docs/documentation/platform/access-controls/abac/managing-user-metadata.mdx
User identities can have metadata attributes assigned directly. These attributes (such as location or department) are used to define dynamic access policies.
</Step>
<Step title="On the User Page, click the pencil icon to edit the selected user.">
</Step>
<Step title="Add metadata via key-value pairs and update the user identity.">
</Step>
</Steps>
Attribute-based access controls are currently only available for policies defined on Secrets Manager projects. You can set ABAC permissions to dynamically set access to environments, folders, secrets, and secret tags.
In your policies, metadata values are accessed as follows:
{{ identity.id }} (always available){{ identity.username }} (always available){{ identity.metadata.<metadata-key-name> }} (available if set)