Skip to content

Managing Access Model Metadata

To enrich an organization’s access model and add valuable contextual information to access items, Admins can utilize metadata attributes. SailPoint includes some default global metadata attributes you can use “out-of-the-box”. You can also create custom metadata attributes for entitlements, access profiles, and roles to add further context.

For the list of default global metadata attributes and descriptions, go to Admin > Access Model > Metadata > Global Metadata > Default.

Both default and custom metadata attributes are included in Search.

Creating Custom Metadata Attributes

You can create up to 250 custom metadata attributes per access object type. Each custom attribute can be assigned up to 5,000 different values.

When creating or editing a custom metadata attribute, Admins can enable multivalued assignments or ad hoc values:

  • Allow Multivalued Assignment – Metadata attributes can be assigned more than one value. Once this is enabled for an attribute, it cannot be undone.
  • Allow Ad Hoc Values – New values of up to 100 characters can be added to the attribute when it is assigned to a role, access profile, or entitlement. Any ad hoc values created are saved even if Allow Ad Hoc Values is later disabled for the attribute.

To create custom metadata attributes:

  1. Go to Admin > Access Model > Metadata.

  2. In the left pane, select the type of metadata attribute you want to create:

    • Entitlement Metadata

    • Access Profile Metadata

    • Role Metadata

    • Global Metadata

  3. Select Create Attribute.

  4. Enter a unique Name for the new custom attribute. The Technical Name is automatically created from the name you enter.

  5. Select Allow Multivalued Assignment and/or Allow Ad Hoc Values if you would like to enable these attribute features.

  6. Add attribute values.

  7. Select Save. The custom metadata attribute appears in the metadata attributes list for the type you selected.

Editing Metadata Attributes

  1. In the metadata attribute list, select Actions > Edit for the attribute you want to edit.

  2. On the Details tab, update the fields and enable attribute features as necessary. The Technical Name cannot be changed.

  3. On the Values tab, you can remove values from the attribute by selecting Delete for the values you want to remove.

  4. After entering all your changes, select Save.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.