# Certificates and Staff

The **Staff and certificate status** card lists every staff member on this device and shows where each one stands. The list is staff-centred: people without a certificate appear too.

> **Where is this card?** The lower half of the **Staff WiFi** screen. The number next to the heading is the total staff count for the device.

---

## 1. Status badges

- **Set up** — has a valid certificate; the device can join the network.
- **Not set up yet** — the staff record exists, the setup has not been run.
- **Not permitted** — the user type is not certificate. This person can open the setup link and still receive nothing. Do not confuse it with “Not set up yet”: this person **cannot** set up at all.
- **Expires soon (%d days)** — fewer than 60 days left on the certificate.
- **Expired** — the certificate is no longer valid and the device has dropped off the network.
- **Revoked** — an administrator revoked the certificate.

Certificates are valid for **825 days** and are **not renewed automatically**. When one expires the staff member drops off the network silently — and everyone who was set up in the same period drops **together**. When you see “Expires soon” badges, have those people run the setup again.

---

## 2. Search and the list limit

The list shows at most **100 staff** at a time. If there are more, you get *“Showing %d of %d staff. Use the search box.”* underneath. Type a name into the box at the top right and press **Search**.

---

## 3. Revoking a certificate

To cut off a departing employee, use **Revoke** on their row. A confirmation appears: *“Revoke this certificate? The device will not be able to connect again and the staff member must run the setup once more.”*

Revoking closes **every valid certificate that person holds on this device**. The same person may have set up as both `ahmet` and `ahmet@company.local`; those are separate records, and leaving one behind would keep that device on the network.

> **When does revocation take effect?** At the device's next network authentication. **A device that is already connected may stay connected until its session ends.** If you need it off immediately, drop the device from the network side as well.

---

## 4. Issued certificates

A separate table lists the certificates produced on this device, with **User**, **Issued**, **Valid until**, **Status** and **Action** columns. The newest record is at the top.

If nobody has run the setup yet: *“No certificates issued yet. They appear here once a staff member opens the setup link and completes it.”*

---

## 5. Orphaned certificates

Below the staff list you may find a collapsible section headed **“Certificates with no matching staff record”**. These were issued before the staff list check was added and cannot be tied to any staff record.

**Revoke them if they are not in use.** A valid certificate with no known owner means a device that can join the network and cannot be tracked in the list.

---

> **Related pages:** **Staff Wi-Fi Administration → Inviting staff**; **Analytics and Reports → 5651 Logs**.