User Permissions Overview
Permissions in the platform control what users can see and do. The system uses a role-based access control structure where users are assigned to user groups, and user groups contain roles that define specific permissions.
How the Permission System Works
The platform uses a three-level permission structure:
Users → are assigned to → User Groups → which contain → Roles
Roles define what actions users can perform and what features they can access. There are two types of roles:
- Application Roles: Define access to records (Assets, Accounts, Portals, etc.), components (Public Link, Location Map, etc.), and administrative features. If a role does not grant access to a record or component, users will not see it in the interface.
- Folder Roles: Define access to specific folders and the assets within them. These roles control visibility and actions available for folder-based content.
User Groups are collections of roles assigned to users. Key characteristics:
- A user group can contain multiple roles (both application and folder roles).
- Users can be assigned to multiple user groups.
- User groups can be designated as admin groups, granting full platform access to all members.
- Individual users can also be granted administrator rights directly, bypassing group-based permissions.
Administrator Rights
A user can hold administrator rights in one of two ways, and the two are tracked separately:
- Directly on the user – admin rights granted to that individual.
- Through an admin user group – admin rights inherited from membership of a group marked as an admin group.
Because these are separate, you can remove direct admin rights from a user who is also in an admin group; they keep admin access through the group until they are removed from it as well.
Only administrators can create or edit other administrators, mark a user group as an admin group, or reset the password of an admin user. For non-admins, the option to grant admin rights is not available.
What Permissions Control
- Record Access: View, edit, or manage specific record types (Assets, Accounts, Portals, Showcases, etc.)
- Component Visibility: Access to features and components in asset details and throughout the platform. Some components also depend on Metadata Profiles for visibility.
- Actions: Upload, download, edit metadata, delete, share, reprocess, manage versions, and more
- Admin Features: Access to administrative configuration including metadata structure, user management, branding, reports, digital rights, integrations, and system settings
Checking a User's Permissions
To confirm what a particular user can see and do, an administrator can log in as that user from the user's profile. This starts a session that shows the platform exactly as that user experiences it, which is the quickest way to verify a permission setup without asking the user to check for you.
While logged in as another user, a banner indicates that you are in their session. You can return to your own administrator account directly from there, without logging out and back in. Returning works even when the other user has very limited permissions.
Tips
- User groups simplify permission management by allowing you to assign roles once and then add users to appropriate groups.
- Folder roles provide granular control over which assets users can access, while application roles control broader platform capabilities.
- Admin groups should be used sparingly and only for trusted users who need full platform access.
- Role names must be unique. If you cannot save a new role, check whether the name is already in use.
- To troubleshoot a "why can't I see this?" question, log in as the user from their profile and check their view directly.
- If you need help designing your permission structure, contact Data Dwell support for assistance.
Related Articles