system account attribute
A descriptive noun phrase, not a standalone defined term, referring to the set of properties or metadata fields that an organization formally assigns to any managed access account — regardless of account type (individual, shared, group, guest, emergency, service, etc.) — that collectively govern how that account may be used. Organizations may define access privileges or other attributes by account or type of account, with examples including restrictions on time of day, day of week, and point of origin. When defining these attributes, organizations consider both system-related requirements and mission/business requirements — such as scheduled maintenance windows or time-zone differences — making the attribute set the formal specification used to create, manage, and audit accounts under an identity governance program.