Specifying additional attributes that can be used to create dynamic user groups
In a dynamic user group, attribute-based rules determine which users are included in the group. By default, you can use a limited set of attributes to create dynamic user groups. However, you might want to use additional attributes when you create the groups.
Before you begin
IBM Software Hub must be configured to use the IBM Cloud Pak foundational services Identity Management Service. For more information, see Integrating with the Identity Management Service.
About this task
By default, you can use only the following attributes from your identity provider (IdP) to define
a dynamic user group:
- Location
- Nationality
- Organization
- User type
However, you might want to use additional attributes when you create a user group. For example,
you might want to:
- Prevent users from accessing a catalog unless they pass a specific training course on handling personally identifiable information.
- Allow users who are involved in a particular initiative to access the project that is associated with the initiative.
IBM Software Hub supports the following methods for specifying additional attributes:
| Option | Use this option if... |
|---|---|
| Using additional attributes from your IdP (recommended) | The attributes that you want to use exist in your IdP. |
| Using a custom attributes provider | The attributes that you want to use do not exist in your IdP |
Both methods append the specified attributes to a user's IBM Software Hub user profile.
Procedure
Use the appropriate method to specify additional attributes that can be used to create dynamic user groups: