Skip to content

ProductNot yet confirmed elsewhere1 publisher3 min readPublished

Apple's Business Manager API does the work; its roles model is what breaks deployments

The expanded API can pull inventory and audit events and assign devices. The 403 error most admins hit first is a permissions problem, and Apple's own docs do not close the gap.

The Product Desk

How we use AISend a correction

Illustration accompanying Apple's Business Manager API does the work; its roles model is what breaks deployments
Generated illustration

What happened

  • At this year's WWDC, Apple announced an expanded Apple Business API that allows IT admins to retrieve device information, review audit events, and assign or unassign devices directly via the API.
  • Properly configuring the API can be frustrating, according to reports from developers cited by 9to5Mac.
  • When testing the new APIs, it has been reported that you are likely to encounter a 403 Forbidden error when using the Audit Events API, with the API returning a message stating that the currently used API key does not allow the request.
  • Apple's documentation for creating an API account in Apple Business says in its data access section that you need permission to access audit events via the Admin API, but it is not clear how to apply that same permission to your account.
  • To fix the 403 error you adjust the permissions on the API account; custom roles are created or edited under Settings > Roles and Permissions, and a custom role can be based on an existing role with permissions added.

Why it matters

Apple used this year's WWDC to announce an expanded Apple Business API that lets IT admins retrieve device information, review audit events, and assign or unassign devices directly through the API [3]. The endpoints are what large fleets have asked for; the part generating friction is the permission model behind them, which developers have reported is frustrating to configure properly [1].

The failure mode is specific and repeatable. According to 9to5Mac's Apple @ Work column, written by Bradley Chambers, an Apple IT admin since 2009 [12], testers calling the Audit Events API are likely to get a 403 Forbidden, with a message stating that the API key in use does not allow the request [2]. The call is not malformed. The API account simply lacks the permission. Apple's documentation does say, in its data access section, that you need permission to access audit events via the Admin API, but per the same report it is not clear how to apply that permission to your account [4]. That is the whole gap: a documented requirement with an undocumented path.

The fix lives in Settings > Roles and Permissions, where you adjust the permissions on the API account, and where a custom role can be based on an existing role with permissions added rather than built from nothing [5]. The default roles are IT Administrator, Marketing Administrator, People Manager, Device Enrollment Manager, and Content Manager [6], five in total [13], and checking every individual organization permission attached to each one is tedious [7].

Two ceilings deserve attention before anyone writes automation against this. An organization can have up to 50 API accounts and create up to 15 custom roles [8]. That works out to roughly 3.3 API accounts per custom role if all fifteen are used [14], so one bespoke least-privilege role per integration is not on the table; roles will be shared across accounts, and that mapping is a design decision rather than something to discover later. The second is a governance detail with wider blast radius: any user who can view, edit, and delete roles can change specific permissions for all default roles [9]. The meaning of IT Administrator in a given tenant is therefore mutable, and one edit reaches everyone holding it.

The documentation gap is currently being filled from outside Apple. AppleShare IT built a web tool, the Apple Business Roles Checker, using Claude to turn Apple's large default roles and permissions document into a wizard-style checklist [10]. An admin selects the organization permissions the API account needs, and the tool identifies which default role already covers them, or shows how to customize an existing role if none does [11].

Worth watching: whether Apple documents the path from the stated audit-events requirement to an actual API account configuration [4], since every day it does not is a day the community tool is load-bearing infrastructure for other people's deployments [10]. Also worth watching is whether the 50-account and 15-custom-role limits hold as more automation moves onto this API [8], and whether editing default roles globally [9] starts showing up in audit findings rather than support threads.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption25
Hype gap+12
Incentives60
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Properly configuring the API can be frustrating, according to reports from developers cited by 9to5Mac.

    ReportedSupportedSource: 9to5Mac, Apple @ Work2 sources— create a free account to open themView cited source
  2. [2]

    When testing the new APIs, it has been reported that you are likely to encounter a 403 Forbidden error when using the Audit Events API, with the API returning a message stating that the currently used API key does not allow the request.

    ReportedSupportedSource: 9to5Mac, Apple @ Work2 sources— create a free account to open themView cited source
  3. [3]

    At this year's WWDC, Apple announced an expanded Apple Business API that allows IT admins to retrieve device information, review audit events, and assign or unassign devices directly via the API.

    ReportedSupportedSource: 9to5Mac, Apple @ WorkView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. 9to5mac.com

    1 article · August 15, 2026

    Apple @ Work: Understanding Apple Business Manager roles and permissions

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Developer Documentation GapsFollow
  • Community-Built IT ToolsFollow
  • Apple Device ManagementFollow
  • AI-Assisted Admin ToolingFollow
  • API Permissions and Role-Based Access ControlFollow

Entities

Loading related stories