> For the complete documentation index, see [llms.txt](https://docs.certinext.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.certinext.io/documentation/user-roles-and-access-control/role-based-access-control/module-by-module-permission-details.md).

# Module-by-Module Permission Details

#### Dashboard

The Dashboard module contains five permissions. Every role - Administrator, Manager, Finance Manager, Standard User, Basic User, Sub-Account User, and Discovery User - is granted access to the Dashboard landing page and the billing/low-credit alert banner. The three analytical charts (Certificates Issued, Expiring Certificates, and Discovery summary) are exclusive to the Administrator.

#### Orders

The Orders module is one of the most permission-rich in the platform, with 52 permissions. All seven roles can view their own orders and start new certificate requests. The Administrator and Manager can approve, cancel, renew, reissue, and edit orders at all three scopes. The Standard User, Basic User, and Sub-Account User can edit, renew, reissue, and recall their own orders only. The Finance Manager can view all orders, track orders, and submit CSRs but cannot approve or cancel orders.

Several capabilities are exclusive to the Administrator: approving own pending orders (self-approval), submitting and replacing CSRs for group orders, adding or removing SANs on any order, attaching documents to any order, managing and revoking public order links, recovering S/MIME private keys, approving EV validation requests, discarding draft orders, bulk-downloading certificates, and bulk-revoking certificates.

<figure><img src="/files/MHjk2cmw7vY6dGDQy5MR" alt=""><figcaption></figcaption></figure>

#### Certificates

The Certificates module holds 21 permissions. Every role except the Discovery User can view and download their own certificates and toggle auto-renewal notifications. The Administrator and Manager have complete control - revoke, suspend, and download at all three scopes. The Standard User, Finance Manager, Basic User, and Sub-Account User can revoke their own certificates only. Export capabilities for expiring certificates lists are largely restricted to the Administrator, with the Standard User and Manager able to export all expiring certificates.

<figure><img src="/files/iZPzyjWJGuhHGbroCxFi" alt=""><figcaption></figcaption></figure>

#### Certificate Authorities

The Certificate Authorities module contains 19 permissions, most of which are Administrator-only. The Administrator can create, edit, suspend, reinstate, revoke, and download private CAs and manage all CA-related products. The Manager can edit private CAs, view all products, suspend and reinstate a CA, revoke a CA certificate, download CA certificates and chains, and download CRLs. The Standard User and Discovery User can only view the Certificate Authorities list.

<figure><img src="/files/KL24xdxxlhsrpC5CQTRh" alt=""><figcaption></figcaption></figure>

#### Discovery

The Discovery module holds 32 permissions. The Administrator has access to all 32. The Discovery User holds 27 of these - the most of any non-Administrator role within this module. A Discovery User can perform the full lifecycle of certificate discovery: add, view, edit, ignore, and delete discovered certificates; manage CA certificates; create, configure, edit, run, stop, pause, and deactivate discovery bots; monitor CT logs; and manage certificates via deployment bots and key stores. The Manager can view discovered certificates at all scopes, view and edit discovered certificates, and view discovery bots.

Permissions exclusive to the Administrator within this module include deleting own and group discovered certificates, scanning for certificate vulnerabilities, downloading CSRs from discovered certificates, and accessing the full certificate detail page.

<figure><img src="/files/TkiTJypleuzVy88rIeBf" alt=""><figcaption></figcaption></figure>

#### Domains

The Domains module holds 17 permissions. The Administrator has full control across all scopes. The Manager can view, add, edit, delete, and verify domains at all scopes. The Standard User, Finance Manager, and Discovery User can only view all domains. All granular detail page access (own, group, all), all group-level editing, and all export capabilities are restricted to the Administrator.

#### Organizations

The Organizations module holds 18 permissions. The Administrator controls all 18. The Manager can view and edit any organisation, delete any organisation, add authorised representatives, and remove them. The Standard User, Finance Manager, and Discovery User can only view all organisations. All fine-grained detail page access and export functions remain with the Administrator.

#### Integration

The Integration module is the largest within CERTInext by permission count, with 50 permissions covering REST API keys, ACME EAB credentials, EST credentials, CA connectors, LDAP connectors and mappings, and DNS connectors.

