Description
Identity Security Cloud Access Model Metadata (AMM) now supports ad hoc (free-form) values, letting admins tag roles, access profiles, and entitlements without maintaining a fixed value list. Admins can configure each metadata attribute to accept ad hoc values only, a static pre-defined list only, or both. This is ideal for values that are numerous or change often — application IDs, project names, training requirements, and other attributes sourced from CMDBs or external systems.
Customers can create up to 250 custom metadata attributes per access object type. Each custom attribute can be assigned up to 5,000 different values. Ad hoc values support up to 100 characters per value.
Problem
AMM previously required a static, pre-defined value list for every metadata attribute, with a practical limit far below what many customers need. Large accounts (e.g., British Telecom with ~6,000 applications) and customers migrating from IIQ cannot maintain static lists for attributes like Application ID, project names, or frequently changing training requirements. PS and customer admins consistently request free-form metadata to support governance, reporting, and access-request integrations.
Solution
Admins can now:
- When creating or editing a custom metadata attribute, enable Allow Multivalued Assignment and/or Allow Ad Hoc Values:
- Allow Multivalued Assignment — the attribute can be assigned more than one value. Once enabled, it cannot be undone.
- Allow Ad Hoc Values — new values of up to 100 characters can be added to the attribute when it is assigned to a role, access profile, or entitlement. Any ad hoc values created are saved even if Allow Ad Hoc Values is later disabled.
- Assign, modify, and remove ad hoc metadata values on roles, access profiles, and entitlements
- Search for access items by ad hoc metadata attribute values
- Use expanded value capacity — up to 5,000 values per attribute
MVP scope includes ad hoc value entry, assignment, modification, removal, and search. Type-ahead suggestions from previously entered values, bulk assign, numeric/date value types, and validation constraints are out of scope for this release.
Who is affected?
This capability is available to Identity Security Cloud customers using Access Model Metadata.
ISC administrators configure attributes; role admins, role sub-admins, source admins, and source sub-admins can assign ad hoc values to the access items they manage.
Action required
To use ad hoc values, an ISC administrator must configure the metadata attribute to accept ad hoc entry. Existing attributes configured for static lists only are unchanged until updated.
After rollout, open Admin → Access Model Metadata to configure or update attributes, then assign values on roles, access profiles, or entitlements as needed.
Important dates
Available now!