Skip to content

List all roles

GET/admins/{adminId}/role-assignments

Organization API · Organization Admins

Get the list of role assignments for given admin.

Required permissionaccount_management:read

Parameters

Name In Type Required Description
X-Organization-ID header string (uuid) Yes Organization ID.
adminId path string Yes Admin ID.

Request samples

curl -X GET "https://api.central.sophos.com/organization/v1/admins/<adminId>/role-assignments" -H "Authorization: Bearer <access-token>" -H "X-Organization-ID: <organization-id>"

import requests

response = requests.get(
    "https://api.central.sophos.com/organization/v1/admins/<adminId>/role-assignments",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Organization-ID": "<organization-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Organization-ID" = "<organization-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api.central.sophos.com/organization/v1/admins/<adminId>/role-assignments" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api.central.sophos.com/organization/v1/admins/<adminId>/role-assignments", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Organization-ID", "<organization-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api.central.sophos.com/organization/v1/admins/<adminId>/role-assignments", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Organization-ID": "<organization-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — A list of role assignments for an admin.

Response fields

itemsarray of objectrequired
Role assignments.
Items must be unique.
Role assignment.
Show child attributesHide child attributes
idstring (uuid)required
Role assignment ID.
roleIdstring (uuid)required
Role ID.
roleNamestring
Role name.
scopeobjectrequired
Role assignment scope.
Show child attributesHide child attributes
typestringrequired
Role assignment scope type.
Must be one of: tenant, allManagedTenants, self, tenantGroup.
idstring (uuid)
Tenant ID. Optional or not present when type is allManagedTenants or self.
namestring
Tenant name. Optional or not present when type is allManagedTenants or self.

Errors

Status Meaning
404 Can't find admin.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "roleId": "00000000-0000-0000-0000-000000000000",
      "roleName": "string",
      "scope": {
        "type": "tenant",
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "string"
      }
    }
  ]
}

See the guide for a narrative walkthrough of this API.