> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/administracionconnectfirma/roles_y_usuarios_firma.md).

# Signature roles and users

Regarding Connect's signing functionality, a user may have one of the following four roles: **Signing administrator**, **Controller**, **Signing administrator and Controller** and **Signer**.

![Signing roles and users](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-6516f65457298cddccefaa7ff301a9b0d250039c%2F01_roles_y_usuarios_firma.png?alt=media)

The administration of these roles is performed from the **Users and Roles** menu in Connect.

* 🧑‍💼 **Signing administrator**: role with the ability to administer signing configuration in Connect.\
  It can be created by a global administrator or another signing administrator.\
  It is defined by the parameters **Name**, **Last names**, **Position**, **Email** and **Contacts and Channels** that it has access to.

  **✅ Can**

  * Create, view, modify, and delete users with signing roles.
  * Create, view, modify, and delete *file groups*.
  * View the signing activity log.

    <br>

    **❌ Cannot**

    * Access the menu **Files**. Therefore, it cannot:
      * Control the signing flow.
      * View, sign, withdraw, recover, or delete files.
      * Post comments on files.
      * View the hash of the files.
* **Signing controller**: role with the ability to monitor the signing flow of files.\
  It can be created by a global administrator or a signing administrator.\
  It is defined by the parameters **Name**, **Last names**, **Position** and **Email**.\
  The participation of signing controllers in the *file groups* is defined during the configuration of the latter.

  **✅ Can**
* 🧑‍💼 **Signing controller**: role with the ability to monitor the signing flow of files.\
  It can be created by a global administrator or a signing administrator.\
  It is defined by the parameters **Name**, **Last names**, **Position** and **Email**.\
  The participation of signing controllers in the *file groups* is defined during the configuration of the latter.

  **❌ Cannot**

  * Access the menu **Files** to monitor the signing flow and its degree of progress (what has been signed, who has signed it, who has not signed it). The menu **Files** will show you only those that are related to the *file groups* in which it is involved.
  * Post comments on files.
  * View the hash of the files.
  * When in the configuration of its participation in the *file groups* the corresponding permission is granted:
    * View the content of files. Viewing will generally be complete, although there are exceptions:
      * When in the *file group* the parameter **Format** with value `Transfer`, viewing is partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** with value `Without format`, viewing the content is not possible.
    * Withdraw files from the signing flow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Manage signing users and signing roles nor *file groups*.
  * View the signing activity log.
  * Sign files.
* 🧑‍💼 **Signing administrator and controller**: role that combines in a single figure the previously described signing administrator and signing controller roles.\
  It can be created by both a global administrator and a signing administrator.\
  It is defined by the parameters **Name**, **Last names**, **Position** and **Email** and **Contacts and Channels** that it has access to.

  **✅ Can**

  * Create, view, modify, and delete users with signing roles.
  * Create, view, modify, and delete *file groups*.
  * View the signing activity log.
  * Access the menu **Files** to monitor the signing flow and its degree of progress (what has been signed, who has signed it, who has not signed it). The menu **Files** will show you only those that are related to the *file groups* in which it is involved.
  * Post comments on files.
  * View the hash of the files.
  * When in the configuration of its participation in the *file groups* the corresponding permission is granted:
    * View the content of files. Viewing will generally be complete, although there are exceptions:
      * When in the *file group* the parameter **Format** with value `Transfer`, viewing is partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** with value `Without format`, viewing the content is not possible.
    * Withdraw files from the signing flow and recover them.
    * Delete files.<br>

  **❌ Cannot**
* 🧑‍💼 **Signer**: role suitable for users who will access the Connect installation being configured to sign files. It can be created by both a global administrator and a signing administrator.\
  It is defined by the parameters:

1. **Name**, **Last names**, **ID number** (mandatory parameter if any of the signer's private key certificates will be held in custody in the SIAVAL Safecert cloud and optional in all other cases), **Position**, **Email**.
2. **Certificates**: for each certificate that the signer is going to use, the following must be specified:

   2.1 **Location of the private key certificate**: this information is necessary for signing to be carried out properly in each of the possible scenarios. All the locations that each private key certificate will have on the different devices from which the user will sign with Connect must be indicated.

