Adding an authorization attribute
Add attributes to provide data used in authorization policies and decision evaluations.
Before you begin
Consider how you will structure attributes in the Attributes tree and the naming conventions that you’ll use.
About this task
Policy authors need to be able to build and manage policies without a deep understanding of the complex underlying data endpoints and data manipulation. When you add attributes, give them names that business users and policy authors will understand. |
Steps
-
Add a new attribute:
-
Go to Authorization → Trust Framework and click the Attributes tab.
-
Click the icon and select Add new Attribute.
-
-
Define general information for the attribute:
-
Enter a unique Name for the attribute.
To ensure that PingOne Authorize can resolve attribute references, the following characters are not allowed in the name:
-
Period (.)
-
Curly brackets ({ })
-
Pipe (|)
-
-
For Description, enter information that describes the attribute’s purpose.
The description is only visible on the Attributes tab, but it can help policy authors understand how to use the attribute in policies.
-
Optional: To nest the attribute under a parent attribute in the tree, select a Parent attribute.
Nesting helps group related attributes together. You can move an attribute to another location in the tree by selecting a different parent attribute. To remove nesting, click the Delete icon and leave the Parent list blank.
-
-
Optional: Add resolvers that define where the attribute pulls information from.
-
Optional: Add value processors that transform the attribute’s value.
-
Optional: Add value settings that define the attribute’s data type and default value.
-
Click Save changes.
You can copy an attribute for reuse by selecting Make Copy from the hamburger menu of that attribute. You cannot copy a portion of an attribute definition, with the exception of resolvers. You must copy the whole attribute definition to duplicate any of its content or manually copy the content between definitions.
If you copy an attribute with child attributes, only the parent is duplicated.
Next steps
After you save the attribute, you can optionally add repetition settings that resolve the attribute’s values from a collection.