> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/firma/administracionconnectfirma/grupoficheros/alta/usuarios_y_grupos_firmantes.md).

# Users and signer groups

On this screen, the users who will be able to perform actions on the files to which the *file group*, or the signing rule, that is being configured. During the association, the specific actions that each one will be able to carry out are defined. This screen varies slightly depending on the purpose of the file group.

## Signing Purpose

![Users-Groups](https://1190478111-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzO0mk2eo5LONjICfqrP8%2Fuploads%2Fgit-blob-177b9fe94eda95d458b2cada531c30af94038218%2F04_usuarios_grupos.png?alt=media)

On the left, the list of all users with the signer role registered in the system is shown. When a selection is made in the list, the actions they may or may not perform are shown on the right, depending on the configuration made for the following parameters:

* **Sign files**: if this option is checked, the user can sign the documents to which the *file group* being configured applies. To do this, they must have private key certificates properly installed or accessible on the computer from which they are going to sign. The private key certificates will be those corresponding to the public key certificates that have been included in the user's configuration in Connect,
* **View and verify files**: if this option is checked, the user can view the content of the documents to which the *file group* being configured applies.

  If the user can view and verify files and the file format is `Transfer`, a choice must be made between partial viewing (cannot see individual operations) or full viewing (can see the entire file). The default value is partial viewing.

  When the Format allows viewing but is not `Transfer`, file viewing for whoever has this permission is always full.
* **Reject or move files**: if this option is checked, the user can remove from the signing flow the files governed by the file group being configured. The files can be withdrawn temporarily or permanently (deleted). The same permission allows documents to be recovered and returned to the signing flow.
* **Signer group**: this combo offers the signer groups registered in the previous screen. If one of them is selected, the signer participates in the *file group* as part of it. If none of them is selected, the signer participates without belonging to a signer group.
* **Electronic certificate**: this combo offers the certificates configured for the signer in the system.

  If one is selected, the signer will only be able to use that one to sign the files to which the file group being configured applies.

  If no selection is made, the signer will choose at the time of signing one of those configured in the platform.
* **Countersignature**: this combo offers the users with signer role who have not yet been configured as signers of the *file group* being configured (it is not possible to act as signer and countersigner simultaneously in the same *file group*).

  📖 A countersignature is a signature applied to another existing signature, with the purpose of supporting, validating, or reinforcing the authenticity of the previous signature and of the document to which it is associated.

  If a selection is made in the combo, the signature of the chosen user will mean validation of the signature previously made by the user being configured.

  If no selection is made, the signature of the user being configured will not be countersigned.

  The same countersigner can countersign the signature of more than one signer. All countersignatures are made with the same certificate.

  📌 **Things to keep in mind**

  > * Countersignature can be an alternative to **Activate signing group order** that was seen in the section **Signer groups**, but in this case the countersigner does not sign the entire document, but exclusively the signature or signatures they countersign.
  > * If countersigners are configured, their countersignatures must be performed for the file to be considered fully signed. However, this type of signature is not taken into account in the total number of required signatures configured in the section **Signer groups** of the *file group*.
* **Optional for XAdES signature**: the following additional parameters only appear if the **Signing Mode** of the *file group* is *XAdES* and the user has signing permission. The parameters are **City**, **Province**, **Postal code**, **Country**, **Signer role**, **Purpose**. These are parameters that can optionally be added to the signatures performed.

## Verification Purpose

![Users-Groups-Verify](https://1190478111-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzO0mk2eo5LONjICfqrP8%2Fuploads%2Fgit-blob-0cf458abad21e199a7fcf050b331858c16cffa54%2F05_usuarios_grupos_verificar.png?alt=media)

Depending on the selection made in the combo, the system users with signer role (local) or the remote signers of the selected contact for the file group are shown on the left.

Depending on the type of user chosen, the options to configure will be different.

![Users-Groups-Verify-Two](https://1190478111-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzO0mk2eo5LONjICfqrP8%2Fuploads%2Fgit-blob-d68926e9012d7a1b2c9033ed7a6724836f96968c%2F06_usuarios_grupos_verificar_dos.png?alt=media)

If a remote user is selected, the configurable parameters are:

* **Signer group**: this combo offers the signer groups registered in the previous step.

  If one of them is selected, the signer participates in the *file group* as part of that signer group.

  If none of them is selected, the signer participates without belonging to a signer group.
* **Electronic certificate**: this combo offers the certificates configured for the remote signer in the system.

  If one is selected, the remote signer will only have been able to use that one to sign the files of the *file group* being configured and any other will be considered invalid.

  If no selection is made, the signature made with any of the certificates configured on the platform will be considered valid.

When a local user is selected, the following screen is displayed:

![Users-Groups-Verify-Three](https://1190478111-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzO0mk2eo5LONjICfqrP8%2Fuploads%2Fgit-blob-73923bf178723fe6d7ca378e0ba7a55b95c870c3%2F07_usuarios_grupos_verificar_tres.png?alt=media)

The user with signer role that is associated with a file group for verification can:

* **View and verify files**: if this option is checked, the user will be able to view the content of the documents belonging to this *file group*. Within this option, it will be possible to select, when the format of the *file group* is `Transfer`, partial or full viewing.
* **Reject or move files**: if this option is checked, the user will be able to temporarily or permanently withdraw (delete) files by taking them out of the signature flow. They will also be able to recover documents belonging to this *file group* to return them to the signature flow.

The purpose of associating a user with signer role to a *file group* for verification is so that they can access the list of received files to view them, withdraw them, comment on them, know their signing status and signers, that is, perform control tasks. In general, a user with signer role will be associated with the *file groups* for verification only if no user with controller role or with administrator and signature controller role has been configured in the system.

📌 **Things to keep in mind**

> A *file group* for signing must have at least one user with signer role registered.\
> A *file group* for verification must have at least one remote signer from the Contact registered.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/firma/administracionconnectfirma/grupoficheros/alta/usuarios_y_grupos_firmantes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
