ETM Identity RBAC - Tag-Based Scoping

Overview

Tag-based scoping in ETM Identity extends Role-Based Access Control (RBAC) by restricting access to assets and findings based on assigned tags. Users can view only the data associated with their assigned scope. 

Tag-based scoping is applied in addition to role-based permissions. Tag-based scoping helps implement granular access control across teams, departments, and business units.

Example: A user assigned the tag Department = Finance can view only assets associated with the Finance tag.

Users must have the required ETM Identity roles and permissions to access application features and data.

Tag-Based Scoping Features

The following are the features of Tag-based scoping:

  • Users can access assets that match their assigned tags.
  • Assets outside the assigned scope are not visible.
  • Supports static and dynamic tagging workflows.
  • Enables business-unit and department-specific access control.

To know more about Tag-based Scoping, refer to Administration Online Help.

Tenant Attributes

Tenant attributes can be used in RBAC implementations and tag-based scoping workflows.

Supported tenant attributes:

  • Tenant ID
  • Tenant Name

Integration Behavior

Integration Behavior
Active Directory (AD) One Active Directory domain belongs to one tenant. Domains can contain multiple users and groups. Tenant information can be used in dynamic tagging workflows.
Microsoft Entra ID Tenant Name and Tenant Domain may contain different values.
AD Agent Tenant Name and Tenant Domain are generally identical.
Okta Tenant-level support is currently unavailable.