---
title: "Restrict code signing management"
description: "Restrict code signing management to organization admins so only admins can manage certificates, signing bundles, and provisioning profiles."
platform: "Cloud"
doc_version: "unversioned"
last_updated: "2026-10-08"
cloud_plans: "Free, Performance, Scale"
version_control: "All supported providers"
---

> For current CircleCI product defaults, deprecated patterns, and Cloud/Server differences, see [AGENTS.md](https://circleci.com/docs/AGENTS.md).
>
> For the complete documentation index and site structure, see [llms.txt](https://circleci.com/docs/llms.txt).

# Restrict code signing management

**Cloud plans:** Free, Performance, Scale

**Version control:** [All supported providers](https://circleci.com/docs/guides/integration/version-control-system-integration-overview/)

By default, organization admins and contributors can manage the certificates, signing bundles, and provisioning profiles used for [iOS and macOS Code Signing](https://circleci.com/docs/guides/execution-managed/ios-codesigning/). An organization admin can turn on a setting that restricts these actions to organization admins only. This page describes what the setting controls and how to turn it on.

## Understand what the setting controls

The setting applies to your whole organization and is off by default. The following table shows who can manage code signing for each state of the setting.

| Setting state | Who can manage code signing |
| --- | --- |
| Off (default) | Organization admins and contributors |
| On | Organization admins only |

Managing code signing includes the following actions:

*   Creating or deleting signing bundles.
    
*   Uploading or deleting certificates.
    
*   Updating or removing provisioning profiles.
    

Every member of your organization can still view certificates and signing bundles, regardless of the setting.

Your role depends on your organization type:

*   `github` and `bitbucket` type organizations: CircleCI uses your role in the VCS provider. GitHub organization owners and Bitbucket workspace owners are organization admins. Other members of the organization or workspace are contributors.
    
*   `circleci` type organizations: You manage roles in CircleCI.
    

For more information, see the [Users, Organizations, and Integrations Guide](https://circleci.com/docs/guides/permissions-authentication/users-organizations-and-integrations-guide/#organizations) and the [Organization Role Permissions Matrix](https://circleci.com/docs/guides/permissions-authentication/roles-and-permissions-overview/#organization-role-permissions-matrix).

## Restrict code signing management to organization admins

Only organization admins can change this setting.

1.  In the [CircleCI web app](https://app.circleci.com), select your org from the org cards on your user homepage.
    
2.  Select **Org** from the sidebar to open your organization settings page.
    
3.  Select **Security**.
    
4.  In the **Code Signing Security Settings** section, turn on **Restrict code signing management to organization admins only**.
    

To allow contributors to manage code signing again, turn off the same toggle.

CircleCI records changes to organization settings in your audit logs as the `organization.settings.update` event. See the [Audit Log Events](https://circleci.com/docs/guides/security/audit-logs/#audit-log-events) section for more information.

## Understand how the restriction applies to the API

CircleCI enforces the setting on the server, so it applies to the web app, CLI, and API requests. When the setting is on, a request from a non-admin user to change code signing assets returns an HTTP 403 response. Requests that list certificates and signing bundles are not affected.

For the API requests used to manage code signing, see [Code Signing API](https://circleci.com/docs/guides/execution-managed/ios-codesigning/#code-signing-api).