Understand critical Software Trust Manager roles and permissions
Assign Software Trust Manager roles to standard users and service users in Account Manager when you add or update a user. See Software Trust Manager user roles for the complete permission list for each role.
Account roles for standard and service users
Role | Intended for | Notable permissions | Security implication |
|---|---|---|---|
Developer | Users responsible for signing, managing signing-related assets, and requesting releases. | Generate keypair, view keypair, generate certificate, view certificate, sign, request release, view threat detection. | Can generate its own keypairs and certificates and sign with them, but cannot approve releases, exports, or deletes. |
Lead | Users responsible for managing cryptographic assets, enforcing policy, and monitoring compliance for other users in the account. | Manage account settings, manage all teams, manage certificate hierarchy, manage certificate profiles, manage keypair, approve keypair export, approve keypair delete, approve release, export audit logs. | The broadest account-scope role. It can manage every keypair, certificate, team, and release in the account, and approve export/delete/release requests raised by other users. Restrict to a small number of authorized administrators and never assign it to a service user used for routine signing. |
Team lead | Users responsible for managing the developers and engineering teams who sign and release software. | Manage my teams, generate/view/import keypair, request/approve keypair export, approve keypair delete, sign, request/approve release. | Scoped to teams the user belongs to rather than the whole account, but still includes approval authority for exports, deletes, and releases within those teams. Assign only to team owners. |
Build engineer | Users or automated pipelines responsible for signing and running threat-detection scans. | View keypair, view certificate, sign, view release, run/view/manage threat detection scans. | No approval or management permissions — appropriate for a CI/CD service user that only needs to sign artifacts already assigned to it and submit them for scanning. |
Signer | Engineers or authenticated devices whose sole responsibility is signing software. | View keypair, view certificate, sign, view release. | The narrowest account-scope role — no create, approve, or manage permissions. Prefer this role for machine/service-user credentials that only need to invoke signing. |
System roles for customer-hosted environments
Role | Intended for | Notable permissions | Security implication |
|---|---|---|---|
Admin | Day-to-day account configuration and enabling Software Trust Manager features. | Manage certificate hierarchy, manage certificate profiles, manage certificate template, manage keypair, view release, export audit logs. | Broadest system-scope role — can change certificate hierarchies and profiles and manage every keypair. Assign only to platform administrators. |
Support | Support teams assisting users with account setup and signing. | View certificate profile/template/certificate, view keypair, view release, view/export audit logs. | Read-only — appropriate for support staff who need visibility without configuration rights. |
System auditor | Monitoring systems and applications for adherence to policy and compliance. | View certificate, view keypair, view release, view/export audit logs. | Read-only, audit-focused — the correct role for compliance and audit personnel; do not add configuration or management permissions to this role. |
Permissions to restrict most tightly
Use this table during access reviews. Several permissions listed here also implicitly grant account-wide (not just assigned-keypair) scope — review the linked role definition before assigning or removing a role.
Permission | Why it matters | Granted by these default roles |
|---|---|---|
Manage keypair | Grants update, suspend, and management rights over every keypair in the account (not just keypairs assigned to the user), including keypair profiles and key rotation. | Lead, Admin |
Approve keypair delete | Keypair deletion is irreversible and invalidates future signing with that key. | Lead, Team lead |
Approve keypair export | Approves export of key material out of the platform's protected storage. | Lead, Team lead |
Approve release | Approves an offline release request, authorizing signed software to ship. | Lead, Team lead |
Manage certificate Profile | Creates and activates certificate Profiles that will be used to create certificates | Lead, Team lead, Admin |
Manage account settings | Changes account-level Software Trust Manager configuration. | Lead |
View and Export audit logs and signature logs | View and Extracts audit and signature log data out of the platform for external review. | Lead, Team lead, Build engineer (requires View audit log), Admin, Support, System auditor |
Review every default role and its permissions before assigning it, and review combined permissions when a user or service user holds multiple roles. If a default role does not exactly match a business need, assign multiple roles or use a narrower role (for example, Signer or Build engineer for automated signing credentials) rather than defaulting to Lead or Admin.