docs/documentation/platform/pki/applications/overview.mdx
Applications are where teams issue and manage certificates. Within an Application, you can:
Each Application represents a service or workload in your organization — a payments API, a mobile backend, an IoT device fleet, or an internal web app. Product admins create Applications and assign team members; teams then operate independently within their assigned Applications.
Members are assigned to Applications with one of three roles:
| Role | Capabilities |
|---|---|
| Admin | Full control — manage enrollment methods, members, alerting, syncs, and approval policies |
| Operator | Issue and manage certificates within the Application |
| Auditor | Read-only — view certificates and Application configuration |
| Method | Best for |
|--------|----------|
| **API** | UI issuance, Infisical Agent, custom integrations |
| **ACME** | Certbot, cert-manager, standard tooling |
| **EST** | Enterprise device enrollment |
| **SCEP** | Network devices, MDM systems |
See [Enrollment Methods](/documentation/platform/pki/applications/enrollment-methods/overview) for detailed configuration.
An **Application** is where a team consumes that profile. One profile can be used by many Applications, each with their own members, enrollment methods, and alerting.