I've got automatic roles granted by IDM based on source registry values such as student. I would prefer to save the filter / criteria (example attribute filter: studentstatus=present) to the nrfRole object so that it would be logically where it belongs but nrfRole class does not seem to have such attribute.
How do you implement such automatic roles? How do you make the role filters accessible to the role admins so that they may add/modify the roles?
Without UA I just use a mapping table that holds all data of roles and role admins can do it online or with Excel but with UA we have the role portan and it seems silly to maintain role definitions in two places.