List of Dimensions
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Query Parameters
attributes, attributes-count, attributes-exists, integration, integration-count, integration-exists Filter by a partial match of the dimension ID
Filter by an exact match of the integration ID
Filter by an exact match of the integration type (polymorphic morph class)
Filter by an exact match of the profile key field
Filter by a partial match of the profile key field
Filter by an exact match of the name field
Filter by a partial match of the name field
Filter by an exact match of the handle field
Filter by a partial match of the handle field
Filter by an exact match of the attributes_enabled field
Filter by an exact match of the conditions_enabled field
Filter by an exact match of the expires_after_days field
Filter by an exact match of the state field
Filter by searching custom metadata key/value pairs for any partial string match
Filter by created before date
Filter by created after date
Filter by updated before date
Filter by updated after date
Filter by expires before date
Filter by expires after date
Filter by deleted before date
Filter by deleted after date
Filter by whether the dimension has a workspace integration (true = has integration, false = no integration)
Include trashed records (with, only, without)
Response
The collection of DirectoryDimensionDetailedResponseData
"drdim_01hq8xyzabc123def456ghi789"
The state of the directory dimension
staged, active, expiring, expired, deactivated The ID of the integration this dimension was sourced from (polymorphic).
Use this together with integration_type when creating an identity-type Policy Condition
"gitg_01hq8xyzabc123def456ghi789"
The type of the integration this dimension was sourced from (polymorphic).
This is the value expected by integration_type when creating an identity-type Policy Condition
"App\\Models\\GoogleIntegration"
The name of the key from the Workspace Integration that is in the Identity metadata array to get values from
"department"
The display name of the dimension. Any dimensions that are imported from the Integration are formatted with Headline/Title case
"Department"
The alpha dash, lowercase abbreviated name of the dimension that is safe to use in email handles and URL paths
"dept"
If enabled, a Directory Attribute record is automatically created for each Dimension Attribute value from the unique Identity metadata profile_key values
If disabled, Attributes in this Dimension will not appear in the list of available options when creating a Rule Condition.
This is used when you want to have metadata about users but do not want future maintenance burden with rulesets using this data
Users will be automatically deprecated if they no longer qualify for at least one rule in the ruleset.
The expires_after_days value determines how many days after they no longer qualify that they still
have access for a graceful transition period when users change job roles.
The value is inherited from the Workspace > Dimension > Attribute/Resource > Rule and can be overridden at
any level to provide shorter revoke time controls when needed.
If the value is 0, this skips the grace period and revokes access immediately after expires_at.
By default, users have perpetual access (as Policy Users) as long as their attributes continue to match
the conditions for the rule. If the rule is designed for just-in-time or short term access, you can
set the expires_at date for all conditional users to be deprecated at that time.
You can use expires_at and expires_after_days=0 together to revoke access immediately.
Best Practice: You should the "low risk" sensible default (ex. 30 days) at the Dimension level and set more strict values at the Attribute/Resource levels where an exception needs to be granted.
A null value means no override is set at this level, so the grace period is inherited from the parent level
30
The dimension's custom key/value metadata added by someone or automation in your organization
The timestamps for the directory dimension record
Counts of related resources.
directory_attributes: int|null audit_logs_parent: int|null, audit_logs_record: int|null, audit_logs_related: int|null, }
1Included related resources
API hyperlinks related to the directory dimension record