Overview
OpalScript is Opal’s scripting language for automating access management workflows integrated deeply with Opal’s access management platform. Built on Starlark (a Python-like language), OpalScript enables you to write custom automation logic and scripts that evaluate conditions, query the access graph and take actions programmatically.Use cases
OpalScript currently supports automated request review and delegation conditions, with more automation types planned:How OpalScript works
Each OpalScript type has access to:- Utility modules: Common functions available to all script types (e.g.,
accessfor access queries,notificationsfor sending notifications,httpandsecretsfor calling external APIs) - Context module: Script-type-specific data about what triggered the script
- Actions module: Script-type-specific operations the script can perform
Create your first workflow
- In Opal, navigate to OpalScript > Editor and create a new script. Give it a name and select an owner. Opal provisions a service user behind the script, owned by the owner you select. This service user is the identity that runs the script.
-
Enter your OpalScript in the editor. For example, to auto-approve all requests:
See Request Review: Get started for the full
contextandactionsAPI reference, and examples for ready-to-use scripts. - Add the script’s service user as a reviewer on any resource or group. When a request is submitted, the script runs automatically.