
IsaacB.81593 (Customer) asked a question.
I was adjusting the privileges of an admin account that enables a connection between an Okta org and Workflows. The flow just searches for accounts in a DEPROVISIONED state and deletes them. I granted the admin standard roles:
- Read
- Group
- Workflows
I created a new connection using this admin.
The flows use two Okta cards:
- Read User
- List Users with Search
When I went to edit the flows and adjust them to use the new connection, I got errors in the Okta cards "could not retrieve fields." I added App admin to the account and the user attributes were displayed in the Okta cards.
Why would you need app admin to retrieve the fields?
Thanks.

Hi @IsaacB.81593 (Customer) , Thank you for reaching out to the Okta Community!
I've checked the permission levels and this is expected behavior due to standard admin role permissions. It says here that the Group Admin, can't "manage profile editor" / "Manage profile mapping", so this means "list user with search" can't pull the data with the Group Admin permissions level.
If you require more granularity for your admin permissions, I recommend setting up a custom admin role.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.
Just released: More Okta Community badges just added