Skip to content

Role-Based Access ​

Overview ​

The DAM uses four workspace roles. Role is stored on the workspace membership record and accessed through getUserModulesAndRoles(workspace) in plugins/helper.js. There is no member, curator, or super admin role.

The Four Roles ​

brand-portal-user ​

External visitors granted access to a specific brand portal. They never see the admin DAM interface.

Can: Access brand portal (brand_portal_access), help & support
Cannot: Upload, manage folders, use search bar, access settings, or any DAM admin operation

viewer ​

Read-only internal workspace member.

Can: Search, share & download, view insights, view versions & download versions, revoke/delete their own share links, access help
Cannot: Upload, create/edit/delete folders, collages, or assets, manage tags, custom fields, settings

manager ​

Content manager with full content lifecycle access.

Can: Everything viewer can + upload, create/edit/delete folders & collages, move content, manage tags, manage custom fields (asset level), add/restore/delete versions, restore trash, create brand portals, manage brand portal users/banners/tiles, manage any share link
Cannot: Account settings, adding users, notification settings, custom field settings (admin panel), empty trash, brand portal customize settings

admin ​

Full workspace administrator.

Can: Everything manager can + account settings, add users, notification settings, announcements, guest upload manager, empty trash, manage custom field types, brand portal customize settings

Role Comparison Summary ​

Areabrand-portal-userviewermanageradmin
Brand portal access✓✓✓✓
Search bar✓✓✓
Share & download✓✓✓
View insights✓✓✓
Upload content✓✓
Create/edit folders✓✓
Create/manage collages✓✓
Edit assets✓✓
Manage tags✓✓
Add/edit custom fields✓✓
Versioning (add/restore)✓✓
Restore trash✓✓
Create brand portals✓✓
Manage brand portal users✓✓
Account settings✓
Add users✓
Notification settings✓
Custom field types (settings)✓
Empty trash✓
Brand portal customize✓

How Role Is Resolved ​

javascript
// plugins/helper.js
const canPerformDamOperation = (workspace, operation) => {
  const user = getUserModulesAndRoles(workspace)
  // user.dam.role is one of: 'brand-portal-user', 'viewer', 'manager', 'admin'
  return DAM_CAPABILITIES[operation].includes(user.dam.role.toLowerCase())
}

The workspace object must be the full workspace record from accessibleWorkspaces in the auth store — not just a workspace ID. The role is resolved from the workspace membership, not from a global user property.

Checking Permissions in Components ​

vue
<script>
export default {
  computed: {
    workspace() {
      const wsId = this.$route.params.workspace_id || this.$getWorkspaceId()
      return this.$store.state.auth.user?.accessibleWorkspaces
        ?.find(w => w.id == wsId)
    },

    // Viewer and above
    canSearch()       { return this.$canUseSearchBar(this.workspace) },
    canShare()        { return this.$canShareDownload(this.workspace) },

    // Manager and above
    canUpload()       { return this.$canUploadContent(this.workspace) },
    canCreateFolder() { return this.$canCreateFolders(this.workspace) },
    canDelete()       { return this.$canDeleteContent(this.workspace) },

    // Admin only
    canManageSettings() { return this.$canAccessAccountSettings(this.workspace) },
    canAddUsers()       { return this.$canAddUsers(this.workspace) },
  }
}
</script>

Middleware ​

Route guards use the same canPerformDamOperation logic:

MiddlewareRequired capabilityEffective minimum role
can-access-dam-modulebrand_portal_accessbrand-portal-user
can-access-dam-settingsaccount_settingsadmin
  • Permissions — full capability matrix and all helper function signatures
  • Folder Management — canCreateFolders, canUseInnerSearch
  • Portals — brand portal capabilities