User identity and attributes
Authorization also considers a user’s identity profile and associated attributes to verify that access aligns with their role and eligibility.
Identity attributes are not assigned directly to users. They are defined within the context of the groups to which the user belongs. When a user becomes a member of a group, they inherit the attributes associated with that group. This ensures that attributes remain aligned with the user’s group affiliation rather than being considered custom, user‑specific properties.
For example, when a user belongs to a specific team or group, the identity attributes they inherit come from that group’s definition. The user does not maintain individual custom attributes outside their group context.