Personalize Notification Templates

Notifications are triggered from the Cymmetri platform for various actions occurring on the platform either through direct action by the end-user or by the virtue of some backend action (such as running of a scheduler for a campaign). Cymmetri platform ships with default notification templates listed below-

  1. Mandatory Notifications

Template
Trigger
Usage
Recipient(s)

Access Code Manager Notification

Triggers when forgot password option used and user does not have email configured

It contains the MFA OTP for the user to enter and reset the forgotten password

User's Manager

Organization Sign-Up

Tenant registration

Sent when a new tenant (organization) is created in the system.

The user performing the registration (initial Organization Admin).

OTP Notification

OTP-based MFA verification

Sends a One-Time Password (OTP) along with its expiry details to verify Multi-Factor Authentication.

The user attempting to log in using MFA.

Password

Admin/Manager password generation

Sends the system-generated password via email for user login.

The user whose password has been generated or reset by an Admin/Manager.

Reset Password

Admin/Manager initiated password reset

Provides a secure reset password link allowing the user to set a new password.

The user whose password reset has been initiated.

Self Registration

User self-registration

Sends account details along with an activation link/button to activate the newly created account.

The self-registered user.

  1. Optional Notifications

Notification Template
Trigger
Usage
Recipient(s)

Application access approval request

When application provisioing is triggered to a user.

The user (typically a manager or administrator) is being notified that a new access or extension request has been submitted and requires their attention. This message identifies who made the request, which application it’s for, and the specific timeframe they are asking for.

Workflow Approver

Application access approval request denied by approver

When an extension or application has been assigned to a user has been rejected via the workflow trigger.

The user is being notified that their request for application access or an extension was not approved. This message directs them to follow up with their system administrator

User who has requested the application/role.

Application access approval request granted

When an extension or application has been assigned to a user succesfully via the workflow trigger.

The user is being notified that their request for application access or an extension has been successfully approved via the workflow approval process. This confirmation specifies the exact timeframe—including the start and end dates—during which the access will be valid.

User who has requested the application/role.

Application assignment

When an application access assigned to a user.

The user is being notified that access to a application has been successfully grantedand dynamically adjusts to confirm new assignments, extension approvals, or the start of provisioning, while clearly stating the validity period for the access.

User who has requested the application/role.

Application scheduled deprovisioning

When an application access assigned to a user is about to expire.

The user is being notified that their access to a specific application is scheduled to be terminated and provides the exact date when the access will end.

User who has requested the application/role.

Campaign Aborted Email Notification

When a campaign aborts.

Notifies relevant stakeholders that the campaign has been aborted.

Configured Campaign Stakeholders in step 4 of the campaign configuration process

Campaign End Email Notification

When a campaign is ends manually/automatically.

The user is being notified that a specific access review campaign has officially concluded. This final summary provides the total number of assignments processed, including the exact counts for approvals, revocations, and any tasks that remained pending by the end date.

Configured Campaign Stakeholders in step 4 of the campaign configuration process

Campaign Start Email Notification

When a campaign is initiated manually/automatically.

The user is being notified that a specific access review campaign has officially launched and provides the key timeline, including the start date and the expected deadline for completion.

All users present as approver in a campaign.

Delegation Assignee Notification

When a user is been assigned as a delegatee.

When a user is designated as a delegate, they are notified via the workflow trigger that they have been granted temporary authority to act on behalf of another user.

Delegatee User

Delegation User Notification

When an existing delegation has been updated.

When a delegation of authority is modified, the system triggers a notification to inform the recipient that their access permissions have been reassigned for a specific period.

Delegating User

Flowable Reconciliation Mail

Flowable-based reconciliation event triggered

Notifies configured recipients regarding reconciliation activity status

Configured Recipients

Group Campaign Aborted Email Notification

When a group campaign has aborted.

Notifies stakeholders of campaign termination

Configured Group Campaign Stakeholders

Group Campaign End Email Notification

When a group campaign has ended.

The user is being notified that a group access review campaign has officially concluded. This message provides a final summary of the results, including the total number of assignments that were approved, revoked, or left pending by the deadline.

Users whose names are mentioned in step 4 of the campaign configuration process.

Group Campaign Start Email Notification

When a group campaign has initiated.

The user is being notified that a new group access review campaign has officially launched. This message provides the key details of the campaign, including the total number of assignments, the review mode, and the final deadline for completion.

All users present as approver in a campaign.

Login Adaptive Failed Notification

When a failed adaptive login attempt is done.

The user is being notified that their account was accessed from a previously unrecognized device. This security alert provides the specific login ID, the IP address used, and the date of the activity so the user can verify the login.

The users whose adaptive mfa has failed.

Login Failed

When a user performs a failed login attempt.

