Bulk Administration of UiPath Orchestrator Entities (Orchestrator Manager)
Orchestrator Manager is an attended desktop tool that lets an Orchestrator administrator perform bulk maintenance on Orchestrator objects — Users, Robots, Machines, Assets, Environments, Processes, Organization Units, Folders, Queues, Packages, Libraries, Triggers and Jobs — from Excel workbooks instead of clicking through the Orchestrator web interface one record at a time. The operator fills a sheet with the records they want created, edited or deleted, chooses the entity and operation on an on-screen panel, and the tool calls the Orchestrator API for each row and writes the outcome back next to that row. The developer describes it as "a tool to help Orchestrator administrators to perform bulk operations on entities … For more details, refer to the manual located in the Documentation folder."
At a glance
| Trigger | Manual, attended. The operator starts the tool; it opens a sign-in form, then a control panel where the entity and operation are chosen. The panel re-opens after each operation until the operator selects Cancel. |
| Frequency | Not recorded in the source — ad hoc, operator-driven. Many operations can be run back-to-back within one session. |
| Systems used | UiPath Orchestrator REST/OData API (on-premises or Automation Cloud); Microsoft Excel; Windows Credential Manager; local file system; HTML input panels rendered by the tool; Active Directory / Orchestrator Directory Service (for folder-user assignment and domain lookup) |
| Inputs | Config.xlsx (sheets Settings and Advanced Settings); Translation.xlsx (sheet Localization); per-entity workbooks in the workbooks folder (Assets, Users, Robots, Machines, Environments, Processes, Packages, Libraries, Queues, Folders, Triggers…), each with one sheet per operation; operator credentials; package .nupkg files and queue-item files for upload |
| Outputs | Refreshed "Get" sheets in the entity workbooks; a Result value on every processed row; new entity IDs written back (AssetID, ProcessID, RobotID, MachineID…); updated values in Config.xlsx; downloaded package files and package "referenced entities" files; exported queue items; log messages and a Logs folder under the workbooks folder |
| Typical run | Not recorded in the source. Batch size is bounded only by the operator's sheet; runs above the configured MaximumRequestsThreshold require an explicit Yes/No confirmation. |
| Owner | Not recorded in the source |
Before you start
- Orchestrator access. An Orchestrator account (on-premises user/password or tenant login, or Automation Cloud Client ID + User Key, or an External Application's App ID + App Secret for the OAuth
client_credentialsflow). The account must hold rights for every entity you intend to change, and must be a member of every Organization Unit/Folder you intend to read — being able to see a folder in a list is not enough; folders the account cannot enter are skipped with a warning. - Know your Orchestrator. You will be asked for the deployment type (on-premises or cloud), URL or account/tenant name, and — for on-premises — the version. Supported versions on the form: 2018.4, 2019.4, 2019.10, 2020.4, 2020.10, 2021.04, 2021.10, 2022.04. Anything else is rejected with "Orchestrator version not supported".
- Files present and closed.
Config.xlsxandTranslation.xlsxmust be readable and closed in Excel — a locked file causes a read failure and a prompt to close it. The entity workbooks live in the folder named byEntitiesWorkbooksFolderPath; if that setting is blank the tool uses%Desktop%\OrchestratorManagerWorkbooks. - Windows Credential Manager (optional). If credentials were previously saved, the sign-in form pre-ticks "use saved credential". Saving a credential writes an entry keyed by credential name + account/URL + tenant.
- Language. Column headings and sheet tab names in the entity workbooks are localised. The tool picks the language from the machine's UI culture (a Japanese branch and an English default exist in the translation logic), unless a language is passed in. Templates are copied from a language-specific folder, so switching machine language mid-life gives you a different set of tab names.
- Certificate validation. There is a
DisableServerCertificateValidationswitch that, when true, turns off TLS certificate checking for the whole session. Confirm with your security owner before using it. - Plan your rollback. The tool has no undo. Deletions and migrations are permanent; the only record of what happened is the Result column in the sheet.
Procedure
Stage 1 — Load configuration and language strings
- Start the tool. If the certificate-validation switch is set to true, server certificate checking is disabled for the session.
