Use one of the following roles based on your requirements. See the table for the list of roles and associated trade-offs:
| Role | Usage | Description |
| Read Only Admin | Allows visibility into your Okta organization and retrieves the following: Applications API tokens Organizational factors Groups and members Identity Providers System Log entries Administrative role assignments User profiles and credentials User types | This is the minimum permission required for Okta. With this you will get detection but not 3rd party app discovery. |
| Super Admin | Includes all Read Only Admin capabilities and additionally retrieves: 3rd Party App Grants | This permission enables 3rd Party Apps discovery and risk scoring. |
To view 3rd Party App risk scoring for Okta in SSPM, you must log in using a service account with the Super Admin role. For more details, refer to Okta OIDC API Scopes Available Only for Super Admins.

