Role Permissions for Intelligent Advisor REST APIs
The following table lists the roles required for permission to perform various Intelligent Advisor REST API tasks.
| REST API for Intelligent Advisor | ROLES | |||||
|---|---|---|---|---|---|---|
| Audits Entries REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Get all audit entries | YES | NO | NO | NO | NO | |
| Get an audit entry | YES | NO | NO | NO | NO | |
| Authorization Providers REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create authorization providers | YES | NO | NO | NO | NO | |
| Delete an authorization provider | YES | NO | NO | NO | NO | |
| Get all authorization providers | YES | NO | NO | NO | NO | |
| Get an authorization provider | YES | NO | NO | NO | NO | |
| Update an authorization provider | YES | NO | NO | NO | NO | |
| Checkpoint Inspect REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Inspect a checkpoint | NO | NO | NO | NO | NO | API Client only |
| Client Certificates REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create client certificates | NO | YES | NO | NO | NO | |
| Create or replace client certificates | NO | YES | NO | NO | NO | |
| Delete a client certificate | NO | YES | NO | NO | NO | |
| Get a client certificate | NO | YES | NO | NO | NO | |
| Get all client certificates | NO | YES | NO | NO | NO | |
| Update a client certificate | NO | YES | NO | NO | NO | |
| Connections REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create connections | NO | YES | NO | NO | NO | |
| Create or replace connections | NO | YES | NO | NO | NO | |
| Delete a connection | NO | YES | NO | NO | NO | |
| Get a connection | NO | YES | YES | YES | YES | Allowed for all users, but only members of the workspace will be able to see connections in their workspaces, however, if they are a Connections administrator then they can see and edit them all |
| Get all connections | NO | YES | YES | YES | YES | Allowed for all users, but only members of the workspace will be able to see connections in their workspaces, however, if they are a Connections administrator then they can see and edit them all |
| Test the connection status | NO | YES | NO | NO | NO | |
| Update a connection | NO | YES | NO | NO | NO | |
| CORS Allowlist REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create a CORS allowlist | NO | YES | NO | NO | NO | |
| Create or replace a CORS allowlist | NO | YES | NO | NO | NO | |
| Get a CORS allowlist | NO | YES | NO | NO | NO | |
| Update a CORS allowlist | NO | YES | NO | NO | NO | |
| Deployments REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Deployments | ||||||
| Create a referencesTo | NO | NO | YES | YES | YES | |
| Create deployments | NO | NO | NO | YES | YES | At least one version must be included |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | |
| Delete a deployment | NO | NO | NO | NO | YES | |
| Delete active deployment version | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Get a deployment | NO | NO | YES | YES | YES | Interviews API role also |
| Get a project definition | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Get a snapshot | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Get active deployment version | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Get all deployments | YES | NO | YES | YES | YES | Only deployments in workspaces the API Client is in will be shown, unless the user is a Permissions administrator in which case they can see all deployments |
| Get available locales | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Get object mappings | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Get URL parameters | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Update a deployment | NO | NO | YES | YES | YES | There are 4 optional fields (listed below) that you must have Manager role for too, if you include the fields |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | |
| Update active deployment version | This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation | |||||
| Deployment Debug Logs | ||||||
| Delete a deployment debug log | NO | NO | NO | NO | YES | |
| Delete deployment debug logs | NO | NO | NO | NO | YES | |
| Get a deployment debug log | NO | NO | NO | NO | YES | |
| Get a deployment debug log content | NO | NO | NO | NO | YES | |
| Get all deployment debug logs | NO | NO | NO | NO | YES | |
| Deployment Debug Events | ||||||
