Yes, MTG CARA provides a differentiated role and rights model. This allows responsibilities to be separated and organizational structures to be represented within the PKI.
The separation of roles and permissions supports the secure operation of PKI infrastructures with elevated security and compliance requirements, for example in accordance with BSI TR-03145.