> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/administracionconnectfirma/roles_y_usuarios_firma.md).

# Signature roles and users

Regarding Connect's signing functionality, a user may have one of the following four roles: **Signature administrator**, **Controller**, **Signature administrator and controller** and **Signer**.

![Signing roles and users](https://64653979-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvdpBggYaSLH9X3nOAiMG%2Fuploads%2Fgit-blob-6516f65457298cddccefaa7ff301a9b0d250039c%2F01_roles_y_usuarios_firma.png?alt=media)

The management of these roles is done from the menu **Users and Roles** of Connect.

* **Signature administrator**: role with the ability to manage signing configuration in Connect.\
  It can be created by a global administrator or another signature administrator.\
  It is defined by the parameters **First name**, **Last name**, **Position**, **Email** and **Contacts and Channels** to which they have access.

  **✅ Can**

  * Create, view, modify and delete users with signing roles.
  * Create, view, modify and delete *file groups*.
  * View the signing activity log.<br>

  **❌ Cannot**

  * Access the **Files**menu. Therefore, they cannot:
    * Control the signing flow.
    * View, sign, withdraw, retrieve or delete files.
    * Post comments about files.
    * View the files' hash.
* **Signature controller**: role with the ability to monitor the signing flow of files.\
  It can be created by a global administrator or a signature administrator.\
  It is defined by the parameters **First name**, **Last name**, **Position** and **Email**.\
  The participation of signature controllers in the *file groups* is defined during the configuration of the latter.

  **✅ Can**

  * Access the **Files** to control the signing flow and its progress (what has been signed, who has signed it, who has not signed). The **Files** menu will show only those that are related to the *file groups* in which they are involved.
  * Post comments about files.
  * View the files' hash.
  * When in the configuration of their participation in the *file groups* the corresponding permission is granted:
    * View the content of files. Visualization will generally be complete, although there are exceptions:
      * When in the *file group* the parameter **Format** is set to `Transfer`, viewing is partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** is set to `Unformatted`, viewing the content is not possible.
    * Withdraw files from the signing flow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Manage signing users and roles nor *file groups*.
  * View the signing activity log.
  * Sign files.
* **Signature administrator and controller**: role that combines the signature administrator and signature controller roles described above into a single figure.\
  It can be created by either a global administrator or a signature administrator.\
  It is defined by the parameters **First name**, **Last name**, **Position** and **Email** and **Contacts and Channels** to which they have access.

  **✅ Can**

  * Create, view, modify and delete users with signing roles.
  * Create, view, modify and delete *file groups*.
  * View the signing activity log.
  * Access the **Files** to control the signing flow and its progress (what has been signed, who has signed it, who has not signed). The **Files** menu will show only those that are related to the *file groups* in which they are involved.
  * Post comments about files.
  * View the files' hash.
  * When in the configuration of their participation in the *file groups* the corresponding permission is granted:
    * View the content of files. Visualization will generally be complete, although there are exceptions:
      * When in the *file group* the parameter **Format** is set to `Transfer`, viewing is partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** is set to `Unformatted`, viewing the content is not possible.
    * Withdraw files from the signing flow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Sign files.
* **Signer**: role suitable for users who will access the Connect installation being configured to sign files. It can be created by either a global administrator or a signature administrator.\
  It is defined by the parameters **First name**, **Last name**, **Position**, **Email** and with between one and five **public key certificates** (extension `.cer`). The public key certificates must be accessible on the machine during configuration and will be uploaded by dragging them or selecting them via the **Open** dialog that appears when clicking the arrow on the image.

  ![Add signer certificates](https://64653979-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvdpBggYaSLH9X3nOAiMG%2Fuploads%2Fgit-blob-3e95c311c39c3f3b9192dea2c0619adf5b095d9a%2F02_certificados_firmante.png?alt=media)

  The participation of signers in the **file groups** is defined during the configuration of the latter.

  **✅ Can**

  * Access the **Files** to view the list of those corresponding to the *file groups* in which they are involved. For each file you can know its overall signing status and the specific signing status with respect to each of the possible signers.
  * Post comments about files.
  * View the files' hash.
  * When in the configuration of their participation in the *file groups* the corresponding permission is granted:
    * View the content of the file. Visualization will generally be complete, although there are exceptions:
      * When in the file group the parameter **Format** is set to `Transfer`is configured, the viewing may be complete or partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** is set to `Unformatted`, viewing the content is not possible.
    * Sign files. For this, the private key certificates must be properly installed or accessible —cloud certificates— in the certificate store of the personal machines from which the signing request will be made. The private key certificates used to sign must correspond to the public key certificates that are part of their configuration.
    * Withdraw files from the signing flow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Manage signing users and roles nor *file groups*.
  * View the signing activity log.
* **Remote signer**: is the author of signatures that, having been made in another entity, are received and verified in the entity whose installation is being configured.\
  The administration of this role is carried out from the menu **Address book → Contact**, tab **Remote signers**. Alternatively, registering users of this role is resolved automatically when using the import of file groups to verify.\
  It can be created by either a global administrator or a signature administrator.\
  It is defined by the parameters **First name**, **Last name** and with between one and five **public key certificates** (extension `.cer`).\
  The participation of remote signers in the *file groups* to verify is defined during the configuration of the latter.

  <br>

  **❌ Cannot**

  * Access the Connect installation in which they are a remote signer.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/administracionconnectfirma/roles_y_usuarios_firma.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
