[Platform] Limit normal user's right with creating new apps or deleting existing apps

Issue

A normal user on the platform has powerful management right to create new apps or delete existing apps assigned to them.

Sometimes, you may not want normal users to be able to create new apps but only manage the credentials of apps assigned to them.

Solution

Since 2025, HERE platform added the "Restricted App Access" role that can limit user's right to create new apps or delete their assigned apps.

The user with the Restricted App Access role can only manage the credentials of the app but has no other management right.

Result

The users with Restricted App Access role can manage the credentials like API keys of their assigned app:

> But they cannot manage the app, note the missing app configuration options it the highlighted area.



If not assigned, the users with Restricted App Access role cannot see the credentials of other's apps or manage them:



They also cannot create new apps, because the new app creation button is missing on their app list page:



Note

The users with the Restricted App Access role can still access the Project Manager with full access and management rights.

Reference

https://www.here.com/docs/bundle/identity-and-access-management-developer-guide/page/topics/concepts.html#roles