# Role Groups

Roles can be organized into groups so you can more easily control access to your application. For example, you can add a role group to an organization for B2B scenarios so that their members can only be assigned roles that belong to this group. These APIs allow you to manage the role groups for your application. You can then use the [Organizations APIs](/openapi/user/organizations.openapi.json) to add the relevant role groups to each organization and the [Members API](/openapi/user/members.openapi.json) can be used to assign roles to their members.


## Servers

Sandbox environment
```
https://api.sbx.transmitsecurity.io/cis
```

US production environment
```
https://api.transmitsecurity.io/cis
```

EU production environment
```
https://api.eu.transmitsecurity.io/cis
```

CA production environment
```
https://api.ca.transmitsecurity.io/cis
```

AU production environment
```
https://api.au.transmitsecurity.io/cis
```

JP production environment
```
https://api.gasne1-ts01.transmitsecurity.io/cis
```

## Security

### bearer

Type: http
Scheme: bearer
Bearer Format: JWT

### UserAccessToken

A token returned upon end-user authentication, which provides access to resources and data for the user and app for which it was generated

Type: http
Scheme: bearer
Bearer Format: JWT

### AdminAccessToken

[object Object]

Type: oauth2
Token URL: /oidc/token
Scopes:

### ClientAccessToken

[object Object]

Type: oauth2
Token URL: /oidc/token
Scopes:

### OrgAdminAccessToken

A token returned upon B2B authentication for a user that has the organizationAdmin or organizationCreator role.

Type: oauth2
Token URL: /oidc/token
Scopes:

## Download OpenAPI description

 - [Role Groups](https://developer.transmitsecurity.com/_bundle/openapi/user/role-groups.openapi.yaml)

 - [POST /v1/applications/{app_id}/role-groups](https://developer.transmitsecurity.com/openapi/user/role-groups.openapi/other/createrolegroup.md): Create a new role group for this application. **Required permissions**: `organizations:create`, `roles:create`.
 - [GET /v1/applications/{app_id}/role-groups](https://developer.transmitsecurity.com/openapi/user/role-groups.openapi/other/getapprolegroups.md): Retrieve a list of all role groups created for this application. **Required permissions**: `organizations:read`, `roles:read`, `organizations:list`, `roles:list`, `orgs:read`.
 - [PUT /v1/applications/{app_id}/role-groups/{group_id}](https://developer.transmitsecurity.com/openapi/user/role-groups.openapi/other/updaterolegroup.md): Update an existing role group for this application. **Required permissions**: `organizations:edit`, `roles:edit`.
 - [DELETE /v1/applications/{app_id}/role-groups/{group_id}](https://developer.transmitsecurity.com/openapi/user/role-groups.openapi/other/deleterolegroup.md): Delete role group. **Required permissions**: `organizations:delete`, `roles:delete`.
 - [POST /v1/applications/{app_id}/role-groups/{group_id}/roles/set](https://developer.transmitsecurity.com/openapi/user/role-groups.openapi/other/setrolestorolegroup.md): Update the roles of an existing role group of your application. This will replace any existing set of roles of that group. **Required permissions**: `organizations:edit`, `roles:edit`.
