Allow Policy Enforcement and Validation for Distribution List Provisioning
Summary
Many organisations use self-service provisioning to create distribution lists, groups, and collaboration resources. While access controls determine who can request these resources, there is often no way to enforce organisational standards during the provisioning process itself.
Problem
Today, administrators can control who is allowed to create resources, but they cannot define and enforce policies that govern what is created.
Common requirements include:
- Naming convention enforcement
- Approved domain validation
- Pattern or format validation
- Resource classification requirements
- Automatic standardisation of user input
- Custom business rules based on organisational needs
Without policy enforcement, organisations must rely on user training, manual reviews, or post-creation remediation to maintain standards.
Proposed Enhancement
Introduce a policy validation framework that is evaluated as part of the provisioning workflow.
Administrators should be able to:
- Validate user input before resource creation
- Define required naming standards
- Restrict values to approved formats or domains
- Apply automatic transformations where appropriate
- Display clear validation messages when requirements are not met
- Configure different policies for different resource types
Example Use Cases
- Enforcing naming standards for distribution lists
- Restricting email domains to approved corporate domains
- Requiring specific prefixes or suffixes
- Enforcing department or region identifiers
- Standardising display names and aliases
- Validating group ownership requirements before creation
Benefits
- Improved governance
- Consistent resource naming and structure
- Reduced administrative overhead
- Better compliance with organisational standards
- Fewer provisioning errors
- Better end-user experience through immediate feedback
Why This Matters
Self-service provisioning is most effective when organisations can trust that resources created through automation comply with their internal standards. Access control answers who can create a resource, while policy validation answers whether the resource itself meets organisational requirements. Both capabilities are needed for scalable governance.
Voting ask: If your organisation uses self-service provisioning and has naming, compliance, governance, or standardisation requirements, please upvote this idea to help prioritise policy enforcement capabilities within provisioning workflows.
PS: I’ve already tried Moveworks/ServiceNow Support and Engineering teams advised to raise a Product idea.