Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents

General information

Info

Roles can be added to users in three ways:

  1. Directly on the user (Role→User)
  2. Inherited via a group which the user is a part of (Role→GroupUser)
  3. Inherited via a group that has the role inherited from another group (Role→Group→Group→User) (Technically, you can have unlimited groups in groups - but the groups must never create a circular reference)

Users can simultaneously have roles added directly and roles inherited via groups - having the same role added twice (or multiple times) doesn't have an impact. Removing e.g. a group with a duplicate role - will still leave your user with the role.

Roles and groups that have been inherited, will be greyed out. (You also inherit download qualities, but our current implementation does not make them show up. In a perfect world, the inherited download qualities would show up as greyed out)

If you have duplicate roles then the role will have a (+) appended

Image Removed

...

List of roles

Note

This list is descriptive, meaning that it's not prescriptive.

Essentially, this means that this list describes what it currently does - not what it's supposed to do. As time goes on, these two things should align 100%.

...

Roles

...

Enables you to use AI tagging on images. Requires additional setup if you don't want to use Digizuite's Azure account for it. Requires an EditMultiComboVlaue to be defined in MM's config manager.

...

Enables one to download an asset and print published assets (assets without a lock).

You need to have download qualities added, to be able to download assets. These are assigned via groups. Groups with download qualities are: "Guest", "Light Users", "Content Creators", "Administrators", and "Super Administrators"

...

Business_Workflow_General_Transition_Executor

...

21

...

Can_Configure_Members

...

...

...

Allows the user to configure MM to use a Member Approval business workflow.

...

Can_Force_Job_Status_Change

...

Allows the user to cancel or delete jobs in both AW and DigiBatch. 

...

Can_Rerun_Workflows

...

...

...

Allows the user to use the "ManualTrigger" AW trigger to start workflows based on simple input data. 

...

29

...

Can_See_Grafana_Shortcut

...

...

...

Allows the user to see the shortcut to Grafana in the MM ui. The login to grafana is separate from their Digizuite login, and has nothing to do with this role. 

...

CanImpersonate

...

...

...

Allows the user to generate access keys for other users. Should only be given to the "System" user, unless you have very good reason for anything else.

...

Enables one to Update other people's comments

...

Enables one to Create (own), Update (own), Delete (own) comments (for tasks and images) and Create (own), Update (own), Delete (own), annotations on images.

It requires Comment_View to function.

...

Enables one to Read (all) comments (assets and tasks) and Read (all) annotations

Gives you the option to access comments directly from the asset overview

...

Editor_Catalogs

...

Editor_Portal

...

Info
iconfalse
titleThis role at its purest
  1. Every time the user reads, it'll skip the mandatory security check.
  2. It'll grant you access to change rights for all items.

Gives you read access to everything you've added - e.g. makes all Catalog and Channel folders appear if you've added "Editor_Catalogs" and "Editor_Portal".

It only gives read access to assets in the DC - I.e. it does not give you read access to assets in the MM (even though it appears that you have read access to them when you look at the channels in DC).

With this, you can give yourself (and others) write access to folders you don't have write access to.

It also adds "System Tools" to the left side menu - but it is blank - meaning that there are not any system tools in it.

It opens up for access to content in Media Manager. Here this role gives you high-level access.

It gives you access to all collections for all users in the system

...

Editor_SystemTools_Config

...

Editor_SystemTools_Dam

...

Enables one to select all catalog and channel folders in System tools → Workflow → AssetSyncFolder → "Sync rootfolder"/"Destination folder". Without this role, one can only select folders that you have read-access to.

...

Editor_SystemTools_Destinations

...

Editor_SystemTools_DigizuiteConfig

...

Editor_SystemTools_License

...

Editor_SystemTools_MediaFormat

...

Editor_SystemTools_MediaFormatType

...

Editor_SystemTools_Metadata

...

Editor_SystemTools_MetaDataLanguage

...

Editor_SystemTools_PlayerTemplate

...

Editor_SystemTools_Profiles

...

Editor_SystemTools_Status

...

