Tejesh,
Anything is possible if you do your research... Community support is not here to provide high level design instructions--we are here to answer specific questions.
In authorization flows, there is a policy decision point (PDP) and a policy enforcement point (PEP). The Gluu Server is the PDP, the corresponding application is the PEP.
You can pass attributes in the SAML assertion or OpenID id_token. The attributes can include roles and other types of identifying information.