| Get a debug event | NO | NO | NO | NO | YES | |
| Get a debug event content | NO | NO | NO | NO | YES | |
| Get all deployment debug events | NO | NO | NO | NO | YES | |
| Deployment Logs | ||||||
| Get all deployment logs | NO | NO | NO | NO | YES | |
| Deployment Versions | ||||||
| Create deployment versions | NO | NO | NO | YES | YES | |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
| Delete a deployment version | NO | NO | NO | NO | YES | |
| Get a deployment version | NO | NO | YES | YES | YES | |
| Get a project definition | NO | NO | YES | YES | YES | |
| Get a snapshot | NO | NO | YES | YES | YES | |
| Get all deployment versions | NO | NO | YES | YES | YES | |
| Get available locales | NO | NO | YES | YES | YES | |
| Get object mappings | NO | NO | YES | YES | YES | |
| Get URL parameters | NO | NO | YES | YES | YES | |
| Update a deployment version | See below. JSON would be empty without one of the below properties. | |||||
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
|
NO | NO | NO | NO | YES | If JSON includes this property, additional permissions are required |
| Hubcertificates REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create a hubcertificate | YES | YES | NO | NO | NO | |
| Delete a hubcertificate | YES | YES | NO | NO | NO | |
| Get a hubcertificate | YES | YES | NO | NO | NO | |
| Update a hubcertificate | YES | YES | NO | NO | NO | |
| List all hub certificates | YES | YES | NO | NO | NO | |
| Jwk REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Get a jwk | No role requirements | |||||
| Get a verify | No role requirements | |||||
| Jwksets REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Jwksets | ||||||
| Create a jwkset generate active key | YES | YES | NO | NO | NO | |
| Get a jwkset | YES | YES | NO | NO | NO | |
| Get all jwksets | YES | YES | NO | NO | NO | |
| Update a jwkset | YES | YES | NO | NO | NO | |
| Jwkset Keys | ||||||
| Delete a JWKSet key | YES | YES | NO | NO | NO | |
| Get a jwkset key | YES | YES | NO | NO | NO | |
| Get all jwkset keys | YES | YES | NO | NO | NO | |
| Message Log Entries REST Endpoints | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Get a message log entry | NO | YES | NO | NO | NO | |
| Get all message log entries | NO | YES | NO | NO | NO | |
| Operations REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Operations | ||||||
| Get all operations | NO | NO | NO | NO | YES | |
| Get an operation | NO | NO | NO | NO | YES | |
| Replace an operation | NO | NO | NO | NO | YES | |
| Interfaces | ||||||
| Get all interfaces | NO | NO | NO | NO | YES | |
| Get an interface | NO | NO | NO | NO | YES | |
| Projects REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Projects (Policy Modeling) | ||||||
| Create projects | NO | NO | NO | YES | NO | |
| Delete a project | NO | NO | NO | YES | NO | |
| Get a project | NO | NO | YES | YES | NO | |
| Get a project inclusions report | NO | NO | YES | YES | NO | Projects that the user doesn't have access to won't be visible |
| Get all projects | YES | NO | YES | YES | NO | |
| Update a project | Not supported | |||||
| Project Versions (Policy Modeling) | ||||||
| Create project versions | NO | NO | NO | YES | NO | |
| Delete a project version | Not supported | |||||
| Get a project version | NO | NO | YES | YES | NO | |
| Get a project version inclusions report | NO | NO | YES | YES | NO | |
| Get all project versions | NO | NO | YES | YES | NO | |
| Update a project version | NO | NO | NO | NO | YES | |
| Projects REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Projects (Decision service, flow and flow scheme projects) | ||||||
| Create projects | NO | NO | NO | NO | YES | |
| Delete a project | NO | NO | NO | NO | YES | |
| Get a project | NO | NO | YES | YES | YES | |
| Get a project inclusions report | Not supported for decision service, flow and flow scheme projects | |||||
| Get all projects | NO | NO | YES | YES | YES | |
| Update a project | NO | NO | NO | NO | YES | If you only have the field "transaction" in the PATCH then check permissions for Update a project version task |
| Project Versions (Decision service, flow and flow scheme projects) | ||||||
| Create project versions | NO | NO | NO | YES | YES | Also used to create or overwrite an existing draft, as opposed to the normal REST pattern of PATCH or PUT on an existing object |
