New Capability: Access Model Metadata Adhoc Values

:sparkles: Description

Identity Security Cloud Access Model Metadata (AMM) now supports ad hoc (free-form) values, letting admins tag roles, access profiles, and entitlements without maintaining a fixed value list. Admins can configure each metadata attribute to accept ad hoc values only, a static pre-defined list only, or both. This is ideal for values that are numerous or change often — application IDs, project names, training requirements, and other attributes sourced from CMDBs or external systems.

Customers can create up to 250 custom metadata attributes per access object type. Each custom attribute can be assigned up to 5,000 different values. Ad hoc values support up to 100 characters per value.

:red_exclamation_mark: Problem

AMM previously required a static, pre-defined value list for every metadata attribute, with a practical limit far below what many customers need. Large accounts (e.g., British Telecom with ~6,000 applications) and customers migrating from IIQ cannot maintain static lists for attributes like Application ID, project names, or frequently changing training requirements. PS and customer admins consistently request free-form metadata to support governance, reporting, and access-request integrations.

:light_bulb: Solution

Admins can now:

  • When creating or editing a custom metadata attribute, enable Allow Multivalued Assignment and/or Allow Ad Hoc Values:
  • Allow Multivalued Assignment — the attribute can be assigned more than one value. Once enabled, it cannot be undone.
  • Allow Ad Hoc Values — new values of up to 100 characters can be added to the attribute when it is assigned to a role, access profile, or entitlement. Any ad hoc values created are saved even if Allow Ad Hoc Values is later disabled.
  • Assign, modify, and remove ad hoc metadata values on roles, access profiles, and entitlements
  • Search for access items by ad hoc metadata attribute values
  • Use expanded value capacity — up to 5,000 values per attribute

MVP scope includes ad hoc value entry, assignment, modification, removal, and search. Type-ahead suggestions from previously entered values, bulk assign, numeric/date value types, and validation constraints are out of scope for this release.

:busts_in_silhouette: Who is affected?

This capability is available to Identity Security Cloud customers using Access Model Metadata.

ISC administrators configure attributes; role admins, role sub-admins, source admins, and source sub-admins can assign ad hoc values to the access items they manage.

:clipboard: Action required

To use ad hoc values, an ISC administrator must configure the metadata attribute to accept ad hoc entry. Existing attributes configured for static lists only are unchanged until updated.

After rollout, open Admin → Access Model Metadata to configure or update attributes, then assign values on roles, access profiles, or entitlements as needed.

:date: Important dates

Available now!

2 Likes

Hi this is nice feature.

if we convert the existing metadata attributes of static lists to adhoc, what will happen to the existing roles/access profiles for which metadata is already assigned from dropdown list.