- The tool reads
Config.xlsx: first the Settings sheet, then the Advanced Settings sheet, and merges the second into the first so both sets of parameters are available together. - It reads the Localization sheet of
Translation.xlsx, keeps the column for the chosen language (Japanese if the machine UI culture is JA; otherwise the English default column), renames that column to "Value", and merges it into the settings. - Every non-blank
Name/Valuepair becomes an in-memory setting used for the rest of the session — this includes sheet names, form labels, error messages, thresholds and endpoints. - If the configuration file cannot be read (typically because it is open in Excel), a message box appears — "It was not possible to read settings. Please make sure that the configuration file is closed and press OK to continue." — and the read is retried up to 3 times, 1 second apart. This message is in English because the translated strings are not loaded yet.
- If
EntitiesWorkbooksFolderPathis blank, the tool defaults it to%Desktop%\OrchestratorManagerWorkbooks.
Stage 2 — Sign in to Orchestrator
- The tool builds an HTML sign-in panel, pre-filled from the last session: Orchestrator type (on-premises / cloud), Orchestrator URL, on-premises tenant name, cloud account name and tenant name, on-premises version, and the workbooks folder path.
- It checks Windows Credential Manager for a saved credential under four possible targets (cloud generic, cloud + account name, on-premises generic, on-premises + URL). If any exists, the "use saved credential" checkbox is shown and ticked; if none exists, the checkbox is hidden.
- Complete the form and submit. If you close or cancel the form, the tool logs "Stopped execution" and ends.
- Any value you changed is written straight back into
Config.xlsxbefore the login is attempted — Orchestrator type and version to the Advanced Settings / Settings sheets as appropriate, and tenant name, cloud tenant name, workbooks folder path and (after login) cloud account name and on-premises URL to Settings. Values are assumed to sit in column B of the sheet. - If cloud is selected: the tool looks for a saved User Key under, in order,
<credentialName>_<account>_<tenant>, then<credentialName>_<account>, then<credentialName>; if "use saved credential" was ticked and none is found it stops with "Credential not found". It then posts either an OAuthclient_credentialsrequest (with the fullOR.*scope list — Monitoring, ML, Tasks, Analytics, Webhooks, Folders, TestSets, Audit, License, Settings, Robots, Machines, Execution, Assets, Administration, Users and more) or arefresh_tokenrequest using the Client ID and User Key. The working Orchestrator URL is then assembled as<AutomationCloudURL>/<account>/<tenant>. - If on-premises is selected: the same three-step saved-credential lookup runs against
<credentialName>_<URL>_<tenant>,<credentialName>_<URL>,<credentialName>. The tool posts either an OAuth request or a body of{"tenancyName":…,"usernameOrEmailAddress":…,"password":…}. The Orchestrator URL is reduced to its scheme + host portion. - If the response is HTTP 200, the bearer token is stored and used for all later calls. Otherwise the raw response is logged as an error, an "Authentication failed" message box is shown, and the sign-in panel re-opens. The loop only ends when a token is obtained or you cancel.
- If you ticked "save credential", the password/User Key is written to Windows Credential Manager under the tenant-specific target.
Note the on-screen account-lockout warning on the form: repeated failed attempts can lock the Orchestrator account.
Stage 3 — Prepare the entity workbooks
- If the workbooks folder does not exist, it is created.
- If the Logs subfolder does not exist (workbooks folder + the configured logs folder name), it is created.
- Every
*.xlsxtemplate in the language-specific templates folder is copied into the workbooks folder only if a file of that name is not already there. Existing workbooks — and therefore your data — are never overwritten.
Stage 4 — Choose the entity and the operation
- The control panel opens, listing the entities: Asset, User, Machine, Robot, Environment, Process, Organization Unit, Folder, Queue, Package, Library, Trigger, Job.