Editor_SystemTools_Stopwords

...

Editor_SystemTools_TranscodeSetting

...

Editor_SystemTools_UserManager_Groups

...

Editor_SystemTools_UserManager_Users

...

Editor_SystemTools_Workflow

...

61

...

EditSso

...

...

...

Allows the user to change the systems SSO settings. Should probably only be given to a select set of super administrators

...

MediaPortal_Admin_StartScreen

...

MediaPortal_Asset_Replacer

...

MediaPortal_Asset_Unpublisher

...

MediaPortal_Collection

...

Enables one to share via the MM UI. Enabling this gives you the ability to share assets via: URL, Zip (email), social media - and if collections are enabled one can also share assets via: New collection (create new), and Existing collection (add to existing).

If collections are enabled, one can share them via: Zip (a package over mail), Social media, and Collection (give people rights to preview the collection from MM)

If the following is enabled "Give new recipients of non-social collections (e.g. not Facebook collections) access to manipulate collections:" via config manager, the recipient will be able to CRUD the collection, else the recipient will only be able to Read the collection.

Sharing over social media makes the shared asset publicly available. One needs to manually revoke the read rights on the asset level, to make it internal again.

...

MediaPortal_Uploader

...

MediaPortal_User

...

Requires "MediaPortal_Share" + some settings in CondigManager to work (See the table in the bottom of this page - ctrl+f "embed")

Adds embed as a sharing option. It only works with videos.

...

Member_Viewer

...

RunningJobs_AdminViewSubmitXML

...

RunningJobs_ChangePriority

...

RunningJobs_EditAll

...

Obsolete - To be deleted

...

RunningJobs_EditOwn

...

Obsolete - To be deleted

...

RunningJobs_View

...

RunningJobs_ViewAll

...

Uploader_ShowFolderSelector

...

Only implemented in DFS. Is used to give users access to upload to the catalog area while using the embedded upload component

...

Note: If both Uploader_ReplaceWithArchive and Uploader_ReplaceWithoutArchive are enabled the user will be asked what he wants to do with the old asset: archive it or delete it.

Features

The other way around - what roles and rights need to be added to enable a feature

Info

MediaPortal_User is needed to access MM - so for all MM features below, it's given that MediaPortal_User is already enabled.

In a lot of instances, you also need read access to assets. I only scarcely add this as a right sometimes. Usually, it's self-evident that one should have read access to an asset to add it to a collection.

The Upload folder (46) is the default folder for uploading. This can be changed - and if changed, use this other folder instead.

For Keywords - Keywords (10192) is default. This can of course also be changed - where you should use this new metadata field instead.

Green = OK

Yellow = Might not be OK

...

Features in MM

...

Enable profile images = True

Enable users to see and edit their account information = True

...

WorkStages_View

WorkStages_View_Others

...

Member_Viewer

WorkStages_View

...

Write access to the asset

Write rights to the metadata fields in "Metadata > Asset > Shared > Tasks" (usually granted via trusted)

...

Member_Viewer

WorkStages_View

WorkStages_Edit_Others

...

Write access to the asset

Write rights to the metadata fields in "Metadata > Asset > Shared > Tasks" (usually granted via trusted)

...

Enable (single- and multi-) download of an asset's predefined qualities

Enable (single- and multi-) download of assets and metadata

Enable download of collections as zip

Asset_Can_Download

Can_Live_Export_Assets_And_Metadata

...

The asset is "public" (no padlock)

Should be added to a group with download qualities: "Guest", "Light Users", "Content Creators", "Administrators", or "Super Administrators"

...

Enable (single- and multi-) download of an asset's predefined qualities

Enable (single- and multi-) download of metadata

Enable download of collections as zip

Asset_Can_Download

Can_Live_Export_Metadata_Only

...

The asset is "public" (no padlock)

Should be added to a group with download qualities: "Guest", "Light Users", "Content Creators", "Administrators", or "Super Administrators"

...

