Sorry for responding to an old post, but we're running into the exact same issue with one our rules. The custom attribute we're trying to filter on has the same name for entitlements/app roles/groups and accounts. However, we would very much prefer not to change each attribute to a unique name, since we like how the tool collapses attributes with the same name into one in overviews such as the User Access tab (see example below).
Are there other ways to work around this? Or perhaps a change in one of the newer (or upcoming) versions that elimanates the need for a workaround? We're currently on version 7.1.0 P09.