Per Connection you can setup SSO Groups for Read and Read / Write. Wanting the ability to have a 3rd group for Per Connection Admin. This would would give that person dbfront admin access for that particular connection. Allow them to change table views, visiblity of tables, etc but only for that one particular connection.
I thought this might be what "Admin Access" does in the connection access tab, but with SSO enabled this just returns a "none selected" and enabling graph API permissions still does not return any security groups to this option.