Skip to main content

Understand critical roles and permissions

Access in DigiCert​​®​​ Trust Lifecycle Manager is determined by:

  • The permissions granted by the user's role.

  • The access scope where those permissions apply.

Access scopes

Scope

Meaning

SYSTEM

Highest scope

Applies across the entire deployment. Reserved for customer-hosted system administration.

ACCOUNT

Applies to all data within a single account.

BUSINESS_UNIT

Applies only to the business units the user is assigned to.

END_USER

Lowest scope

Self-service portal users acting on their own certificates. Blocked from administrative operations.

Account roles

Assign these roles to standard and service users. Choose the most restrictive role that provides the access required for their responsibilities.

Role

Grants

Sensitivity

Manager

Set up the account and manage day-to-day operations.

  • Manage enrollments, profiles, templates, certificate issuance, import, recovery, renewal, revocation, suspension, and resumption.

  • Manage automation, business units, certificate owners, connectors, seats, scans, and reports.

Highest

Effectively full account control. Restrict tightly.

User and certificate manager

Manage seats, enrollments, certificates, and reports. Read-only on profiles, templates, business units, and connectors.

High

Can issue and revoke certificates.

Certificate profile manager

Create and manage certificate profiles and templates.

High

Controls the algorithms used for issuance and directly affects FIPS posture.

Recovery manager

Recover escrowed certificates and keys.

Highest

Grants access to private key material.

Import manager

Import certificates from external CAs.

Moderate

Can introduce externally issued trust into the inventory.

Infrastructure admin

View and manage client tools.

Moderate

Reporting admin

View and manage reports.

Moderate

Reports can contain inventory detail.

Certificate owners manager

View and manage certificate owners only.

Low

SSP manager

Configure the self-service portal only.

Moderate

Controls what end users may do.

Custom attribute manager

View and manage custom attributes only.

Low

CMDB Integration Config Manager

Add and manage ServiceNow CMDB connectors only.

Moderate

View only

Read-only access to account data.

Low

Preferred default for auditors and observers.

System roles for customer-hosted environments

Role

Grants

Sensitivity

TLM admin

Superadmin for managing Trust Lifecycle Manager users, accounts, and workflows across the deployment.

Highest

Grant to the minimum number of named individuals and review every cycle.

Technical support

Read-only access to account data for support purposes, including audit logs.

Moderate

Grant only for the duration of an active support engagement.

Read only

Read-only access to user and account setup data, including audit logs.

Low

Permissions to restrict most tightly

Regardless of which role carries them, treat the following permissions as privileged. Apply least-privilege review, separation of duties, and periodic recertification to these permissions.

Permission

Why it is sensitive

Recover

Grants recovery of escrowed private keys. This is the most sensitive permission in the product.

Profile / Template

Controls key algorithms, key sizes, and signature algorithms used for issuance. These settings directly affect your FIPS posture.

Create

Allows issuance of new certificates.

Revoke

Allows revocation, which can cause outages if misused.

Suspend / Resume

Allows suspension and reinstatement of trust.

Import

Allows external certificates to enter the managed inventory.

Connectors

Establishes trust relationships with external CAs and cloud services.

Automation

Allows automated actions against managed endpoints.

Business units

Changes tenant boundaries and can widen a user's effective data access.

SSP Portal config

Controls which operations end users may perform on their own certificates.

Logs

Audit records may contain sensitive operational detail.