One list of who exists, and what they are.
Universal Directory centralizes user profiles and attributes from whatever systems already hold them, so downstream applications provision and authorize from one record. Our work is attribute design that drives group membership and provisioning across the estate.
Universal Directory is the source of truth about people and their attributes. Everything downstream, including group membership in Atlassian, is only as good as what it holds.
What it is
Universal Directory centralizes user profiles and attributes from whatever systems already hold them, so downstream applications provision and authorize from one record.
It is for organizations maintaining several partly-overlapping user lists, which is the normal state after a few years and a merger.
What it does
One profile per person
Assembled from the systems that already hold parts of it.
Attributes that drive access
Group membership and entitlement derived from attributes rather than maintained by hand.
Vendors identifiable
External collaborators carry an attribute that policy can act on.
Where it fits
L1, identity and access. It is the record everything else derives from. Group membership in Atlassian, vendor identification, and access reviews all read from these attributes, so an attribute that is wrong here is wrong everywhere at once.
What we do with it
Attribute design
Deciding which attributes drive access, which is the decision that makes provisioning automatic.
Mapping into the estate
Attributes to Atlassian groups, so membership follows the record rather than a request.
Keeping it true
Attribute quality decays. Maintaining it is an operation, not a migration task.
Where it earns its place
An estate with vendors and employees in one pool
Without an attribute distinguishing them, no policy can treat them differently.
An organization automating provisioning
Automation is only as good as the attributes it reads.