Enable (single- and multi-) download of an asset's predefined qualities

Enable (single- and multi-) download of assets

Enable download of collections as zip

Asset_Can_Download

Can_Live_Export_Asset_Only

...

The asset is "public" (no padlock)

Should be added to a group with download qualities: "Guest", "Light Users", "Content Creators", "Administrators", or "Super Administrators"

...

Asset_Can_Download

Asset_Can_Download_Custom_Quality

...

Custom quality color spaces = must have content

Custom quality image types = must have content

Enable custom quality download = true

...

MediaPortal_Share

...

Table of Contents

General information

Info

Roles can be added to users in three ways:

  1. Directly on the user (Role→User)
  2. Inherited via a group which the user is a part of (Role→GroupUser)
  3. Inherited via a group that has the role inherited from another group (Role→Group→Group→User) (Technically, you can have unlimited groups in groups - but the groups must never create a circular reference)

Users can simultaneously have roles added directly and roles inherited via groups - having the same role added twice (or multiple times) doesn't have an impact. Removing e.g. a group with a duplicate role - will still leave your user with the role.

Roles and groups that have been inherited, will be greyed out. (You also inherit download qualities, but our current implementation does not make them show up. In a perfect world, the inherited download qualities would show up as greyed out)

If you have duplicate roles then the role will have a (+) appended

Image Added


List of roles

idRoleDescription
2UploaderThis role is obsolete
25Editor_SystemTools_ProfilesGives access to see and edit profiles in DAM administration view
27Editor_SystemTools_UserManager_UsersGives access to see and edit users in DAM administration view
29Editor_CatalogsGives access to edit catalog folders in DAM administration view
30Viewer_CatalogsGives access to see catalog folders in DAM administration view
36Editor_SystemTools_UserManager_GroupsGives access to see and edit groups in DAM administration view
37Editor_SystemTools_MetadataGives access to see and edit metadata definitions
38AdministratorAdministrator role used for all administration APIs
41Editor_SystemTools_DestinationsGives access to see and edit destinations in DAM administration view
42Editor_SystemTools_DamThis role is obsolete
43Editor_SystemTools_DigizuiteConfigGives access to see and edit Digizuite constants in DAM administration view
44Editor_SystemTools_MediaFormatGives access to see and edit media formats in DAM administration view
45Editor_SystemTools_TranscodeSettingGives access to see and edit transcodes in DAM administration view
46Editor_PortalThis role is deprecated, but in use for the old API when editing channel folders. Only used in the DAM Administration view
50Editor_Portal_AdminSame as above (Editor_portal)
52RunningJobs_ViewGives access to see your own upload progress
54RunningJobs_ViewAllGives access to see all upload progress
55RunningJobs_EditOwnThis role is obsolete
57RunningJobs_EditAllThis role is obsolete
58RunningJobs_ChangePriorityThis role is obsolete
59RunningJobs_AdminViewSubmitXMLThis role is obsolete
60Uploader_ShowFolderSelectorThis role is obsolete
61Uploader_ReplaceWithArchiveThis role is obsolete
62Uploader_ReplaceWithoutArchiveThis role is obsolete
65Editor_SystemTools_ConfigThis role gives access to product configuration including searches, labels and configuration
67VP3_Portal_Admin_StartScreenThis role is obsolete
68VP3_Portal_Admin_VideoSlidesThis role is obsolete
72ItemControlAdminThis role is obsolete
74Editor_SystemTools_AlwaysAllowItemSecurityEditThis role ignores all item security - use carefully!
76MediaPortal_Admin_StartScreenAllows editing of start screen in Media Manager
77MediaPortal_Admin_UsersThis role is obsolete
78MediaPortal_Admin_LogThis role is obsolete
79MediaPortal_Admin_TrashThis role is obsolete
80MediaPortal_UserBasic user role that gives access to login into MediaManager
81MediaPortal_CollectionGives access to collections
82MediaPortal_UploaderGives access to upload from MediaManager
83MediaPortal_DownloaderThis role is obsolete
84Editor_SystemTools_PlayerTemplateThis role is obsolete
85Editor_SystemTools_StopwordsThis role gives access to edit stopwords for Search2
86Editor_SystemTools_LicenseThis role gives access to edit Digizuite licenses
87Editor_SystemTools_StatusThis role is obsolete
88Editor_SystemTools_WorkflowThis role is obsolete
90Editor_SystemTools_MediaFormatTypeThis role gives access to edit media format type setup
91Editor_SystemTools_MetaDataLanguageThis role gives access to manage languages
92MediaPortal_Asset_ReplacerThis role is obsolete
93MediaPortal_Asset_UnpublisherThis role is obsolete
94Upload_OnlyThis role is deprecated, but used in the Digizuite administration to restrict users to only see the upload dialog
95Member_ViewerThis roles allows user to see information about other users
103Comments_CRUDGives access to see, add, delete and edit own commets
104Comments_ViewGives access to see comments
105Comments_Admin_DeleteGives access to delete all comments