- It lists the operations available across those entities, including: Get, Get Credential, Create, Create Credential, Edit, Edit Credential, Delete, Add/Remove Environment Robots, Add/Remove User Organization Units, Add/Remove User Roles, Update Process to Latest Package Version, Rollback Process to Previous Package Version, Update Process to Specified Package Version, Download/Upload Queue Items, Download/Upload Package or Library, Get Package Referenced Entities, Get Folders' Users, Assign/Unassign Folder User, Add/Remove Folder User Roles, Migrate Classic to Modern, Enable/Disable Trigger, Installed Robots, Assign/Unassign Folder Machine, Link or Unlink, Edit User Mappings.
- If the deployment is on-premises, the version is passed to the panel so that version-dependent options are hidden. The developer's own example: "Organization Units should not appear when using Orchestrator 2019.10+." The classic→modern folder migration option is likewise gated by an
Enable202004FolderMigrationsetting. - Choose one of three actions:
- Execute (submit) — runs the operation (Stages 5–10).
- Open workbook — opens that entity's workbook in Excel so you can fill in or review the rows, then returns to the panel. If the file cannot be opened (for example it is locked), the error message is shown and you return to the panel.
- Cancel — logs "Stopped execution" and ends the session.
- Your entity and operation choices are remembered and pre-selected next time the panel opens in this session.
Stage 5 — Route to the right entity handler
- The tool dispatches to the manager for the chosen entity (Machine, Asset, User, Robot, Environment, Process, Organization Unit, Folder, Queue, Package, Library, Trigger, Job). Packages and Libraries share one handler and differ only by workbook and API endpoint.
- If the entity or the entity/operation combination is not supported, a warning or error is logged and an "Unsupported entity" / "Unsupported operation" message box is shown. No API calls are made.
Stage 6 — Read your request rows from the workbook
- The tool opens the entity's workbook at
<workbooks folder>\<entity workbook file name from Config>and reads the sheet whose name matches the chosen operation (e.g. the sheet named byCreateOperationName,DeleteOperationName,AddRemoveUserRolesOperationName). - Because the visible column headings are localised, the tool renames the columns positionally to canonical internal names before doing anything else. Examples from the source:
- Assets → Create: OUFolderName, AssetName, Description, Scope, RobotUserName, Type, Value, AssetID, Result
- Assets → Create Credential: OUFolderName, AssetName, Description, Scope, RobotUserName, Value, Password, AssetID, Result
- Assets → Delete: OUFolderID, OUFolderName, AssetID, AssetName, Result
- Assets → Link or Unlink: AssetID, OUFolderName, LinkOrUnlink, Result
- Robots → Create: OUFolderName, HostingType, RobotName, MachineName, RobotType, Username, Password, RobotID, Result
- Machines → Create: Type, Name, Description, UnattendedSlots, NonProductionSlots, TestAutomationSlots, Key, ID, Result
- Machines → Edit User Mappings: MachineID, UsersToAssign, UsersToUnassign, Result
- Processes → Create: OUFolderName, EnvironmentName, PackageName, PackageVersion, ProcessName, Description, InputArguments, ProcessID, Result
- Processes → Update to Specified Package Version: OUFolderName, ProcessName, PackageVersion, Result
- Users → Add/Remove Roles: UserID, AddRolesNames, RemoveRolesNames, Result
- Users → Add/Remove Organization Units: UserID, AddOUsNames, RemoveOUsNames, Result
- Packages/Libraries → Download: Name, Version, DownloadFolderPath, DownloadedPackageFilePath, Result
- Packages/Libraries → Upload: PackageFilePath, Result
- Only "unprocessed" rows are selected: rows whose Result cell is empty but which have at least one other populated cell. This makes a re-run safely resumable — rows that already succeeded or already carry an error message are skipped, so you should clear the Result cell of any row you want retried.
Stage 7 — Confirm scope and guard against oversized runs
- If the number of planned requests exceeds
MaximumRequestsThreshold, a Yes/No message box appears. Answer No and the operation aborts cleanly with "Operation canceled by user"; answer Yes and a warning is logged and the run proceeds. - For "Get" operations on folder-scoped entities (Assets, Get Credential Assets, Robots, Environments, Processes, Packages), a folder picker opens listing all Organization Units / Folders the account can see. Select the ones to cover. If you close the picker or select nothing, no folders are processed. If Organization Units are disabled on the target Orchestrator (the folder list contains a single "N/A" entry), the picker is skipped.
