Skip to main content

Understand critical Software Trust Manager roles and permissions

Assign Software Trust Manager roles to standard users and service users in Account Manager when you add or update a user. See Software Trust Manager user roles for the complete permission list for each role.

Account roles for standard and service users

Role

Intended for

Notable permissions

Security implication

Developer

Users responsible for signing, managing signing-related assets, and requesting releases.

Generate keypair, view keypair, generate certificate, view certificate, sign, request release, view threat detection.

Can generate its own keypairs and certificates and sign with them, but cannot approve releases, exports, or deletes.

Lead

Users responsible for managing cryptographic assets, enforcing policy, and monitoring compliance for other users in the account.

Manage account settings, manage all teams, manage certificate hierarchy, manage certificate profiles, manage keypair, approve keypair export, approve keypair delete, approve release, export audit logs.

The broadest account-scope role. It can manage every keypair, certificate, team, and release in the account, and approve export/delete/release requests raised by other users. Restrict to a small number of authorized administrators and never assign it to a service user used for routine signing.

Team lead

Users responsible for managing the developers and engineering teams who sign and release software.

Manage my teams, generate/view/import keypair, request/approve keypair export, approve keypair delete, sign, request/approve release.

Scoped to teams the user belongs to rather than the whole account, but still includes approval authority for exports, deletes, and releases within those teams. Assign only to team owners.

Build engineer

Users or automated pipelines responsible for signing and running threat-detection scans.

View keypair, view certificate, sign, view release, run/view/manage threat detection scans.

No approval or management permissions — appropriate for a CI/CD service user that only needs to sign artifacts already assigned to it and submit them for scanning.

Signer

Engineers or authenticated devices whose sole responsibility is signing software.

View keypair, view certificate, sign, view release.

The narrowest account-scope role — no create, approve, or manage permissions. Prefer this role for machine/service-user credentials that only need to invoke signing.

System roles for customer-hosted environments

Role

Intended for

Notable permissions

Security implication

Admin

Day-to-day account configuration and enabling Software Trust Manager features.

Manage certificate hierarchy, manage certificate profiles, manage certificate template, manage keypair, view release, export audit logs.

Broadest system-scope role — can change certificate hierarchies and profiles and manage every keypair. Assign only to platform administrators.

Support

Support teams assisting users with account setup and signing.

View certificate profile/template/certificate, view keypair, view release, view/export audit logs.

Read-only — appropriate for support staff who need visibility without configuration rights.

System auditor

Monitoring systems and applications for adherence to policy and compliance.

View certificate, view keypair, view release, view/export audit logs.

Read-only, audit-focused — the correct role for compliance and audit personnel; do not add configuration or management permissions to this role.

Permissions to restrict most tightly

Use this table during access reviews. Several permissions listed here also implicitly grant account-wide (not just assigned-keypair) scope — review the linked role definition before assigning or removing a role.

Permission

Why it matters

Granted by these default roles

Manage keypair

Grants update, suspend, and management rights over every keypair in the account (not just keypairs assigned to the user), including keypair profiles and key rotation.

Lead, Admin

Approve keypair delete

Keypair deletion is irreversible and invalidates future signing with that key.

Lead, Team lead

Approve keypair export

Approves export of key material out of the platform's protected storage.

Lead, Team lead

Approve release

Approves an offline release request, authorizing signed software to ship.

Lead, Team lead

Manage certificate Profile

Creates and activates certificate Profiles that will be used to create certificates

Lead, Team lead, Admin

Manage account settings

Changes account-level Software Trust Manager configuration.

Lead

View and Export audit logs and signature logs

View and Extracts audit and signature log data out of the platform for external review.

Lead, Team lead, Build engineer (requires View audit log), Admin, Support, System auditor

Review every default role and its permissions before assigning it, and review combined permissions when a user or service user holds multiple roles. If a default role does not exactly match a business need, assign multiple roles or use a narrower role (for example, Signer or Build engineer for automated signing credentials) rather than defaulting to Lead or Admin.