PingOne Platform APIs

Roles and Permissions in PingOne

The ability to perform an action in PingOne is determined by Role-Based Access Control (RBAC). For example, when you initiate a request to a PingOne endpoint, you must have the role required by the endpoint to execute the request. Roles define the permissions available to users with that role.

You’ll notice that our endpoint documentation uses icons to indicate the role or roles needed to access the endpoint (refer to Read All Built-in Admin Roles for an example).

The PingOne roles are:

Role Can Assign

Organization Admin

Environment Admin

Environment Admin

All roles except Organization Admin

Identity Data Admin

Identity Data Admin, Identity Data Read-Only Admin, Help Desk Admin

DaVinci Admin

DaVinci Admin, DaVinci Read-Only Admin

Custom Role Admin

None

Application Owner

None

Identity Data Read-Only Admin

None

Configuration Read-Only Admin

None

DaVinci Read-Only Admin

None

Client Application Developer

None

Help Desk Admin

None