- For Packages only, an extra Tenant option is added to the picker when folder-level packages are supported — that is, on cloud, or on-premises 2020.10 and above.
- Before writing new "Get" results, the tool reads the existing rows on that sheet and clears the range
A2:Z<last row>(never row 1, so headers survive). The clear happens before the API call, deliberately, so that a failed refresh cannot leave stale data looking current.
Stage 8 — Pre-fetch reference data once for the whole batch
- Before looping through rows, the tool retrieves the current state of everything the sheet references — folders/OUs, existing assets, robots, users, machines, environments, processes, roles, packages — filtered to just the names or IDs that appear in your rows. The developer's rationale: "Get current data beforehand for confirmation purposes and to reduce the number of requests."
- Filters are built to suit the Orchestrator version: cloud or on-premises 2020.10+ uses the OData
INoperator (Id in (1,2,3),Name in ('A','B')); 2020.4 and older uses OR'd equality conditions and is capped at roughly 10 conditions per query because "there is a limit to the number of conditions specified in a query … usually less than 20". - Long filter lists are split across several GET requests to stay under URL length limits (a filter longer than 1,800 URL-encoded characters is dropped rather than sent), and paged responses are fetched in batches of
RequestBatchSizeand merged into a single result set. - If a selected folder cannot be read (rights problem), that folder alone fails: the error is logged, the run continues with the other folders, and at the end a warning box tells you not all folders could be accessed. The developer's note: "Even if a user is able to see all OUs/Folders, they might not be a member of some OUs/Folders and thus not be able to access restricted resources."
Stage 9 — Process each row and call Orchestrator
- Rows are processed one at a time; a status line "
<Entity> - <Operation>: n / total" is shown while running. Assets are an exception: rows are grouped by folder name + asset name, so a global default value and several per-robot or per-user values of the same asset are handled as one unit. - For each row the tool validates the inputs and resolves names to IDs from the data cached in Stage 8, then builds and sends the request. Every call carries the target folder's ID in the
X-UIPATH-OrganizationUnitIdheader, unless the ID is 0 (in which case the header is omitted — 0 is not a valid Orchestrator ID). - Concrete examples from the source:
- Create asset —
POST /odata/Assetswith Name, Description, ValueType (text / bool / integer / credential), ValueScope (Global, or PerRobot for both per-robot and per-user assets, "to maintain backwards compatibility"), plus RobotValues/UserValues and, if a global default is also supplied,HasDefaultValue. Expected response 201; the new AssetID is written back. - Edit asset —
PUT /odata/Assets(<id>). Blank cells mean "keep current value", so the current values are read first and re-sent. Editing an asset that has per-robot or per-user values is rejected. - Delete asset —
DELETE /odata/Assets(<id>), expected response 204. - Create process —
POST /odata/Releases. The developer flags the naming trap: "Processes are actually exposed by the Release endpoints. The Processes endpoints refer to Packages."ProcessKeycarries the package name,ProcessVersionthe package version. If no Environment is given the process is created in a modern folder and named after the package; if an Environment is given the default name follows Orchestrator's own conventionPackageName_EnvironmentName. A name you supply overrides both. - Delete process —
DELETE /odata/Releases(<id>), expected response 204. - Update / rollback package version —
POSTagainst the Releases endpoints for the named process, resolved from the folder + process name.
- Create asset —
- Delete operations demand a matching ID and name. Before deleting, the tool checks that the folder ID matches the folder name and that the entity ID matches the entity name given on the same row. Any mismatch stops that row — "To prevent accidental deletion, the workflow confirms whether the … name specified match[es] the names of the given IDs."
- If the token expires mid-run (HTTP 401 containing "not authenticated" — the token lasts about 30 minutes by default), the tool logs a warning and re-opens the sign-in panel so the operator can re-authenticate. Once a new token is obtained, the failed request is retried by the retry scope. The operator must be present at the machine to complete the form; the run does not continue unattended.
- Between requests the tool waits
RequestIntervalmilliseconds — "optional delay between requests to lessen the burden on Orchestrator due to a large number of consecutive requests."
