identity.getActiveLinks()
Professional-looking. Nonexistent.
The gate reflects over your actual classpath and refuses methods or enum constants that are not present.
iiq-rules-mcp checks AI-authored SailPoint IdentityIQ rules against your own JAR, DTD, registry, classpath, and exports—before the rule reaches import or production.
Full features during trial · One active device · Works with Claude Desktop and MCP clients
No matching member was found on the reflected Application API in the configured IdentityIQ classpath.
Syntax alone is not enough. The expensive mistakes depend on IdentityIQ contracts the model cannot reliably infer from prose.
identity.getActiveLinks()
The gate reflects over your actual classpath and refuses methods or enum constants that are not present.
String previous = oldvalue;
Every variable read is checked against the authoritative inputs for that exact rule type.
return { "user": "jdoe" };
Signature and return contracts are grounded in the rule registry, not guessed from a generic example.
The composite gate gathers each substrate once, runs the checks in a deterministic order, and returns a closed-vocabulary verdict.
Understand the verdictsDOCTYPE, CDATA, DTD structure, and storage limits.
Declared type and inputs against the registry contract.
Named IIQ objects resolved against your optional export.
Parsed with bsh.Parser; analyzed code is never executed.
Every read checked against the variables IIQ actually injects.
Classes, methods, inheritance, and nested enums verified by reflection.
Security, maintainability, and performance surfaced separately.
Every gating stage was positively verified against a named substrate.
A substrate contradicted the artifact and the finding identifies the repair.
The required evidence was unavailable or could not answer the question.
A useful heuristic or review note that never pretends to be a hard failure.
The gate is the final decision point. Supporting tools help the model choose the correct rule type and contract before it writes code.
Search the complete rule-type universe and inspect exact type metadata before drafting.
Expose injected inputs, expected outputs, and contract notes without relying on memory.
Ask whether a class, method, field, constructor, or enum exists on your configured classpath.
Resolve Applications, Rules, Workgroups, and other named objects against your local export catalog.
Catch malformed XML, invalid attributes, fragile source packaging, and measured storage limits.
Collect findings, substrate evidence, and licensing status in a consistent response envelope.
Six real scenarios were run with identical model settings and judged against a live IdentityIQ 8.1 installation. Every result was retained.
| Scenario | Without grounding | With iiq-rules-mcp |
|---|---|---|
| AD correlation | Confirmed | Confirmed |
| HR BuildMap | Confirmed | Confirmed |
| Identity creation | Confirmed with an unsupported signature argument | Confirmed |
| Certification exclusion | Refuted: read a variable IIQ does not inject | Confirmed |
| Web Services OAuth | Confirmed | Confirmed |
| Certification escalation | Refuted: invented an XML attribute rejected by the DTD | Confirmed |
The honest finding: most ungrounded drafts looked fine. Nothing on their face identified which two would fail.
Verification runs locally. You bring the licensed substrates; the product does not redistribute SailPoint software or upload your rule library.
Point the server at your licensed identityiq.jar, WEB-INF/lib, sailpoint.dtd, and optional export.
BeanShell is parsed only, and SailPoint classes are loaded for reflection without initialization.
The MCP surface exposes framework facts and verdicts, not a searchable copy of your rule repository.
Missing or contradictory substrates stop confirmation instead of silently weakening the gate.
The seven-day trial includes the full product and is limited to one trial per person and device.
Use the signed wheel supplied by SimplifyAuth.
uv tool install --force .\iiq_rules_mcp-1.6.3-py3-none-any.whl
Use the email where purchase and renewal messages should arrive.
iiq-rules-activate trial --email you@example.com
Restart the client fully, then run iiq_grounding_status to confirm the version and substrates.
Request the trial wheelIndividual plans cover one named user on one active device. Enterprise licensing is tailored to your organization and delivery model.
Renewing early never loses paid time: a renewal extends from your current expiry date. Individual purchases are one-time payments through Razorpay.
Your licensed identityiq.jar, WEB-INF/lib directory, sailpoint.dtd, and a JDK. An export-clean catalog is optional but enables local object-reference verification.
No. BeanShell is parsed with bsh.Parser and never interpreted. SailPoint classes are loaded for reflection without class initialization.
No rule source, IIQ JAR, DTD, export, filesystem path, or customer record is sent to SimplifyAuth. Licensing sends only the licensee email (when you start a trial or activate), the license identifier, and salted device-component hashes.
The current calibration evidence is against IdentityIQ 8.1. Other 8.x releases use the same substrate mechanisms but should be treated as unverified until calibrated against that installation.
Verification tools stop issuing verdicts and return a clear licensing message. iiq_grounding_status remains available for diagnosis. Renewals extend from the current expiry date.
Run iiq-rules-activate deactivate on the currently licensed device, then activate the IIQR key on the new device. Two self-service migrations are available per calendar year; lost-device cases are handled through support.
No. iiq-rules-mcp is an independent SimplifyAuth product and is not affiliated with, endorsed by, or sponsored by SailPoint Technologies.
Run the full product for seven days, or talk to us about an enterprise agreement for your team.
Weighing an enterprise agreement, a bulk of individual licenses, or just have a question before you buy? Send us the details and we'll come back with the right fit.