   ![Configuration of a signer certificate](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-9118c2cafe8c4e0c0cea57de8737a8799a81e0df%2F05_configuracion_certificado_firmante.png?alt=media)

   That location can be:

   * Windows certificate store, whether the certificate is installed in Windows or hosted in the cloud but the corresponding provider CSP is available. This location allows the use of the certificate being configured in the Windows operating system.
   * Cloud: the certificate is held in a cloud whose service provider is integrated with Connect and the corresponding license has been purchased.

   📌 **Important**

   > Certificate configuration is done one by one because for each one it is necessary to specify the location(s) of the private key certificate.

   2.2 **Public key certificate**: once all the locations that the private key certificate will have on the different computers and devices from which the user will initiate signing requests have been indicated, it is necessary to provide the public key certificate for Connect configuration. This certificate —extension `.cer`— can be uploaded:

   * By dragging the file
   * By searching for it with the file explorer on the computer where Connect is installed
   * If one of the locations of the private key certificate is the cloud —the check *Cloud* will be marked—, by selecting the corresponding provider in the combo box and clicking the **Get .cer**.\
     In this case, a pop-up window will show the list of cloud certificates associated with the signer being configured, and the one to be associated with the signer in Connect must be selected.

   ![Signer cloud certificates](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-2c69e4e58a3a35c4ff8e54f263e2fb4b824a4f16%2F06_listado_certificados_nube.png?alt=media)

   To be able to use the **Get .cer** button, it is essential to have properly configured the provider at:\
   **Local settings** → **Electronic signature** → **Cloud signing**\
   and have the corresponding license.

   Once the public key certificate has been added to the configuration, the list below shows it together with the locations of its corresponding private key certificate.

   ![Signer's certificate registration](https://1386330368-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2jqgE5yyM3S58JKHROiz%2Fuploads%2Fgit-blob-a08cde87ca210dad19da2804f6f3b8629d576651%2F02_certificados_firmante.png?alt=media)

The participation of signers in the **file groups** is defined during the configuration of the latter.

**✅ Can**

* Access the menu **Files** to display the list of those corresponding to the *file groups* in which it is involved. For each file, you can know its overall signing status and the specific signing status for each of the possible signers.
* Post comments on files.
* View the hash of the files.
* When in the configuration of its participation in the *file groups* the corresponding permission is granted:
  * View the content of the file. Viewing will generally be complete, although there are exceptions:
    * When in the file group the parameter **Format** with value `Transfer`, viewing may be complete or partial (individual operations are omitted).
    * When in the *file group* the parameter **Format** with value `Without format`, viewing the content is not possible.
  * Sign files. To do this, the private key certificates must be properly installed or accessible --cloud certificates-- in the certificate store of the personal devices from which the signing request will be initiated. The private key certificates used to sign will be those corresponding to the public key certificates that are part of your configuration.
  * Withdraw files from the signing flow and recover them.
  * Delete files.<br>

**❌ Cannot**

* Manage signing users and signing roles nor *file groups*.
* View the signing activity log.
* 🧑‍💼 **Remote signer**: is the author of signatures that, having been made in another entity, are received and verified in the entity whose installation is being configured.\
  The administration of this role is carried out from the menu **Address Book → Contact**, tab **Remote signers**. Alternatively, creating users for this role is handled automatically when file group import is used for verification.\
  It can be created by both a global administrator and a signing administrator.\
  It is defined by the parameters **Name**, **Last names** and with the **public key certificates** (extension `.cer`) corresponding to the private key certificates used for signing.\
  The participation of remote signers *file groups* to verify is defined during the configuration of the latter.

  **❌ Cannot**

  * Access the Connect installation in which you are a remote signer.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/administracionconnectfirma/roles_y_usuarios_firma.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
