2. Certificate Collections
Manage certificates in logical groups, with granular access control and alerting.
A Certificate Collection is a logical bucket used to group certificates, domains, agents and everything else. Collections can represent multiple applications, different teams within an organization, or any other division that makes sense for your org.
When you need more than one
One Collection is fine until you need one of these:
- Separate access. You can give a user access to one Collection and not another. Account admins always see everything.
- Separate alerts. Email alert preferences are per user, per Collection — handy when different teams own different environments.
- Environment isolation. Putting prod and staging in separate Collections makes it impossible for a staging certificate deployment to affect a production agent.
Collections List
The certificate collections list shows all your collections in one place. You can see the status of certs, domains being monitored and agents.
Collection Dashboard
Each Certificate Collection has a dashboard that provides a glanceable view of the status of certificates, domains and agents. Anything that isn’t green is worth investigation.
Some other sections you might find on the dashboard:
- Domains Expiring Soon — monitored domains whose served certificate is close to expiry.
- Certificates Expiring Soon — certificates expiring usually mean a renewal job failed, or something else is going on that requires investigation.
- Incomplete Agents — agents that need approval, configuration, or attention. See Agent lifecycle states.
- Upcoming Renewals — certificates renewing in the next 7 days.