Dom Directory ACL access for Recertifying users

I just got finished setting the ACL in our Domino Directory for our 2nd level admins to “Author” with the user, net, and group create/modify roles. However, now the 2nd level admins cannot re-certify a user who let their ID expire. They get a message to the effect that “the ID can be updated, but not the person document can not be, continue yes/no?” I had to bump them back up to Editor access. Is this right?