Right now you can manage attribute release policy based on requester (entityID) - it's good but it might be quite heavy to consume by Shib-idp if in there is few thousands serviceproviders in you circle of trust.
Implementing this new feature will be quite tricky:
*) to merge into current logic
*) keep backward compatibility
*) (not confusing) presentation and management
Any proposals are welcome