Skip to main content

Order approval delegation

DigiCert provides an automated delegation process in CertCentral that streamlines certificate issuance for certificate products that require approval from a verified contact or authorized representative.

This process eliminates the need for repeated manual approvals for each certificate order while maintaining compliance with authorization requirements for certificate approvals. Delegated approvals allow qualifying certificate orders to be issued immediately after the required validations, such as domain and organization validation, are complete.

A single delegation request automatically applies to every organization the verified contact or authorized representative represents and every certificate product they’re authorized to approve.

How does the delegation process work?

  1. DigiCert validates a verified contact or authorized representative to approve specific certificate products for one or more organizations.

  2. The verified contact or authorized representative delegates their approval authority for:

    • All organizations they currently represent and any they represent in the future.

    • All certificate products they’re currently authorized to approve and any they’re authorized to approve in the future.

  3. An Aministrator submits a delegation request for a CertCentral user or Service User.

  4. CertCentral sends the verified contact or authorized representative an email with the subject: Request to delegate authority for approving certificate orders for CertCentral.

  5. The verified contact or authorized representative completes the one-time delegation approval.

  6. Administrators can track the request status (pending, approved, or rejected) from the user or Service User details page.

  7. After the delegation is approved, qualifying certificate orders submitted by the delegated user or Service User are automatically approved when the order includes the same verified contact or authorized representative.

Supported products for verified contact delegation

Verified contacts can approve these certificate products available in CertCentral and CertCentral Europe:

  • EV TLS

  • EV Code Signing

  • Code Signing

  • Verified Mark

  • Common Mark

Supported products for authorized representative delegation

Authorized representatives can approve these certificate products available in CertCentral Europe:

  • EU Qualified eSeal

  • EU Qualified eSeal PSD2

  • EU Qualified Personal Organisation

  • EU Qualified Website Authentication Certificate

  • EU Qualified Website Authentication Certificate PSD2

  • PKIo Personal Organisation

  • PKIo Qualified eSeal

  • PKIo Private Person

  • PKIo Personal Organisation - Authentication/Encryption

  • PKIo Organisation - Authentication/Encryption

  • PKIo Private Person - Authentication/Encryption

  • PKIo Private Services Server

Delegation details

Scope of approval

A delegation automatically applies to every organization the verified contact or authorized representative represents and every certificate product they’re authorized to approve. This includes organizations and certificate products they may be authorized to approve in the future.

Example

A verified contact can approve EV TLS and Verified Mark certificate orders for Organization 1 and Organization 2. After delegation, the delegated approver can also approve those orders. Later, the verified contact is authorized to approve Code Signing certificate orders for Organization 3. The delegated approver automatically gains approval authority for those certificate orders as well.

Eligible CertCentral roles for delegation

Verified contacts and authorized representatives can delegate their authority to:

  • Administrators

  • Managers

  • Service users

They can’t delegate authority to:

  • Finance Managers

  • Standard Users

  • Limited Users

Service users

Service Users have API-only access to your CertCentral account. You must be an Administrator to create Service Users. Service Users inherit the permissions of the administrator. Learn more about adding a service user.

Order requirement

The delegated approver must include the same verified contact or authorized representative who delegated their approval authority when submitting the certificate order. Otherwise, the order follows the standard approval process and isn’t automatically approved.