106Asset_Can_DownloadGives access to download assets - Please note that download is controlled by a set of roles and download qualities
107Asset_Can_Download_Custom_QualityGives access to download custom download qualities if enabled by configuration
108Asset_Can_ReplaceAllows users to replace assets
109Asset_Can_ReviseAllows users to replace an asset with a trim or crop
110Asset_Can_CropAllows users to crop and trim assets
111AuditTrail_ViewAllows users to view audit trail for assets
112Ai_AddAllows users to use AI capabilities if enabled and configured
113Can_Change_Styling_And_ThemingAllows user to change styling and theming when Brand portal is not enabled
114WorkStages_ViewThis role allows the user to see asset status' they are assigned to
115WorkStages_Edit_OthersThis role allows editing of asset status' they are not assigned to
116WorkStages_View_OthersThis role allows users to always see asset status
117GDPR_AdminAllows users to do GDPR actions
121Saved_Searches_CRUDGives access to saved searches
122Ai_TranslateGives access to use metadata translation API's
123Integration_Endpoints_ViewAllows users to see integration endpoints
124Integration_Endpoints_CRUDAllows users to edit integration endpoints
125Asset_Can_Delete_PermanentlyAllows users to permanently delete assets
126Can_Edit_Automation_WorkflowAllows editing of automations
127Can_View_LogsAllows users to see system logs
128Can_View_Automation_Workflow_StatusAllows users to see the status of automations 
129Can_Live_Export_Assets_And_MetadataFull access for downloading and exporting assets and it's metadata
130Can_Live_Export_Asset_OnlyGives access to download assets
131Can_Live_Export_Metadata_OnlyGives access to export metadata for assets
132Business_Workflow_ViewGives access to see the workflow definitions
133Business_Workflow_CRUDGives access to edit the workflow definitions
134Download_Approval_BypassIf download approval is enabled, this role bypasses it
135Download_Approval_AdminGives access to configure download approval
136Copyright_Notification_BypassIf copyright notification is enabled, this role bypasses it
138Youtube_AdminGives access to configure Youtube integrations
139Business_Workflow_Instance_View_OthersThis role allows the users to see tasks in Workflows they are not assigned to
140Asset_Can_Download_AnyBypasses all download rules
141Can_See_Grafana_ShortcutGives access to system monitoring
142Comments_Admin_UpdateGives access to edit all comments
143Business_Workflow_General_Transition_ExecutorAllows users to do transitions in workflow tasks that has no user constraints on transition
144Business_Workflow_Instance_DeleteAllows user to delete workflow tasks
147Business_Workflow_Instance_ViewAllows users to see workflow tasks they are assigned to
148Business_Workflow_Instance_TransitionAllows users to see transitions
149Business_Workflow_Instance_AssignAllows assigning workflow tasks to other people
150EditSsoAllows editing of SSO settings
151CanImpersonateAllows a user to create accesskeys for other users. Be careful with this role as it allows bumping user access. Should only be used for System user
152FileRepository_ReadUsed for files in workflows. This gives the users access to see attached files
153FileRepository_Read_SecretUsed for files in workflows. This gives the users access to see secret attached files
154FileRepository_UploadUsed for files in workflows. This gives the users access to see upload files
155FileRepository_DeleteUsed for files in workflows. This gives the users access to see delete uploaded files
156MailTemplates_CRUDAllows users to edit mail templates
157Can_Force_Job_Status_ChangeAllows users to change job status, for example restarting a failed job
158Can_Configure_MembersUsed in MediaManager to allow editing users. This is behind a feature flag in current version. Will be available in the future
159Can_Rerun_WorkflowsThis allows users to run automations with a manual trigger
160ItemCheckInOut_CRUDThis gives access to check-in and check-out
161ChannelFolder_CRUDAllows the user to edit Channel folders. As of this release this is new API not being used in any UI and therefore this role is not needed on users
162ChannelFolder_ViewAllows the user to seeChannel folders. As of this release this is new API not being used in any UI and therefore this role is not needed on users
163ConfigManagement_AdminAllows users to edit configuration for products. This is new API and not available through UI yet.
170Creative_Cloud_ConnectorAllows users access to Creative cloud connector
171Can_See_Generic_Job_StatusAllows users to see generic job status - for instance elastic re-indexing 
172Can_Admin_Accelerated_SearchAllows users to see status for search administration in Media Manager
173Smart_Asset_Picker_ConnectorAllows users to use the embedded Media Manager UI
174Can_configure_portalsAllows editing of Digizuite portals
175Can_view_portalsAllows users to see Digizuite portals
176Can_view_metadataAllows users to see the metadata tab on asset details
177Can_view_related_assetsAllows users to see the related assets tab on asset details
178Can_manage_filters_and_fieldsAllows users to setup filters and free text searching


