Role Permissions for Intelligent Advisor REST APIs

The following table lists the roles required for permission to perform various Intelligent Advisor REST API tasks.

Table 1. Role permissions for REST API tasks
REST API for Intelligent Advisor ROLES  
Audits Entries REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Get all audit entries YES NO NO NO NO  
Get an audit entry YES NO NO NO NO  
Authorization Providers REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create authorization providers YES NO NO NO NO  
Delete an authorization provider YES NO NO NO NO  
Get all authorization providers YES NO NO NO NO  
Get an authorization provider YES NO NO NO NO  
Update an authorization provider YES NO NO NO NO  
Checkpoint Inspect REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Inspect a checkpoint NO NO NO NO NO API Client only
Client Certificates REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create client certificates NO YES NO NO NO  
Create or replace client certificates NO YES NO NO NO  
Delete a client certificate NO YES NO NO NO  
Get a client certificate NO YES NO NO NO  
Get all client certificates NO YES NO NO NO  
Update a client certificate NO YES NO NO NO  
Connections REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create connections NO YES NO NO NO  
Create or replace connections NO YES NO NO NO  
Delete a connection NO YES NO NO NO  
Get a connection NO YES YES YES YES Allowed for all users, but only members of the workspace will be able to see connections in their workspaces, however, if they are a Connections administrator then they can see and edit them all
Get all connections NO YES YES YES YES Allowed for all users, but only members of the workspace will be able to see connections in their workspaces, however, if they are a Connections administrator then they can see and edit them all
Test the connection status NO YES NO NO NO  
Update a connection NO YES NO NO NO  
CORS Allowlist REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create a CORS allowlist NO YES NO NO NO  
Create or replace a CORS allowlist NO YES NO NO NO  
Get a CORS allowlist NO YES NO NO NO  
Update a CORS allowlist NO YES NO NO NO  
Deployments REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Deployments            
Create a referencesTo NO NO YES YES YES  
Create deployments NO NO NO YES YES At least one version must be included
  • if { "workspace": ...} included

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "debugLoggingState": { ... } } inc.

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "workspaceReferences": ...} is included and value is different from existing references

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "compatibilityMode": [value]} if included and value is not "latest"

NO NO NO NO YES  
Delete a deployment NO NO NO NO YES  
Delete active deployment version           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Get a deployment NO NO YES YES YES Interviews API role also
Get a project definition           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Get a snapshot           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Get active deployment version           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Get all deployments YES NO YES YES YES Only deployments in workspaces the API Client is in will be shown, unless the user is a Permissions administrator in which case they can see all deployments
Get available locales           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Get object mappings           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Get URL parameters           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Update a deployment NO NO YES YES YES There are 4 optional fields (listed below) that you must have Manager role for too, if you include the fields
  • if { "workspace": ...} included

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "debugLoggingState": { ... } } inc.

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "workspaceReferences": ...} is included and value is different from existing references

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "compatibilityMode": [value]} if included and value is not "latest"

NO NO NO NO YES  
Update active deployment version           This is an /activeVersion shortcut, same permissions as the same Deployment Versions operation
Deployment Debug Logs            
Delete a deployment debug log NO NO NO NO YES  
Delete deployment debug logs NO NO NO NO YES  
Get a deployment debug log NO NO NO NO YES  
Get a deployment debug log content NO NO NO NO YES  
Get all deployment debug logs NO NO NO NO YES  
Deployment Debug Events            
Get a debug event NO NO NO NO YES  
Get a debug event content NO NO NO NO YES  
Get all deployment debug events NO NO NO NO YES  
Deployment Logs            
Get all deployment logs NO NO NO NO YES  
Deployment Versions            
Create deployment versions NO NO NO YES YES  
  • if { "activeVersionFlag": [boolean value]} is included and value is different from activated status

NO NO NO NO YES If JSON includes this property, additional permissions are required
Delete a deployment version NO NO NO NO YES  
Get a deployment version NO NO YES YES YES  
Get a project definition NO NO YES YES YES  
Get a snapshot NO NO YES YES YES  
Get all deployment versions NO NO YES YES YES  
Get available locales NO NO YES YES YES  
Get object mappings NO NO YES YES YES  
Get URL parameters NO NO YES YES YES  
Update a deployment version           See below. JSON would be empty without one of the below properties.
  • if { "activeVersionFlag": [boolean value]} is included and value is different from activated status

NO NO NO NO YES If JSON includes this property, additional permissions are required
  • if { "dataSource": { ...} } is included

