20% of Part II — permission scoping, not just access.
4 tasks · this deck covers task 4 of 4 — the last one in this task set
↑ Administrator Roles OverviewThis exact task already has a full course deck — built for Part I's API Functions section, where it's an exam concept. Here it shows up again as something you actually have to click through and do.
Rather than re-teach the same facts twice, this is a pointer to the deck that already covers it in full: inherited permissions, the service-account best practice, the 30-day lifecycle, and network zone/IP restrictions.
The reason this shows up under Administrator Roles specifically: creating an API token is itself an admin action tied to whichever admin's account creates it — the same "who created it" logic that governs custom admin roles and their permissions in this use case.
Sources: help.okta.com — API.htm (full deck: API Functions Module 1)
✓ Administrator Roles — 4 of 4 courses complete (labs still to come)