Hello again, seems that u're struggling with this :)
I believe that u're running 1.2/3 version so are in same situation as me, for bare metal domains you need to set the EPG to isolated, uSeg as you mention is strong related to VMM but is not exclusive, see here an output of: http://d2zmdbbm9feqrf.cloudfront.net/2016/usa/pdf/BRKACI-2320.pdf Cisco Live 2016:
You u Will be able to use uSeg on EPG using IP/MAC as attribute.
HTH,
KR,
AL