Skip to content

Organizations, users & roles

Tenant and child organizations

Your tenant is your whole CertIntel account. Inside it, child organizations are the unit almost everything else is scoped to: monitored targets, certificates, API keys, install tokens, and DNS delegations each belong to one child organization, or - for select resources, at a tenant administrator's discretion - are left tenant-wide (visible/usable across every organization in the tenant).

A small account might run everything in a single default organization. A larger one splits by team, business unit, region, or customer, so that e.g. an organization administrator in one team can't see or touch another team's certificates and keys.

Built-in roles

Roles are assigned per-user, either within one organization or, for a tenant administrator, across the whole tenant. Every built-in role below is organization-scoped except the Platform roles, which only ever apply to the reserved platform tenant on a platform-mode deployment.

Role What it grants
Viewer Read-only monitoring plus organization/key metadata.
Observer Viewer access plus observability endpoints; changes nothing.
Operator Day-to-day monitoring: edit targets, create/revoke write-scoped keys. No deletes.
Administrator Full management of monitoring data, keys, users, alerts, and identity providers within scope. Not tenant administration unless separately granted.
DNS Delegation Manager Manage Delegated DNS-01 records and their update credentials within scope only - no access to monitoring data, users, or other settings.

A user can hold tenant administrator authority in addition to (or instead of) an organization role - that's what lets someone manage every organization, create tenant-wide resources, and grant roles to other users.

Platform roles (platform-mode deployments only)

Role What it grants
Platform Observer Cross-tenant read-only plus observability.
Platform Operator Cross-tenant read plus act-as; cannot delete tenants or run database tasks.
Platform Administrator Every permission across every tenant, plus tenant lifecycle and database tasks.

Platform roles can only ever be held under the reserved platform tenant - a hosted tenant's administrator can never grant themselves or anyone else a Platform role.

Custom roles

If the built-in roles don't match how your organization is structured, you can define a custom role from a specific set of permissions (monitoring read/write, key management, user management, alerts, identity providers, and more) and assign it the same way as a built-in one.

SSO and roles

If your organization signs in through an identity provider, role assignment is driven by claims in the provider's token instead of - or alongside - roles assigned directly in CertIntel, and is fully resynced on every login. See OIDC / SSO overview for the full model, including the CertIntel.* claim convention that maps directly to the roles above.

Plans and limits

Each tenant has an entitlement plan controlling limits like the number of child organizations, monitored targets, and alert destinations available. If an action is blocked by a plan limit, the error explains which limit was hit; contact your CertIntel administrator or provider to adjust it.