The Administrator has access to all 50 permissions, including exclusive capabilities to create, edit, test, deactivate, delete, and manage LDAP Connectors, along with configuring role mappings, attribute mappings, and discovery settings.

The Manager and Discovery User share a broad set of integration permissions. They can manage CA Connectors (including emSign, emCA, Microsoft AD CS, DigiCert, Sectigo, EJBCA, and Let's Encrypt), manage DNS Connectors, view LDAP Connector configurations, access API credential history, and manage REST API and ACME EAB credentials based on their assigned permissions.

The Standard User and Basic User can no longer create REST API or ACME EAB credentials. Instead, they can view and use only the API credentials that have been assigned to them by their Account Administrator, ensuring improved administrative control and stronger security governance.

The Sub-Account User can view and manage API credentials based on the permissions assigned by the parent account administrator, in accordance with the organization's access policies.

<figure><img src="/files/BmiTzNxKoOtuO9OggyjV" alt=""><figcaption></figcaption></figure>

#### Keys

The Keys module holds 25 permissions, almost all of which are exclusive to the Administrator. Only four permissions extend to other roles: the Manager and Discovery User can view all keys, view key profiles, and view the key store. The Standard User can only view all keys. Every other capability - creating, rotating, deleting, and editing keys; managing CSR templates and provisioning templates; managing the bot installer; and managing KMIP clients and KEK configuration - is reserved for the Administrator.

#### Provisioning

The Provisioning module holds 31 permissions, with the vast majority exclusive to the Administrator. The Manager and Discovery User can view all provisioned certificates and all provisioning bots. The Standard User can view all provisioned certificates. Every other provisioning capability - managing, configuring, scanning, refreshing, rotating, rejecting, and deleting provisioned certificates; creating, configuring, and editing provisioning bots; managing S/MIME orders and profiles; and managing agentless provisioning target servers - belongs exclusively to the Administrator.

<figure><img src="/files/9K6DyHyVQOdgvvJvxkBH" alt=""><figcaption></figcaption></figure>

#### Billing

The Billing module holds 11 permissions. The Administrator and Finance Manager share complete billing access. The Manager can add credits, view and download statements, view and download all invoices, download credit notes, and submit credit withdrawal requests, but cannot redeem vouchers or manage Discovery subscriptions. The Standard User can view ledger statements and all invoices and download their own invoices. The Basic User and Sub-Account User can only view and download their own invoices.

#### Reports

The Reports module holds 16 permissions. The Administrator has access to all 16. The Finance Manager can view and export Orders Reports, Overall Statistics, Commission Reports, All Certificates Reports, Sales Summary, and Product Price List reports - covering 11 of the 16 permissions. The Manager can view (but not export) Orders Reports, Overall Statistics, Commission Reports, All Certificates Reports, Key Store Reports, Key Reports, and Sales Summary reports. The Discovery User, Standard User, Basic User, and Sub-Account User have no access to any report.

#### Settings

The Settings module is the most permission-rich in the platform with 58 permissions. It covers profile management, account configuration, user and group management, custom roles, IP restrictions, custom fields, reporting tags, audit logs, licence management, scheduling, LDAP mappings, agents, and discovery permission groups.

Every role can view their own profile, update their own profile attributes, and change their own password. The Administrator is the only role that can add new users, deactivate users, manage custom roles, create and edit custom fields and reporting tags, configure scheduled tasks, manage agents, configure LDAP role and attribute mappings, manage discovery permission groups, and export audit logs. The Manager can view and edit account configuration, edit any user, export user lists, allocate group credits, view IP restrictions, view and manage the licence, view scheduled tasks, and view audit logs. The Finance Manager can edit account information, invite users, view groups, allocate group credits, and view audit logs. The Discovery User can view all users, view the licence, manage the licence, and access the Tools page.

#### Sub-Accounts

The Sub-Accounts module holds 12 permissions. The Administrator holds all 12. The Finance Manager has the broadest sub-account access of any non-Administrator role - they can view the list, create and edit sub-accounts, allocate and withdraw funds, create and manage price lists, and deactivate price lists. The Manager can view the sub-accounts list and view price lists. The Sub-Account User can view and edit price lists. The Basic User can only edit price lists. The Standard User can also edit price lists.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.certinext.io/documentation/user-roles-and-access-control/role-based-access-control/module-by-module-permission-details.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
