> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Plan

export const Term = ({term, children}) => {
  const terms = {
    "desired-state": "What should be true for a worker: the accounts and access they should have, given who they are and their lifecycle stage.",
    connector: "An integration with one of your systems.",
    source: "An HRIS Klef pulls its workers from.",
    target: "A connector Klef writes to.",
    "worker-model": "Klef's own record of each worker.",
    worker: "Klef's own record of one person.",
    policy: "A rule that sets the desired state for a group of workers at each lifecycle stage.",
    plan: "The set of operations needed to make reality match desired state, shown before it applies.",
    operation: "A single change described in a plan.",
    reconciler: "The engine that compares desired state to your live systems and produces a plan.",
    resource: "A reusable piece a policy uses: a script, a lookup table, or a secret.",
    segment: "A saved group of workers, defined by conditions over their attributes. A policy applies to one segment, or to everyone.",
    "lifecycle-stage": "Where a worker is right now: Pre-start, Active, Leave, Suspended, or Terminated.",
    mastering: "Taking a worker field's value from a connected system instead of your HRIS."
  };
  return <Tooltip tip={terms[term]}>{children}</Tooltip>;
};

A plan details the difference between your policies and what the external system holds. A plan lets you review the changes that would be made downstream to achieve <Term term="desired-state">desired state</Term>.

<Frame caption="A plan with its changes grouped by field">
  <img src="https://mintcdn.com/klef/M0QfE1SpDP4T0o0l/images/plan-detail.png?fit=max&auto=format&n=M0QfE1SpDP4T0o0l&q=85&s=7d4c74af0100cfcd2625be8e182cf0d6" alt="A plan's summary of operations, workers, and problems" width="1455" height="779" data-path="images/plan-detail.png" />
</Frame>

## The Anatomy of a Plan

### Statuses

| Status           | Meaning                                                |
| ---------------- | ------------------------------------------------------ |
| Generating       | Klef is comparing desired state to your systems.       |
| Ready for review | Plan ready for review.                                 |
| Approved         | Plan is approved but has yet to be executed.           |
| Executing        | Plan is being executed downstream.                     |
| Done             | Plan is finished.                                      |
| Done with errors | The apply finished, and at least one operation failed. |
| Failed           | The plan failed to execute.                            |
| Superseded/Stale | A newer plan replaced this one.                        |

### Operations

An <Term term="operation">operation</Term> is one change to a downstream account.

| Operation  | What it does                                                   |
| ---------- | -------------------------------------------------------------- |
| Create     | Creates an account that does not exist downstream.             |
| Update     | Writes the fields that no longer match.                        |
| Set access | Adds and removes grants, such as groups, licenses or channels. |
| Set link   | Points a link field to another account, such as a manager.     |
| End item   | Drops an item from a collection downstream.                    |
| Adopt      | See [adoption](/docs/adoption).                                     |
| Forget     | Stops tracking an account in Klef.                             |
| Detach     | User manually stops tracking an account in Klef.               |
| Set claims | Changes which policies claim an account.                       |
| Set items  | Records which collection items Klef manages.                   |

### Problems

A problem is something Klef noticed but could not act on by itself.

<Frame caption="A plan's problems, with a conflict expanded">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/plan-problems.png?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=dfd9429d48076711d300d6cd5f51a10d" alt="A plan's problems" width="1030" height="597" data-path="images/plan-problems.png" />
</Frame>

A variety of problems can occur. The follow problems can be corrected by the user:

| Problem                | Meaning                                                                                                               |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------- |
| Conflict               | Two or more policies write different values to one field                                                              |
| Account already exists | A duplicate account was prevented from being created.<br />This can be resolved by [adopting the account](/docs/adoption). |
| Could not evaluate     | Invalid policy                                                                                                        |

### Notifications

If a policy sends messages, the plan lists each one with its rendered text and recipients.

## Running on a Schedule

Once you've determined the policies behave in the way you expect, you can configure your workspace to apply policies on a schedule. This setting can be found under **Workspace** settings as **Apply plans automatically**.

<Frame>
  <img src="https://mintcdn.com/klef/M0QfE1SpDP4T0o0l/images/workspace-settings.png?fit=max&auto=format&n=M0QfE1SpDP4T0o0l&q=85&s=02129f892e680c99a0196e4bd9b25093" alt="The workspace settings page" width="1439" height="857" data-path="images/workspace-settings.png" />
</Frame>

<CardGroup cols={2}>
  <Card title="Anatomy of a policy" icon="file-shield" href="/docs/policy">
    Every part of a policy document, from the outside in.
  </Card>

  <Card title="Adoption" icon="user-check" href="/docs/adoption">
    Bringing accounts that already exist under Klef.
  </Card>
</CardGroup>
