We have multiple websites that share the same customer base but doing different kind of business. We already have a server that acts as a centralized identity service - it manages customers, their businesses and customer's roles in the businesses.
Because of the existence of this centralized identity service, we decide to add single-sign-on to this service - i.e. to make it act as a SSO identity provider.
A customer may have roles in multiple businesses - he could be an admin in business A and a technician in business B. When he logs in, our centralized identity service makes him to pick a business to login.
Question: does SAML response contain fields/attributes to carry this information: "The user has logged into business B as a technician"?
This document answers the question I asked:
http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html