Roles and permissions

Four roles, one per account. The tables below are generated from the same seed file the installer applies, so they are what your installation actually enforces.

The four roles

Role in the interfaceRole identifierHolds
Adminsystem_adminEvery permission below
Manageroperator12 of 38 permissions
Verifierverifier4 of 38 permissions
Viewerviewer3 of 38 permissions

Permission by role

PermissionIdentifierAdminManagerVerifierViewer
View usersusers.viewYes
Create usersusers.createYes
Update usersusers.updateYes
Disable usersusers.disableYes
Reset 2FAusers.reset_2faYes
Create verifiersverifiers.createYes
Update verifiersverifiers.updateYes
Disable verifiersverifiers.disableYes
Manage rolesroles.manageYes
Manage permissionspermissions.manageYes
View coursescourses.viewYesYesYes
Create coursescourses.createYes
Update coursescourses.updateYes
Archive coursescourses.archiveYes
View participantsparticipants.viewYesYes
Create participantsparticipants.createYesYes
Update participantsparticipants.updateYesYes
View certificatescertificates.viewYesYesYesYes
Create certificatescertificates.createYesYes
Update certificatescertificates.updateYesYes
Submit certificatescertificates.submitYes
Assign certificatescertificates.assignYesYes
Verify certificatescertificates.verifyYesYes
Return certificatescertificates.returnYesYes
Reject certificatescertificates.rejectYesYes
Revoke certificatescertificates.revokeYes
Export certificatescertificates.exportYesYes
Download certificate PDFscertificates.download_pdfYes
Generate certificate documentscertificates.issueYesYes
Archive certificatescertificates.archiveYes
Restore archived certificatescertificates.restoreYes
Soft-delete eligible certificatescertificates.deleteYes
Create importsimports.createYesYes
View importsimports.viewYesYes
View reportsreports.viewYes
View audit logsaudit.viewYesYes
View email queueemail_queue.viewYes
Manage settingssettings.manageYes

Rules that are not in the table

Permissions decide what an account may do. Four rules decide who may hold them, and they are enforced on the server, not by hiding buttons.

Read-only review

A Viewer can inspect active certificate records, course and occurrence lists, template metadata and the append-only system log. It cannot create, edit, delete, assign or verify business records, import/export certificates, generate PDFs or open configuration screens. Its own account profile and sign-in security remain available. Record access is separate from the protected edit screen; changing the address to an edit or write route is denied.

Creating accounts

  1. Sign in as an Admin and open Users.
  2. Choose Create user, enter the name, email address and role.
  3. The account receives an activation link valid for 24 hours. Nothing is usable until the person follows it, sets a password and pairs an authenticator.
  4. If the link expires, use Resend activation on the same screen.

Verifier accounts belong to an organisation, and that organisation name is what the public certificate page shows as the approving body. Set it when you create the account.

Two-factor authentication is not optional for internal accounts. An account that requires it and has not paired an authenticator yet is offered the QR code at its first sign-in, and cannot get past that screen without a working code. Recovery codes are shown once, at pairing.

Disabling an account

Use Disable rather than deleting. Disabling revokes every active session at once, keeps the audit trail intact, and leaves the certificates that account issued untouched. A disabled verifier cannot be assigned new certificates, and any certificate already assigned to it has to be reassigned by a Manager.