User permissions and access control in Digital Asset Management

The secret to an effective Digital Asset Management (DAM) system is access, but that involves restricting access as much as it does granting it.

This can be relatively easy to handle for smaller organisations, but as you grow, managing individual permission sets can become unmanageable.

In this article, we’re going to explore designing a DAM permission model that can scale.

READ MORE: Why you should take DAM security seriously

Why a well-planned DAM permissions model beats ‘permissions by exception’

A mistake organisations often make is allowing their permissions model to emerge over time based on ad hoc requests and changing needs. 

For example, when the DAM is launched, team members are given varied levels of access based on the expectations of what they’ll need. However, when those needs change over time, they’re simply granted ad hoc enhanced access. Although this might appear to be efficient and offer flexibility, over time these decisions create a permissions structure that nobody fully understands.

This is known as managing permissions by exception. Every request for access is treated on a case-by-case basis, without considering how the change fits with the wider organisation. Staff change roles, contractors retain access even after their projects have ended, and users continue to have access to areas of the DAM they no longer require.

As a result of this messy permissions structure, DAM Managers often find it easier to simply grant increasingly broad permissions rather than untangling the existing ones, creating a gradual drift towards everyone having access to almost everything.

The best way to avoid this is to actually design your permissions model, building access around clearly defined roles and responsibilities. How this looks in practice is that contributors, reviewers, external agencies and admins each receive the level of access they need to perform their role, and nothing more. When new people join the organisation or move within it, they simply inherit the permissions associated with their role instead of accumulating broad access over time. This is made even simpler when using single sign-on since your internal SSO groups can be mapped to corresponding RersourceSpace groups. 

This role-based approach improves DAM security, simplifies admin and makes it much easier to maintain governance. It also gives users a much better and clearer experience, because they only see the assets, collections and features that are relevant to them.

Identifying DAM user types

So, how do you do this within your own organisation? Start by taking the time to identify the different user types that will be interacting with the DAM system.

For example:

  • Administrators need full control over the system, including user management, configuration and governance functionality.
  • Contributors need to be able to upload new assets, but not necessarily to publish them without a review stage first.
  • Editors require the ability to update metadata, organise collections and manage content.
  • Viewers simply need to be able to search, browse and download approved assets, without the ability to make changes.
  • External users, including agencies, freelancers or partners, should only have access to the specific areas and functionality required for specific projects.

By defining these user types first, you can build a permissions model around real responsibilities rather than individual requests, creating a consistent, scalable framework that is easier to manage as your organisation grows and new users join the system.

Apply ‘least privilege’ and group by need

Once you've defined your user types, the next step is to apply the principle of ‘least privilege’. In simple terms, this means every role should receive only the level of access required to carry out its responsibilities. Rather than anticipating every possible future requirement, start with the minimum permissions and expand them only where there is a genuine operational need.

A group-based approach also makes managing permissions much easier, because instead of configuring access for every individual user, they’re assigned to a group that reflects their role or department. When responsibilities change, you can update the group’s permissions rather than editing dozens of user accounts individually, or move a user to a different group if their role changes

This is particularly valuable when applied to sensitive content, because permissions can be applied at an asset level. This ensures that restricted campaign materials, confidential documents or sensitive imagery are only visible to authorised users.

Handling external contributors

Many organisations work with agencies, freelancers, photographers and other partner organisations, but these groups also need access to approved content. This isn’t as easy to manage as users within your organisation, but most DAM systems will offer functionality that can help.

With a DAM like ResourceSpace, you can create dedicated external user roles with tightly controlled permissions. For many external users, read-only or download-only access will be sufficient, allowing contributors to find and retrieve approved assets (they have permission to see) without viewing internal collections or editing metadata. This ensures the wider system is protected, while giving external users the resources they need to complete their work efficiently.

If you want to provide assets for review but don’t want them to be downloaded and used by the external user, watermarked previews provide an additional layer of protection by allowing users to evaluate content without accessing the original high-resolution file.

What’s more, time-limited share links that expire offer a far more secure alternative to emailing attachments or granting permanent access to a shared drive. Access can be set to automatically end when it’s no longer required, reducing the risk of outdated links or forgotten permissions remaining active.

READ MORE: How ResourceSpace solves... public access

By treating external access as a carefully managed workflow, organisations can collaborate with partners while maintaining control over their assets and protecting sensitive content.
Permissions are not set and forget
You should design your user permissions model from day one of using a DAM system, but this isn’t a set-and-forget process, and you need to review these processes on a regular basis.

Organisations are changing all of the time, with employees moving between departments, new teams being created, contractors finishing projects, and external partners starting and ending relationships. If access is never revisited, permissions gradually become outdated, increasing both security and compliance risks.

With this in mind, build regular user permission reviews into your governance processes. This should include regularly auditing who has access to which assets, collections and administrative functions, and confirming that each user still requires that level of access. This needs to be completed for external users too, so review temporary accounts, shared collections and expiring links to ensure access is removed once a project has concluded.

This is particularly important for organisations working with personal data, licensed content or commercially sensitive assets, because demonstrating appropriate access controls can form an important part of wider compliance requirements. By routinely auditing permissions and keeping access aligned with current responsibilities, your DAM remains secure, manageable and ready to scale without accumulating unnecessary risk over time.

How ResourceSpace handles permissions and access

ResourceSpace provides your organisation with full control over your assets, with granular, advanced security and permissions features that makes it easy for DAM Managers to access.

This includes:

  • Enterprise single sign-on and multi-factor authentication, supporting Microsoft Azure Active Directory, Oracle Directory, OAuth, LDAP and more.
  • Configurable multi-user privacy, allowing DAM Managers to create fully configurable environments that are isolated from the main DAM.
  • Consent management tools that make it easy to ensure that assets are only used if they have the relevant permissions.

To find out more about how ResourceSpace can help your organisation manage permissions, book a free discovery call with one of our DAM experts below.

Article hashtags

Subscribe: RSS feed / e-mail