Where They're Used
The same Source dropdown appears in four places. What differs is the pool of attributes
your ${...} placeholders draw from, and when the value is computed.
The four places
| Screen | Placeholders resolve against | Computed at |
|---|---|---|
| Application → Attribute Mapping | the user's identity attributes | provisioning dispatch (create / update / add-to-group) |
| Application → Account Association | the discovered account's attributes | aggregation, when correlating accounts to identities |
| Privileged Asset → Attribute Mapping | the user's identity attributes | provisioning of the privileged account |
| Privileged Asset → Account Association | the discovered account's attributes | aggregation correlation |