Stage 10 — Write results back
- Whatever happens, each processed row gets a Result value: the configured success text on success, or the exception message on failure. For grouped asset rows, the same Result and the same new AssetID are written to every row in the group.
- Where the operation creates something, the new ID is written to the ID column on that row (AssetID, ProcessID, RobotID, MachineID…).
- The in-memory cache is updated as it goes — created entities are added so later rows in the same batch see the duplicate-name check correctly, deleted entities are removed, and a failed edit has its local change discarded.
- Review the Result column before doing anything else. It is the only record of what succeeded.
Stage 11 — Optional: classic-to-modern folder migration
- Choose entity Folder, operation Migrate classic to modern. A dedicated migration workbook is created listing the entities held in the classic folder, with a sheet per entity type (Processes, Assets, Queues, Environments, Robots, Triggers).
- A confirmation panel names the classic folder being migrated. Confirm or cancel.
- Rows can target the same modern folder for everything, or a different modern folder per row. On the per-row sheets, only rows whose Result is empty and whose Modern Folder name is filled in are processed.
- For each process being migrated the tool: downloads the package to
<workbooks folder>\<PackageDownloadFolderPath>(creating the folder if needed), verifies the package's dependencies against the minimum versions listed in thePackagesMinimumDependenciesVersionssetting, deletes the temporary package file, then creates the equivalent release in the target modern folder. - If the classic folder, the modern folder or the process cannot be found, that row fails with a specific message written to its Result cell (column E on the Processes sheet), a migration-exception flag is raised, and the remaining rows continue.
Stage 12 — Continue or finish
- When the operation ends — successfully or after its errors have been shown — the control panel re-opens. Choose another entity/operation, open a workbook, or cancel.
- Choosing Cancel logs "Stopped execution" and ends the session.
Exceptions and recovery
| Condition | What the automation does | What the operator should do |
|---|---|---|
Config.xlsx / Translation.xlsx unreadable (file open) |
English message box "It was not possible to read settings. Please make sure that the configuration file is closed and press OK to continue.", then retries — 3 attempts, 1 second apart | Close the workbook in Excel and press OK. If it still fails, check file permissions and path. |
| A setting to be updated is not found in the sheet | Raises "Parameter not found" | Check that the parameter row exists on the Settings / Advanced Settings sheet and that its value sits in column B. |
| Login returns anything other than HTTP 200 | Logs the raw response as an error, shows "Authentication failed", re-opens the sign-in panel | Re-check URL, tenant, account and credentials. Heed the on-form lockout warning — do not brute-force. |
| "Use saved credential" ticked but no matching Credential Manager entry (tenant-specific, then account/URL-specific, then legacy target all missing) | Stops with "Credential not found" | Untick the box and enter credentials manually, ticking "save credential" to store them. |
| Unsupported on-premises version or Orchestrator type in config | Throws while building the sign-in form | Correct OnPremisesOrchestratorVersion / OrchestratorType in Config.xlsx to a supported value. |
| Token expires mid-run (401 "not authenticated") | Logs a warning and re-opens the sign-in panel for re-authentication; once a new token is obtained the failed request is retried by the retry scope | Stay at the machine — the run is not unattended. Complete the sign-in form when it re-appears. If you cancel it or re-authentication fails, the run stops; restart the session and re-run the affected rows after clearing their Result cells. |
| Connectivity failure (status 0) or server error 500–599 | Retries MakeHTTPRequestNumberOfRetries times at MakeHTTPRequestRetryInterval ms |
If retries are exhausted, check network/Orchestrator health and re-run the affected rows after clearing their Result cells. |
| Unexpected status code, or the response is not valid JSON (e.g. a redirect returning HTML) | Fails that row with a "process entity failure" / "invalid response" message written to Result | Verify the endpoint and the Orchestrator version setting; the HTML-response case usually means a wrong URL. |
Planned requests exceed MaximumRequestsThreshold |
Yes/No prompt. No → operation cancelled cleanly with "Operation canceled by user"; Yes → warning logged, run proceeds | Decide deliberately. Consider splitting the batch. |
| Any other error inside an operation | Logged with message and source, generic "Error during execution" box; the session continues | Read the Result column to see which rows completed; investigate, clear Results, re-run. |