Features

The other way around - what roles and rights need to be added to enable a feature


Info

MediaPortal_User is needed to access MM - so for all MM features below, it's given that MediaPortal_User is already enabled.

In a lot of instances, you also need read access to assets. I only scarcely add this as a right sometimes. Usually, it's self-evident that one should have read access to an asset to add it to a collection.

The Upload folder (46) is the default folder for uploading. This can be changed - and if changed, use this other folder instead.

For Keywords - Keywords (10192) is default. This can of course also be changed - where you should use this new metadata field instead.

Green = OK

Yellow = Might not be OK

...

Features in DC

...

Changes in roles from the last version to this

Added

...

Can_Force_Job_Status_Change

Removed

...

Changed

OldNewNote

MediaPortal_Share

MediaPortal_Collection

Features in MM

RolesRightsConfigManager
Upload assets via MM + see "Your uploads"MediaPortal_Upload Write access to "Upload" folder (Usually granted through the "Trusted" group)


Enable users to change their profile information

Enable users to see and edit their account information = True
Upload/change profile image via MMMediaPortal_Upload 

Enable profile images = True

Enable users to see and edit their account information = True

Restore old asset version via MMAsset_Can_ReplaceWrite access to "Upload" folder (Usually granted through the "Trusted" group) (Having write access to Content does nothing)
Replace asset + See "Asset History" (Not audit trail)Asset_Can_ReplaceWrite access to the asset
See asset statuses + Enable the "My tasks" viewWorkStages_ViewRead access to the asset
Enable the "All tasks" view

WorkStages_View

WorkStages_View_Others

Read access to the asset
Change/set assets' statuses (on assets not already assigned to other users - Meaning only assets where you or none is assigned)

Member_Viewer

WorkStages_View

Write access to the asset

Write rights to the metadata fields in "Metadata > Asset > Shared > Tasks" (usually granted via trusted)


Change/set assets' statuses (regardless of who they're assigned to)

Member_Viewer

WorkStages_View

WorkStages_Edit_Others

Write access to the asset

Write rights to the metadata fields in "Metadata > Asset > Shared > Tasks" (usually granted via trusted)


PrintingAsset_Can_DownloadThe asset is "public" (no padlock)

Enable (single- and multi-) download of an asset's predefined qualities

Enable (single- and multi-) download of assets and metadata

Enable download of collections as zip

Asset_Can_Download

Can_Live_Export_Assets_And_Metadata


Enable sharing assets to/via collections (Create new, Add to existing)

