These are AWS SSO identity store attributes that you can configure for use in attributes-based access control (ABAC).
You can create permission policies that determine who can access your AWS resources based upon the configured attribute value(s).
When you enable ABAC and specify AccessControlAttributes, AWS SSO passes the attribute(s) value of the authenticated user into IAM for use in policy evaluation.
A set of key-value pairs that are used to manage the resource.
Tags can only be applied to permission sets and cannot be applied to corresponding roles that AWS SSO creates in AWS accounts.