Skip to main content

Understand account management responsibilities

Account provisioning, authentication, two-factor authentication, sign-in methods, user and service user management, role assignment, and API credential lifecycle are provided by Account Manager.

Software Trust Manager's responsibilities are limited to:

  • Accepting and validating sessions and API credentials issued by Account Manager.

  • Enforcing Software Trust Manager product roles and permissions on every request.

  • Rejecting requests without a valid Account Manager-issued session or API credential.

  • Recording product activity in Software Trust Manager audit logs.

    When you create an automated integration with Software Trust Manager (for example, a build pipeline that requests signatures), create a dedicated service user in Account Manager for that integration. A service user has API access only and cannot sign in interactively. Do not use a person's account or credentials for a shared integration, and generate a dedicated client authentication certificate + API key per integration rather than sharing one across pipelines