policy configurations against specific identities
* Manage datasources available for lifecycle operations

See the [Lifecycle Management](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management.md) product documentation for information about the basic components of Lifecycle Management, such as Policies, Access Profiles, and available actions for Lifecycle Management Integrations.

### Base URL

These endpoints are available under `{{VezaURL}}/api/private/` for private APIs and `{{VezaURL}}/api/v1/` for stable APIs. You must use the appropriate prefix when calling the API, for example:

```bash
curl -X GET 'https://your-org.vezacloud.com/api/private/lifecycle_management/policies'
```

### Authentication

### Available Endpoints

#### Identity Operations

Identities represent users managed by Lifecycle Management policies. Each identity is discovered from a policy's configured source of identity (such as Okta, Workday, or Active Directory) and tracks the user's access profiles, entitlements, and lifecycle state.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Get Identity</strong></td><td>Retrieve detailed identity information including access profiles and attributes</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/getidentity.md">Get Identity</a></td></tr><tr><td><strong>List Identity Entitlements</strong></td><td>Get all roles, groups, and entitlements assigned to an identity</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/listidentityentitlements.md">List Identity Entitlements</a></td></tr></tbody></table>

#### Access Profile Operations

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Create Access Profile</strong></td><td>Create a new access profile with entitlements and settings</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/createaccessprofile.md">Create Access Profile</a></td></tr><tr><td><strong>List Access Profiles</strong></td><td>Retrieve all access profiles with filtering and pagination</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/listaccessprofiles.md">List Access Profiles</a></td></tr><tr><td><strong>Update Access Profile Labels</strong></td><td>Modify labels and metadata for an access profile</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/updateaccessprofilelabels.md">Update Access Profile Labels</a></td></tr><tr><td><strong>Update Access Profile Members</strong></td><td>Modify entitlements and permissions within an access profile</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/updateaccessprofilemembers.md">Update Access Profile Members</a></td></tr><tr><td><strong>List Access Profile Members</strong></td><td>View entitlements and permissions in an access profile</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/listaccessprofilemembers.md">List Access Profile Members</a></td></tr><tr><td><strong>Update Access Profile Version</strong></td><td>Create new versions and manage access profile lifecycle</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/updateaccessprofileversion.md">Update Access Profile Version</a></td></tr></tbody></table>

#### Policy Operations

Policies define automated workflows triggered by changes in a source of identity. Each policy creates and manages a set of identities, tracking which workflows have executed and what access has been provisioned for each user.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Create Policy</strong></td><td>Create a new lifecycle management policy with conditions</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/createpolicy.md">Create Policy</a></td></tr><tr><td><strong>List Policies</strong></td><td>Retrieve all policies with filtering and pagination</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/listpolicies.md">List Policies</a></td></tr><tr><td><strong>Get Policy</strong></td><td>Retrieve details for a specific policy</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/getpolicy.md">Get Policy</a></td></tr><tr><td><strong>Update Policy State</strong></td><td>Change policy execution state (running, paused, dry run)</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/updatepolicystate.md">Update Policy State</a></td></tr><tr><td><strong>Update Policy Configuration</strong></td><td>Modify policy workflows, conditions, and actions</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/updatepolicyconfiguration.md">Update Policy Configuration</a></td></tr><tr><td><strong>Add Condition to Policy</strong></td><td>Add conditional logic to policy workflows</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/addconditiontopolicyconfiguration.md">Add Condition to Policy Configuration</a></td></tr><tr><td><strong>Add Action to Policy</strong></td><td>Add actions to policy workflows</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/addactiontopolicyconfiguration.md">Add Action to Policy Configuration</a></td></tr></tbody></table>

#### Administrative & Testing Operations

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Run Dry Run on Identity</strong></td><td>Test policy execution against specific identities without making changes</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/rundryrunonidentity.md">Run Dry Run on Identity</a></td></tr><tr><td><strong>List Available Integrations</strong></td><td>Discover lifecycle management capabilities by integration type</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/listavailableintegrations.md">List Available Integrations</a></td></tr><tr><td><strong>Create Access Profile Type</strong></td><td>Create custom access profile types for organizational needs</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/createaccessprofiletype.md">Create Access Profile Type</a></td></tr><tr><td><strong>List Access Profile Types</strong></td><td>Retrieve available access profile types</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles/listaccessprofiletypes.md">List Access Profile Types</a></td></tr><tr><td><strong>Parallel Execution Settings</strong></td><td>Configure concurrent workflow processing and paused task handling</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/parallelexecutionsettings.md">Parallel Execution Settings</a></td></tr></tbody></table>