| Delete a project version | NO | NO | NO | YES | YES | Only supported for draft versions |
| Get a project version | NO | NO | YES | YES | YES | |
| Get a project version inclusions report | Not supported for decision service, flow and flow scheme projects | |||||
| Get all project versions | NO | NO | YES | YES | YES | |
| Update a project version | NO | NO | NO | YES | YES | A draft version cannot have a description, whereas a published (non-draft) version can. A draft can become a published version via this Update task, whereas a published version cannot become a draft via this Update task. Updating the content of a draft is performed via the POST (Create a project version) task. Only a Manager can update the description (for non-draft versions). |
| SSL Certificates REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create or replace SSL certificates | NO | YES | NO | NO | NO | |
| Create SSL certificates | NO | YES | NO | NO | NO | |
| Delete a SSL certificate | NO | YES | NO | NO | NO | |
| Get a SSL certificate | NO | YES | NO | NO | NO | |
| Get all SSL certificates | NO | YES | NO | NO | NO | |
| Update a SSL certificate | NO | YES | NO | NO | NO | |
| Statistics REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Empty statistics | NO | NO | YES | YES | YES | Must be member of workspace the deployment is in |
| Retrieve statistics | NO | NO | YES | YES | YES | |
| Test Suites REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Test Suites | ||||||
| Create test suites | NO | NO | NO | YES | YES | Must be member of workspace the test suite is in |
| Delete a test suite | NO | NO | NO | YES | YES | |
| Get a test suite | NO | NO | NO | YES | YES | |
| Get all test suites | NO | NO | NO | YES | YES | |
| Update a test suite | NO | NO | NO | YES | YES | |
| Test Cases | ||||||
| Create test cases | NO | NO | NO | YES | YES | |
| Delete a test case | NO | NO | NO | YES | YES | |
| Get a test case | NO | NO | NO | YES | YES | |
| Get all test cases | NO | NO | NO | YES | YES | |
| Update a test case | NO | NO | NO | YES | YES | |
| Test Runs | ||||||
| Create test runs | NO | NO | NO | YES | YES | |
| Delete a test run | NO | NO | NO | YES | YES | |
| Get a test run | NO | NO | NO | YES | YES | |
| Get all test runs | NO | NO | NO | YES | YES | |
| Update a test run | NO | NO | NO | YES | YES | |
| Test Run Deployments | Must be member of workspace the test suite is in | |||||
| Get a test run deployment | NO | NO | NO | YES | YES | |
| Get all test run deployments | NO | NO | NO | YES | YES | |
| Test Run Deployment Results | NO | NO | NO | YES | YES | |
| Get all test run deployment results | NO | NO | NO | YES | YES | |
| Test Run Projects | Must be member of workspace the test suite is in | |||||
| Get a test run project | NO | NO | NO | YES | YES | |
| Get all test run projects | NO | NO | NO | YES | YES | |
| Test Run Project Results | Must be member of workspace the test suite is in | |||||
| Get a test case result | NO | NO | NO | YES | YES | |
| Get all test run project results | NO | NO | NO | YES | YES | |
| Users REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create or replace users | YES | NO | NO | NO | NO | |
| Create users | YES | NO | NO | NO | NO | |
| Delete a user | YES | NO | NO | NO | NO | |
| Get a user | YES | NO | NO | NO | NO | |
| Get all users | YES | NO | NO | NO | NO | |
| Update users | NO | YES | NO | NO | NO | |
| Workspaces REST API | Permissions administrator | Connections administrator | Viewer | Author | Manager | Notes |
| Create or replace workspaces | YES | NO | NO | NO | NO | |
| Create workspaces | YES | NO | NO | NO | NO | |
| Delete a workspace | YES | NO | NO | NO | NO | |
| Get a workspace | NO | NO | NO | NO | NO | Only members of a workspace can see a specific workspace if they are a member of it, however, if they are a Permissions administrator, then they can see and edit it. The "users" property will only contain the current user if they do not have this permission (Permissions administrator role). |
| Get all workspaces | NO | NO | NO | NO | NO | Only members of a workspace can see all workspaces if they are a member of it, however, if they are a Permissions administrator, then they can see and edit all. The "users" property will only contain the current user if they do not have this permission (Permissions administrator role). |
| Update a workspace | YES | NO | NO | NO | NO | |