Skip to main content
User attributes allow you to map user-specific variables to Omni operations, such as querying, dashboarding, and data access. These attributes can be used in dashboard filters or workbooks or to filter embedded content.
The user attributes settings page, showing a list of defined attributes.

Use user attributes to define data access, filter content, and more

Requirements

Organization Admin permissions are required to create and modify user attributes, including assigning them to users.

Creating user attributes

To define a new user attribute, navigate to Settings > Attributes and click the New Attribute button.Each user attribute has the following settings:
  • Name: The name of the user attribute, how it will be displayed in the UI
  • Reference: How the attribute will be referenced in code, such as in the model
  • Type: Used to check that valid values are assigned to users. String and Number data types are allowed.
  • Multiple values: Specifies whether multiple values can be assigned to a user for this attribute
  • Description: Explanation of the attribute or how it will be used
  • Default value: Optional. Set a default value that all users will inherit if a value is not directly assigned to them.
Do not set a default value for attributes used in access filters or access grants. Omni assigns the default value to all users immediately upon account creation. If the default value matches a values_for_unfiltered value, those users will receive unfiltered data.Leave the default blank to ensure that users without an assigned value receive an error or no rows, which is visible and fixable.

Assigning attributes to users

The steps in this section apply to all user types, including email-only and embed.
After defining a user attribute, you can assign values to individual users.
  1. Navigate to Settings > Attributes.
  2. Click the attribute you want to set.
  3. In the attribute’s page, click the Users tab.
  4. In the list of users, locate the user you want to work with. Use the toggles above the table to filter the list by:
  5. Click the Edit value button in user’s row.
  6. In the dialog that displays, enter the value for the user.
  7. Click Save.
The Source column shows - when the user has the default value and User setting when a value is set for the user.

Default system user attributes

Most system attributes are read-only. Each attribute below says where you can set it, if you can.
Omni’s default user attributes will be marked with a System badge in the Settings > Attributes page.
number
default:"empty|null"
A special virtual attribute that allows Organization Admins to set an organization-wide default AI credit limit for users. Unlike regular user attributes that assign individual values per user, this virtual attribute sets a default that applies to all users that don’t have set individual credit limits. By default, users have unlimited AI credits.To set this for an embed user with URL parameters, use the embed userAttributes parameter.Click this attribute in Settings > Attributes to open the configuration page for the attribute. See Managing AI credit usage for full details on configuring per-user credit limits.
boolean
default:"true"
If true, the user can create, save, or move content in their personal My documents folder. When false, My documents is hidden in the sidebar and content operations default to the organization scope. Controlled with the Personal content access setting in each user’s settings page.
boolean
default:"false"
If true, the split-view AI chat panel opens on the right side of the screen with the document or dashboard on the left. When false, the chat panel opens on the left.Use this attribute to set the behavior for embed users or a default for your users. Individual users can update their preference with the Chat panel on the right setting in their account settings.
string
Requires Custom email sender on a verified domain. Omni sends these emails through Amazon SES.The From display name on deliveries and alerts sent to this user. Falls back to the organization’s saved custom sender when unset. Not shown or settable for embed users.Set this value on the user’s settings page.
string
Requires Custom email sender on a verified domain. Omni sends these emails through Amazon SES.The part before @ in the From address on deliveries and alerts sent to this user. Falls back to the organization’s saved custom sender when unset. Not shown or settable for embed users.Set this value on the user’s settings page.
boolean
If true, the user is an Organization Admin.
string
The user’s email address.
string
The user’s embedded entity name. For example, Blobs R Us
string
The user groups that the user is a member of. The value will be a comma-separated list of user group names, for example Blob Sales, Blob Marketing
string
A unique identifier for the user. For example, 91abbe19-b0de-4537-bc62-cec1d95420c9
string
The user’s locale code. Possible values are:See the Localization guide for more information.
string
The user’s name. For example, Blob Ross or Blobby Parton
string
The user’s timezone, which is set using the Query timezone setting on the user’s profile. For example, UTC or America/Los_Angeles

Common questions

Yes. User attributes can be used in a few ways to control data access:
  • Access filters, which allow you to restrict the rows of data a user can access within a topic. Access filters apply the values assigned on a user attribute to the WHERE clause of every SQL query a user runs, filtering out to only the data designated to that user:
    Filter by brand_name
  • Access grants, which define topic- and field-level permissions. Omni will map a user’s attribute value to a corresponding allowed value and determine if the user has the necessary permissions to access that topic or field:
    Grant access for user group
  • Fields. User attributes can be referenced in fields using Mustache syntax, for example: {{ omni_attributes.<attribute-name> }}. This construct can be used to:
    • Provide conditional access to a field, or
    • To hash a field based on a user attribute. This can be done by using a CASE statement in the SQL definition for a field. For example, the following name_hidden and name_hashed examples demonstrate how to use user attributes to hide or hash a name field as an alternative to using access grants to remove access entirely:
      Hide or hash field based on user attribute
Yes. User attributes can be used to parameterize the connection queries run against while in an Omni branch. Refer to the Dynamically switching database environments guide for more information and setup steps.
Yes. Shared extension models use user attributes to route users to the correct model extension. You define a mapping in the parent model’s dynamic_shared_extensions parameter that links user attribute values to specific extensions.
Yes. There are a few ways to do this:
  • Dashboard Markdown tiles. You can use user attributes in dashboard Markdown tiles with Mustache syntax. For example, {{metadata.userAttributes.<user_attribute>.values}} would return the value of the specified user attribute.
  • Dashboard deliveries. User attributes can be used to personalize deliveries, including messages (where supported) and the data included in the delivery.
Yes. The steps for assigning a user attribute are the same regardless of user type. To view email-only users when working with a specific attribute, click the Email Only toggle in the attribute’s Users tab:The Email Only toggle highlighted in the Users tab of a user attribute.
Yes. Refer to the Default system attributes section for more information.
Yes, if an Organization Admin has provisioned it. See User-selected attribute values for how users switch values themselves, and how to provision which values they’re allowed to switch to.

Next steps