| One or more selected folders cannot be read | Skips only that folder, clears the "all folders accessed" flag, logs the failure, shows a "Failed to access OU/Folder" warning | Data for the skipped folders is missing from the sheet. Get folder membership for your account and re-run. |
| Delete row where the ID does not match the name | Row rejected with "ID and name do not match" or "not found"; nothing is deleted | Re-run a Get to refresh the sheet with correct ID/name pairs, then retry. |
| Invalid row data — missing folder/asset/process name, missing or unsupported scope or type, invalid boolean/integer value, duplicate asset or process name, per-robot and per-user values on the same asset, multiple values for one robot/user, assets-per-user on on-prem < 2020.10, per-robot default value on on-prem < 2019.10 | Specific message written to that row's Result; processing continues with the next row | Fix the row, clear its Result cell, re-run the operation. |
| Duplicate package/library versions returned by Orchestrator (known Orchestrator defect) | Affected entities are skipped, a warning is logged and a message box lists them; creating a process on a duplicated package version fails | Resolve the duplicate in Orchestrator before retrying those rows. |
| Malformed ID in a cell (FormatException) | Writes "ID invalid or not specified" to that row's Result | Correct the ID cell (no text, no stray spaces) and re-run. |
| Row already has a Result value | Row is skipped | Intentional — clear the Result cell for any row you want to reprocess. |
| Unsupported entity or operation selected | Warning/error logged, message box shown, no API calls | Choose a combination valid for your Orchestrator version. |
| "Open workbook" fails (file locked) | Shows the error message, returns to the control panel | Close the workbook elsewhere and retry. |
Data handled
| Item | Contents | Source |
|---|---|---|
| Configuration dictionary | All settings and all localised strings for the session: Orchestrator type/URL/tenant/account/version, workbooks folder, thresholds, retry counts, request interval and batch size, sheet names, form labels, error texts, and — after login — the bearer Token and the working OrchestratorURL | Config.xlsx (Settings + Advanced Settings) merged with the chosen language column of Translation.xlsx; updated in place during sign-in |
| Authentication data | Orchestrator type, URL, tenant names, account name, Client ID / User Key or username / password, workbooks folder path, and the "use saved credential", "save credential" and "use OAuth flow" flags | The sign-in panel, submitted as JSON |
| Entity / Operation selection | Which entity and which operation the operator picked, plus the action (submit / openWorkbook / cancel); remembered so the next panel pre-selects them | The control panel, submitted as JSON |
| Selected OU/Folders | The folders the operation should cover, as name + ID; for Packages may include a synthetic "Tenant" row with ID 0 | The folder picker panel, filtered from the full folder list retrieved from Orchestrator |
…Details tables (AssetsDetails, UsersDetails, RobotsDetails, ProcessesDetails, MachinesDetails, PackagesLibrariesDetails) |
The operator's request rows, read from the operation's sheet with localised headings renamed to canonical column names | The entity workbook |
Unprocessed…Details |
The subset of the above that will actually be sent: empty Result cell, at least one other cell populated | Filtered in memory |
…Data tables (AssetsData, RobotsData, UsersData, MachinesData, ProcessesData, OUFoldersData, RolesData, PackagesData, EnvironmentsData) |
The current state of Orchestrator for the entities named in the sheet — used to resolve names to IDs, detect duplicates, and confirm IDs before deletion; kept in step with each successful create/delete during the batch | Orchestrator GET calls made in Stage 8 |
| OData filter | The $filter= clause built from the names/IDs in the sheet, in IN-operator or OR'd-equality form depending on Orchestrator version, and split if too long |
Built from the request rows |
| OperationResult | Per row: the configured success text, or the caught exception's message | Set in the try/catch around each row; always written back in the Finally block |
| AllOUFoldersAccessed flag | False if any selected folder could not be read | Set during the Get…Data loops; drives the "Failed to access OU/Folder" warning |
| DuplicateEntitiesMessage / DuplicatePackageLibraryVersionsList | Packages or libraries with duplicated versions, which are skipped | Detected while retrieving package/library data |
| Migration workbook | Per classic folder, the processes, assets, queues, environments, robots and triggers to migrate, each row carrying a target modern folder name and a Result cell | Created by the migration routine from Orchestrator data |
Not determinable from the source
- Who operates the tool, and what approval or change-control governs bulk creates and deletes.
