PingOne Platform APIs

Roles and Permissions in PingOne

The ability to perform an action in PingOne is determined by Role-Based Access Control (RBAC). For example, when you initiate a request to a PingOne endpoint, you must have the role required by the endpoint to execute the request. Roles define the permissions available to users with that role.

You’ll notice that our endpoint documentation uses icons to indicate the role or roles needed to access the endpoint (refer to Read All Built-in Admin Roles for an example).

The PingOne roles are:

Role Icon Abbr. Can Assign

Organization Admin

Organization Admin role

ORG

Environment Admin

Environment Admin

Environment Admin role

ENV

All roles except Organization Admin

Identity Data Admin

Identity Data Admin role

IDA

Identity Data Admin, Identity Data Read-Only Admin, Help Desk Admin

DaVinci Admin

DaVinci Admin role

DVA

DaVinci Admin, DaVinci Read-Only Admin

Custom Role Admin

Custom Role Admin role

ROLE

None

Application Owner

Application Owner role

APP‑O

None

Identity Data Read-Only Admin

Identity Data Read Only role

IDA-R

None

Configuration Read-Only Admin

Configuration Read Only role

CFA-R

None

DaVinci Read-Only Admin

DaVinci Admin Read Only role

DVA‑R

None

Client Application Developer

Client Application Developer role

APP

None

Help Desk Admin

Help Desk Admin role

HDA

None