
AndrewB.52439 (Vivun Inc) asked a question.
Hello!
I'm about to embark on the exciting path of automating birthright app assignments using a set of groups that are sync'd and controlled by my HR system. So, for example, the Engineering Okta group contains everyone in the Engineering department in BambooHR.
So... I'll assign that Engineering group to the Github app... and voila! Magic.
But... every once in a while, I encounter the need for an access "anomaly" let's say. For example... sales users who give notice may have Salesforce access revoked ahead of their exit date (but retain access to other systems). If I tie Salesforce access to the Sales Okta group... my hands get tied here. I'd have to either get very creative with a new custom group or very manual individual assignments... or use the controls in the app itself, in this case disable the user in Salesforce.
I'm curious if those are my two best options... or am I not thinking of something better?

Hello @AndrewB.52439 (Vivun Inc)
I hope you are having a great day
Thank you for posting in this scenario, you can create manually custom attributes that match your requirement you can learn more about this topic at the link below:https://support.okta.com/help/s/article/How-to-create-a-new-custom-attribute-in-Okta?language=en_US
If you need further assistance you can also feel free to post this question in our Okta Developer Forum https://devforum.okta.com, this is a place for the Okta developer community to interact.
Have a great day ahead
Henry E.
Okta Inc