The user is being notified of multiple failed login attempts on their account from a specific IP address. This security alert warns the user that their account has either been temporarily locked or is approaching a lockout, providing the number of attempts remaining before access is restricted.

The users whose login has failed.

MFA Failed Notification

When a user performs a failed MFA.

The user is being notified of multiple failed MFA attempts on their account. This security alert provides the login ID, IP address, and date of the attempts, while also warning the user if their account is about to be locked or if a lockout has already occurred.

The users whose mfa has failed.

Mover Notification

When a mover process is inititaed.

The user is notified that a mover has been triggered and lists the applications that will be removed.

The users whose mover process is initiated.

Password Expiry Notification

When a users password is about to expire in X no. of days.

The user is being notified about the status of their password. This message informs them that their password has either already expired or is about to expire, and it provides the exact date along with a request to update it immediately.

The users whose password is about to expire.

Reconciliation Aborted

When a reconncilation has been aborted.

The user is being notified that a reconciliation process was stopped or cancelled before it could finish and provides the exact reason for the interruption and the time the process was aborted.

The users whose name is present in the applications notification section.

Reconciliation Completion

When a reconncilation has completed.

The user is being notified that a reconciliation process has successfully finished and provides the exact end time and a summary of the final results.

The users whose name is present in the applications notification section.

Reconciliation Failed

When a reconncilation has failed.

The user is being informed that the reconciliation process has failed and provides the exact reason for the failure and the time it occurred.

The users whose name is present in the applications notification section.

Reconciliation Initiation

When a reconncilation has begun.

The user is being notified that a reconciliation process has officially started and provides the start time and confirms that the task is currently in progress.

The users whose name is present in the applications notification section.

Requestee Notification

When the requested action by the requestor has been approved.

The user is being notified about the current status of an application request submitted by a specific requester. This message confirms whether the request was approved or updated

The user for whom the request for an application/role is made.

Requestor Notification

When a user requests for an action mentioned in workflow for another user.

The user is informed about the current status of an application request initiated. It also includes a description of the event.

The user has requested for an application/role for a user.

Review Assignment Notification

When the campaign approver has pending tasks. This is triggered from under the Campaign namely, Pending notification waiting period.

The user has pending campaign assignments that require a review before the specified end date. This notice provides the campaign details and current stage to ensure the required actions are completed on time.

Sent to the reviewer at the start of the campaign.

Reviewer Notification

When the campaign approvers have not taken any actions on the assignments assigned to them.

The user has pending campaign assignments that require immediate review and action. This summary includes the campaign details and the total number of pending tasks that must be completed before the specified end date.

Sent to the reviewer after the number of days configured in pending notification fields have got over.

Self Approval Notification

When a self approval is perfomed from under the Workflow Section.

When a self-approval request is triggered by a user's own action, the system sends a notification to confirm that the request has been successfully submitted and is being processed.

The user who self approved their own request.

User Activation

When a new user is onboarded.

An admin added the user to the platform and provided their login credentials. The user must sign in using the provided link within the specified time limit before the access token expires.

The user who is onboarded into the organization.

User Notification

When a campaign is initiated manually/automatically.

When a reviewer has not yet completed their assigned campaign tasks, the system triggers this reminder to ensure the pending applications are reviewed before the deadline.

The reviewer who still has pending reviews in a campaign.

User Threshold

When the threshold count exceeds more than set in the User Threshold Config under the Configurations section.

The user exceeded the threshold and must manually increase the limit to continue. Once the limit is adjusted, the process can be retried from the dashboard within 24 hours before the records are automatically archived.

The users whose name is mentioned in the User threhold configuration.

Workflow Notification

When a workflow with expiry is set.

When an approval task is pending, the designated reviewer is notified that a specific request requires their attention before the indicated expiration date.

The approver who has to approve the request.

Please note: The above notifications are available out of the box. The system also allows custom notifications to be triggered for specific events using the Cymmetri Webhooks. The custom action trigger can call an existing Cymmetri notification template or a custom template can be included in the webhook code.

The default templates may be modified by the administrator using the following process:

  1. Access the notification templates menu by clicking on the configuration menu on the left-hand side menu bar and then clicking on the Notification templates pop-up menu.

  2. Click on the eye icon to preview the corresponding template

  1. Values in <> anchor tags and ${} reflect macros.

  2. Click on the pencil icon shown above the image to edit the template.

  3. We may treat this template as an email and edit the subject of the email.

    By default, the email notification will be sent to the corresponding affected end-user, but selecting the toggle option for “Send notification to Reporting Manager” will also copy the mail to the Reporting Manager of the affected end-user, allowing for offline follow-up for the notification.

  4. The administrator may edit the HTML using the provided HTML editor to add/change any template button/text/background. The macros required for the particular template are already provided in the sample default notification template.

  5. Click on the Save button to save the notification template.

Last updated