> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/administracionconnectfirma/grupoficheros/alta/usuarios_y_grupos_firmantes.md).

# Users and signer groups

On this screen the users who will be able to perform actions on the files to which the *file group*, or the signing rule, that is being configured, apply are associated. During the association the specific actions that each one will be able to carry out are defined. This screen varies slightly depending on the purpose of the file group.

## Purpose Sign

![Users-Groups](https://64653979-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvdpBggYaSLH9X3nOAiMG%2Fuploads%2Fgit-blob-177b9fe94eda95d458b2cada531c30af94038218%2F04_usuarios_grupos.png?alt=media)

On the left the list shows all users with the signer role registered in the system. When a selection is made in the list, on the right the actions that they will or will not be able to perform are shown depending on the configuration made of the following parameters:

* **Sign files**: if this option is checked, the user can sign the documents to which the *file group* that is being configured applies. To do so, they must have the private key certificates properly installed or accessible on the device from which they are going to sign. The private key certificates must correspond to the public key certificates that have been included in the user's configuration in Connect,
* **View and verify files**: if this option is checked, the user can view the contents of the documents to which the *file group* that is being configured to apply.

  applies. If the user can view and verify files and the file format is `Transfer`, you must choose between partial view (cannot see individual operations) or full view (can see the entire file). The default value is partial view.

  When the Format supports viewing but is not `Transfer`, viewing of the files for someone with this permission is always complete.
* **Reject or move files**: if this option is checked, the user can remove from the signing flow the files governed by the file group that is being configured. Files can be withdrawn temporarily or permanently (delete). The same permission allows recovering documents to return them to the signing flow.
* **Signer group**: this combo offers the signer groups registered on the previous screen. If one of them is selected, the signer participates in the *file group* as part of it. If none of them is selected, the signer participates without belonging to a signer group.
* **Electronic certificate**: this combo offers the certificates configured for the signer in the system.

  If one is selected, the signer will only be able to use that one to sign the files to which the file group being configured applies.

  If no selection is made, the signer will choose one of those configured on the platform at the time of signing.
* **Counter-signature**: this combo offers the users with signer role who have not yet been configured as signers of the *file group* that is being configured (it is not possible to act as signer and counter-signer simultaneously on the same *file group*).

  📖 A counter-signature is a signature applied over an existing signature, with the purpose of endorsing, validating or reinforcing the authenticity of the prior signature and of the document to which it is associated.

  If a selection is made in the combo, the signature of the chosen user will imply validation of the signature previously made by the user being configured.

  If no selection is made, the signature of the user being configured will not be counter-signed.

  The same counter-signer can counter-sign the signature of more than one signer. All counter-signatures are made with the same certificate.

  📌 **To keep in mind**

  > * The counter-signature can be an alternative to **Activate order of signer groups** that was seen in the section **Signer groups**, but in this case the counter-signer does not sign the entire document but exclusively that signature or signatures that they counter-sign.
  > * If counter-signers are configured, their counter-signatures must be made for the file to be considered fully signed. However, this type of signatures are not taken into account in the totalizer of required signatures that has been configured in the section **Signer groups** of the *file group*.
* **Optional for XAdES signing**: the following additional parameters only appear if the **Signing Mode** of the *file group* is *XAdES* and the user has signing permission. The parameters are **City**, **Province**, **Postal code**, **Country**, **Signer's role**, **Purpose**. These are parameters that can optionally be added to the signatures made.

## Purpose verify

![Users-Groups-Verify](https://64653979-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvdpBggYaSLH9X3nOAiMG%2Fuploads%2Fgit-blob-0cf458abad21e199a7fcf050b331858c16cffa54%2F05_usuarios_grupos_verificar.png?alt=media)

Depending on the selection made in the combo, on the left the system users with signer role (local) or the remote signers of the contact selected for the file group are shown.

Depending on the type of user chosen, the options to configure will be different.

![Users-Groups-Verify-Two](https://64653979-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvdpBggYaSLH9X3nOAiMG%2Fuploads%2Fgit-blob-d68926e9012d7a1b2c9033ed7a6724836f96968c%2F06_usuarios_grupos_verificar_dos.png?alt=media)

If a remote user is selected, the configurable parameters are:

* **Signer group**: this combo offers the signer groups registered in the previous step.

  If one of them is selected, the signer participates in the *file group* forming part of that signer group.

  If none of them is selected, the signer participates without belonging to a signer group.
* **Electronic certificate**: this combo offers the certificates configured for the remote signer in the system.

  If one is selected, the remote signer will only have been able to use that one to sign the files of the *file group* that is being configured and any other will be considered invalid.

  If no selection is made, the signature made with any of the certificates that the remote signer has configured on the platform will be considered valid.

When a local user is selected, the following screen is shown:

![Users-Groups-Verify-Three](https://64653979-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvdpBggYaSLH9X3nOAiMG%2Fuploads%2Fgit-blob-73923bf178723fe6d7ca378e0ba7a55b95c870c3%2F07_usuarios_grupos_verificar_tres.png?alt=media)

The user with signer role who is associated with a file group to verify can:

* **View and verify files**: if this option is checked, the user will be able to view the content of the documents belonging to this *file group*. Within this option it will be possible to select, when the format of the *file group* is `Transfer`, partial or complete viewing.
* **Reject or move files**: if this option is checked, the user will be able to withdraw temporarily or permanently (delete) files by removing them from the signing flow. They will also be able to recover documents belonging to this *file group* to return them to the signing flow.

The purpose of associating a user with signer role to a *file group* to verify is so that they can access the list of received files to view them, remove them, comment on them, know their signing status and signers, in other words, perform control tasks. In general, some user with signer role will be associated to the *file groups* to verify only if no user with controller role or with administrator and signature controller role has been configured in the system.

📌 **To keep in mind**

> A *file group* to sign must have at least one user with signer role registered.\
> A *file group* to verify must have at least one remote signer of the Contact registered.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/administracionconnectfirma/grupoficheros/alta/usuarios_y_grupos_firmantes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