The asset is "public" (no padlock)

Enable embed as a sharing option for videos

MediaPortal_Video_Embed

MediaPortal_Share

The "Embed player user" has read rights to the video assets

Choose available embed video sizes = must have content

Choose available embed video qualities = must have content

Embed player user = must have content (usually "Guest")

Should be added to a group with download qualities: "Guest", "Light Users", "Content Creators", "Administrators", or "Super Administrators"


Enable (single- and multi-) download of an asset's predefined qualities

Enable (single- and multi-) download of metadata

Enable download of collections as zip

Asset_Can_Download

Can_Live_Export_Metadata_Only


The asset is "public" (no padlock)

Add asset to own collectionMediaPortal_CollectionThe asset is "public" (no padlock)Enable ability to CRUD own collectionsMediaPortal_CollectionEnable ability to CRUD own collections + CRUD collections shared to oneself/OthersMediaPortal_CollectionGive new recipients of non-social collections (e.g. not Facebook collections) access to manipulate collections = trueEnable non-pre-existing users to read collections on an SSO siteMediaPortal_CollectionAllow shared collection users to bypass login required screen = true
Enable user to use AI Tagging + your site has external accessAi_Add

Write access to the asset (only images)

Enable AI tagging functionality for metadata field = Keywords(10192) (Keywords must be autotranslate = true)
If you want AI tagging but don't have external accessAi_Add

Write access to the asset (only images)

Enable AI tagging functionality for metadata field = Keywords(10192) (Keywords must be autotranslate = true)

Use local analysis for AI services = true

Enable CRUD of own saved searchesSaved_Searches_CRUDEnable crop/trim (share it via email)

Asset_Can_Crop

Enable crop/trim + Replace original asset with crop/trim + Restore to an older version of an asset

Asset_Can_Crop

Asset_Can_Replace

Write access to the asset

Write access to the Uploads folder OR the Content folder (The option to restore requires "write access" to the Uploads folder)

Enable crop/trim + Make new child asset with crop/trim

Asset_Can_Crop

Asset_Can_Revise

Write access to the asset

Write access to the Uploads folder OR the Content folder

Have filter open every time you access the MMAutomatically expand filter pane in asset list = trueMake all filters be expanded every time you access MM

Automatically expand filter pane in asset list = true

Automatically expand individual filters in asset list = true

Make asset ID shownShow asset ID in asset list = trueEnable password resetEnable the option to reset one's password = true

Enable self sign-up

where users can choose their own password

Enable self sign up = true

Template user for self sign up users = A user with all the rights, roles, and groups your users should have (User must be enabled)

Allow users to chose a password on signup = true

Auto-created user folder ID = the ID of the folder where you want your users to go.

Enable email verification for self-sign up (when self sign-up already is enabled)

where users can choose their own password

Enable self sign up = true

Template user for self sign up users = A user with all the rights, roles, and groups your users should have (User must be disabled)

Allow users to chose a password on signup = true

Verification when a user is created using self sign up = Email verification

Enable admin verification for self-sign up (when self sign-up already is enabled)

where users can choose their own password

Enable self sign up = true

Template user for self sign up users = A user with all the rights, roles, and groups your users should have (User must be disabled)

Allow users to chose a password on signup = true

Verification when a user is created using self sign up = Admin verification

Administrative verification email = the admin's email

Enable that refreshing MM will log one outEnable persistent login = falseEnable reading other peoples' comments and annotationsComment_ViewEnable commenting and annotating

Comment_View

Comment_CRUD

Enable commenting and annotating + tagging other users

Comment_View

Comment_CRUD

Member_Viewer

Access the task list

Business_Workflow_Instance_View

Edit workflows

Business_Workflow_CRUD

Business_Workflow_View

Request download of an asset's predefined formats.

Can single download approved assets.

Can single download if bypassed with a bit field.

