Standard administrator roles and permissions

Use these tables to compare standard admin permissions for Okta features, settings, and tasks.

Org-wide settings

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View and run reports ● ● ● ● ●
View Okta settings (themes, logo, contact info) ● ● ● ●
Grant access to Okta Support ●
Manage Profile Editor ● ● ● ●*
Manage profile mappings ● ● ●*
Manage sensitive attributes ●
Edit Okta settings ● ●
Add, remove, and view administrators ●
Add, delete, and edit authorization server scope, claim, and policies ● ● ●
View authorization server scope, claim, and policy ● ● ● ● ●
View System Log (system events) ● ● ● ● ● ● ● ●
Edit email and SMS template ● ●
Edit default email settings for other admins ●
View Device Trust enablement setting ● ● ●
Enable Device Trust setting ● ●
Close or retry tasks ● ●
Send custom notifications to users ● ●
Apply multibrand customization ● ●
Manage (enable, disable, update) CAPTCHA enablement settings ● ●
View CAPTCHA enablement settings ● ● ●
Manage log streaming ●
View Import Monitoring ●
Manage labels ●
View labels ● ● ●

* — Permissions apply only to OIDC apps.

User management

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View users ● ● ●* ● ● ● ●* ● ● ● ● ●
Create users ● ● ●*
Delete users ● ● ●*
Suspend users ● ●° ●*°
Deactivate users ● ● ●*
Activate users ● ●° ●*°
Change user types ● ● ●*
Sign out users ● ● ●*
Clear user sessions ● ●° ●*° ●*°
View logs ● ●° ●* ●° ●°
Edit profiles ● ● ●* ●^
Password resets, MFA resets ● ● ●* ●*
Choose not to receive email notifications about locked user accounts ● ● ●* ● ● ●
Reset user behavior profile ● ●° ●* ●*
View user behavior profile ● ● ●

View user types

●

●

●

●

Clear users' Chrome data ● ●° ●*° ●*°

* — Permissions apply only to groups that the admin is allowed to manage.

^ — Permissions apply only on user import for apps that don't have profile source configured.

° — Admin can perform the action on super admins.

Group management

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View groups ● ● ●* ● ● ● ●* ● ● ● ● ●
Add users to groups ● ●° ●^° ●*°
Add users to a group with assigned admin privileges ●
Remove users from groups ● ●° ●^° ●*°
Create groups ● ●
Manage group rules ● ●

View group rules ● ● ● ● ● ● ●

● ●

Assign admin privileges to a group ●
Delete groups ● ●

Edit group MFA authenticators

● ● ●

* — Permissions apply only to groups that the admin is allowed to manage.

^ — Permissions to create, add, and remove users apply only to groups that the group admin manages. Group admins can create new users in groups that they manage, remove users from groups that they manage, and move users between groups that they manage.

× — Permissions apply only if the admin has access to all users and groups.

° — The admin can perform the action on super admins.

AI agents

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View AI agents ● ● ● ●
Create, update, and delete AI agents ● ● ● ●

Agent Gateway

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View Agent Gateways ● ●
Create, update, and delete Agent Gateways ● ●

Service accounts management

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
Create, edit, or remove service accounts ●
View service accounts ●

Application management

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View applications or application instances ● ●^ ● ● ●* ● ● ●
Add and configure applications ● ●^ ●*
Assign user access to applications ● ●^ ●*
Create users in staged status through app import ● ●^
Configure AI agent imports for an app integration ● ●
Create, update, and delete client authorization settings for an AI agent provider app ● ●

* — Permissions apply only to OIDC apps.

^ — Permissions apply only to apps that the app admin is allowed to manage.

Devices

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
Manage devices ● ●
View devices and device details ● ● ● ● ●
Suspend or deactivate devices ● ●
View and add Device Assurance policies ● ●

View device integrations

● ● ●
Generate device recovery PIN ● ● ●

Hooks

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View hooks ● ●
Create and configure hooks ●

Policies

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View Global Session Policies ● ●
Add/update/delete Global Session Policies ● ●
Add/update/delete Global Session Policy rules ● ●

View app sign-in policies

● ● ●* ●

Add/update/delete app sign-in policies

● ●*

Assign app sign-in policies to apps

● ●*

Add/update/delete app sign-in policies rules

● ●*

View user profile policies

● ●

Add/update/delete user profile policies

●
Drag and drop policies for prioritization ●
Edit MFA authenticators in policies ●

* — Permissions apply only to app sign-in policies. App admins can manage app sign-in policies only if they're allowed to manage all apps assigned to the policy.

Org security

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View network zones ● ● ● ●
Manage network zones ● ●
View org behavior profile ● ● ●
Manage org behavior profile ● ●
View ThreatInsight configuration ● ● ●
Manage ThreatInsight configuration ● ●

Multifactor Authentication

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin

Configure authenticators

● ●
Enable MFA for the Admin Dashboard ●
Authorize RADIUS Agent ● ● ● ●

API tokens

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
Create user tokens ●* ●* ●* ●* ●*
View user tokens ● ● ●^ ●* ● ●*
Clear user tokens ● ●* ●* ●* ●^ ●*
View user social tokens ● ● ● ●
Manage tokens ● ● ● ●* ●*

* — Admins can only perform the action on themselves.

^ — Permissions apply only to self and scoped members.

OpenID Connect end-to-end scenario

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
Create and modify an OIDC App, including registering an OAuth client. Can be restricted to OIDC client apps. ● ● ●
Add a social IDP ● ●
Read-only access to OAuth clients through the API ● ● ● ● ●

Identity Governance

Access certifications admin and access requests admin roles are available only if you're subscribed to Okta Identity Governance.

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View all campaigns ● ●
Create campaigns ● ●
Edit/launch scheduled campaigns ● ●
End active campaigns ● ●
Manage user access applications within Access Requests ● ●
Act as an administrator within Access Requests ● ●

Manage group ownership

● ●

●*

* — App admins can only assign or remove group owners. They can't manage group membership by adding or removing users from the group.

Realms

Okta Identity Governance is required for realms. See Okta Identity Governance for more information.

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
Create realms ● ●
View realms ● ● ●
View realms designation ● ● ● ● ● ● ● ● ●

Update realms

● ●
Delete realms ● ●
Update user realms designation (move user from one realm to another) ● ●

Mover users individually

● ●
Bulk move users between realms ●

Create realms assignment

●
Setting up a workflow with realms ● ● ●

MCP and resource servers

Permission
Super Admin
Org Admin
Group Admin
App Admin
Read-only Admin
Mobile Admin
Help Desk Admin
Report Admin
API Access Management Admin
Group Membership Admin
Access Requests Admin
Access Certifications Admin
AI Agent Admin
View MCP servers ● ●
Create, update, and delete MCP servers ● ●
View resource servers ● ●
Create, update, and delete resource servers ● ●

Workflows

The Okta super admin and the Workflows Administrator role have full administration and management privileges within the Okta Workflows product.

A user or group assigned to the Workflows Administrator role can't grant the Workflows Administrator role to other users or groups in the Okta org. Only an Okta super admin can assign that role through the Okta Admin Console.

All Okta Workflows roles are assigned to users and groups using the Workflows Console, except for the Workflows Administrator role. See Manage Workflow roles.