ResourceSpace has changed the way the DEC uses content, making it much easier for us to quickly make assets available both internally and externally during our emergency appeals.
Blog
24th July 2026

The secret to an effective Digital Asset Management (DAM) system is access, but that involves restricting access as much as it does granting it.
This can be relatively easy to handle for smaller organisations, but as you grow, managing individual permission sets can become unmanageable.
In this article, we’re going to explore designing a DAM permission model that can scale.
READ MORE: Why you should take DAM security seriously
A mistake organisations often make is allowing their permissions model to emerge over time based on ad hoc requests and changing needs.
For example, when the DAM is launched, team members are given varied levels of access based on the expectations of what they’ll need. However, when those needs change over time, they’re simply granted ad hoc enhanced access. Although this might appear to be efficient and offer flexibility, over time these decisions create a permissions structure that nobody fully understands.
This is known as managing permissions by exception. Every request for access is treated on a case-by-case basis, without considering how the change fits with the wider organisation. Staff change roles, contractors retain access even after their projects have ended, and users continue to have access to areas of the DAM they no longer require.
As a result of this messy permissions structure, DAM Managers often find it easier to simply grant increasingly broad permissions rather than untangling the existing ones, creating a gradual drift towards everyone having access to almost everything.
The best way to avoid this is to actually design your permissions model, building access around clearly defined roles and responsibilities. How this looks in practice is that contributors, reviewers, external agencies and admins each receive the level of access they need to perform their role, and nothing more. When new people join the organisation or move within it, they simply inherit the permissions associated with their role instead of accumulating broad access over time. This is made even simpler when using single sign-on since your internal SSO groups can be mapped to corresponding RersourceSpace groups.
This role-based approach improves DAM security, simplifies admin and makes it much easier to maintain governance. It also gives users a much better and clearer experience, because they only see the assets, collections and features that are relevant to them.
So, how do you do this within your own organisation? Start by taking the time to identify the different user types that will be interacting with the DAM system.
For example:
By defining these user types first, you can build a permissions model around real responsibilities rather than individual requests, creating a consistent, scalable framework that is easier to manage as your organisation grows and new users join the system.
Once you've defined your user types, the next step is to apply the principle of ‘least privilege’. In simple terms, this means every role should receive only the level of access required to carry out its responsibilities. Rather than anticipating every possible future requirement, start with the minimum permissions and expand them only where there is a genuine operational need.
A group-based approach also makes managing permissions much easier, because instead of configuring access for every individual user, they’re assigned to a group that reflects their role or department. When responsibilities change, you can update the group’s permissions rather than editing dozens of user accounts individually, or move a user to a different group if their role changes
This is particularly valuable when applied to sensitive content, because permissions can be applied at an asset level. This ensures that restricted campaign materials, confidential documents or sensitive imagery are only visible to authorised users.
Many organisations work with agencies, freelancers, photographers and other partner organisations, but these groups also need access to approved content. This isn’t as easy to manage as users within your organisation, but most DAM systems will offer functionality that can help.
With a DAM like ResourceSpace, you can create dedicated external user roles with tightly controlled permissions. For many external users, read-only or download-only access will be sufficient, allowing contributors to find and retrieve approved assets (they have permission to see) without viewing internal collections or editing metadata. This ensures the wider system is protected, while giving external users the resources they need to complete their work efficiently.
If you want to provide assets for review but don’t want them to be downloaded and used by the external user, watermarked previews provide an additional layer of protection by allowing users to evaluate content without accessing the original high-resolution file.
What’s more, time-limited share links that expire offer a far more secure alternative to emailing attachments or granting permanent access to a shared drive. Access can be set to automatically end when it’s no longer required, reducing the risk of outdated links or forgotten permissions remaining active.
READ MORE: How ResourceSpace solves... public access
By treating external access as a carefully managed workflow, organisations can collaborate with partners while maintaining control over their assets and protecting sensitive content.
Permissions are not set and forget
You should design your user permissions model from day one of using a DAM system, but this isn’t a set-and-forget process, and you need to review these processes on a regular basis.
Organisations are changing all of the time, with employees moving between departments, new teams being created, contractors finishing projects, and external partners starting and ending relationships. If access is never revisited, permissions gradually become outdated, increasing both security and compliance risks.
With this in mind, build regular user permission reviews into your governance processes. This should include regularly auditing who has access to which assets, collections and administrative functions, and confirming that each user still requires that level of access. This needs to be completed for external users too, so review temporary accounts, shared collections and expiring links to ensure access is removed once a project has concluded.
This is particularly important for organisations working with personal data, licensed content or commercially sensitive assets, because demonstrating appropriate access controls can form an important part of wider compliance requirements. By routinely auditing permissions and keeping access aligned with current responsibilities, your DAM remains secure, manageable and ready to scale without accumulating unnecessary risk over time.
ResourceSpace provides your organisation with full control over your assets, with granular, advanced security and permissions features that makes it easy for DAM Managers to access.
This includes:
To find out more about how ResourceSpace can help your organisation manage permissions, book a free discovery call with one of our DAM experts below.