- How often it is used and typical row volumes per batch.
- The actual configured values of
MaximumRequestsThreshold,RequestBatchSize,RequestInterval, retry count/interval,AutomationCloudURLand the per-entity workbook file names — these live inConfig.xlsx, which is not part of the outline. - The exact sheet tab names for each operation: they come from localised config keys (
GetOperationName,CreateOperationName, …), so the visible names depend on the language in use. - The full list of operations actually supported per entity — the Folder, Queue, Trigger, Job and Organization Unit managers were not expanded in the source.
- Endpoints and request bodies for several sub-operations (update/rollback package version requests, link/unlink, edit user mappings, all Job operations).
- Where downloaded packages, exported queue items and referenced-entity files are stored long term, and who consumes them.
- Whether the Logs folder actually receives files, or whether logging goes only to the Orchestrator/Studio execution log.
- How credentials are provisioned and rotated, and the policy on using "save credential" to write them to Windows Credential Manager.
- How the
DisableServerCertificateValidationflag is governed in production — when true it disables TLS certificate checks. - Downstream effects of migrations and deletions; no rollback path exists beyond the per-row Result column.
How this SOP was checked
Generated from the project's source files and audited against them. Audit verdict: minor issues, confidence high.
Covers the real business flow end-to-end and traceably: config/localization load with 3x/1s retry, the HTML sign-in panel and credential-manager lookup order, config write-back to Config.xlsx column B, workbook template seeding, control-panel entity/operation selection with submit/openWorkbook/cancel, per-entity dispatch, positional column renaming (column lists verified against ColumnNames defaults), unprocessed-row filter, MaximumRequestsThreshold gate, folder picker + Tenant option gating (Package AND cloud/on-prem>=202010), sheet clearing A2:Z before the refresh call, OData filter variants (IN vs OR'd, 10-condition cap, 1800-char drop), pagination/merge, X-UIPATH-OrganizationUnitId omission when 0, Releases-vs-Processes endpoint trap, delete ID/name confirmation, Finally-block Result write-back, cache updates, and classic->modern process migration (download package, verify dependencies, delete temp file, create release, result to column E). Correctly flags what the outline cannot support (Folder/Queue/Trigger/Job/OU managers unexpanded, actual config values, several request endpoints). Discrepancies found are localized, not structural.
1 correction from the audit was applied to the procedure above.
Remaining minor notes, not corrected:
- Stage 2 step 4 — Says cloud account name and on-premises URL are written back to Config.xlsx '(after login)'. In MakeAuthenticationRequest_Cloud.xaml and MakeAuthenticationRequest_OnPremises.xaml, UpdateConfigurationFile for CloudAccountName / OnPremisesOrchestratorURL runs before the authentication HTTP request. (Remove '(after login)' — all changed values, including cloud account name and on-premises URL, are written to Config.xlsx before the authentication request is sent.)
- Stage 7, ordering of items 2 and 4 — Numbered order implies the folder picker opens before the sheet is cleared. In the Get blocks (Assets, Robots, Environments, Processes, Packages) the sequence is: read previous rows -> clear A2:Z -> PromptUserForOUFolders -> Get...Data -> write range. (Reorder: clear the previous Get results first, then prompt for Organization Units/Folders, then call Orchestrator and write the refreshed rows.)
- Stage 9 step 1 — Presents the '<Entity> - <Operation>: n / total' progress line as generic to all row processing. In the expanded source, ReportExecutionStatus.xaml is invoked only from AssetManager.xaml (create, create credential, edit, edit credential, delete loops); other managers' loops do not call it. (Scope the statement to Asset operations, or note that progress reporting is confirmed only for Assets in the source.)