> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/administracionconnectfirma/grupoficheros/alta/usuarios_y_grupos_firmantes.md).

# Signers and signer groups

On this screen, the users who will be able to perform actions on the files to which the *file group*, or the signing rule, being configured are associated. During the association, the specific actions each one will be able to carry out are defined. This screen varies slightly depending on the purpose of the file group.

## Signing Purpose

![Users-Groups](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-177b9fe94eda95d458b2cada531c30af94038218%2F04_usuarios_grupos.png?alt=media)

On the left, the list of all signer-role users registered in the system is shown. When a selection is made in the list, on the right the actions they will or will not be able to perform are shown depending on the configuration of the following parameters:

* **Sign files**: if this option is checked, the user can sign the documents to which the *file group* being configured applies. To do so, they must have the private key certificates properly installed or accessible on the computer from which they are going to sign. The private key certificates will correspond to the public key certificates that have been included in the user's configuration in Connect,
* **View and verify files**: if this option is checked, the user can view the contents of the documents to which the *file group* being configured applies.

  If the user can view and verify files and the file format is `Transfer`, a choice must be made between partial viewing (they cannot see the individual operations) or full viewing (they can see the entire file). The default value is partial viewing.

  When the Format allows viewing but is not `Transfer`, the viewing of the files for the person with this permission is always full.
* **Reject or move files**: if this option is checked, the user can take the files governed by the file group being configured out of the signing flow. The files can be withdrawn temporarily or permanently (deleted). The same permission allows documents to be recovered to return them to the signing flows.
* **Signers group**: this dropdown offers the signer groups registered in the previous screen. If one of them is selected, the signer participates in the *file group* as part of it. If none of them is selected, the signer participates without belonging to a signer group.
* **Electronic certificate**: this dropdown offers the certificates configured for the signer in the system.

  If one is selected, the signer will only be able to use that one to sign the files to which the file group being configured applies.

  If no selection is made, the signer will choose at the time of signing one of the ones configured on the platform.
* **Counter-sign**: this dropdown offers the users with signer role who have not yet been configured as signers of the *file group* being configured (it is not possible to act as signer and countersigner simultaneously in the same *file group*).

  📖 Countersigning is a signature applied over an existing signature, with the purpose of supporting, validating, or reinforcing the authenticity of the previous signature and the document to which it is associated.

  If a selection is made in the dropdown, the signature of the chosen user will mean the validation of the signature previously made by the user being configured.

  If no selection is made, the signature of the user being configured will not be countersigned.

  The same countersigner can countersign the signature of more than one signer. All countersignatures are made with the same certificate.

  📌 **To keep in mind**

  > * Countersigning can be an alternative to **Enable signer group order** which was seen in the section **Signer Groups**, but in this case the countersigner does not sign the entire document but exclusively the signature or signatures to which they countersign.
  > * If countersigners are configured, their countersignatures must be made for the file to be considered fully signed. However, these types of signatures are not taken into account in the total number of required signatures that has been configured in the section **Signer Groups** of the *file group*.
* **Optional for XAdES signing**: the following additional parameters only appear if the **Signing Mode** of the *file group* is *XAdES* and the user has signing permission. The parameters are **City**, **Province**, **Postal code**, **Country**, **Signer role**, **Purpose**. These are parameters that can optionally be added to the signatures made.

📌 **Remember**

> The maximum number of signers that can be associated with file groups of the same channel-local code is limited by license (feature `signers` with respect to local code).

## Verification Purpose

![Users-Groups-Verify](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-0cf458abad21e199a7fcf050b331858c16cffa54%2F05_usuarios_grupos_verificar.png?alt=media)

Depending on the selection made in the dropdown, on the left are shown the system users with signer role (local) or the remote signers of the selected contact for the file group.

Depending on the type of user chosen, the options to configure will be different.

![Users-Groups-Verify-Two](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-d68926e9012d7a1b2c9033ed7a6724836f96968c%2F06_usuarios_grupos_verificar_dos.png?alt=media)

If a remote user is selected, the configurable parameters are:

* **Signers group**: this dropdown offers the signer groups registered in the previous step.

  If one of them is selected, the signer participates in the *file group* as part of that signer group.

  If none of them is selected, the signer participates without belonging to a signer group.
* **Electronic certificate**: this dropdown offers the certificates configured for the remote signer in the system.

  If one is selected, the remote signer will only have been able to use that one to sign the files of the *file group* being configured and any other will be considered invalid.

  If no selection is made, the signature made with any of the certificates configured on the platform will be considered valid.

When a local user is selected, the following screen is shown:

![Users-Groups-Verify-Three](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-73923bf178723fe6d7ca378e0ba7a55b95c870c3%2F07_usuarios_grupos_verificar_tres.png?alt=media)

The signer-role user associated with a file group for verification can:

* **View and verify files**: if this option is checked, the user will be able to view the contents of the documents belonging to this *file group*. Within this option, when the format of the *file group* is `Transfer`, partial or full viewing can be selected.
* **Reject or move files**: if this option is checked, the user will be able to temporarily or permanently withdraw (delete) files by taking them out of the signing flow. They will also be able to recover documents belonging to this *file group* to return them to the signing flow.

The goal of associating a signer-role user with a *file group* to verify is so that this user can access the list of received files to view them, withdraw them, comment on them, know their signing status and signers, that is, perform control tasks. In general, some user with signer role will be associated with the *file groups* to verify only if no user with controller role or with signing controller and administrator role has been configured in the system.

📌 **To keep in mind**

> A *file group* to sign must have at least one user with signer role registered.\
> A *file group* to verify must have at least one remote signer from the Contact registered.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/administracionconnectfirma/grupoficheros/alta/usuarios_y_grupos_firmantes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
