
2vvfu (2vvfu) asked a question.
Is it possible for an administrator to be able to administer which groups can use which apps (and which permissions a group has for each app) *without* giving that administrator permissions to "Add Apps" or edit existing app config?
Thanks!

Hi Harry,
If you are asking about creating a SWA app with an additional field, search the OIN for "Template". The SWA template you are looking for, I believe, is Template Plugin App 3 fields. There are several other Templates available, but pretty sure that will get you the extra field you need.
Here are the admin roles with their specific permission https://help.okta.com/en/prod/Content/Topics/Security/administrators-admin-comparison.htm.
For your specific request, you can assign to users specific groups and applications admin permissions. This will grant them the ability to assign specific groups to specific applications(that they administrate) and they will not be able to add any new applications. The only limitation is that when they do have admin rights over an application they will be able to modify the application configuration.
Great, thanks. So I think I cannot do my use case: allow an admin to be able to create groups, and assign applications to that group (with specific permissions), and then assign that group to users, but NOT alter how the application is configured.
OK, I believe that means more up front work to define the groups and permissions, then allow admins to just use those groups. That should work. Thanks!