ArcGIS Enterprise on Kubernetes provides multiple ways for organizations to manage how their members access and interact with its content. One way is by assigning members specific privileges through custom roles that include administrative privileges, such as the ability to manage an organization's security configuration. These custom roles allow organizations to delegate administrative tasks without having to assign the default administrator role to multiple members.
Only members assigned specific administrative and Publisher role privileges will be able to access the ArcGIS Enterprise Administrator API itself. Further access to resources and operations is restricted based on the endpoints that are associated with, or required by, their role's privileges.
Privilege-based access
Members are only able to access some endpoints in the ArcGIS Enterprise Admin API based on the privileges assigned to their role. Resources and operations that are not accessible to members are inaccessible through the UI or return errors if they are accessed through URL paths.
The following table shows which administrative privileges are authorized to access the ArcGIS Enterprise Admin API that can be assigned to users:
| Administrative privilege category | Privilege name | 
|---|---|
| Members | Manage licenses | 
| Groups | Links to organization-specific group | 
| Content | Update | Delete | 
| Portal Settings | Security and Infrastructure | Servers | Organization website | 
In addition to the administrative privileges listed above, users assigned the Publisher default role will also be able to access the ArcGIS Enterprise Admin API.
Endpoint access
The following sections outline the access provided to each administrative privilege, as well as which endpoints are available to users assigned the Publisher role.
Organizations
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | Servers | Manage licenses | Links to organization-specific group | |
| Security and infrastructure | Servers | Update | Delete | Manage licenses | Links to organization-specific group | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | Links to organization-specific group | |
| Security and infrastructure | Links to organization-specific group | |
| Security and infrastructure | Links to organization-specific group | |
| Security and infrastructure | Links to organization-specific group | |
| Security and infrastructure | Links to organization-specific group | |
| Manage licenses | |
| Manage licenses | |
| Manage licenses | |
| Manage licenses | |
| Manage licenses | |
| Servers | |
| Servers | |
| Servers | |
| Servers | |
| Servers | |
| Servers | |
| Servers | |
| Servers | |
| Default administrator role | |
| Default administrator role | 
Services
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | |
| Security and infrastructure | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Feature layer | Geoprocessing | Publisher role | |
| Organization webhooks | |
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | 
Security
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | 
Uploads
| Endpoint | Privileges | 
|---|---|
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | 
Data stores
| Endpoint | Privileges | 
|---|---|
| Update | Publisher role | |
| Update | Publisher role | |
| Update | Publisher role | |
| Update | Publisher role | |
| Update | Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | |
| Publisher role | 
System
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | Servers | Manage licenses | Organization website | |
| Default administrator role | |
| Security and infrastructure | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | Servers | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Security and infrastructure | Servers | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Manage licenses | |
| Manage licenses | |
| Organization website | |
| Organization website | |
| Organization website | |
| Organization website | |
| Organization website | |
| Organization website | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Servers | |
| Servers | |
| Servers | |
| Servers | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | 
Logs
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | Servers | Delete | Manage licenses | Links to organization-specific group | Publisher role | |
| Security and infrastructure | Servers | Delete | Link to organization-specific group | |
| Security and infrastructure | Servers | Delete | Manage licenses | Links to organization-specific group | Publisher role | |
| Security and infrastructure | Servers | Delete | Manage licenses | Links to organization-specific group | Publisher role | |
| Security and infrastructure | Servers | Delete | Manage licenses | Links to organization-specific group | Publisher role | |
| Security and infrastructure | Servers | Delete | Manage licenses | Links to organization-specific group | Publisher role | |
| Security and infrastructure | Servers | Delete | Links to organization-specific group | |
| Security and infrastructure | Servers | Delete | Links to organization-specific group | 
Overview
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | 
Mode
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | |
| Security and infrastructure | 
Usage statistics
| Endpoint | Privileges | 
|---|---|
| Default administrator role | |
| Default administrator role | 
Jobs
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | Update | Delete | Publisher role | |
| Security and infrastructure | Update | Delete | Publisher role | 
Health Check
| Endpoint | Privileges | 
|---|---|
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | |
| Security and infrastructure | 
Cloud
| Endpoint | Privileges | 
|---|---|
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role | |
| Default administrator role |