Recertification - names.nsf access level

Hello in our company all admins have manager righst to the names.nsf with all user roles. Now we want chance this to have abetter overview. I have reduce the ACL for the Normal admins to Author with the roule of Group Creator, Server Crator, User Creator, Net Creator. In all douemnts in the names.nsf on the admin tab the local admin group is entrede so each admin should be able to maitain his user.

If a user sends now a recertification request via email and a admin goes to action and try to recert the user he receive a erorr message that he is not allowed to updae the person doc in the names.nsf

If he recertifie the user via the admin client, by selectin the user and recert if works fine.

did you have any idea why it wont work via the email ?