#### Provisioning Activity Operations

The Provisioning Activity APIs provide visibility into the execution history of lifecycle management workflows. These endpoints map to the tabs on the [Provisioning Activity](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/getting-started/activity-log.md) page in the Veza UI.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Triggered Workflows</strong></td><td>List, inspect, export, unblock, and restart triggered workflow tasks</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/triggeredworkflows.md">Triggered Workflows</a></td></tr><tr><td><strong>Workflow Actions</strong></td><td>List, inspect, and export action events within workflow tasks</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/workflowactions.md">Workflow Actions</a></td></tr><tr><td><strong>Integration Jobs</strong></td><td>List, inspect, export, and push results for integration-level job events</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/integrationjobs.md">Integration Jobs</a></td></tr><tr><td><strong>Events</strong></td><td>List, inspect, and export granular entity-level change records</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/events.md">Lifecycle Events</a></td></tr><tr><td><strong>Provisioning Status</strong></td><td>Live workflow task counts for a policy extraction run, overall and per workflow</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/provisioningstats.md">Provisioning Status</a></td></tr><tr><td><strong>Extraction Events</strong></td><td>List recent extractions consumed by a policy (Recent Extractions filter)</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/extractionevents.md">Extraction Events</a></td></tr><tr><td><strong>Extraction Runs</strong></td><td>Recent extraction runs for a policy with per-step processing metrics</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/activitylog/extractionruns.md">Extraction Runs</a></td></tr></tbody></table>

#### Datasource Discovery Operations

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>List Lifecycle Management Datasources</strong></td><td>Discover which datasources have lifecycle management enabled and their basic capabilities</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/management/datasources/listlifecyclemanagerdatasources.md">List Lifecycle Manager Datasources</a></td></tr><tr><td><strong>Get Lifecycle Management Datasource</strong></td><td>Get detailed information about a specific datasource including supported actions, syncable attributes, and grantable entitlements</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/management/datasources/getlifecyclemanagerdatasource.md">Get Lifecycle Manager Datasource</a></td></tr><tr><td><strong>List by Action Type</strong></td><td>Find datasources that support specific action types and entity relationships</td><td><a href="/4yItIzMvkpAvMVFAamTf/developers/api/management/datasources/listlifecyclemanagerdatasourcesbyactiontype.md">List by Action Type</a></td></tr></tbody></table>

### Getting Started

To get started with the Lifecycle Management APIs:

1. **Discover available datasources** - Use the [Datasource Discovery Operations](#datasource-discovery-operations) to identify which datasources support lifecycle management
2. **Configure authentication** - Ensure you have the required API authentication configured (a personal API key for a Veza Root Team Administrator)
3. **Create access profiles** - Review the [Access Profile APIs](/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/accessprofiles.md) for creating and manage access collections
4. **Build policies** - Review the [Policy APIs](/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies.md) for endpoints to build automated provisioning workflows
5. **Test configurations** - Use the [Dry Run capabilities](/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management/policies/rundryrunonidentity.md) before deploying to production

For conceptual information about Lifecycle Management, see the [Lifecycle Management documentation](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management.md).

### Related APIs

For managing datasources that support lifecycle management capabilities:

* [Data Sources API](/4yItIzMvkpAvMVFAamTf/developers/api/management/datasources.md) - Core datasource management operations
* [Lifecycle Management Datasources](/4yItIzMvkpAvMVFAamTf/developers/api/management/datasources/listlifecyclemanagerdatasources.md) - Discover lifecycle-enabled datasources

### API Status

{% hint style="warning" %}
**Development Status**: The Veza Lifecycle Management APIs are in active development and subject to change. These APIs are provided under the `/private` API collection, and specifications may evolve as capabilities are added or modified.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veza.com/4yItIzMvkpAvMVFAamTf/developers/api/lifecycle-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