Business_Workflow_Instance_Transition

Business_Workflow_Instance_View

Asset_Can_Download

Download approval must be set up

The asset is "public" (no padlock)

Request download of an asset's predefined formats.

Can single download approved assets.

Can single and multi download if bypassed with a bit field.

Business_Workflow_Instance_Transition

Business_Workflow_Instance_View

Asset_Can_Download

Can_Live_Export_Asset_Only

Download approval must be set up

The asset is "public" (no padlock)

Request a custom quality download

Business_Workflow_Instance_Transition

Business_Workflow_Instance_View

Asset_Can_Download_Custom_Quality

Download approval must be set up

The asset is "public" (no padlock)

Circumvent the download approval processDownload_Approval_Bypass

Download approval must be set up

Have enabled either standard or custom download

Approve or deny download requests

Business_Workflow_Instance_View

Business_Workflow_Instance_Transition

Download_Approval_Admin

You must be auto-assigned via the accompanying workflow as per the documentationEnable copyright notificationFollow the documentation: In short, you need to set it up via the config manager settings + metadata settingsCircumvent the copyright notificationCopyright_Notification_BypassHave copyright notifications enabledUpload both insecure and secure attachments on tasks

FileRepository_Upload

View own and others' insecure attachments on tasks

FileRepository_Read

View insecure and own secure attachments on tasks

FileRepository_Read

The upload constraint you upload with must have the "secret" bit set to true

View own and others' secure attachments on tasks + insecure attachments

FileRepository_Read

FileRepository_Read_Secret

Enable intro screenChoose intro screen mode: Splashscreen or Disclaimer
Info

The CCC requires all its users to have the "Asset_Can_Download" role + read access to assets.

...

Features in CCC

...

Administrator

Member_Viewer

...

Write access to "Upload" folder (Usually granted through the "Trusted" group)

Write access to the asset

...

Enable duplicate asset check = true

Should be added to a group with download qualities: "Guest", "Light Users", "Content Creators", "Administrators", or "Super Administrators"


Enable (single- and multi-) download of an asset's predefined qualities

Enable (single- and multi-) download of assets

Enable download of collections as zip

Asset_Can_Download

Can_Live_Export_Asset_Only


The asset is "public" (no padlock)

Should be added to a group with download qualities: "Guest", "Light Users", "Content Creators", "Administrators", or "Super Administrators"


Download custom qualities

Asset_Can_Download

Asset_Can_Download_Custom_Quality

The asset is "public" (no padlock)

Custom quality color spaces = must have content

Custom quality image types = must have content

Enable custom quality download = true

Enable sharing (URL, Social)MediaPortal_ShareThe asset is "public" (no padlock)
Enable sharing (Zip)

MediaPortal_Share

Can_Live_Export_Asset_Only

The asset is "public" (no padlock)
Enable embed as a sharing option for videos

MediaPortal_Video_Embed

MediaPortal_Share

The "Embed player user" has read rights to the video assets

Choose available embed video sizes = must have content

Choose available embed video qualities = must have content

Embed player user = must have content (usually "Guest")

Enable sharing assets to/via collections (Create new, Add to existing)

MediaPortal_Share

MediaPortal_Collection

The asset is "public" (no padlock)
Add asset to own collectionMediaPortal_CollectionThe asset is "public" (no padlock)
Enable ability to CRUD own collectionsMediaPortal_Collection

Enable ability to CRUD own collections + CRUD collections shared to oneself/OthersMediaPortal_Collection
Give new recipients of non-social collections (e.g. not Facebook collections) access to manipulate collections = true
Enable non-pre-existing users to read collections on an SSO siteMediaPortal_Collection
Allow shared collection users to bypass login required screen = true
Enable user to use AI Tagging + your site has external accessAi_Add

Write access to the asset (only images)

Enable AI tagging functionality for metadata field = Keywords(10192) (Keywords must be autotranslate = true)
If you want AI tagging but don't have external accessAi_Add

Write access to the asset (only images)

Enable AI tagging functionality for metadata field = Keywords(10192) (Keywords must be autotranslate = true)

