Skip to main content

Attribute management

From Mattermost v12.0, you define an attribute once in Attribute Management, then choose which resources can use it. An attribute such as Department or Clearance has a single definition (display name, name, type, options, and an optional AD/LDAP or SAML source) that's shared by every resource it applies to. Attribute Management replaces the User Attributes page used in earlier releases. For servers before v12.0, see User attributes.

Attributes defined here are the attributes you reference in attribute-based access control (ABAC) policies, for example user.attributes.department.

To open Attribute Management, go to System Console > System Attributes > Attribute Management. Only system admins can create, edit, or delete attributes.

Upgrade to v12.0: existing user attributes​

After the conversion:

  • User attribute names, IDs, and user values don't change, so existing ABAC policies that reference user.attributes.<name> continue to work.
  • Options, visibility, who can set the value, and AD/LDAP or SAML mappings carry over.
  • If an existing name isn't a valid attribute name, or is already used by another attribute, the new definition gets an adjusted name. The user attribute keeps its original name, so policies aren't affected.
  • Attributes created by plugins and protected attributes aren't converted.

If the server isn't licensed when it starts, the conversion is skipped and runs on a later restart once a license is applied.

Review attributes​

The Attribute Management page lists every attribute alphabetically by display name. Use Search attributes to filter by display name, name, or type. Select a row to edit an attribute.

ColumnShows
AttributeThe display name.
TypeThe attribute type, such as Text or Select.
Applies toThe resources that use the attribute, such as Users or Channels.
SourceWhere values come from: Managed here, AD/LDAP, SAML, or the name of the plugin that owns the attribute.
OptionsThe number of options, or Free Text for types without preset values.

The Classification attribute used by classification markings is shown as Definition is read-only. Manage its levels from the Classification Markings page by selecting Open Classification Markings in its row.

Create an attribute​

  1. Select New attribute.
  2. In the Definition section, enter the following details:
    • Display name: The label admins and users see. Up to 40 characters.
    • Unique name: Generated from the display name. Select Edit to change it. The name is the internal identifier used in access control policies and integrations, and must be unique. It must start with a letter or underscore and can contain only letters, numbers, and underscores. Reserved CEL words aren't allowed: true, false, null, in, as, break, const, continue, else, for, function, if, import, let, loop, package, namespace, return, var, void, and while.
    • Type: Select one of the following:
      • Text: A value typed in for each resource.
      • Phone: A phone number.
      • URL: A web address.
      • Select: A single value chosen from a list of options.
      • Multiselect: One or more values chosen from a list of options.
      • Ranked: A single value chosen from an ordered list, where each option ranks higher or lower than the others, such as Public, Secret, and Top Secret. Because the options are ordered, access control policies can compare a ranked attribute against a threshold, for example clearance is at least Secret.
      • Hierarchical: Values organized as parents and children, up to 100 parents per value and 100 levels deep. Available only when the PropertyFieldGraph feature flag is enabled, and only when you create an attribute. A hierarchical attribute can't be converted to another type.
    • Options: For Select, Multiselect, and Ranked attributes, enter each option and press Enter or Tab. At least one option is required. Options can be up to 64 characters and must be unique. Select an option to rename it, move it to another position, or remove it. For Ranked attributes, options are shown from lowest to highest rank; select an option to change its rank.
  3. Optionally, link the attribute to an external source.
  4. In the Applies to section, select Add resource and choose the resources the attribute applies to.
  5. Select Save.

You can define up to 200 attributes in total, and up to 20 attributes can apply to Users.

Synchronize an attribute's user values from your identity provider instead of managing them in Mattermost. AD/LDAP or SAML synchronization must already be configured. See AD/LDAP groups or SAML 2.0 for details.

  1. In the Definition section, select Link to external source, then select AD/LDAP or SAML.
  2. Enter the name of the attribute in your AD/LDAP directory or SAML response to sync the value from, then save.

You can link both AD/LDAP and SAML to the same attribute. Linked sources are listed under Synced with.

Choose the resources an attribute applies to​

Each resource you add has its own settings. Select a resource to expand its settings, or select Remove resource to remove it.

Users​

  • Profile display: Controls whether the attribute appears on user profiles: Always, When set (default), or Hidden.
  • Who can set the value: Member lets users set their own value, and system admins can still change it. System Administrator restricts the value to system admins and identity provider synchronization.

To view or update an individual user's values, see Manage user attributes.

Channels​

Channels is available only when the ChannelAttributes feature flag is enabled. Only admins can set channel values.

  • Changing the value: Controls how a channel's value can change after it's set:
    • Can be changed at any time (default)
    • Can only be raised, never lowered (Ranked attributes only)
    • Can only be lowered, never raised (Ranked attributes only)
    • Cannot be changed once set
  • Display location: Where the value is shown in the channel: Header, Channel Info, or Banner. You can select more than one location. The value is always shown in Channel Info.
  • Required: When enabled, a channel must have a value for this attribute before it can be created. Available only when the ChannelAttributesRequired feature flag is also enabled.

Edit an attribute​

Select an attribute's row, or select More actions > Edit attribute, make your changes, and select Save.

  • Unique name and Type can't be changed while the attribute applies to a resource. To change them, you must remove every resource and save, which permanently deletes all values stored for the attribute. Adding the resources back afterwards doesn't restore those values. Before you remove a resource, record any values you need to keep so you can set them again.
  • When you change the Display name, the new name also applies to each resource that uses the attribute, unless that resource's label was customized separately.
  • Changes to options apply to every resource that uses the attribute.

Delete an attribute​

  1. In the attribute's row, select More actions > Delete attribute.
  2. Select Delete to confirm.

Deleting an attribute permanently removes its definition and can't be undone. You can't delete an attribute while it still applies to a resource. Edit the attribute, remove every resource from Applies to, save, then delete it.

Attribute access modes​

Attributes created in Attribute Management use the public access mode, so their values are visible to every admin editing a policy that references them. Plugins can create attributes with restricted access modes. See Attribute access modes for details.