ETM Identity RBAC - Tag-Based Scoping
Overview
Tag-based scoping in ETM Identity extends Role-Based Access Control (RBAC) by restricting access to assets and findings based on assigned tags. Users can view only the data associated with their assigned scope.
Tag-based scoping is applied in addition to role-based permissions. Tag-based scoping helps implement granular access control across teams, departments, and business units.
Example: A user assigned the tag Department = Finance can view only assets associated with the Finance tag.
Users must have the required ETM Identity roles and permissions to access application features and data.
Tag-Based Scoping Features
The following are the features of Tag-based scoping:
- Users can access assets that match their assigned tags.
- Assets outside the assigned scope are not visible.
- Supports static and dynamic tagging workflows.
- Enables business-unit and department-specific access control.
To know more about Tag-based Scoping, refer to Administration Online Help.
Tenant Attributes
Tenant attributes can be used in RBAC implementations and tag-based scoping workflows.
Supported tenant attributes:
- Tenant ID
- Tenant Name
Integration Behavior
| Integration | Behavior |
|---|---|
| Active Directory (AD) | One Active Directory domain belongs to one tenant. Domains can contain multiple users and groups. Tenant information can be used in dynamic tagging workflows. |
| Microsoft Entra ID | Tenant Name and Tenant Domain may contain different values. |
| AD Agent | Tenant Name and Tenant Domain are generally identical. |
| Okta | Tenant-level support is currently unavailable. |