NO NO NO NO YES If JSON includes this property, additional permissions are required
Hubcertificates REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create a hubcertificate YES YES NO NO NO  
Delete a hubcertificate YES YES NO NO NO  
Get a hubcertificate YES YES NO NO NO  
Update a hubcertificate YES YES NO NO NO  
List all hub certificates YES YES NO NO NO  
Jwk REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Get a jwk           No role requirements
Get a verify           No role requirements
Jwksets REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Jwksets            
Create a jwkset generate active key YES YES NO NO NO  
Get a jwkset YES YES NO NO NO  
Get all jwksets YES YES NO NO NO  
Update a jwkset YES YES NO NO NO  
Jwkset Keys            
Delete a JWKSet key YES YES NO NO NO  
Get a jwkset key YES YES NO NO NO  
Get all jwkset keys YES YES NO NO NO  
Message Log Entries REST Endpoints Permissions administrator Connections administrator Viewer Author Manager Notes
Get a message log entry NO YES NO NO NO  
Get all message log entries NO YES NO NO NO  
Operations REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Operations            
Get all operations NO NO NO NO YES  
Get an operation NO NO NO NO YES  
Replace an operation NO NO NO NO YES  
Interfaces            
Get all interfaces NO NO NO NO YES  
Get an interface NO NO NO NO YES  
Projects REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Projects (Policy Modeling)            
Create projects NO NO NO YES NO  
Delete a project NO NO NO YES NO  
Get a project NO NO YES YES NO  
Get a project inclusions report NO NO YES YES NO Projects that the user doesn't have access to won't be visible
Get all projects YES NO YES YES NO  
Update a project           Not supported
Project Versions (Policy Modeling)            
Create project versions NO NO NO YES NO  
Delete a project version           Not supported
Get a project version NO NO YES YES NO  
Get a project version inclusions report NO NO YES YES NO  
Get all project versions NO NO YES YES NO  
Update a project version NO NO NO NO YES  
Projects REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Projects (Decision service, flow and flow scheme projects)            
Create projects NO NO NO NO YES  
Delete a project NO NO NO NO YES  
Get a project NO NO YES YES YES  
Get a project inclusions report           Not supported for decision service, flow and flow scheme projects
Get all projects NO NO YES YES YES  
Update a project NO NO NO NO YES If you only have the field "transaction" in the PATCH then check permissions for Update a project version task
Project Versions (Decision service, flow and flow scheme projects)            
Create project versions NO NO NO YES YES Also used to create or overwrite an existing draft, as opposed to the normal REST pattern of PATCH or PUT on an existing object
Delete a project version NO NO NO YES YES Only supported for draft versions
Get a project version NO NO YES YES YES  
Get a project version inclusions report           Not supported for decision service, flow and flow scheme projects
Get all project versions NO NO YES YES YES  
Update a project version NO NO NO YES YES A draft version cannot have a description, whereas a published (non-draft) version can. A draft can become a published version via this Update task, whereas a published version cannot become a draft via this Update task. Updating the content of a draft is performed via the POST (Create a project version) task. Only a Manager can update the description (for non-draft versions).
SSL Certificates REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create or replace SSL certificates NO YES NO NO NO  
Create SSL certificates NO YES NO NO NO  
Delete a SSL certificate NO YES NO NO NO  
Get a SSL certificate NO YES NO NO NO  
Get all SSL certificates NO YES NO NO NO  
Update a SSL certificate NO YES NO NO NO  
Statistics REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Empty statistics NO NO YES YES YES Must be member of workspace the deployment is in
Retrieve statistics NO NO YES YES YES  
Test Suites REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Test Suites            
Create test suites NO NO NO YES YES Must be member of workspace the test suite is in
Delete a test suite NO NO NO YES YES  
Get a test suite NO NO NO YES YES  
Get all test suites NO NO NO YES YES  
Update a test suite NO NO NO YES YES  
Test Cases            
Create test cases NO NO NO YES YES  
Delete a test case NO NO NO YES YES  
Get a test case NO NO NO YES YES  
Get all test cases NO NO NO YES YES  
Update a test case NO NO NO YES YES  
Test Runs            
Create test runs NO NO NO YES YES  
Delete a test run NO NO NO YES YES  
Get a test run NO NO NO YES YES  
Get all test runs NO NO NO YES YES  
Update a test run NO NO NO YES YES  
Test Run Deployments           Must be member of workspace the test suite is in
Get a test run deployment NO NO NO YES YES  
Get all test run deployments NO NO NO YES YES  
Test Run Deployment Results NO NO NO YES YES  
Get all test run deployment results NO NO NO YES YES  
Test Run Projects           Must be member of workspace the test suite is in
Get a test run project NO NO NO YES YES  
Get all test run projects NO NO NO YES YES  
Test Run Project Results           Must be member of workspace the test suite is in
Get a test case result NO NO NO YES YES  
Get all test run project results NO NO NO YES YES  
Users REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create or replace users YES NO NO NO NO  
Create users YES NO NO NO NO  
Delete a user YES NO NO NO NO  
Get a user YES NO NO NO NO  
Get all users YES NO NO NO NO  
Update users NO YES NO NO NO  
Workspaces REST API Permissions administrator Connections administrator Viewer Author Manager Notes
Create or replace workspaces YES NO NO NO NO  
Create workspaces YES NO NO NO NO  
Delete a workspace YES NO NO NO NO  
Get a workspace NO NO NO NO NO Only members of a workspace can see a specific workspace if they are a member of it, however, if they are a Permissions administrator, then they can see and edit it. The "users" property will only contain the current user if they do not have this permission (Permissions administrator role).
Get all workspaces NO NO NO NO NO Only members of a workspace can see all workspaces if they are a member of it, however, if they are a Permissions administrator, then they can see and edit all. The "users" property will only contain the current user if they do not have this permission (Permissions administrator role).
Update a workspace YES NO NO NO NO