Managed Attribute
The Managed Attribute object: a governed entitlement with an owner and description.
A Managed Attribute is an entitlement that has been enriched for governance with an owner, description and classification.
- What the Managed Attribute object represents
- Key attributes and relationships
- How it is created and maintained
- Where it appears in governance
A Managed Attribute is an entitlement that has been enriched for governance, given an owner, a plain-language description, and often a classification or risk score. Where a raw entitlement is just a cryptic value read from a target, a Managed Attribute is that value made meaningful to humans who must request, approve and certify it.
Why enrichment matters
Reviewers cannot make a real decision about CN=APP_GRP_0472. Given the Managed Attribute “Finance, read/write to the general ledger, owned by the Finance Systems team”, they can. Enrichment is therefore the difference between certifications that reduce risk and certifications that are rubber-stamped. It is one of the highest-return, lowest-glamour activities in a programme.
What a Managed Attribute adds
- Owner, who is accountable for and can certify this access.
- Description, what the entitlement actually grants, in business language.
- Classification / risk, so sensitive access can be prioritised and reviewed more often.
How they are created
Managed Attributes are created by promoting entitlement values discovered during aggregation. You do not need to enrich everything at once, start with the sensitive, high-risk entitlements where good descriptions and owners deliver the most governance value.
Managed Attributes in the bigger picture
They feed directly into the access request catalogue (clear items to request), certifications (reviewable items) and policy (well-understood building blocks for SoD). Poor entitlement metadata undermines all three, which is why enrichment is foundational rather than cosmetic.
Common pitfalls
- Leaving entitlements raw, so requests and certifications are opaque.
- No owner assigned, so no one is accountable for the access.
- Trying to enrich everything at once instead of prioritising by risk.