Appearance
Role-Based Access ​
Overview ​
The DAM uses four workspace roles. Role is stored on the workspace membership record and accessed through getUserModulesAndRoles(workspace) in plugins/helper.js. There is no member, curator, or super admin role.
The Four Roles ​
brand-portal-user ​
External visitors granted access to a specific brand portal. They never see the admin DAM interface.
Can: Access brand portal (brand_portal_access), help & support
Cannot: Upload, manage folders, use search bar, access settings, or any DAM admin operation
viewer ​
Read-only internal workspace member.
Can: Search, share & download, view insights, view versions & download versions, revoke/delete their own share links, access help
Cannot: Upload, create/edit/delete folders, collages, or assets, manage tags, custom fields, settings
manager ​
Content manager with full content lifecycle access.
Can: Everything viewer can + upload, create/edit/delete folders & collages, move content, manage tags, manage custom fields (asset level), add/restore/delete versions, restore trash, create brand portals, manage brand portal users/banners/tiles, manage any share link
Cannot: Account settings, adding users, notification settings, custom field settings (admin panel), empty trash, brand portal customize settings
admin ​
Full workspace administrator.
Can: Everything manager can + account settings, add users, notification settings, announcements, guest upload manager, empty trash, manage custom field types, brand portal customize settings
Role Comparison Summary ​
| Area | brand-portal-user | viewer | manager | admin |
|---|---|---|---|---|
| Brand portal access | ✓ | ✓ | ✓ | ✓ |
| Search bar | ✓ | ✓ | ✓ | |
| Share & download | ✓ | ✓ | ✓ | |
| View insights | ✓ | ✓ | ✓ | |
| Upload content | ✓ | ✓ | ||
| Create/edit folders | ✓ | ✓ | ||
| Create/manage collages | ✓ | ✓ | ||
| Edit assets | ✓ | ✓ | ||
| Manage tags | ✓ | ✓ | ||
| Add/edit custom fields | ✓ | ✓ | ||
| Versioning (add/restore) | ✓ | ✓ | ||
| Restore trash | ✓ | ✓ | ||
| Create brand portals | ✓ | ✓ | ||
| Manage brand portal users | ✓ | ✓ | ||
| Account settings | ✓ | |||
| Add users | ✓ | |||
| Notification settings | ✓ | |||
| Custom field types (settings) | ✓ | |||
| Empty trash | ✓ | |||
| Brand portal customize | ✓ |
How Role Is Resolved ​
javascript
// plugins/helper.js
const canPerformDamOperation = (workspace, operation) => {
const user = getUserModulesAndRoles(workspace)
// user.dam.role is one of: 'brand-portal-user', 'viewer', 'manager', 'admin'
return DAM_CAPABILITIES[operation].includes(user.dam.role.toLowerCase())
}The workspace object must be the full workspace record from accessibleWorkspaces in the auth store — not just a workspace ID. The role is resolved from the workspace membership, not from a global user property.
Checking Permissions in Components ​
vue
<script>
export default {
computed: {
workspace() {
const wsId = this.$route.params.workspace_id || this.$getWorkspaceId()
return this.$store.state.auth.user?.accessibleWorkspaces
?.find(w => w.id == wsId)
},
// Viewer and above
canSearch() { return this.$canUseSearchBar(this.workspace) },
canShare() { return this.$canShareDownload(this.workspace) },
// Manager and above
canUpload() { return this.$canUploadContent(this.workspace) },
canCreateFolder() { return this.$canCreateFolders(this.workspace) },
canDelete() { return this.$canDeleteContent(this.workspace) },
// Admin only
canManageSettings() { return this.$canAccessAccountSettings(this.workspace) },
canAddUsers() { return this.$canAddUsers(this.workspace) },
}
}
</script>Middleware ​
Route guards use the same canPerformDamOperation logic:
| Middleware | Required capability | Effective minimum role |
|---|---|---|
can-access-dam-module | brand_portal_access | brand-portal-user |
can-access-dam-settings | account_settings | admin |
Related Documentation ​
- Permissions — full capability matrix and all helper function signatures
- Folder Management —
canCreateFolders,canUseInnerSearch - Portals — brand portal capabilities