Skip to main content
GET
Describe a Dimension

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

dimension
string
required

Directory Dimension ID

Query Parameters

filter[id]
string
filter[trashed]
string

Can be a value of with (response will contain deleted items as well), only (will contain only deleted items), or any arbitrary value (will contain only not deleted items).

include
enum<string>[]
Available options:
attributes,
attributes-count,
attributes-exists,
integration,
integration-count,
integration-exists
filter
string

Response

DirectoryDimensionDetailedResponseData

id
string
required
Example:

"drdim_01hq8xyzabc123def456ghi789"

state
enum<string>
required

The state of the directory dimension

Available options:
staged,
active,
expiring,
expired,
deactivated
integration_id
string | null
required

The ID of the integration this dimension was sourced from (polymorphic).

Use this together with integration_type when creating an identity-type Policy Condition

Example:

"gitg_01hq8xyzabc123def456ghi789"

integration_type
string | null
required

The type of the integration this dimension was sourced from (polymorphic).

This is the value expected by integration_type when creating an identity-type Policy Condition

Example:

"App\\Models\\GoogleIntegration"

profile_key
string | null
required

The name of the key from the Workspace Integration that is in the Identity metadata array to get values from

Example:

"department"

name
string
required

The display name of the dimension. Any dimensions that are imported from the Integration are formatted with Headline/Title case

Example:

"Department"

handle
string
required

The alpha dash, lowercase abbreviated name of the dimension that is safe to use in email handles and URL paths

Example:

"dept"

attributes_enabled
boolean
required

If enabled, a Directory Attribute record is automatically created for each Dimension Attribute value from the unique Identity metadata profile_key values

conditions_enabled
boolean
required

If disabled, Attributes in this Dimension will not appear in the list of available options when creating a Rule Condition.

This is used when you want to have metadata about users but do not want future maintenance burden with rulesets using this data

expires_after_days
integer | null
required

Users will be automatically deprecated if they no longer qualify for at least one rule in the ruleset.

The expires_after_days value determines how many days after they no longer qualify that they still have access for a graceful transition period when users change job roles.

The value is inherited from the Workspace > Dimension > Attribute/Resource > Rule and can be overridden at any level to provide shorter revoke time controls when needed.

If the value is 0, this skips the grace period and revokes access immediately after expires_at.

By default, users have perpetual access (as Policy Users) as long as their attributes continue to match the conditions for the rule. If the rule is designed for just-in-time or short term access, you can set the expires_at date for all conditional users to be deprecated at that time.

You can use expires_at and expires_after_days=0 together to revoke access immediately.

Best Practice: You should the "low risk" sensible default (ex. 30 days) at the Dimension level and set more strict values at the Attribute/Resource levels where an exception needs to be granted.

A null value means no override is set at this level, so the grace period is inherited from the parent level

Example:

30

metadata
object
required

The dimension's custom key/value metadata added by someone or automation in your organization

timestamp
TimestampStateData · object
required

The timestamps for the directory dimension record

count
string[]
required

Counts of related resources.

directory_attributes: int|null audit_logs_parent: int|null, audit_logs_record: int|null, audit_logs_related: int|null, }

Minimum array length: 1
included
object
required

Included related resources

API hyperlinks related to the directory dimension record