Use local analysis for AI services = true

Enable CRUD of own saved searchesSaved_Searches_CRUD

Enable crop/trim (share it via email)

Asset_Can_Crop



Enable crop/trim + Replace original asset with crop/trim + Restore to an older version of an asset

Asset_Can_Crop

Asset_Can_Replace

Write access to the asset

Write access to the Uploads folder OR the Content folder (The option to restore requires "write access" to the Uploads folder)


Enable crop/trim + Make new child asset with crop/trim

Asset_Can_Crop

Asset_Can_Revise

Write access to the asset

Write access to the Uploads folder OR the Content folder


Have filter open every time you access the MM

Automatically expand filter pane in asset list = true
Make all filters be expanded every time you access MM

Automatically expand filter pane in asset list = true

Automatically expand individual filters in asset list = true

Make asset ID shown

Show asset ID in asset list = true
Enable password reset

Enable the option to reset one's password = true

Enable self sign-up

where users can choose their own password



Enable self sign up = true

Template user for self sign up users = A user with all the rights, roles, and groups your users should have (User must be enabled)

Allow users to chose a password on signup = true

Auto-created user folder ID = the ID of the folder where you want your users to go.

Enable email verification for self-sign up (when self sign-up already is enabled)

where users can choose their own password



Enable self sign up = true

Template user for self sign up users = A user with all the rights, roles, and groups your users should have (User must be disabled)

Allow users to chose a password on signup = true

Verification when a user is created using self sign up = Email verification

Enable admin verification for self-sign up (when self sign-up already is enabled)

where users can choose their own password



Enable self sign up = true

Template user for self sign up users = A user with all the rights, roles, and groups your users should have (User must be disabled)

Allow users to chose a password on signup = true

Verification when a user is created using self sign up = Admin verification

Administrative verification email = the admin's email

Enable that refreshing MM will log one out

Enable persistent login = false
Enable reading other peoples' comments and annotationsComment_View

Enable commenting and annotating

Comment_View

Comment_CRUD



Enable commenting and annotating + tagging other users

Comment_View

Comment_CRUD

Member_Viewer



Access the task list

Business_Workflow_Instance_View



Edit workflows

Business_Workflow_CRUD

Business_Workflow_View



Request download of an asset's predefined formats.

Can single download approved assets.

Can single download if bypassed with a bit field.

Business_Workflow_Instance_Transition

Business_Workflow_Instance_View

Asset_Can_Download

Download approval must be set up

The asset is "public" (no padlock)


Request download of an asset's predefined formats.

Can single download approved assets.

Can single and multi download if bypassed with a bit field.

Business_Workflow_Instance_Transition

Business_Workflow_Instance_View

Asset_Can_Download

Can_Live_Export_Asset_Only

Download approval must be set up

The asset is "public" (no padlock)


Request a custom quality download

Business_Workflow_Instance_Transition

Business_Workflow_Instance_View

Asset_Can_Download_Custom_Quality

Download approval must be set up

The asset is "public" (no padlock)


Circumvent the download approval processDownload_Approval_Bypass

Download approval must be set up

Have enabled either standard or custom download


Approve or deny download requests

Business_Workflow_Instance_View

Business_Workflow_Instance_Transition

Download_Approval_Admin

You must be auto-assigned via the accompanying workflow as per the documentation
Enable copyright notification
Follow the documentation: In short, you need to set it up via the config manager settings + metadata settings



Circumvent the copyright notificationCopyright_Notification_BypassHave copyright notifications enabled
Upload both insecure and secure attachments on tasks

FileRepository_Upload



View own and others' insecure attachments on tasks

FileRepository_Read



View insecure and own secure attachments on tasks

FileRepository_Read

The upload constraint you upload with must have the "secret" bit set to true


View own and others' secure attachments on tasks + insecure attachments

FileRepository_Read

FileRepository_Read_Secret



Enable intro screen

Choose intro screen mode: Splashscreen or Disclaimer


Info

The CCC requires all its users to have the "Asset_Can_Download" role + read access to assets.