Skip to content

Client Role Targets

Client role targets allow you to limit the app or group resources for a standard role that's assigned to a client (app) within your org. You can define admin roles to target groups, apps, and app instances.

  • Group targets: Grant an admin permission to manage only a specified group. For example, an admin role may be assigned to manage only the IT group.
  • App targets: Grant an admin permission to manage all instances of an OIN-cataloged app integration. For example, an admin role can manage all customer instances of an OIN-cataloged app, such as Salesforce or Facebook.
  • App instance targets: Grant an admin permission to manage an instance of an OIN-catalog app. For example, there may be a few Salesforce app instances configured for each sales region of an org. You can configure an admin to manage two Salesforce instances in a specific region and not the other regional Salesforce instances.

Note: You can only use the Client Role Targets API with standard roles. For custom roles, use Resource Sets to define specific targets. See the Role Assignments concept.

Languages
Servers
https://{yourOktaDomain}