For the complete documentation index, see llms.txt. This page is also available as Markdown.

Module-by-Module Permission Details

Dashboard

The Dashboard module contains five permissions. Every role - Administrator, Manager, Finance Manager, Standard User, Basic User, Sub-Account User, and Discovery User - is granted access to the Dashboard landing page and the billing/low-credit alert banner. The three analytical charts (Certificates Issued, Expiring Certificates, and Discovery summary) are exclusive to the Administrator.

Orders

The Orders module is one of the most permission-rich in the platform, with 52 permissions. All seven roles can view their own orders and start new certificate requests. The Administrator and Manager can approve, cancel, renew, reissue, and edit orders at all three scopes. The Standard User, Basic User, and Sub-Account User can edit, renew, reissue, and recall their own orders only. The Finance Manager can view all orders, track orders, and submit CSRs but cannot approve or cancel orders.

Several capabilities are exclusive to the Administrator: approving own pending orders (self-approval), submitting and replacing CSRs for group orders, adding or removing SANs on any order, attaching documents to any order, managing and revoking public order links, recovering S/MIME private keys, approving EV validation requests, discarding draft orders, bulk-downloading certificates, and bulk-revoking certificates.

Certificates

The Certificates module holds 21 permissions. Every role except the Discovery User can view and download their own certificates and toggle auto-renewal notifications. The Administrator and Manager have complete control - revoke, suspend, and download at all three scopes. The Standard User, Finance Manager, Basic User, and Sub-Account User can revoke their own certificates only. Export capabilities for expiring certificates lists are largely restricted to the Administrator, with the Standard User and Manager able to export all expiring certificates.

Certificate Authorities

The Certificate Authorities module contains 19 permissions, most of which are Administrator-only. The Administrator can create, edit, suspend, reinstate, revoke, and download private CAs and manage all CA-related products. The Manager can edit private CAs, view all products, suspend and reinstate a CA, revoke a CA certificate, download CA certificates and chains, and download CRLs. The Standard User and Discovery User can only view the Certificate Authorities list.

Discovery

The Discovery module holds 32 permissions. The Administrator has access to all 32. The Discovery User holds 27 of these - the most of any non-Administrator role within this module. A Discovery User can perform the full lifecycle of certificate discovery: add, view, edit, ignore, and delete discovered certificates; manage CA certificates; create, configure, edit, run, stop, pause, and deactivate discovery bots; monitor CT logs; and manage certificates via deployment bots and key stores. The Manager can view discovered certificates at all scopes, view and edit discovered certificates, and view discovery bots.

Permissions exclusive to the Administrator within this module include deleting own and group discovered certificates, scanning for certificate vulnerabilities, downloading CSRs from discovered certificates, and accessing the full certificate detail page.

Domains

The Domains module holds 17 permissions. The Administrator has full control across all scopes. The Manager can view, add, edit, delete, and verify domains at all scopes. The Standard User, Finance Manager, and Discovery User can only view all domains. All granular detail page access (own, group, all), all group-level editing, and all export capabilities are restricted to the Administrator.

Organizations

The Organizations module holds 18 permissions. The Administrator controls all 18. The Manager can view and edit any organisation, delete any organisation, add authorised representatives, and remove them. The Standard User, Finance Manager, and Discovery User can only view all organisations. All fine-grained detail page access and export functions remain with the Administrator.

Integration

The Integration module is the largest within CERTInext by permission count, with 50 permissions covering REST API keys, ACME EAB credentials, EST credentials, CA connectors, LDAP connectors and mappings, and DNS connectors.

The Administrator holds all 50 permissions, including exclusive control over LDAP connector creation, editing, deactivation, deletion, connection testing, role mapping, attribute mapping, and discovery. The Manager and Discovery User share a significant subset: they can view all API keys and credentials, manage all CA connectors (emSign, emCA, Microsoft AD CS, DigiCert, Sectigo, EJBCA, Let's Encrypt), manage DNS connectors, view LDAP connector lists, and view API credential history. The Standard User, Basic User, and Sub-Account User can only view and generate their own REST API keys and ACME EAB credentials.

Keys

The Keys module holds 25 permissions, almost all of which are exclusive to the Administrator. Only four permissions extend to other roles: the Manager and Discovery User can view all keys, view key profiles, and view the key store. The Standard User can only view all keys. Every other capability - creating, rotating, deleting, and editing keys; managing CSR templates and provisioning templates; managing the bot installer; and managing KMIP clients and KEK configuration - is reserved for the Administrator.

Provisioning

The Provisioning module holds 31 permissions, with the vast majority exclusive to the Administrator. The Manager and Discovery User can view all provisioned certificates and all provisioning bots. The Standard User can view all provisioned certificates. Every other provisioning capability - managing, configuring, scanning, refreshing, rotating, rejecting, and deleting provisioned certificates; creating, configuring, and editing provisioning bots; managing S/MIME orders and profiles; and managing agentless provisioning target servers - belongs exclusively to the Administrator.

Billing

The Billing module holds 11 permissions. The Administrator and Finance Manager share complete billing access. The Manager can add credits, view and download statements, view and download all invoices, download credit notes, and submit credit withdrawal requests, but cannot redeem vouchers or manage Discovery subscriptions. The Standard User can view ledger statements and all invoices and download their own invoices. The Basic User and Sub-Account User can only view and download their own invoices.

Reports

The Reports module holds 16 permissions. The Administrator has access to all 16. The Finance Manager can view and export Orders Reports, Overall Statistics, Commission Reports, All Certificates Reports, Sales Summary, and Product Price List reports - covering 11 of the 16 permissions. The Manager can view (but not export) Orders Reports, Overall Statistics, Commission Reports, All Certificates Reports, Key Store Reports, Key Reports, and Sales Summary reports. The Discovery User, Standard User, Basic User, and Sub-Account User have no access to any report.

Settings

The Settings module is the most permission-rich in the platform with 58 permissions. It covers profile management, account configuration, user and group management, custom roles, IP restrictions, custom fields, reporting tags, audit logs, licence management, scheduling, LDAP mappings, agents, and discovery permission groups.

Every role can view their own profile, update their own profile attributes, and change their own password. The Administrator is the only role that can add new users, deactivate users, manage custom roles, create and edit custom fields and reporting tags, configure scheduled tasks, manage agents, configure LDAP role and attribute mappings, manage discovery permission groups, and export audit logs. The Manager can view and edit account configuration, edit any user, export user lists, allocate group credits, view IP restrictions, view and manage the licence, view scheduled tasks, and view audit logs. The Finance Manager can edit account information, invite users, view groups, allocate group credits, and view audit logs. The Discovery User can view all users, view the licence, manage the licence, and access the Tools page.

Sub-Accounts

The Sub-Accounts module holds 12 permissions. The Administrator holds all 12. The Finance Manager has the broadest sub-account access of any non-Administrator role - they can view the list, create and edit sub-accounts, allocate and withdraw funds, create and manage price lists, and deactivate price lists. The Manager can view the sub-accounts list and view price lists. The Sub-Account User can view and edit price lists. The Basic User can only edit price lists. The Standard User can also edit price lists.

Last updated