Skip to main content

User Roles

DPP Kit uses a two-layer role system: a user role (set at registration) and an organization role (set per org membership).

User Roles

Your user role determines which credential types you can issue and how many organizations you can manage.

User RoleDescriptionMax OrgsCredential Access
Facility/Product ManagerPrimary users who manage a single organization's credentials1All types
PractitionerAgencies managing credentials for multiple clientsUnlimitedAll types across all orgs
Standards BodyIssues conformity credentials (DCCs)1All types (focus on DCC)
Governing BodyOversees and audits credential ecosystems1Read-only + audit

Your user role is chosen during registration and determines the account type.

Organization Roles

Within each organization, members have an access level that controls what they can do:

Org RolePermissions
AdminFull access. Can issue all credential types (DFR, DIA, DPP, DTE, DCC), manage organization settings, invite users, and revoke credentials.
EditorCan issue DPP, DTE, and DCC credentials. Read-only access to DFR and DIA. Cannot manage organization settings or invite users.
ViewerRead-only access to all credentials and the dashboard. Cannot issue or modify anything.
tip

When you create an organization, you're automatically assigned the Admin role for that organization.

Role Combinations

A user's effective permissions are the intersection of their user role and org role. For example:

  • A Practitioner with Admin access to Org A and Editor access to Org B can do everything in Org A but cannot create DFRs in Org B
  • A Facility/Product Manager with Admin access has full control of their single organization
  • A Standards Body user with Admin access will typically focus on issuing DCCs

Inviting Users

Only Admin users can invite new members to an organization. When inviting, you choose:

  1. Email — The invitee's email address
  2. User Role — Their account type (if they're a new user)
  3. Access Level — Their org role (Admin, Editor, or Viewer)
  4. Organizations — Which organizations to grant access to (relevant for practitioners managing multiple orgs)