Netskope provides predefined DOMs to support SaaS security posture evaluation across applications. However, some SaaS applications, such as Okta, allow you to define custom attributes specific to your organization (for more information, see add custom user attributes).
This article explains how you can leverage such custom attributes in your detections within SSPM.
Prerequisites
- The required attribute is not already available in the predefined DOM.
- The attribute exists in the source application metadata (API listing response).
- The attribute is needed for policy evaluation or posture assessment.
- You have the following details ready:
- Attribute name
- Attribute data type
- Description or use case
Procedure
Step 1: Submit request to add a custom attribute
-
Create a support ticket or contact your Netskope representative to add a custom attribute.
-
Provide the following information in the support ticket:
-
Subject: Request to Add Custom Attribute to Predefined DOM.
-
Appsuite: Application suite for which you are making the request.
-
Resource Type: See Resource Types article to learn more.
-
Requested attribute information:
-
Attribute Name: Exact field name from the API response.
-
Attribute Data Type: For example: String, Boolean, Integer, Array.
-
Description / Purpose: Purpose and how it will be used in rule evaluations.
Example Request
Field Value Subject Request to Add Custom Attribute to Predefined DOM App Suite Microsoft 365 Resource Type SharePoint Site Attribute Name sensitivityLabel Attribute Data Type String Description Require the SharePoint site sensitivityLabel for rule evaluation in SSPM. The property exists in the resource metadata but it is not exposed as a DOM attribute.
-
-
Step 2: Attribute Addition
After you submit the request:
- Netskope will review your request and reach out if additional details are required.
- You will receive a notification indicating whether the request is approved or rejected, along with the reason for the decision.
- If your request is approved, the custom attribute will be added for your tenant with subsequent releases.
Step 3: Verification
Once the custom attribute is added to your tenant-specific DOM, verify it as follows:
- Log in to your SSPM tenant.
- Navigate to API-enabled Protection > Security Posture SaaS > Inventory.
- In the Resources tab, choose Switch to NGL option.
- Write an NGL with usage of the newly added custom attribute.
Step 4: Create Rule using a Custom Attribute
Once your custom attribute is added, you can use it to create custom rules and build NGL, as follows:
- Log in to your SSPM tenant.
- Navigate to Policies > SaaS Security Posture Management.
- In the Rules tab, click Add Rule.
- Create a New Custom Rule in the side panel via Create From Scratch option. See Adding a New Custom Rule for detailed steps.

