> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/firma/administracionconnectfirma/roles_y_usuarios_firma.md).

# Signature roles and users

Regarding the Connect signing functionality, a user may have one of the following four roles: **Signing Administrator**, **Controller**, **Signing Administrator and Controller** and **Signer**.

![Signing roles and users](https://1190478111-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzO0mk2eo5LONjICfqrP8%2Fuploads%2Fgit-blob-6516f65457298cddccefaa7ff301a9b0d250039c%2F01_roles_y_usuarios_firma.png?alt=media)

The administration of these roles is done from the menu **Users and Roles** of Connect.

* **Signing Administrator**: role with the ability to manage signing configuration in Connect.\
  It can be created by a global administrator or another signing administrator.\
  It is defined by the parameters **Name**, **Surnames**, **Position**, **Email** and **Contacts and Channels** to which they have access.

  **✅ Can**

  * Create, view, modify, and delete users with signing roles.
  * Create, view, modify, and delete *file groups*.
  * View the signing activity log.<br>

  **❌ Cannot**

  * Access the menu **Files**. Therefore, they cannot:
    * Control the signing workflow.
    * View, sign, withdraw, recover, or delete files.
    * Post comments on files.
    * View the file hash.
* **Signing Controller**: role with the ability to monitor the file signing workflow.\
  It can be created by a global administrator or a signing administrator.\
  It is defined by the parameters **Name**, **Surnames**, **Position** and **Email**.\
  The participation of signing controllers in the *file groups* is defined during the configuration of the latter.

  **✅ Can**

  * Access the menu **Files** to control the signing workflow and its progress (what has been signed, who has signed it, who has not signed it). The menu **Files** will show you only those that are related to the *file groups* in which they are involved.
  * Post comments on files.
  * View the file hash.
  * When, in the configuration of your participation in the *file groups* the corresponding permission is granted:
    * View file content. Viewing will generally be complete, although there are exceptions:
      * When in the *file group* the parameter **Format** with value `Transfer`, viewing is partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** with value `No format`, content viewing is not possible.
    * Remove files from the signing workflow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Manage users and signing roles nor *file groups*.
  * View the signing activity log.
  * Sign files.
* **Signing Administrator and Controller**: role that combines, in a single figure, the signing administrator and signing controller roles described above.\
  It can be created by either a global administrator or a signing administrator.\
  It is defined by the parameters **Name**, **Surnames**, **Position** and **Email** and **Contacts and Channels** to which they have access.

  **✅ Can**

  * Create, view, modify, and delete users with signing roles.
  * Create, view, modify, and delete *file groups*.
  * View the signing activity log.
  * Access the menu **Files** to control the signing workflow and its progress (what has been signed, who has signed it, who has not signed it). The menu **Files** will show you only those that are related to the *file groups* in which they are involved.
  * Post comments on files.
  * View the file hash.
  * When, in the configuration of your participation in the *file groups* the corresponding permission is granted:
    * View file content. Viewing will generally be complete, although there are exceptions:
      * When in the *file group* the parameter **Format** with value `Transfer`, viewing is partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** with value `No format`, content viewing is not possible.
    * Remove files from the signing workflow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Sign files.
* **Signer**: role suitable for users who will access the Connect installation being configured to sign files. It can be created by either a global administrator or a signing administrator.\
  It is defined by the parameters **Name**, **Surnames**, **Position**, **Email** and with between one and five **public key certificates** (extension `.cer`). The public key certificates will be accessible on the machine during configuration and will be uploaded by dragging them or selecting them through the dialog **Open** displayed by clicking the arrow in the image.

  ![Signer certificate registration](https://1190478111-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzO0mk2eo5LONjICfqrP8%2Fuploads%2Fgit-blob-3e95c311c39c3f3b9192dea2c0619adf5b095d9a%2F02_certificados_firmante.png?alt=media)

  The participation of signers in the **file groups** is defined during the configuration of the latter.

  **✅ Can**

  * Access the menu **Files** to display the list of those corresponding to the *file groups* in which they are involved. For each file, you can know its overall signing status and the specific signing status with respect to each of the possible signers.
  * Post comments on files.
  * View the file hash.
  * When, in the configuration of your participation in the *file groups* the corresponding permission is granted:
    * View the file content. Viewing will generally be complete, although there are exceptions:
      * When in the file group, the parameter **Format** with value `Transfer`, viewing may be complete or partial (individual operations are omitted).
      * When in the *file group* the parameter **Format** with value `No format`, content viewing is not possible.
    * Sign files. To do this, the private key certificates must be properly installed or accessible --cloud certificates-- in the certificate store of the personal devices from which the signing request will be initiated. The private key certificates used to sign will be the ones corresponding to the public key certificates that are part of your configuration.
    * Remove files from the signing workflow and recover them.
    * Delete files.<br>

  **❌ Cannot**

  * Manage users and signing roles nor *file groups*.
  * View the signing activity log.
* **Remote signer**: is the author of signatures that, having been made in another entity, are received and verified in the entity whose installation is being configured.\
  The administration of this role is carried out from the menu **Address Book → Contact**, tab **Remote signers**. Alternatively, the registration of users for this role is resolved automatically when the file group import for verification is used.\
  It can be created by either a global administrator or a signing administrator.\
  It is defined by the parameters **Name**, **Surnames** and with between one and five **public key certificates** (extension `.cer`).\
  The participation of remote signers in the *file groups* to verify is defined during the configuration of the latter.

  <br>

  **❌ Cannot**

  * Access the Connect installation in which they are a remote signer.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/firma/administracionconnectfirma/roles_y_usuarios_firma.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
