> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/gcp-identities/workforce-providers.md).

# Workforce Providers

The **Workforce Providers** page provides a list of enumerated Workforce Identity Pool Providers in GCP. Workforce Providers define how external workforce (human user, e.g., SAML or OIDC identity providers such as Entra ID) identities federate into a Workforce Identity Pool.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-264a5a5c1f01910b0cdc81a9edfd6ce00e8cc556%2FGCPWorkforceProviderListPage.png?alt=media" alt=""><figcaption><p>Workforce Providers</p></figcaption></figure>

### Workforce Providers Details

The Details page includes the **`Details`**, **`Attribute Condition`**, and **`Attribute Mapping`** tabs, and a **`Graph »`**` `` ``button ` for enhanced navigation and analysis. A badge (e.g., **SAML**) indicates the provider type.

{% hint style="info" %}
You can analyze objects in the `Graph module` by clicking the **`Graph »`** button on the upper right side.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-560c94b59db7a84089ee743e47a6bc1768972a9d%2FGCPWorkforceProviderDetailPage.png?alt=media" alt=""><figcaption><p>GCP Workforce Provider Details</p></figcaption></figure>

The Details tab contains attributes about the GCP Workforce Provider. The page also includes an **Issues** panel that lists any security findings related to the provider, along with a Risk score and Exposure Point.

### Information

| Attribute     | Description                                                                                                                |
| ------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Display Name  | The human-readable name of the provider (e.g., `Entra-ID`).                                                                |
| Name          | The full resource path of the provider (e.g., `locations/global/workforcePools/workforce-pool-test-2/providers/entra-id`). |
| SAML Provider | Indicates the provider uses SAML federation.                                                                               |
| State         | The lifecycle state of the provider (e.g., `ACTIVE`).                                                                      |
| Description   | A free-text description of the provider (e.g., `test`).                                                                    |
| Disabled      | Indicates whether the provider is currently disabled.                                                                      |

### **Attribute Condition**

Displays the CEL condition used to restrict which external identities may federate through the provider.

### **Attribute Mapping**

Displays the mapping between external identity attributes and Google Cloud attributes.

#### **Issues**

Lists security findings associated with the provider (e.g., *Workforce Identity Federation Provider Has No Attribute Condition*), each tagged with relevant categories such as Least Privilege or Credential Security, and a severity rating (e.g., High).
